Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Today, organizations rely heavily on technology for their operations, to secure important information and provide services in a digital world. Digital transformation opens up new opportunities, but also poses an increasing challenge for businesses and institutions in the field of cybersecurity. Data breaches, financial losses, reputational damage, and compliance issues are ongoing challenges for organizations in all industries due to security weaknesses and regulatory shortcomings. . With the ever-evolving nature of cyber attacks, businesses need to enhance security infrastructures and tackle regulatory weaknesses exposing vital systems to attack. Knowing about these weaknesses and shortcomings is critical to developing cybersecurity-resilient strategies and to keeping stakeholders happy. Understanding Security Weaknesses in Modern Organizations Security weaknesses are potential points of attack in systems, networks, applications, or organizational processes. Such vulnerabilities can result from old technologies, inadequate security protocols, human error, or lack of risk management. Security vulnerabilities are often not identified until after an actual security incident. Unfortunately, the hackers are out and looking for these vulnerabilities, and proactive security assessments are more critical than ever. Common Types of Security Weaknesses Multiple security flaws are frequent causes of cyber incidents, including: Weak password policies Computers and systems that are not patched. Misconfigured cloud environments Inadequate access controls Lack of cybersecurity training for employees: Insufficient network monitoring Third-party vendor vulnerabilities If these issues are not addressed by the organizations, they leave chances for unauthorized access, malware infection, ransomware attack, and data theft. Human Error Remains a Major Risk Cybersecurity risks cannot be totally removed by technology. Employees can be the biggest vulnerability in anorganization's security. Phishing, social engineering, and unintentional disclosure remain problems for all users of the internet. Regular cybersecurity awareness training is a must for organizations to ensure that their employees are well-equipped to recognize threats and follow secure practices. Creating a culture of security helps limit successful attacks. The Growing Impact of Regulatory Shortcomings Regulatory safeguards are critical to the security of data, accountability, and best cybersecurity practices. But many of the regulations have a difficult time catching up with the ever-changing technology and new cyber threats. Regulatory gaps can be caused by laws, standards, or regulatory enforcement that do not respond to today's security challenges. These gaps can make organizations vulnerable to compliance requirements and decrease cybersecurity effectiveness. Challenges Facing Current Regulatory Frameworks There are several challenges to the existing regulatory frameworks. Rapid Technological Evolution The pace of change in technology far outpaces many regulatory processes. AI, cloud technology, Internet of Things (IoT) devices, and linked health systems present novel challenges that the current regulatory framework may not adequately cover. This is why organizations can sometimes find themselves in a situation where their cybersecurity is not as good as the technology they are using. Inconsistent Global Regulations Companies with a global presence often have varying cybersecurity and data protection needs. The mismatch makes it difficult to achieve compliance and raises the complexity of operations. There are multiple legal frameworks that organizations must navigate through, and security controls can be a challenge to keep effective, creating compliance gaps. Limited Enforcement Capabilities Regulations may be present, but regulatory bodies may not have the resources or authority to ensure that these are adhered to. Ifsome organizations don't see a return on investment, then they don't invest. Weak enforcement of the rules lowers the incentive for some organizations to make cybersecurity investments. Oversight and tangible consequences promote compliance and security practices. The Relationship Between Security Weaknesses and Regulatory Gaps Vulnerabilities and shortcomings in security often compound one another in a vicious cycle. Lack of definition in regulations can lead to under-investment in security. Likewise, a high degree of susceptibility can reveal already identified weaknesses of the regulatory frameworks. As healthcare institutions handle patient information and medical apparatus, they are particularly vulnerable to cybersecurity concerns, for instance. Regulatory bodies are keeping their requirements on the rise as part of their efforts to counter these risks. An FDA cybersecurity deficiency letter may indicate that a medical device manufacturer's cybersecurity documentation, risk assessment, or cybersecurity controls need to be improved before meeting regulatory expectations. This is a prime example of the ever-increasing link between cybersecurity readiness and regulatory compliance . Finding Problems Before Someone Else Does Most organizations only stumble upon their own security holes after a painful audit or a live incident. By then, the weakness might have been an open door for years. Regular risk assessments aren't just about checking boxes; they’re about brutal honesty. You have to look at your shadow IT, your sprawling permissions, and your third-party dependencies with a skeptical eye. The real goal isn't creating