Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 10 articles for you...
79

CloudLinux: TuxCare Provides Vital Security For Atlas V Rocket Operations

CloudLinux's TuxCare services are now providing automated security patches and updates for the systems supporting the Atlas V rocket . “Protecting US [and world] national security means having the ability to launch important payloads into space. TuxCare from CloudLinux is proud to do our part to support the [US] Department of Defense and the Space Force by providing critical security patches for ULA’s Atlas V rocket,” said Jim Jackson, president and CRO of CloudLinux. . In a world where some question the code-share channels of open source communities and the use of components that may (or indeed may not) bring into question their provenance, prowess and performance… CloudLinux is an organisation on a mission to increase security, stability and availability of Linux servers and devices. Headquartered in Palo Alto, CloudLinux Inc. develops a hardened Linux distribution, Linux kernel live security patching, extended support options for Linux and web server security software. . CloudNative strengthens Falcon 9 rocket integrity through dynamic updates, crucial for defense strategies and aerospace operations.. CloudLinux,TuxCare,Automated Patching,Atlas V,Security Patching. . LinuxSecurity.com Team

Calendar%202 Aug 02, 2021 User Avatar LinuxSecurity.com Team Security Projects
83

Cyber Storm Exercise Elevates National Defense Against Cyber Threats

Vital US infrastructure including power grids and banking systems have been put under simulated attack in a week-long security exercise called Cyber Storm. The war game drew in 115 agencies from the FBI and CIA to the Red Cross, the Department of Homeland Security said. IT companies and state and foreign governments also played a role in responding to the mock attacks. . The exercise had given the US "an excellent opportunity to enhance our nation's cyber security," the US said.. The UK’s Cyber Shield exercise focused on vital services, strengthening the nation's resilience to simulated cyber threats.. Cyber Defense, Infrastructure Protection, Security Exercise, Cybersecurity Training, National Security. . LinuxSecurity.com Team

Calendar%202 Feb 13, 2006 User Avatar LinuxSecurity.com Team Hacks/Cracks
82

Exploring Richard Clarke's Legacy in Cybersecurity and National Defense

In all the recent ruckus about the strained relationship between the Federal Government and the computer security community, it is fitting to now remember Richard Clarke. He's been grabbing headlines lately on the strength of a book claiming that he warned Bush about Al Queda but was ignored, a charge that might strike even Bush-haters as odd, given Clarke's illustrious record of causing nothing to be done about terrorism for all the time he was the head terrorism czar. What has he been really up to, instead? Hawking the yet-to-materialize threat of cyber-terrorism, on the theory that real terrorists want to virus and spam us to submission. This is the Terrorism --> Cyberterrorism Czar, folks, and the best excuse the Feds have for trying to tell us how to be secure. . . .. The retirement of Richard Clarke is appropriate to the reality of the war on terror. Years ago, Clarke bet his national security career on the idea that electronic war was going to be real war. He lost, because as al Qaeda and Iraq have shown, real action is still of the blood and guts kind. In happier times prior to 9/11, Clarke -- as Bill Clinton's counter-terror point man in the National Security Council -- devoted great effort to convincing national movers and shakers that cyberattack was the coming thing. While ostensibly involved in preparations for bioterrorism and trying to sound alarms about Osama bin Laden, Clarke was most often seen in the news predicting ways in which electronic attacks were going to change everything and rewrite the calculus of conflict. September 11 spoiled the fun, though, and electronic attack was shoved onto the back-burner in favor of special operations men calling in B-52 precision air strikes on Taliban losers. One-hundred fifty-thousand U.S. soldiers on station outside Iraq make it perfectly clear that cyberspace is only a trivial distraction. Saddam will not be brought down by people stealing his e-mail or his generals being spammed with exhortations to surrender. Clarke's career in subsequentpresidential administrations was a barometer of the recession of the belief that cyberspace would be a front effector in national security affairs. After being part of the NSC, Clarke was dismissed to Special Advisor for Cyberspace Security on October 9th in a ceremony led by National Security Advisor Condoleeza Rice and new homeland security guru Tom Ridge. If it was an advance, it was one to the rear -- a pure demotion. Instead of combating terrorists, Clarke would be left to wrestle with corporate America over computer security, a match he would lose by pinfall. Ridding the world of bad guys and ensuring homeland safety was a job for CIA wet affairsmen, the FBI, the heavy bomb wing out of Whiteman Air Force Base -- anyone but marshals in cyberspace. Information "Sharing" and Cruise Missiles The Slammer virus gave Clarke one last mild hurrah with the media. But nationally, Slammer was a minor inconvenience compared to relentless cold weather in the east and the call up of the reserves. But with his retirement, Clarke's career accomplishments should be noted. In 1986, as a State Department bureaucrat with pull, he came up with a plan to battle terrorism and subvert Muammar Qaddafi by having SR-71s produce sonic booms over Libya. This was to be accompanied by rafts washing onto the sands of Tripoli, the aim of which was to create the illusion of a coming attack. When this nonsense was revealed, it created embarrassment for the Reagan administration and was buried. The link for this article located at SecurityFocus is no longer available. . The retirement of Richard Clarke is appropriate to the reality of the war on terror. Years ago, Clar. recent, ruckus, about, strained, relationship, between, federal, government. . Anthony Pell

