Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
APT36 is a highly sophisticated APT (Advanced Persistent Threat) group known for conducting targeted espionage in South Asia and is strongly linked to Pakistan. . While this APT group is known for targeting the following Indian sectors: Government Defense Education Since 2013, this APT group has been active, and to conduct cyber espionage, it uses the following methods:- Credential harvesting Malware distribution Here below, we have mentioned the resources used by APT36:- Custom-built remote administration tools targeting Windows Lightweight Python-compiled cyber espionage tools serving specific purposes targeting Windows and Linux Weaponized open-source C2 frameworks like Mythic Trojanized installers of Indian government applications like KAVACH multi-factor authentication Trojanized Android apps Credential phishing sites targeting Indian government officials Zscaler analysts dubbed the Windows backdoor used by APT36 ‘ElizaRAT,’ because of unique strings in observed C2 commands. The link for this article located at CyberSecurity News is no longer available. . APT36 utilizes tailored malicious software targeting Indian governmental divisions such as education and defense, representing significant risks.. APT36,CyberEspionage,GovernmentMalware,EducationSecurity,DefenseAttacks. . Brittany Day
Federal legislators have begun the process of better securing the open-source software used by government agencies with a new bill titled “Securing Open Source Software Act of 2022.” . Sens. Gary Peters, D-Mich., and Rob Portman, R-Ohio, introduced the legislation that seeks to address open source software risks in government. The proposed Bill, S. 4913, now awaits action by the Committee on Homeland Security and Governmental Affairs. The legislation comes after a hearing Peters and Portman convened on Feb. 2 to investigate the Log4j incident that was discovered in December 2021. It directs the Cybersecurity and Infrastructure Security Agency (CISA) to help ensure that open-source software is used safely and securely by the federal government, critical infrastructure, and others. . Senators Tina Smith and Mike Lee proposed a bill aimed at improving the safety of open-source applications across federal departments.. Open Source Software, Cybersecurity Act, Government Security, Software Risks. . Brittany Day
As Senate Judiciary Committee Chair Lindsey Graham has continued his latest quest to undermine encryption with a hearing whose sole purpose seemed to be tomisleadingly arguethat encryption represents a "risk to public safety." The Defense Department has weighed in to say that's ridiculous. As you may recall, the DOJ and the FBI have been working overtime to demonize encryption and pretend -- against nearly all evidence -- that widespread, strong encryption somehow undermines its ability to stop criminals. Learn more in an interesting TechDirt article: . However, it appears that other parts of the government are a bit more up to date on these things. Representative Ro Khanna has forwarded a letter to Senator Graham that he received earlier this year from the Defense Department's CIO Dana Deasy, explaining just how important encryption actually is. The letter highlights how DoD employees rely on the kind of strong encryption found on mobile devices and in VPN services to protect the data of their employees, both at rest (on the devices) and in transit (across the network). . The Security Agency stresses the necessity of securing data as it faces persistent challenges from politicians such as Elizabeth Warren.. Encryption Importance, Government Security, Public Privacy, Cybersecurity Debate, DoD Encryption. . Brittany Day
Are you a Massachusetts resident? Face surveillance by government poses a threat to our privacy, chills protest in public places, and amplifies historical biases in our criminal justice system. Massachusetts has the opportunity to become the first state to stop government use of this troubling technology, from Provincetown to Pittsfield. Learn more: . Massachusetts residents: tell your legislature to press pause on government use of face surveillance throughout the Commonwealth. Massachusetts bills S.1385 and H.1538 would place a moratorium on government use of the technology, and your lawmakers need to hear from you ahead of an Oct. 22 hearing on these bills. Concern over government face surveillance in our communities is widespread. Polling from the ACLU of Massachusetts has found that more than three-quarters, 79 percent, support a statewide moratorium . . Citizens of Massachusetts: urge your lawmakers to halt the deployment of facial recognition technology by the state.. Massachusetts, Face Surveillance, Privacy Rights, Government Monitoring. . LinuxSecurity.com Team
The current federal government shutdown, the longest in United States history, is in its fourth week, with no clear path to resolution. With 800,000 federal employees on full or partial leave as a result, cybersecurity experts raised an early alarm about how the shutdown would impact US cybersecurity. . Those early concerns have since compounded, and evolved into a mounting crisis. Most intelligence and law enforcement work is continuing during the shutdown, because the Department of Defense already has its funding established for 2019. And a large number of critical federal employees outside of DoD are being asked to report to work uncompensated until they can receive backpay. But crucially, from a cybersecurity perspective, organizations within the Department of Homeland Security—including the new Cybersecurity and Infrastructure Security Agency launched in November—are operating with a skeleton crew. The link for this article located at Wired is no longer available. . The current national impasse creates major vulnerabilities in cybersecurity for American enterprises and vital systems.. Federal Shutdown Impact, US Cybersecurity, Government Security Risks, CISA Operations. . Brittany Day
At the DarkReading News Desk, live from Black Hat, industry experts Dan Kaminsky, Richard Bejtlich, Katie Moussouris, Paul Kurtz, and Rod Beckstrom talked about how government is hurting and could be helping infosec. . Last week we debuted the Dark Reading Video News Desk, streaming live from Black Hat, featuring over 30 interviews with speakers, trainers, and sponsors from the conference. Over the coming weeks, all the individual interviews will be posted here on Dark Reading. . Last week we debuted the Dark Reading Video News Desk, streaming live from Black Hat, featuring over. darkreading, black, industry, experts, kaminsky, richard, bejtlich. . Pooja Shah
Echoing the concerns many US-based technology companies have about US-led surveillance programs, Yahoo Chief Information Security Officer Alex Stamos asked the director of the National Security Agency some pointed questions concerning proposed or existing backdoors placed in encryption technologies.. The responses from NSA Director Adm. Mike Rogers only underscored the growing divide. The frank exchange occurred Monday at the Cybersecurity for a New America conference in Washington DC. It came 17 months after materials leaked by former NSA subcontractor Edward Snowden documented NSA-engineered backdoors were built into widely used cryptography technologies so that government agents could decrypt communications. . Discussions reveal worries over privacy and state access in encryption systems during a prominent summit.. Encryption Backdoors, NSA Surveillance, Cybersecurity, Privacy Issues, Technology Risks. . LinuxSecurity.com Team
Gov. Nikki Haley. The link for this article located at The State is no longer available. . The link for this article located at The State is no longer available.. nikki, haley, article, located, state, longer. . Alex
Get the latest Linux and open source security news straight to your inbox.