Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 29 articles for you...
209

Insider Threats and Security Measures for Open Source Ecosystems

The recent discovery of a backdoor in XZ Utils , a widely used Linux tool, raises concerns about the security of the open-source ecosystem. While the open-source community successfully reacted to remove the malware , this event highlights the presence of spies within their midst and the need for stricter security measures. . Potential solutions exist, such as external certification processes or code reviews by external companies, but implementing them can be challenging. Understanding & Overcoming Insider Threats in Open-Source Environments The power of the open source community to quickly respond to crises like the XZ Utils backdoor must be highlighted, as exemplified by ethical hackers ' prompt removal of the malware. However, this also raises critical questions about the overall security and trust within the open-source ecosystem. One intriguing point to consider is the comparison between this incident and an internal corporate hack carried out by a disgruntled employee. It suggests that just as organizations face insider threats, the open source community may also be vulnerable to similar espionage acts. This analogy sparks curiosity and forces organizations to consider the implications of insider threats in a community built on trust. Recent attacks have raised thought-provoking questions regarding the need for stricter security measures in the open-source ecosystem. Implementing an external certification process or having external companies conduct code reviews and certify software could help reduce risk. However, these approaches have potential complications and legal liabilities. This tradeoff leads businesses to critically assess the balance between security measures and the fundamental principles of open-source collaboration. Organizations must also consider risks from within, where trusted users or contributors may abuse access or introduce malicious activity, making internal fraud prevention a critical part of securing Linux and open-source environments. Thisincident has significant implications for security practitioners, particularly Linux admins, infosec professionals, internet security enthusiasts, and sysadmins. It challenges them to reevaluate their trust in contributors and consider implementing additional security training and measures to mitigate insider threats. CISOs and cybersecurity teams must always consider the potential risks insiders pose and explore ways to conduct internal source code reviews on open-source software. Looking ahead, the long-term consequences of this incident could result in a more cautious approach to open-source collaboration. Change will come slowly, and the open-source community may need to adapt to evolving threats by implementing new security measures and creating awareness of insider risks. Improving Open Source Security: Our Final Thoughts The recent XZ Utils backdoor incident and its implications for the open-source ecosystem highlight the need for security practitioners to remain vigilant and proactive in addressing insider threats while questioning the potential consequences of implementing stricter security measures. As security practitioners, reflecting on the vulnerabilities within open-source environments and considering how you can contribute to a safer and more secure community is critical. . Mitigating insider threats in open-source environments requires implementing strict code audits, certification processes, and fostering a transparent community culture to report issues.. insider threat, open source security, ethical hacking, security measures, code review. . Brittany Day

Calendar 2 May 08, 2024 User Avatar Brittany Day Security Trends
83

Capital One Data Breach: Ex-Amazon Employee Used Cloud For Mining

Did you know that the ex-Amazon employee responsible for the Capital One breach earlier this year used the infiltrated cloud servers to mine cryptocurrency? Learn the details in this interesting The Next Web article: . The former Amazon Web Services employee thought to be behind the data breach of Capital One bank earlier this year appears to have also used the infiltrated cloud servers to surreptitiously mine cryptocurrency. According tocourt documents, Paige Thompson was indicted yesterday after hackingCapital One bank and 30 other entities, and has been charged with wire fraud, and computer fraud and abuse. Thompson allegedly created a software program to scan for and identify cloud customers that had incorrectly configured their firewalls, and in doing so, had left their systems exposed to external attacks. It appears that Thompson was able to exploit the vulnerability and send remote commands to servers to take control of those systems. The link for this article located at The Next Web is no longer available. . A past worker from Amazon hacked into Capital One's infrastructure to extract cryptocurrency. Uncover the specifics surrounding the violation.. Data Breach, Cloud Security, Cryptocurrency Mining, Insider Threats, AWS Vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Aug 29, 2019 User Avatar LinuxSecurity.com Team Hacks/Cracks
81

Morrisons: Insider Breach Liability Appeal Ruling Impact on Employees

Supermarket giant Morrisons has been told by the Court of Appeal that it is liable for the actions of a malicious insider who breached data on 100,000 employees, setting up a potential hefty class action pay-out.. An original High Court ruling last year said the UK chain was “vicariously liable” for the actions of former employee Andrew Skelton — a disgruntled internal auditor who published the details, which included NI numbers, birth dates and bank account data. The link for this article located at InfoSecurity is no longer available. . Morrisons grapples with accountability following unauthorized access to worker information, igniting fears of a potential collective lawsuit compensation.. Morrisons Liability Case, Insider Threat, Data Breach, Employee Information, Class Action Risks. . LinuxSecurity.com Team

