Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
76

OpenInfra Foundation Joins Linux Foundation: Enhancing Open-source Security

Exciting news has just reached the open-source community: OpenStack , now known as OpenInfra Foundation , is joining forces with the Linux Foundation . This significant move promises greater collaboration and operational efficiency throughout the community. . Linux security admins now have new opportunities to leverage advanced security practices supported by the extensive resources of the Linux Foundation, with improved integration and compliance with global security standards. In addition, this partnership underscores the significance of secure infrastructure in supporting cutting-edge technologies like AI . By aligning these two powerful organizations, their combined expertise and governance should strengthen security protocols further, making collaborative efforts more robust and streamlined. Let's examine the significance of this partnership and its potential benefits for open-source security/ Strengthening Open-source Collaboration The open-source community thrives on cooperation, as evidenced by the recent merger between OpenInfra Foundation (formerly OpenStack) and the Linux Foundation. By joining forces, these two powerhouses aim to amp up their impact in areas critical for modern infrastructure; not simply pooling resources but creating synergies that strengthen robustness, security, scalability, and longevity of open-source projects. This is particularly beneficial for Linux security administrators hoping this alliance will bring new methodologies and tools to make their tasks more efficient and effective. OpenInfra's decision to collaborate with the Linux Foundation is wise. Although its governance will remain unchanged, collaboration unlocks unrivaled expertise and resources within both organizations. Thanks to their long history of nurturing innovative projects, this relationship provides fertile ground for OpenInfra to expand and improve initiatives, providing security admins access to improved tools and practices without disrupting current governance structures. Enhancing Security Practices One of the main benefits of this merger is its potential to strengthen security practices across both organizations' projects. The Linux Foundation has an impressive record of creating and enforcing security standards that should now extend into OpenInfra's tools and frameworks. This cross-pollination should lead to more resilient and secure open-source infrastructures. As Linux security administrators, integration means having more structured and well-maintained security protocols. The Linux Foundation's Core Infrastructure Initiative and Open Source Security Foundation aim to identify and mitigate vulnerabilities early. With more deeply embedded OpenInfra projects providing a stronger basis on which to build secure environments, fewer vulnerabilities will slip through cracks. Operational Efficiency and Governance Aligning with the Linux Foundation offers another great advantage in terms of operational efficiency. The organization boasts a well-tested governance model, which helps projects run smoothly and scale. OpenInfra's adherence to this model will mean adopting best practices in project management that streamline development cycles and lead to faster implementation of security features. We security administrators will benefit from this governance model in two ways. Integration of new features and updates should become simpler within your systems. More predictable release cycles and documentation will reduce the overhead of keeping systems secure and up-to-date , potentially decreasing the patching frenzy that typically follows less structured release cycles. Supporting Cutting-edge Technologies Ensuring a secure foundational infrastructure is necessary at the forefront of cutting-edge technologies. With their complex computational demands, Artificial Intelligence (AI) and Machine Learning (ML) necessitate a secure yet scalable infrastructure. OpenInfra and the Linux Foundation's partnership strives to support this by making sure open-source toolsused for AI/ML are not only robust but also safe. AI applications often involve sensitive data that requires stringent security measures to safeguard against breaches. As OpenInfra projects align closer with Linux Foundation's standards, these security measures for such applications will strengthen AI/ML solutions providers' confidence that their infrastructure's security can meet these requirements head-on. Better Integration with Global Security Standards The Linux Foundation's dedication to upholding global security standards is another hallmark of its collaboration. Projects under its umbrella are known for complying with these standards, making regulatory requirements easier for organizations to meet. With OpenInfra now part of this ecosystem, organizations can expect improved alignment with international security regulations such as GDPR and HIPAA. Linux security administrators working in regulated industries know firsthand that assuring compliance is often time-consuming. Thanks to increased adherence to security protocols and standards introduced by this merger, this process will become streamlined, reducing administrative burden and mitigating risk from noncompliance penalties. Leveraging Expertise and Resources One key advantage of joining forces is access to available expertise and resources. The Linux Foundation houses numerous projects and working groups specializing in technology and security, which OpenInfra projects can now leverage by joining forces. For us admins, this means having access to an expansive community of security experts who can offer insights and assistance with specific security challenges. Leveraging collective knowledge through forums, working groups, or direct collaboration can significantly boost your capabilities and security strategies, creating an ecosystem designed for continuous learning and improvement that keeps you at the forefront of security practices. Final Thoughts & Looking Ahead OpenInfra's integration into the Linux Foundationmarks an exciting step forward for open-source projects, especially those focused on security. Collaboration, robust security practices, operational efficiency, and compliance with global standards will likely all improve over time, setting new benchmarks for creating and maintaining these projects. This merger marks an exciting time in our community as the OpenInfra Foundation and Linux Foundation join forces to advance infrastructure security and efficiency. Stay engaged, stay secure, and embrace what this game-changing collaboration will offer! . Linux cybersecurity professionals can now benefit from improved protective strategies, resulting from a partnership with the Linux Foundation.. OpenInfra, Linux Foundation, Open Source Security, Security Practices, Compliance Standards. . Brittany Day

Calendar%202 Mar 13, 2025 User Avatar Brittany Day Organizations/Events
210

Navigating Language-Level Vulnerabilities In Patch Management

The patch management process can be painful, tedious, and time and labor intensive. Often, all this effort is for no other purpose than to maintain the operational status quo. And for devs or sysadmins, patch management has to happen on top of handling every-day activities as well as any other additional challenges that occur during service interruptions or system reboots. . When it comes to language-level vulnerabilities, patching challenges today present a proverbial “one-step-forward-two-steps-back” environment for developers. You know what we’re talking about…the hop-on/hop-off/hop-on again merry-go-round of patch management just to ensure a reasonable level of operations, security and compliance. And despite best efforts, there’s always another vulnerability (or two or three or TEN!) right around the corner. When it comes to vulnerabilities, every security professional worth their salt knows that there is no single security answer. Yes, you can implement advanced threat protection, zero trust, and endpoint security. But those solutions aren’t going to get you to the 99.999% solution. An ongoing vulnerability patch management process must be a key component of the overall security solution. . The field of cybersecurity is rapidly changing, particularly regarding language-level vulnerabilities that stem from deeper flaws in programming environments and libraries. Patch Management, Security Compliance, Language Level Vulnerability, Operational Stability. . Brittany Day

Calendar%202 Dec 20, 2022 User Avatar Brittany Day Security Vulnerabilities
77

Data Center Risk Management: 75% Lack Preparedness Against Disruptions

Business technology managers are facing tough challenges as data centers grow larger and more complex. More than 75% of all companies have experienced a business disruption in the past five years, including 20% who say the disruption had a serious impact on the business, according to a recent survey of data center managers. Despite the critical nature of data center operations to business, nearly 17% reported they have no risk management plan, and less than 5% have plans that address viruses and security breaches. . The results, which were announced Tuesday at the Data Center World conference in Atlanta, are part of survey of nearly 200 members of AFCOM, a leading association for data center managers. "Data center professionals need to prepare for what is going on," said Jill Eckhaus, president of AFCOM. "If we don't prepare, companies are not going to be able to run their facilities efficiently. We are hoping we can raise awareness." The link for this article located at Security Pipeline is no longer available. . Data hubs encounter growing intricacies, with approximately 75% reporting interruptions; merely 17% possess contingency strategies.. Data Center Operations,Risk Management,Business Technology. . LinuxSecurity.com Team

Calendar%202 Mar 22, 2006 User Avatar LinuxSecurity.com Team Server Security
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200