Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
GitHub has announced that their Advisory Database for security data is now open to contributions from experts. The full contents of the Advisory Database have already been published to encourage collaboration. . GitHub senior product manager Kate Catlin explained that the company has teams of security researchers that review all changes and help keep security advisories up to date. But with the amount of new vulnerabilities and different attack vectors emerging each day, the company believes members of its community may be able to share additional insights and intelligence on CVEs. . Explore the innovations brought by GitHub's new Advisory Database, designed to enhance cybersecurity understanding and promote collaboration between developers and security professionals. GitHub Advisory Database, Collaboration Insights, Security Contributions. . LinuxSecurity.com Team
Arbor Networks' Sam Curry talks about disclosure, bounty programs, and vulnerability marketing with CSO, in the first of a series of topical discussions with industry leaders and experts.. Hacked Opinions is an ongoing series of Q&As with industry leaders and experts on a number of topics that impact the security community. The first set of discussions focus on disclosure and how pending regulation could impact it. In addition, we asked about marketed vulnerabilities such as Heartbleed and bounty programs, do they make sense? The link for this article located at CSO Online is no longer available. . Hacked Opinions is an ongoing series of Q&As with industry leaders and experts on a number of topics. arbor, networks', curry, talks, about, disclosure, bounty, programs, vulnerability, marketing. . LinuxSecurity.com Team
The National Security Agency. A slide deck from a presentation by a member of OTP. Comprehensive overview of NSA's virtual private network tactics illustrated via an informative slide deck.. VPN Strategies, National Security Agency, Network Protection, Cybersecurity Techniques. . Dave Wreski
Kaspersky Academy continues its new project . The next interlocutor is Enrique Pel The link for this article located at Kaspersky is no longer available. . The next interlocutor is Enrique PelThe link for this article located at Kaspersky is no longer avai. kaspersky, academy, continues, project, interlocutor, enrique, pelthe. . Alex
Open source software can be one answer to combating the global surveillance of innocent citizens, said security expert Mikko Hypponen in his keynote last week at LinuxCon and CloudOpen Europe in Edinburgh.. Advances in computing and the rise of global networks have made the storage and transmission of data cheap and easy. This has created unparalleled connectivity, progress and innovation, Hypponen said. But it The link for this article located at Linux.com is no longer available. . Open source software can enhance global security by addressing surveillance risks through transparency, community audits, and custom privacy features for users. Open Source Software,Cybersecurity Insights,Mikko Hypponen,Global Security,Privacy Technology. . LinuxSecurity.com Team
The 4th annual Hacker Halted USA information security conference, which runs from October 29-31 in Miami, will showcase 50 of the world. advanced infosec training classes from Hacker Halted Academy The link for this article located at SF Gate is no longer available. . Attend the 5th Annual Cybersecurity Unlocked event in San Francisco to gain expert knowledge and participate in high-level security workshops from November 15-17.. Hacker Halted, Miami Conference, Infosec Training. . Anthony Pell
This is the third in a series of interviews with C-level executives responsible for cyber security and privacy in business and government, who also happen to be thought leaders. (Remember, as I mentioned previously, "C-level executive" and "thought leader" are not synonyms.). In this issue, I discuss a range of issues related to the hard work of web security with Jeremiah Grossman, founder and Chief Technology Officer of WhiteHat Security. He is responsible for web application research and development, and is a high-profile industry evangelist, taking his message far and wide from the familiar haunts of BlackHat Briefings and other cyber security venues even unto the rarified air of TEDxMaui. A founding member of the Web Application Security Consortium (WASC), Grossman is a leading voice in web application security. Before launching WhiteHat, Grossman worked as an information security officer at Yahoo! The link for this article located at CSO Online is no longer available. . Delve into essential perspectives on web security as articulated by Jeremiah Grossman, a prominent figure in the realms of application security and cybersecurity promotion.. Web Security, Application Security Insights, Cyber Threat Mitigation. . Dave Wreski
IT security experts have long loved to troll through hacker forums to gather intelligence on emerging threats and even (as in the ill-fated case of HBGary Federal CEO Aaron Barr) try to profile the hackers themselves. But as a report from IT security firm Imperva shows, many of the so-called hacker portals out there are more hangouts for newbie hackers (and possibly a few budding FBI informants) looking at how to get started in the game. . The article located at arsTechnica is no longer available. . Hacker forums serve as complex networks for novice hackers and seasoned professionals, fostering learning and gathering insight into emerging threats and techniques.. Hacker Training, Cybersecurity Intelligence, Threat Analysis. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.