Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 606
Alerts This Week
Warning Icon 1 606

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 15 articles for you...
209

Evolving OpenSSL Threats: Defense Strategies After Heartbleed

In 2014, the cybersecurity community witnessed a critical OpenSSL vulnerability, “ Heartbleed ,” which changed how the world perceived digital security. It is considered to be among the most serious flaws in internet history. Heartbleed not only exposed the weaknesses in popular cryptographic protocols but also the potential repercussions of a small coding error. . Following the Heartbleed event, the cybersecurity landscape experienced a dramatic change as the emphasis shifted to fortifying security protocols and resolving the root causes of vulnerabilities. Several upgrades, improved code standards, stringent security audits, and a dedication to addressing identified vulnerabilities were the outcomes of this momentum. However, as with any constantly evolving technology, vulnerabilities continued to emerge in OpenSSL despite these efforts. The post-Heartbleed vulnerabilities remind us that security is an ongoing process, and we must remain vigilant, ensuring that security practices align with the latest security recommendations. The link for this article located at Security Boulevard is no longer available. . Following the Equifax breach, the landscape of digital security shifted dramatically, highlighting the critical need for persistent awareness.. OpenSSL Threats,Cybersecurity Trends,Code Vulnerabilities,Protocol Security. . Brittany Day

Calendar%202 Nov 17, 2023 User Avatar Brittany Day Security Trends
67

OpenSSL: Urgent Downgrade Needed Due To Severe Cert Issue

Organizations that installed the June 11 OpenSSL update need to pull it back immediately after a serious certificate validation error was discovered and patched today in a new update.. The bug was reported two weeks ago to the OpenSSL project by Google researcher Adam Langley and BoringSSL The link for this article located at ThreatPost is no longer available. . The bug was reported two weeks ago to the OpenSSL project by Google researcher Adam Langley and Bori. organizations, installed, openssl, update, immediately. . LinuxSecurity.com Team

Calendar%202 Jul 10, 2015 User Avatar LinuxSecurity.com Team Cryptography
67

OpenSSL Risks With Multiple Fix Projects That May Impact Security

Nobody questions that OpenSSL is a vital part of the Internet's infrastructure. So many fundamentals are built on top of it and in so many places. Too much is at stake for it to be vulnerable to yet another Heartbleed, the dangers of which may linger for some time in embedded and client devices.. That's why the efforts, plural, to fix OpenSSL and make it more maintainable are so heartening. But having three such projects in the works, all operating in parallel, may be the wrong kind of plurality. The link for this article located at InfoWorld is no longer available. . Worries grow regarding OpenSSL's oversight as several initiatives work on repairs at the same time; a threat to online safety.. OpenSSL Management, Cybersecurity Risks, Infrastructure Security, Project Coordination. . LinuxSecurity.com Team

Calendar%202 Jul 14, 2014 User Avatar LinuxSecurity.com Team Cryptography
67

OpenSSL Project: Enhancements for Enhanced Security and Encryption

The OpenSSL Project is planning a number of changes to ensure its security component, used across millions of computers across the Internet, is in tip-top shape.. OpenSSL is an open-source code library that encrypts communications between a computer and a server using SSL/TLS (Secure Sockets Layer/Transport Layer Security). It is a fundamental defense for keeping e-commerce transactions, email and other data unreadable if the traffic is intercepted. The link for this article located at TechWorld is no longer available. . OpenSSL is embarking on major revisions to fortify its security features, aiming for improved encryption standards and enhanced data safeguarding.. OpenSSL Changes, Security Roadmap, Encryption Improvements. . LinuxSecurity.com Team

Calendar%202 Jul 02, 2014 User Avatar LinuxSecurity.com Team Cryptography
67

Heartbleed Analysis Reveals OpenSSL Licensing Challenges to Engagement

Weeks after the OpenSSL debacle, the question still stands: Why did so few people show up to work on such widely-used and important code? Since the problem arose, funds have flowed in to fix it at the behest of corporate giants, but before the crises, few volunteers participated. One leading open source expert has suggested a reason: licensing.. An interesting comment from David A. Wheeler, an expert in government use of open source, asks whether the OpenSSL project's use of a rarely seen open source license was partly responsible for a lack of community engagement and oversight. In the context of a longer paper highlighting technical facets of addressing Heartbleed, Wheeler says: The link for this article located at InfoWorld is no longer available. . An interesting comment from David A. Wheeler, an expert in government use of open source, asks wheth. weeks, openssl, debacle, question, still, stands, people. . LinuxSecurity.com Team

Calendar%202 May 02, 2014 User Avatar LinuxSecurity.com Team Cryptography
67

OpenSSL Security Advisory: Allegations of a Potential Scam by Hacker

Security experts have expressed doubts about a hacker claim that there. A group of five hackers writes in a posting on Pastebin that they worked for two weeks to find the bug and developed code to exploit it. They The link for this article located at PC World is no longer available. . Security experts express doubts regarding claims by hackers alleging the discovery of a vulnerability in OpenSSL following the Heartbleed incident, labeling it as a potential hoax.. OpenSSL Threat,Bug Exploit Analysis,Hacker Claims,Encryption Security. . LinuxSecurity.com Team

