Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
On May 10th, 2019, the US Congress passed an order requiring federal agencies to patch a Linux bug that can be used to gain root access. The bug, known as "Looney Tunables," was discovered by security researchers in January and allows attackers to change the value of any kernel parameter on Linux systems running the 3.10 kernel or earlier. . While most Linux distributions have already patched this bug, some Linux installations may still be vulnerable if they do not receive regular updates from their vendors. Since the Looney Tunables bug affects older versions of the Linux operating system, it could be present on many servers and other devices running older versions of OpenStack and other open-source software packages. This could mean that large numbers of systems might remain vulnerable to attack even after being patched by their vendors. . Even with updates released for Daffy Dynamics, a lot of Unix platforms may remain at risk if not consistently patched.. Linux Bug Patch, Looney Tunables, Security Advisory. . Brittany Day
The Biden Administration has extended the deadline for federal agencies to submit documentation proving that the software they use was developed with appropriate security practices, because the form for reporting on such matters isn't complete. . Since coming into office in 2021, the Administration has focused on cybersecurity for the both the government and private sectors, with an emphasis on hardening the software supply chain in the wake of such incidents as the SolarWinds attack. One of the Administration's tactics was requiring software vendors to attest to their use of federal software development standards defined by the National Institute of Standards and Technology's (NIST's) Secure Software Development Framework [PDF]. The deadline for government agencies to collect attestation certificates from their vendors was September 14. But that dog ain't going to hunt just yet. . The Biden Administration's extension of software security compliance highlights the ongoing hurdles in vendor preparedness.. Software Security, Cybersecurity Compliance, Vendor Attestation, NIST Standards. . Brittany Day
The OpenSSL library of encryption algorithms has just been patched by the OS Software Institute. This open source module has been utilized at many government agencies, and is an interesting example of two things: the effectiveness of Open Source technologies in the most demanding environments and how the kind of work that still needs to be done in the government sector regarding secure Internet infrastructure: "For FIPS 140-2 validated software no changes are permitted without prior CMVP approval so neither of these patches can be applied to the v1.1.1 distribution for the purposes of producing a validated module," Steve Marquess of OSSI said in the announcement of the patches. That means that for the time being federal users must continue using the flawed software or patch it and go out of compliance. . The link for this article located at Government Computer News is no longer available. . Critical OpenSSL vulnerabilities addressed by the National Software Agency, affecting regulatory adherence and safeguarding systems.. OpenSSL, Encryption Flaws, Compliance, Security Patch, Open Source. . LinuxSecurity.com Team
The Office of Personnel Management today outlined a four-step process for agencies to follow to ensure employees, contractors and others who access federal systems are adequately trained in IT security. . . .. The Office of Personnel Management today outlined a four-step process for agencies to follow to ensure employees, contractors and others who access federal systems are adequately trained in IT security. The final rule, effective today, requires agencies to develop an IT security training plan. The plan should identify employees with significant cybersecurity responsibilities and provide role-specific training as detailed by the National Institute of Standards and Technology guidance. The link for this article located at gcn.com is no longer available. . The National Institute of Standards and Technology describes a comprehensive approach for implementing robust cybersecurity awareness programs within government agencies.. IT Security Training, Cybersecurity Training, Federal Agencies. . Anthony Pell
The Commerce Department has formally approved the new standard for the minimum level of cryptography in federal security products, replacing a standard that had been in effect for seven years. With the approval June 27, security products used by agencies for . . . . The Commerce Department has formally approved the new standard for the minimum level of cryptography in federal security products, replacing a standard that had been in effect for seven years. With the approval June 27, security products used by agencies for sensitive, unclassified information must be certified under the National Institute of Standards and Technology's Federal Information Processing Standard (FIPS) 140-2, Security Requirements for Cryptographic Modules. The new FIPS 140-2 standard, which replaces the 140-1 standard from 1994, goes into effect Nov. 25. The link for this article located at FCW is no longer available. . The Commerce Department has formally approved the new standard for the minimum level of cryptography. commerce, department, formally, approved, standard, minimum, level, cryptography. . Anthony Pell
At a time when federal regulators are pushing commercial Web sites to adopt the "fair information practices," only three percent of federal Web sites currently adhere to their own standards, according to a new report. The report, drafted by the General . . . . At a time when federal regulators are pushing commercial Web sites to adopt the "fair information practices," only three percent of federal Web sites currently adhere to their own standards, according to a new report. The report, drafted by the General Accounting Office (GAO), found that while all 65 of the federal Web sites surveyed collected personal identifying information from visitors, only 22 percent disclosed that they might allow third-party "cookies"--small text files used to track a users' Web surfing habits--and that 14 percent actually allowed their placement. The link for this article located at Computer User is no longer available. . Recent findings from the GAO report indicate that merely 3% of federal websites comply with their established privacy protocols.. Federal Privacy Compliance, Web Security Standards, User Data Protection. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.