Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -4 articles for you...
76

Exploring OpenSSF's Initiatives to Mitigate Log4j-Like Flaws

More critical flaws similar to Log4Shell found in open source are almost inevitable, but Open Source Security Foundation ’s (OpenSSF’s) goal is to make those incidents rare and continually make the attackers’ job harder, a Linux Foundation executive noted. . Founded in 2020, OpenSSF is a cross-industry organization hosted by the Linux Foundation that brings together individuals and companies including Cisco , GitHub, Google , and VMware , to develop better security tools and practices for open source application development without bias toward a specific ecosystem or vendor. The organization offers automation tools, educational materials, and courses and develops various projects and frameworks — including Supply Chain Levels for Software Artifacts (SLSA) , Secure Supply Chain Consumption Framework (S2C2F) , Software Bill of Materials (SBOM) Everywhere , and Alpha-Omega — to improve security for the open source community, David Wheeler, Director of open source supply chain security at Linux Foundation, told SDxCentral. “Certainly nobody wants another Log4j, [but] a major vulnerability in software that beats open source or closed source is probably inevitable,” he said. “So the goal is to make these kinds of problems rare. And so we are working towards that end.” Wheeler noted OpenSSF offers open source security courses that specifically educate students not to make the mistake that happened in Apache Log4j 2 Java library. “Unfortunately, LogShell was not, as far as anyone can tell, intentional maliciousness. It was an honest mistake, in part due to the complexity of code, and in part, frankly due to people who are doing the development not knowing how to do certain kinds of secure software development, and the tools that really support them either,” he said. . The Linux Foundation is focused on preventing vulnerabilities akin to Log4j by promoting robust security measures throughout open-source development ecosystems.. OpenSSF, Open SourceSecurity, Log4j Incident, Risk Management, Secure Development. . Brittany Day

Calendar 2 Mar 13, 2023 User Avatar Brittany Day Organizations/Events
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here