Calendar%202 Mar 23, 2004 User Avatar Anthony Pell Government
82

DOD Action Needed: Enhancing Cybersecurity for National Defense

The Defense Department must do more to guard against cyber threats, said Robert Lentz, the department's director of information assurance. "As our dependence on information networks increases, it creates new vulnerabilities, as adversaries develop new ways of attacking and disrupting . . . . The Defense Department must do more to guard against cyber threats, said Robert Lentz, the department's director of information assurance. "As our dependence on information networks increases, it creates new vulnerabilities, as adversaries develop new ways of attacking and disrupting U.S. forces," he said. "Everyone must be made aware of his or her role in assuring the nation's information." Lentz, speaking late last week to a House Subcommittee on terrorism, unconventional threats and capabilities, said that in recent years the department has become more reliant on off-the-shelf products proven in the commercial world. But some experts said that off-the-shelf code can require frequent security patches because holes repeatedly emerge in commercial code. And off-the-shelf software mainly comes from people with no security clearance or workers in other countries. The link for this article located at FCW is no longer available. . Robert Lentz highlights the urgent need for the Defense Department to strengthen its strategies in response to increasing cyber threats.. Defense Cybersecurity,Cyber Threats Management,Software Security Issues. . Anthony Pell

Calendar%202 Jul 29, 2003 User Avatar Anthony Pell Government
82

Bush's National Terrorism Center Proposal for Improved Data Sharing

President Bush in his State of the Union address last night reiterated how much his administration will depend upon technology for homeland defense. Among his list of domestic proposals, Bush said he is instructing the CIA, FBI, Defense Department and Homeland Security Department to develop a Terrorist Threat Integration Center to merge and analyze all threat information in a single location. . .. President Bush in his State of the Union address last night reiterated how much his administration will depend upon technology for homeland defense. Among his list of domestic proposals, Bush said he is instructing the CIA, FBI, Defense Department and Homeland Security Department to develop a Terrorist Threat Integration Center to merge and analyze all threat information in a single location . Our government must have the very best information possible, Bush said. We will use it to make sure the right people are in the right places to protect all our citizens. During his nearly one-hour speech, technology played a part in two areas: the new terrorism center and the use of sensors as a part of early warning system against bioterrorism. (Click here for a White House synopsis of initiatives) The center, which will be headed by senior government officials appointed by the CIA director, will oversee a national counterterrorism tasking and requirements system and maintain shared databases with the CIA, FBI, HSD and DOD. It also will maintain an up-to-date database of known and suspected terrorists, which will be accessible to federal and non federal officials. The White House released a fact sheet on the proposal that said the center would ensure that intelligence information from all sources is shared, integrated and analyzed seamlessly, and then acted upon quickly. The integration piece will be critical across all the databases, said David McClure, vice president for E-Government at the Council for Excellence in Government, a Washington non-partisan organization. The system must be able to assembleinformation quickly and intelligently and analyze it and disseminate even more quickly. McClure said it will be a challenge to put a system together because so much information will come from so many different sources. He said it will be important for the system to have high-speed connections and software that can examine and distribute it across agencies and levels of government. Michael Scardaville, a policy analyst for homeland security at the Heritage Foundation, a Washington conservative think tank, said by creating the mechanism for agencies to share information will improve data transfers. We really have been lacking an institutional solution to our information sharing problem, he said. This is a step in that direction. Scardaville said the technology must take the human element out of sharing. If an analyst must physically transfer information, then it will not be as effective, he said. Anyone should be able to access the information at any time on their own. He also said work being done by the Defense Advanced Research Projects Agency is a possible solution to the data sharing problem. The center would be the ideal place to use the technology developed by the Total Information Awareness program, Scardaville said. Databases could be linked without having to take all that information out of the database. An analyst could query the data from outside the host network instead of doing traditional data mining. At least to some extent, the administration s proposal for the center follows one of the recommendations of the Gilmore Commission to assess the domestic response capabilities to terrorism involving weapons of mass destruction. The commission suggested a forming a national counterterrorism center separate from the CIA, FBI and HSD. It would be responsible to fuse intelligence information from all foreign and domestic sources, the report said. McClure said he was somewhat surprised that Bush did not mention some of the recent E-government progress in the government to citizenportfolio, such as the IRS free file launch and the GovBenefits Web site. The link for this article located at GCN is no longer available. . President Bush in his State of the Union address last night reiterated how much his administration w. president, state, union, address, night, reiterated, administration. . Anthony Pell

