Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 7 articles for you...
82

APT36 Threatens Indian Government Agencies with Custom Malware

APT36 is a highly sophisticated APT (Advanced Persistent Threat) group known for conducting targeted espionage in South Asia and is strongly linked to Pakistan. . While this APT group is known for targeting the following Indian sectors: Government Defense Education Since 2013, this APT group has been active, and to conduct cyber espionage, it uses the following methods:- Credential harvesting Malware distribution Here below, we have mentioned the resources used by APT36:- Custom-built remote administration tools targeting Windows Lightweight Python-compiled cyber espionage tools serving specific purposes targeting Windows and Linux Weaponized open-source C2 frameworks like Mythic Trojanized installers of Indian government applications like KAVACH multi-factor authentication Trojanized Android apps Credential phishing sites targeting Indian government officials Zscaler analysts dubbed the Windows backdoor used by APT36 ‘ElizaRAT,’ because of unique strings in observed C2 commands. The link for this article located at CyberSecurity News is no longer available. . APT36 utilizes tailored malicious software targeting Indian governmental divisions such as education and defense, representing significant risks.. APT36,CyberEspionage,GovernmentMalware,EducationSecurity,DefenseAttacks. . Brittany Day

Calendar%202 Sep 16, 2023 User Avatar Brittany Day Government
209

Importance of Teaching Secure Software Development Practices

Addressing a decades-old deficiency in coding curriculums could have a profound effect on the security of the software supply chain, a leading expert on the subject tells The Daily Swig . . In particular, David A Wheeler, director of open source supply chain security at the Linux Foundation, draws a link between a failure to incorporate security into entry-level developer courses and the vast majority of vulnerabilities belonging to a small number of common bug classes. The IT PhD and Certified Information Systems Security Professional (CISSP) also moonlights as adjunct professor of computer science at Virginia’s George Mason University, and in 2020 concluded a 33-year spell at the US Institute for Defense Analyses. . Focusing on cybersecurity within programming education may strengthen the integrity of software supply chains, asserts David A. Wheeler.. Secure Coding Practices, Software Supply Chain, Developer Education, Open Source Security. . Brittany Day

Calendar%202 Dec 14, 2022 User Avatar Brittany Day Security Trends
83

San Diego Unified School District Data Breach Exposes 500,000 Records

A hacker has stolen the personal details of over 500,000 San Diego Unified School District staff and students; the district revealed in a breach notice posted on its website on Friday, before the Christmas holiday.. The breach occurred because the attacker gained access to staff credentials via a tactic known as phishing -- sending authentic-looking emails that redirect users to fake login pages were attackers collect login credentials. The link for this article located at ZDNet is no longer available. . The breach occurred because the attacker gained access to staff credentials via a tactic known as ph. hacker, stolen, personal, details, diego, unified, school, district, staff. . LinuxSecurity.com Team

Calendar%202 Dec 25, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Melbourne High School Incident Reports Appalling Healthcare Data Leak

A data breach has taken place at a Melbourne high school which resulted in the confidential healthcare records of students being published online.. The security incident, which took place at Strathmore secondary college in Melbourne, was deemed "nothing short of appalling" by Victoria education minister, James Merlino, as reported by The Guardian. The link for this article located at ZDNet is no longer available. . The security incident, which took place at Strathmore secondary college in Melbourne, was deemed 'no. breach, taken, place, melbourne, school, which, resulted, confidential, healthca. . LinuxSecurity.com Team

Calendar%202 Aug 23, 2018 User Avatar LinuxSecurity.com Team Privacy
78

Chrome OS Terminal App Enables Upcoming Linux Program Support

Soon, Chromebooks might be able to run Linux programs. That possibility already was hinted at last February but might be coming really soon with the appearance of the Terminal app in Chrome OS’ dev channel.. It almost feels ironic that Linux support is still coming to the Linux-based Chrome OS. But like with Android, which also uses the Linux kernel, Google has modified it so much that there is very little semblance to Linux. Coming full circle, Chrome OS could soon run Linux software somewhat directly, opening the OS and Chromebooks to use cases beyond education or enterprise. The link for this article located at SlashGear is no longer available. . Linux support is rolling out for Chrome OS, enabling Chromebooks to run Linux programs, which enhances their versatility.. Linux support, Chromebook, Terminal app, software compatibility, application development. . LinuxSecurity.com Team

