Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
'Experimental mitigations' in a custom kernel could make life harder for hackers. . Google says it uses Linux in "almost everything" from Chromebooks to the cloud. Now it is increasing its rewards for security researchers who can spot flaws in the open-source operating system. Since 2020, Google has run an open-source Kubernetes-based Capture-the-Flag (CTF) project called kCTF which allows researchers to connect to its Google Kubernetes Engine (GKE) instances, and try to hack them to capture a flag. Every 'flag' caught so far has been a container breakout through a Linux kernel vulnerability. . Microsoft, heavily invested in cloud computing, increases incentives for developers uncovering software vulnerabilities, fortifying system defenses.. Linux Kernel Flaws, Google Security, Open Source Research, Kubernetes Capture-the-Flag. . LinuxSecurity.com Team
Linux is everywhere and it needs extra protection, according to Google. "We are constantly investing in the security of the Linux Kernel because much of the internet, and Google – from the devices in our pockets, to the services running on Kubernetes in the cloud – depend on the security of it," said Eduardo Vela from the Google Bug Hunters Team . . Google has kicked off a special three-month bug bounty targeting flaws in the Linux kernel with triple the rewards for security researchers. The new bounty, announced this week , looks to harden the Linux kernel in specific edge cases. It's offering up to $31,337 ( Leet ) to security researchers who can exploit privilege escalation in Google's lab environment with a patched vulnerability; and $50,337 for anyone who can finds a previously undisclosed or zero-day flaw, or for discovering a new exploit technique. . Google has introduced a quarterly bug bounty program targeting vulnerabilities within the Linux kernel, significantly enhancing incentives for security researchers.. Linux Kernel Security, Bug Bounty Program, Security Research, Exploit Techniques. . Brittany Day
Researchers have three months to find problems in the software for net-connected devices like baby monitors and refrigerators. . Microsoft wants Azure Sphere to be a really secure foundation for internet of things devices like webcams and garage doors, so it's offering researchers up to $100,000 to find a way to break into the technology. Azure Sphere combines an approved processor with Microsoft's own customized version of Linux called Sphere OS and a security service to detect problems and issue updates. . Microsoft has introduced a substantial $100K initiative to attract bug hunters, enhancing Azure Sphere's security for smart home tech, showcasing its commitment to safeguarding IoT devices.. Azure Sphere Security,Bug Bounty Program,IoT Device Protection. . LinuxSecurity.com Team
Microsoft is offering hackers up to $100,000 if they can break the security of the company’s custom Linux OS. The software giant built a compact and custom version of Linux last year for its Azure Sphere OS, which is designed to run on specialized chips for its Internet of Things (IoT) platform. The OS is purpose-built for this platform, ensuring basic services and apps run isolated in a sandbox for security purposes. . Microsoft now wants hackers to test the security of the Azure Sphere OS, paying up to $100,000 if the Pluton security subsystem or Secure World sandbox is breached. The bug bounty program is part of a three-month research challenge that runs from June 1st until August 31st. “We will award up to $100,000 bounty for specific scenarios in the Azure Sphere Security Research Challenge during the program period,” explains Sylvie Liu, a security program manager at Microsoft’s Security Response Center. . Google is providing $150,000 for evaluating the security of its Android platform, showcasing a significant initiative in enhancing cybersecurity.. Azure Sphere OS, Microsoft Security, bug bounty program, IoT security. . LinuxSecurity.com Team
Want to help lock down Kubernetes and make some money while you're at it? The Cloud Native Computing Foundation has a new bug bounty program for you. . Kubernetes , the container orchestration program, has become hotter than hot. Everyone -- and I mean everyone -- is adopting it . But with quarterly major updates and everyone rushing to deploy it, security is a real worry. Thus, the Kubernetes Product Security Committee, funded by the Cloud Native Computing Foundation (CNCF) is launching a new bug bounty program to reward Kubernetes security bug hunters. The bug bounty program has been in a private beta release for several months now. Almost two years since the initial proposal, the program is now ready for all security researchers. The link for this article located at ZDNet is no longer available. . Participate in the exciting Kubernetes security initiative to enhance digital safety and receive incentives for your findings.. Kubernetes Bug Bounty, Container Security, Cloud Native Computing. . LinuxSecurity.com Team
Following an attack that breached one of its servers, NordVPN is taking several steps in an effort to show customers that it can still provide secure access to the internet. Learn more: . NordVPN is taking steps to ensure customers that it can stay true to its promise of providing "secure and private access to the internet" after admitting that an attacker breached one of its servers. To start with, its in-house team of penetration testers will now be working with cybersecurity firm VerSprite to conduct comprehensive penetration testing, intrusion handling and source code analysis. The firm will also help NordVPN form an independent cybersecurity advisory committee as part of their long-term partnership. In an effort to find vulnerabilities before a bad actor does again, it's also launching a bug bounty program over the next few weeks. NordVPN also promises to undergo a complete a full-scale third-party independent security audit covering its hardware, software, backend architecture, backend source code and internal procedures in 2020. The link for this article located at Engadget is no longer available. . Following a server compromise, NordVPN is bolstering its security protocols by implementing comprehensive audits and introducing a bug bounty initiative.. NordVPN, Security Audit, Threat Management, Bug Bounty, Cybersecurity Enhancement. . LinuxSecurity.com Team
In this article, Threatpost catches up with David Baker, the chief security officer at Bugcrowd, about the future of bug bounty programs. While bug-bounty programs may seem like a cure-all solution for companies looking discover vulnerabilities in their systems more efficiently, the fact remains that a program could overwhelm a firm’s internal security team and cause other major headaches if implemented the wrong way. . “You have to realize that the crowd is going to find a lot more vulnerabilities than your typical in-house pen-test team. So oftentimes, there’s this engineering push back, like hold on, we don’t have our internal processes set up,” David Baker, chief security officer at Bugcrowd told Threatpost. Threatpost caught up with Baker to discuss the right — and wrong — approaches for implementing a bounty program that can boost companies’ security effectively with minimal operational disruption. The link for this article located at Threatpost is no longer available. . Exploring strategies for successful bug bounty programs reveals the importance of clarity, communication, and community engagement in enhancing security and processes. Bug Bounty Programs, Security Approaches, Vulnerability Management, Crowdsourced Testing, Operational Efficiency. . LinuxSecurity.com Team
Dropbox has uncovered 264 vulnerabilities, paying out US$319,300 in bounties, after a one-day bug hunt in Singapore that brought together hackers from 10 nations around the world. Hosted by bug bounty platform HackerOne, the live event saw 45 of its members from countries such as Japan, India, Australia, Hong Kong, and Sweden, and some as young as 19, galvanise in the city-state in an attempt to infiltrate Dropbox's targeted systems. . The cloud storage vendor days earlier had revealed parts of its "attack" scope, so HackerOne members already had identified and submitted dozens of potential bugs before the live event. According to a company spokesperson, the focus this time was on Dropbox and its recent acquisition of digital workflow platform, HelloSign. The link for this article located at ZDNet is no longer available. . Dropbox's bug hunt uncovered 264 vulnerabilities, rewarding hackers with $319,300 for their findings in Singapore.. dropbox, uncovered, vulnerabilities, paying, us$319, bounties, one-day. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.