Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 3 articles for you...
83

Malicious Attacks Increased Data Breaches To 24% In 2009 Affected Firms

Data breaches at U.S. companies attributed to malicious attacks and botnets doubled from 2008 to 2009 and cost substantially more than breaches caused by human negligence or system glitches, according to a new Ponemon survey to be released on Monday.. The incidence of malicious attacks rose from 12 percent in 2008 to 24 percent last year, according to the 2009 Annual Study: U.S. Cost of a Data Breach survey conducted by the Ponemon Institute and sponsored by PGP Corp. The cost per compromised record involving a criminal act averaged $215, about 40 percent higher than breaches from negligence and 30 percent higher than those from glitches, the survey found. For the first time, companies reported in the survey that data-stealing malware caused their breaches. The average organizational cost of a data breach increased nearly 2 percent to $6.75 million in 2009, while the average cost per compromised record per breach rose only $2 to $204. The most expensive breach in the survey was nearly $31 million and the least expensive was $750,000. Meanwhile, 42 percent of all cases reported in the survey involved mistakes made at third parties, such as outsourcers, and 36 percent of the cases involved lost or stolen laptops or other mobile devices. For the study, 45 U.S. companies from 15 different industries were surveyed. The figures include business costs including expenditures for detection, notification, and response, as well as the economic impact of lost or diminished customer trust and confidence as measured by customer turnover rates. The link for this article located at CNET is no longer available. . Cybersecurity incidents surged dramatically between 2010 and 2011, highlighting an escalating danger to businesses along with increased expenses stemming from security violations.. Data Breach Costs, Malicious Attacks Increase, Ponemon Study, Botnets Impact, Security Compromise. . LinuxSecurity.com Team

Calendar%202 Jan 25, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
79

Overview Of Project Quant: Enhancing Patch Management Efficiency

Securosis, Microsoft team up to solicit input for building a metrics model that measures efficiency and costs of security patching. Security consulting firm Securosis is spearheading a new effort to create metrics to quantify the cost and efficiency of an organization's security patching process. . Rich Mogull, founder of Securosis, says to date there's no real way to accurately measure the cost and productivity of an organization's security patch management process. "Those fully quantified [IT] risk models don't apply and the numbers aren't accurate," he says. "It's also bothered me to see those uber-metrics approaches that get an overview of everything in the security program. So why not start with one thing we can accurately measure and use it as a core for building security metrics?" Securosis, with the financial backing of Microsoft for the initial phase of the project, will gather input in an open submission process for the so-called Project Quant metrics model. Version 1 is planned for release by the end of June. The link at DarkReading is no longer available. . Uncover an innovative project aimed at evaluating expense and effectiveness in security update handling through a collaboration between Securosis and Microsoft.. Patch Management, Security Metrics, Cost Efficiency, Securosis Initiative. . LinuxSecurity.com Team

Calendar%202 Apr 23, 2009 User Avatar LinuxSecurity.com Team Security Projects
82

IRS Financial Losses: Missing Automated Fraud Detection Costs Taxpayers

The lack of an automated refund fraud detection system that would have allowed the U.S. Internal Revenue System to screen 2006 tax returns could cost the agency between $200 million and $300 million, the IRS told the U.S. Senate Finance Committee last week. . The link for this article located at ComputerWorld is no longer available. . The IRS faces weak fraud detection, harming finances and increasing taxpayer losses while eroding trust. Urgent action is needed to enhance security measures. Fraud Detection System, IRS Financial Loss, Tax Return Screening. . Brittany Day

Calendar%202 Jul 18, 2006 User Avatar Brittany Day Government
67

Comparative Analysis of Data Protection Costs and Breach Recovery

Protecting customer records is a magnitude less expensive than paying for cleanup after a data breach or massive records loss, a research company said Tuesday. Gartner analyst Avivah Litan said in a research note that data protection is cheaper than a data breach. She recently testified on identity theft at a Senate hearing held after the Department of Veterans Affairs lost 26.5 million vet identities. . "A company with at least 10,000 accounts to protect can spend, in the first year, as little as $US6 per customer account for just data encryption, or as much as $US16 per customer account for data encryption, host-based intrusion prevention, and strong security audits combined," Litan said in an accompanying statement. The link for this article located at ITNews.com is no longer available. . 'A company with at least 10,000 accounts to protect can spend, in the first year, as little as $US6 . protecting, customer, records, magnitude, expensive, paying, cleanup, breac. . LinuxSecurity.com Team

Calendar%202 Jun 07, 2006 User Avatar LinuxSecurity.com Team Cryptography
74

Evaluating Skype for Business: Risks and Security Concerns

Although cost savings and improved communications are luring enterprises to Skype, the popular voice over IP service may violate security policies, industry experts have warned. Burton Group recommended enterprises assess the risks vs. rewards of Skype as the simplest solution for evaluating its use. . In the analyst firm's report entitled "Debunking the Hype About Skype," senior Burton Group analyst Irwin Lazar pointed out that enterprise use of Skype is growing. Those contacted by the analyst cited significant reduction in long distance and mobile phone costs due to extremely low global long-distance rates, as well as Skype's ability to deliver unified communications service for both internal and external use as primary business drivers to investigate Skype. The link for this article located at SCMagazine is no longer available. . Businesses seek out Zoom for cost-effectiveness, although specialists caution about possible cybersecurity vulnerabilities.. Skype VoIP Security, Enterprise Communication Risk, IT Security Assessment. . Brittany Day