Calendar 2 Oct 23, 2018 User Avatar LinuxSecurity.com Team Privacy
81

Analysis of GDPR Effects on Insider Threats in UK and Germany

According to new research from Clearswift, the introduction of GDPR has led to a slight drop in insider threats in both the UK and Germany. Survey respondents said that insider threats make up 65% of reported incidents in 2018, compared to 73% last year.. German companies reported similar declines, with insider error incidents at 75% this year, down from 80% last year. The research surveyed 400 senior IT decision makers from global organizations with more than 1,000 employees and found that 38% of IT security incidents occur as a direct result of their employees’ actions, with 75% of all incidents originating from their extended enterprise, which includes employees, customers and suppliers. Former employees represent 13% of cybersecurity incidents for the participating organizations. The link for this article located at InfoSecurity is no longer available. . Studies indicate a reduction in insider threats following the implementation of GDPR, underscoring advancements in IT security among firms.. Insider Threats, GDPR Impact, IT Security, Data Protection. . LinuxSecurity.com Team

Calendar 2 Jul 22, 2018 User Avatar LinuxSecurity.com Team Privacy
83

Analyzing Insider Threats And Their Impact On Enterprise Security

If recent statistics are any indication, enterprise security teams might be greatly underestimating the risk that insider threats pose to their organizations.. One study, by Crowd Research Partners, shows just 3% of executives pegged the potential cost of an insider threat at more than $2 million. Yet, according to Ponemon Institute, the average cost of insider threats per year for an organization is more than $8 million.. Research indicates that merely 4% of leaders misjudge the financial impact of insider threats at $2.5 million, whereas the typical expenses are above $9 million.. Insider Threat, Financial Risks, Security Cost Assessment. . LinuxSecurity.com Team

Calendar 2 Jun 30, 2018 User Avatar LinuxSecurity.com Team Hacks/Cracks
76

Uncovering Insider Threats: Insights from DerbyCon 5.0 Conference

Salted Hash is in Louisville, Kentucky for DerbyCon 5.0. All weekend long, in-between talks and training, this blog will be updated with various items of note from the show or thoughts form those attending. Today's starter topic is insider threats. . This topic isn't new, but it hasn't really gone away either. A friend shared some data from a company called Bay Dynamics. They do predictive analytics, so insider threats is a subject they're rather interested in following. . Delve into revelations about insider threats shared at DerbyCon 5.0, highlighting advancements in predictive analytics and engaging discussions around proactive security measures.. insider threat, security conference, DerbyCon, predictive analytics. . Dave Wreski

Calendar 2 Mar 14, 2017 User Avatar Dave Wreski Organizations/Events
82

Obama's Insider Threat Initiative: Leaker Detection and Concerns

The Obama Administration has a comprehensive "insider threat" program to detect leakers from within government. This is pre-Snowden. Not surprisingly, the combination of profiling and "see something, say something" is unlikely to work.. In an initiative aimed at rooting out future leakers and other security violators, President Barack Obama has ordered federal employees to report suspicious actions of their colleagues based on behavioral profiling techniques that are not scientifically proven to work, according to experts and government documents. The link for this article located at Schneier on Security is no longer available. . In an initiative aimed at rooting out future leakers and other security violators, President Barack . obama, administration, comprehensive, 'insider, threat', program, detect, leakers, within. . Dave Wreski

Calendar 2 Jul 29, 2013 User Avatar Dave Wreski Government
81

Managing Privileged Access for Data Security and Compliance

While most attention today is placed on containing complex malware and outside hacking threats, enterprises could significantly improve their risk posture by taking a look at how well they manage the access they give privileged insiders, such as network and database administrators and other IT professionals. What most organizations find is that they don't have a firm enough grip on the access these users have.. To keep sensitive information safe and to maintain regulatory compliance, it's crucial that privileged insider access be properly managed. The link for this article located at CSO Online is no longer available. . To keep sensitive information safe and to maintain regulatory compliance, it's crucial that privileg. while, attention, today, placed, containing, complex, malware, outside, hacking, threats. . LinuxSecurity.com Team

Calendar 2 Dec 23, 2011 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here