Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The US government’s cybersecurity agency CISA is giving federal agencies an early February deadline to patch a critical -- and already exploited -- security vulnerability in the widely used CentOS Control Web Panel utility. . The agency added the CVE-2022-44877 flaw to its KEV (Known Exploited Vulnerabilities) catalog and set a February 7th deadline for federal agencies to test and deploy an available fix. Security researchers warned earlier this month that the publication of proof-of-concept code and a YouTube video demonstration would lead to live attacks. Soon after, threat-hunting outfits GreyNoise and Shadowserver spotted signs of exploitation in the wild. . CISA includes a critical vulnerability in CentOS Control Web Panel on its urgent patch list, requiring federal entities to rectify exploitation risks by February 7.. CentOS Patch, Control Web Panel Flaw, Cybersecurity Updates. . Brittany Day
Tech giants and federal agencies meet at the White House to discuss open-source software security, a response to the widespread Log4j vulnerability that’s worrying industry and cyber leaders. . Among the attendees are companies like Apple, Facebook and Google, as well as the Apache Software Foundation, which builds Log4j , a ubiquitous open-source logging framework for websites. “Building on the Log4j incident, the objective of this meeting is to facilitate an important discussion to improve the security of open source software — and to brainstorm how new collaboration could rapidly drive improvements,” a senior administration official said in advance of the meeting. . Top executives convene at the Pentagon to tackle the urgent privacy risks triggered by the new software vulnerabilities.. Open Source Security, Log4j Vulnerability, Tech Summit, Software Collaboration, Cybersecurity Initiatives. . Brittany Day
Amid a report today that the Trump White House plans to cut the administration's cybersecurity coordinator position altogether, new data shows how US federal government agencies continue to struggle to close security holes in their software.. Politico reported that the administration has eliminated the White House cybersecurity position, which was recently vacated by former head Rob Joyce, who has returned to the National Security Agency. Politico said it had obtained an email to the White House National Security Council staff from John Bolton aide Christine Samuelian: "The role of cyber coordinator will end," in an effort to "streamline authority" in the NSC, which includes two senior cybersecurity directors, she said in the email, according to Politico. The link for this article located at DarkReading is no longer available. . Politico reported that the administration has eliminated the White House cybersecurity position, whi. report, today, trump, white, house, plans, administration's, cybersecurity, coord. . Brittany Day
A controversial draft law, which one senator called a "surveillance bill by another name," has passed the Senate. CISA, the Cybersecurity Information Sharing Act (S. 754), will allow private companies to share cyber-threat data with the federal government, including personal user data, in an effort to prevent cyberattacks, such as those on the scale of Target, Home Depot, and Sony. . Companies that share data with federal agencies, including the National Security Agency (NSA), will be given legal and liability protections from lawsuits relating to data sharing. . Companies that share data with federal agencies, including the National Security Agency (NSA), will . controversial, draft, which, senator, called, 'surveillance, another, passe. . Alex
Since its founding in 1992, Defcon has been a venue where anarchists, geeks, and employees of three-letter federal agencies became unlikely comrades under a live-and-let-live credo that placed the love of computer tinkering above almost everything else. . No more. As tensions mount over the broad and indiscriminate spying of Americans and foreigners by the National Security Agency, Defcon organizers are asking feds to sit out this year's hacker conference. "For over two decades DEF CON has been an open nexus of hacker culture, a place where seasoned pros, hackers, academics, and feds can meet, share ideas and party on neutral territory," Jeff Moss, aka The Dark Tangent, wrote in a blog post published Wednesday night. "Our community operates in the spirit of openness, verified trust, and mutual respect.". In light of increasing concerns regarding civil liberties and monitoring, Defcon's planning committee urges federal law enforcement to refrain from attending this year's convention.. Defcon Conference, Hacker Culture, Federal Agencies. . Dave Wreski
Half of U.S. government Web sites are vulnerable to commonplace DNS attacks because they haven't deployed a new authentication mechanism that was mandated in 2008, a new study shows.. The Office of Management and Budget (OMB) issued a mandate requiring federal agencies to deploy an extra layer of security The link for this article located at Network World is no longer available. . National bodies struggle with DNS protection as legacy verification techniques prevail, heightening vulnerability to cyber threats.. DNS Security, Federal Agencies, Cyber Attacks, Outdated Security, Website Security. . LinuxSecurity.com Team
In 2008, the Office of Management and Budget directed federal agencies to improve their domain name server (DNS) security by implementing DNS security extensions (DNSSEC), but 15 months later, many are still struggling to get there. The good news is that since OMB's December 2009 deadline passed, agencies are starting to catch up, taking advantage of both products and services coming on the market to make it easier to apply DNSSEC.. Agencies were "caught with their guard down because they were unprepared to deal with it," said Branko Miskov, director of product management at DNS appliance maker BlueCat Networks, which is working with several agencies on DNSSEC deployments. "We've made pretty good progress, especially from December until now," said Derek McUmber, chief executive officer of Data Mountain Solutions Inc., a subcontractor to the General Services Administration, which supports agencies in implementing DNSSEC. About a third of federal agencies now have digitally signed their dot.gov sub-domains, he said, up from only 20% six months ago. The link for this article located at Search Security is no longer available. . Government bodies are enhancing internet safety through DNSSEC deployment following early challenges resulting from insufficient readiness.. DNS Security,DNS Implementation,Federal Agencies,Network Protection. . Anthony Pell
Linux kernel maintainer Linus Torvalds has charged that Itanium designers "threw out all the good parts of the x86." One emerging niche for Itanium, though, seems to be high-speed encryption and decryption. For instance, encryption and key management provider Eruces Inc. of Lenexa, Kan., is bullish on Itanium. Eruces devotes a large chunk of its business to federal intelligence agencies. The company's symmetric key management system encrypts documents, programs and databases, using a centralized KeyServer to generate and manage keys. . The link for this article located at GCN is no longer available. . The link for this article located at GCN is no longer available.. linux, kernel, maintainer, linus, torvalds, charged, itanium, designers, 'threw. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.