Calendar%202 Mar 16, 2006 User Avatar Brittany Day Network Security
77

Understanding Patch Management Costs And IT Resource Challenges

Security and vulnerability patching has become one of the top concerns for IT managers, but has also left many IT teams fighting a losing battle as the job of patching competes with day-to-day system maintenance and security tasks. . The patching issue became a more prominent problem for businesses worldwide in 2003 when the Slammer worm was unleashed on the Internet. In the first minute after it started spreading, Slammer doubled the number of web servers it infected every eight seconds. Within 10 minutes, 90% of all vulnerable machines had been infected – leaving businesses with a £500m bill to fix the havoc Slammer created. Yet the patch to fix the vulnerability that Slammer exploited had been available for six months. If the majority of those infected had patched their systems, Slammer would have been a minor blip. So why aren’t businesses catching on to patching? The bottom line is that many IT teams simply do not have the resources or time. Just researching the 4,000+ vulnerabilities published by security monitoring body CERT in the last year would demand hundreds of man-hours. And although an IT staff may be online regularly to see what patches are released, they cannot be 100 percent sure that all systems are properly patched. Then there’s the cost issue. Recent research from analysts at The Yankee Group found that it can cost as much as $1 million to manually deploy a single patch in a 1,000-node network environment. The costs include the manual labour involved in fixing problems and system downtime while patches are being applied. The link for this article located at Security Park is no longer available. . Updating software consistently poses significant challenges for IT departments; financial constraints and limited manpower obstruct prompt remediation of at-risk platforms.. Patch Management,Vulnerability Updates,Resource Allocation. . LinuxSecurity.com Team

Calendar%202 Apr 20, 2005 User Avatar LinuxSecurity.com Team Server Security
78

Linux Versus Windows: A Comprehensive Cost and Security Comparison 2023

Which operating system, Linux or Windows, is cheaper, more secure, and lower risk? Countless hours have been spent debating the question, and last week, Microsoft CEO Steve Ballmer sparked the argument again. In a letter E-mailed to customers, Ballmer contended that a growing body of data proves that Windows beats its open-source competitor on all three fronts. . . .. Which operating system, Linux or Windows, is cheaper, more secure, and lower risk? Countless hours have been spent debating the question, and last week, Microsoft CEO Steve Ballmer sparked the argument again. In a letter E-mailed to customers, Ballmer contended that a growing body of data proves that Windows beats its open-source competitor on all three fronts. "It's pretty clear that the facts show that Windows provides a lower total cost of ownership than Linux, the number of security vulnerabilities is lower on Windows, and Windows' responsiveness on security is better than Linux," Ballmer wrote. "And Microsoft provides uncapped IP [intellectual-property] indem- nification of their products, while no such comprehensive offering is available for Linux or open source." (For more on Microsoft's intellectual-property and indemnification strategy, see story, Microsoft Deepens Indemnity) Ballmer also touted Windows' strengths as a platform for companies migrating enterprise-resource-planning applications from Unix systems, and he highlighted a handful of companies, Equifax Inc. among them, that have opted for Windows over Linux. The position paper comes with Windows Server 2003 sales continuing to rise at a healthy rate but with Linux growing even faster. Ballmer would like to change some minds. The link for this article located at informationweek.com is no longer available. . Which operating system, Linux or Windows, is cheaper, more secure, and lower risk? Countless hours h. which, operating, system, linux, windows, cheaper, secure, lower, countless, hours. . LinuxSecurity.com Team

Calendar%202 Nov 04, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
74

Identifying Barriers to Effective Defense-in-Depth for Enterprises

Why haven't enterprises already done defense-in-depth? We found six barriers to pushing firewall technology to the port level. Cost. The cost of adding firewall "brains" to the inside of the network is substantial, especially compared to the continued cost reduction of . . . . Why haven't enterprises already done defense-in-depth? We found six barriers to pushing firewall technology to the port level. Cost. The cost of adding firewall "brains" to the inside of the network is substantial, especially compared to the continued cost reduction of standard networking switches and routers. Performance. Firewalls have proven themselves on Internet-speed links, but most enterprises have significantly higher flow rates within the network than towards the Internet. Common tasks such as file sharing and backups would bring a firewall designed for Internet speeds to its knees on a 100 Mbps Ethernet link. . Organizations face hurdles in deploying defense-in-depth and firewalls, including a lack of skilled personnel, integration issues, budget constraints, and evolving threats. Firewall Technology, Network Security, Defense-in-Depth, Performance Barriers, Cost Management. . Anthony Pell

Calendar%202 Jun 13, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200