Calendar%202 Apr 23, 2018 User Avatar LinuxSecurity.com Team Vendors/Products
77

Exploring Secure Coding Education Challenges in Programming

We've been trying to educate programmers about writing secure code for at least a decade and it flat-out hasn't worked. While I'm the first to agree that beating one's head against the wall shows dedication, I am starting to wonder if we've chosen the wrong wall. What's Plan B? . . .. It doesn't seem that a day goes by without someone announcing a critical flaw in some crucial piece of software or other. Is software that bad? Are programmers so inept? What the heck is going on, and why is the problem getting worse instead of better? One distressing aspect of software security is that we fundamentally don't seem to "get it." In the 15 years I've been working the security beat, I have lost track of the number of times I've seen (and taught) tutorials on "how to write secure code" or read books on that topic. It's clear to me that we're: * Trying to teach programmers how to write more secure code * Failing miserably at the task We're stuck in an endless loop on the education concept. We've been trying to educate programmers about writing secure code for at least a decade and it flat-out hasn't worked. While I'm the first to agree that beating one's head against the wall shows dedication, I am starting to wonder if we've chosen the wrong wall. What's Plan B? The link for this article located at acmqueue.com is no longer available. . Ongoing awareness is essential since programming vulnerabilities endure, prompting inquiries into the adequacy of cybersecurity training.. Secure Coding, Education Challenges, Software Protection. . LinuxSecurity.com Team

Calendar%202 Jun 29, 2004 User Avatar LinuxSecurity.com Team Server Security
74

K-12 Network Security Concerns: Privacy and Integrity Challenges

In many ways, a K-12 public education data network will be designed and constructed in the same manner as any other business data network. While all business networks will have some degree of security built into them, a K-12 school environment presents special needs and requirements. It goes beyond the obvious items such as physical security, routers, sub-netting, firewalls, and anti-virus. These will be addressed as well, but we will be looking at several other very important issues, which include privacy (confidentiality), data integrity, and content filtering.. . .. In many ways, a K-12 public education data network will be designed and constructed in the same manner as any other business data network. While all business networks will have some degree of security built into them, a K-12 school environment presents special needs and requirements. It goes beyond the obvious items such as physical security, routers, sub-netting, firewalls, and anti-virus. These will be addressed as well, but we will be looking at several other very important issues, which include privacy (confidentiality), data integrity, and content filtering. There are laws in place regarding privacy and the confidentiality of student information. There are repeated concerns with students hacking into school data systems and modifying files. It is also a hot topic regarding having Internet content filtering within schools. We will be doing some comparisons between the United States and Canada in regards to these items. As well, funding always comes up in any conversation pertaining to the public school system, so this will be looked at too. Many decisions that are made are done within the confines of the available funding structure. Enterprise network hardware SANS We are all used to seeing large data centres located behind locked doors, maybe even several doors, with alarms; possibly even with a security guard out front. Some of you may have even encountered this setting before starting to actually work in the IT world. What thesepeople were subscribing to even then, was Law #3 of the Ten Immutable Laws of Security. It states "If a bad guy has unrestricted physical access to your computer, it's not your computer anymore" (Microsoft). However, much more than just the computer room portion of the data network needs to be secured. It extends to the other physical devices as well, such as the routers, hopefully located within a locked wiring closet, and with access for only a limited number of personnel. The link for this article located at Sans Institute is no longer available. . K-12 public schools face significant hurdles in ensuring security, focusing on student privacy, data integrity, and effective content filtering for a safer learning space. K12 Network Security, Education Data Privacy, Network Integrity, Content Filtering Solutions. . Anthony Pell

Calendar%202 Dec 22, 2003 User Avatar Anthony Pell Network Security
74

Gunderson High School Network Security Assurance For Parents

When Gunderson High School launched its wireless network this fall, some parents were alarmed. Would a hacker be able to break into student laptops? View sensitive information stored on district servers? Tamper with grades? Cliff Herlth, the tech resource teacher, assured . . . . When Gunderson High School launched its wireless network this fall, some parents were alarmed. Would a hacker be able to break into student laptops? View sensitive information stored on district servers? Tamper with grades? Cliff Herlth, the tech resource teacher, assured them the network was secure. Only certain computers with registered wireless cards could connect to it. To anyone who lacked the proper technical IDs, the school network was virtually invisible. ``The only way you could get on our network at all if you are not on the list is by plugging in,' Herlth said. In other words, an electronic intruder would have to physically enter the school and connect to an ethernet cable. The link for this article located at Mercury News is no longer available. . When Gunderson High School launched its wireless network this fall, some parents were alarmed. Would. gunderson, school, launched, wireless, network, parents, alarmed, would. . Anthony Pell

Calendar%202 Nov 13, 2003 User Avatar Anthony Pell Network Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200