Calendar%202 Jan 29, 2003 User Avatar Anthony Pell Government
82

White House Cybersecurity Strategy: Teamwork Over Government Rules

Under intense lobbying by industry groups, a White House panel studying ways to protect America's high-tech backbone has dropped several security ideas and turned others into topics for discussion rather than government mandates, according to the latest version of the plan. . . . . Under intense lobbying by industry groups, a White House panel studying ways to protect America's high-tech backbone has dropped several security ideas and turned others into topics for discussion rather than government mandates, according to the latest version of the plan. The ideas that have been dropped include requiring companies to pay money into a fund to improve national computer security and restricting use of emerging wireless networks until their security is approved, according to the draft obtained by The Associated Press. "We're just identifying the stuff we already know to be a problem, and saying it's a problem," said Russ Cooper of network security firm TruSecure Corp. who was briefed on the plan. "I thought there was going to be some meat, and there's not." The link for this article located at CNN.com is no longer available. . The White House panel emphasizes collaboration in cybersecurity, advocating for voluntary guidelines over strict regulation and stressing the need for trust between sectors. Government Cybersecurity Policy, Industry Influence on Security, High-Tech National Defense. . Anthony Pell

Calendar%202 Sep 17, 2002 User Avatar Anthony Pell Government
82

Impact of Industry Lobbying on National Cybersecurity Plans

Under intense lobbying by industry groups, a White House panel studying ways to protect America's high-tech backbone has dropped several security ideas and turned others into topics for discussion rather than government mandates, according to the latest version of the plan. . . . . Under intense lobbying by industry groups, a White House panel studying ways to protect America's high-tech backbone has dropped several security ideas and turned others into topics for discussion rather than government mandates, according to the latest version of the plan. The ideas that have been dropped include requiring companies to pay money into a fund to improve national computer security and restricting use of emerging wireless networks until their security is approved, according to the draft obtained by The Associated Press. "We're just identifying the stuff we already know to be a problem, and saying it's a problem," said Russ Cooper of network security firm TruSecure Corp. who was briefed on the plan. "I thought there was going to be some meat, and there's not." The cybersecurity panel headed by President Bush's computer security adviser, Richard Clarke, is expected to release its recommendations Wednesday. Clarke adviser Andy Purdy said Monday the panel has decided to put its ideas out for public comment for two months before sending it to the president. The link for this article located at CNN.com is no longer available. . Under intense lobbying by industry groups, a White House panel studying ways to protect America's hi. under, intense, lobbying, industry, groups, white, house, panel, studying, protect. . Anthony Pell

Calendar%202 Sep 17, 2002 User Avatar Anthony Pell Government
82

U.S. Cybersecurity Efforts: Coordination Challenges in National Security

Years after orders from the White House to beef up the security of the nation's most important computer systems, the government is having trouble identifying which organizations should be involved and how they should be coordinated, according to a new report. . . . . Years after orders from the White House to beef up the security of the nation's most important computer systems, the government is having trouble identifying which organizations should be involved and how they should be coordinated, according to a new report. President Bush's recent proposal to create a Cabinet-level Department of Homeland Security said at least 12 organizations oversee protection of important infrastructure. But the General Accounting Office, the investigating arm of Congress, said it identified at least 50 organizations already involved in such efforts, usually focused on protecting vital computer networks. The GAO said those groups include five advisory committees, six organizations under the White House, 38 groups under executive agencies and three others. Within the Defense Department alone, the GAO found seven organizations. The link for this article located at TechNews.com is no longer available. . Years after orders from the White House to beef up the security of the nation's most important compu. years, orders, white, house, security, nation's, important, compu. . Anthony Pell

Calendar%202 Jul 23, 2002 User Avatar Anthony Pell Government
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200