Calendar%202 Apr 28, 2014 User Avatar LinuxSecurity.com Team Cryptography
67

Heartbleed: OpenSSL Security Flaw Exposes Data Theft Risks

Many of the websites you use at home and in the office are vulnerable to hacking, according to researchers who uncovered a security flaw in OpenSSL, the open-source software that is used to encrypt online communications. Websites and apps that encrypt data with a password likely use OpenSSL, and the cryptographic library is used to secure the servers that work with more than 66 percent of active websites on the Internet.. The bug, dubbed The link for this article located at International Business Times is no longer available. . Explore the implications of the Heartbleed vulnerability in OpenSSL, which leaves websites vulnerable to data breaches, and examine its impact on the security landscape of the internet.. OpenSSL Flaw, Heartbleed Bug, Online Security Threat, Data Protection. . LinuxSecurity.com Team

Calendar%202 Apr 09, 2014 User Avatar LinuxSecurity.com Team Cryptography
67

OpenSSL 1.0.0 Major Release: Enhanced Security And New Features

With more than twelve years of development, the first v1.0.0 release of OpenSSL is now available. The OpenSSL project team is pleased to announce the release of version 1.0.0 of our open source toolkit for SSL/TLS. This new OpenSSL version is a major release and incorporates many new features as well as major fixes compared to 0.9.8n. . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA1 OpenSSL version 1.0.0 released ============================= OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org:443/ The OpenSSL project team is pleased to announce the release of version 1.0.0 of our open source toolkit for SSL/TLS. This new OpenSSL version is a major release and incorporates many new features as well as major fixes compared to 0.9.8n. For a complete list of changes, please see . The most significant changes are: o RFC3280 path validation: sufficient to process PKITS tests. o Integrated support for PVK files and keyblobs. o Change default private key format to PKCS#8. o CMS support: able to process all examples in RFC4134 o Streaming ASN1 encode support for PKCS#7 and CMS. o Multiple signer and signer add support for PKCS#7 and CMS. o ASN1 printing support. o Whirlpool hash algorithm added. o RFC3161 time stamp support. o New generalised public key API supporting ENGINE based algorithms. o New generalised public key API utilities. o New ENGINE supporting GOST algorithms. o SSL/TLS GOST ciphersuite support. o PKCS#7 and CMS GOST support. o RFC4279 PSK ciphersuite support. o Supported points format extension for ECC ciphersuites. o ecdsa-with-SHA224/256/384/512 signature types. o dsa-with-SHA224 and dsa-with-SHA256 signature types. o Opaque PRF Input TLS extension support. o Updated time routines to avoid OS limitations. We consider OpenSSL 1.0.0 to be the best version of OpenSSLavailable and we strongly recommend that users of older versions upgrade as soon as possible. OpenSSL 1.0.0 is available for download via HTTP and FTP from the following master locations (you can find the various FTP mirrors under * * The distribution file name is: o openssl-1.0.0.tar.gz Size: 4010166 MD5 checksum: 89eaa86e25b2845f920ec00ae4c864ed SHA1 checksum: 3f800ea9fa3da1c0f576d689be7dca3d55a4cb62 The checksums were calculated using the following commands: openssl md5 openssl-1.0.0.tar.gz openssl sha1 openssl-1.0.0.tar.gz Yours, The OpenSSL Project Team... Mark J. Cox Nils Larsch Ulf Möller Ralf S. Engelschall Ben Laurie Andy Polyakov Dr. Stephen Henson Richard Levitte Geoff Thorpe Lutz Jänicke Bodo Möller -----BEGIN PGP SIGNATURE-----Version: GnuPG v1.4.9 (GNU/Linux) iQEVAwUBS7C22aLSm3vylcdZAQI6TggAxWKuZFWcdtoBIfJpvHbdVlVJUe2O4tO7 +wHqMRANGZLx+io2KXxe1s3/qaKTOtlhP44jTDSRFxn418RLlZ4VS/I/mlKbEd7s tFgT34z8u8Et6oj5OwN8XbzwvkEGv+Ytf15Oub9DLa6doQ0xehaIKn+BHuDUeZup IVQkkAplKOMV77rfCZQWcApWVOPs6d0tP7F4uWHUNElzVFF6U2G38qKymJEIotUk a9kH7uS1EXFz0j4Fm7oVbE8tvrDQJa71Odtvt3N++Qppd+e5OgnU9klh7fnZ78Ae APfz3vPBLhItyGnpeBNwppFcKiPtG9M6Bthw+AsGVnsDiieHdHmGTg==Wfex -----END PGP SIGNATURE-----______________________________________________________________________ OpenSSL Project https://www.openssl.org:443/ Announcement Mailing List This email address is being protected from spambots. You need JavaScript enabled to view it. Automated List Manager This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA1 OpenSSL version 1.0.0 released ========================. twelve, years, development, first, release, openssl. . LinuxSecurity.com Team

Calendar%202 Mar 29, 2010 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200