another compliance report. It is figuring out where your crown jewels are, how they’re actually held together, and exactly how bad things get when the current defenses buckle. Visibility is just as vital as assessment. If you aren't monitoring your environment, you’re flying blind. Real-time logging catches the noise—the weird privilege escalation,the odd admin behavior, or the spike in traffic—long before a user reports a problem. If you can’t see the activity, you effectively don’t have a defense. Focus on the Controls That Fail Most Often Security reviews often turn up the same recurring ghosts. Access control is usually the biggest offender. Employees shift roles, contractors come and go, and "temporary" service accounts turn permanent. Because the business keeps running, nobody notices the access bloat until a breach happens. If an account with stale, excessive permissions gets hijacked, the blast radius is almost always worse than anyone anticipated. Software maintenance is equally fragile. Often, it isn't that a patch is missing; it’s that the organization has lost track of the asset. Legacy servers and "forgotten" applications often sit outside the normal update rhythm. You can’t patch what you don’t know you own. Then there is training. Annual slideshows might satisfy an auditor, but they rarely prepare a human to spot a sophisticated social engineering attempt. Effective training feels less like a corporate mandate and more like a tactical briefing—giving employees realistic scenarios and a clear, non-punitive path to report when something just doesn’t look right. Where Regulation Still Struggles Organizations aren’t the only ones playing catch-up. The reality is that regulatory frameworks move like tectonic plates, while the technology we’re building on moves like a jet engine. We’re trying to secure cloud-native architectures, fragmented supply chains, and remote-first teams using rulebooks that were written for a different era. Because of that disconnect, security teams often spend thousands of hours performing "compliance theater"—ticking boxes for an auditor—instead of actually shoring up their defenses. It’s a massive drain on resources that could be better spent on real security. What we actually need is clearer, more pragmatic guidance. Right now, when requirements are vague, it’sa guessing game. Auditors interpret things one way, security teams another, and the work devolves into busywork. Real progress happens when a regulator tells us what outcome they need, rather than forcing a checklist that was outdated three years ago. Industry collaboration is the only way out of this trap. When security practitioners, vendors, and regulators actually speak the same language—sharing what’s breaking in the trenches rather than just reciting standards—we all get smarter. It’s about learning from each other’s scars so we don’t repeat the same expensive mistakes. Accountability still matters, of course, but it’s only effective when the goalposts aren't constantly moving. When the requirements are practical and the link between good hygiene and staying in business is obvious, organizations don't just comply—they invest. Final Thoughts Most of the time, security failures aren't the result of some high-tech, movie-style "zero-day" attack. They’re usually just boring, preventable stuff: an unpatched server, an old account that should have been deleted, or a total lack of visibility into what’s happening on the network. The hardest part of this job isn't spotting the gaps; it’s finding the discipline to close them before they end up on the evening news. The teams that actually move the needle don't obsess over "perfect" security. They obsess over the fundamentals. They know exactly what assets they’re running, who has the keys to them, and they’ve set up enough monitoring to actually see when something looks off. Regulators have to hold up their end of the bargain, too. They need to ensure that compliance isn't just a hurdle but a framework that keeps pace with the tech we’re actually using today. At the end of the day, the goal isn't a flawless system—because that doesn't exist. The goal is to shrink the window of opportunity so that a small human oversight doesn't spiral into a catastrophic failure. . Organizations face ongoing cybersecuritychallenges due to security weaknesses and regulatory gaps. Discover common flaws and proactive measures.. cybersecurity risk assessment,data protection compliance,security weaknesses analysis,regulatory compliance gaps. . Anthony Pell
As Linux security admins, staying abreast of evolving regulations is vital to ensuring the resilience and compliance of our systems. A recent initiative by the Linux Foundation Europe and OpenSSF to support implementation of the European Union Cyber Resilience Act (CRA) promises to transform how we manage security and compliance within the open-source software ecosystem by formalizing guidelines and tools that meet the stringent requirements set out by the CRA. . By mandating measures like secure software design, robust vulnerability reporting, and transparent Software Bills of Materials (SBOMs), our day-to-day operations will experience a noticeable shift towards more disciplined security practices. Let's examine this initiative and its implications for your Linux security administration and your systems' compliance with CRA's standards and regulations. Understanding the Cyber Resilience Act To fully appreciate this initiative, it is necessary to understand the Cyber Resilience Act (CRA) . Enforced since December 2024, this comprehensive regulation seeks to increase digital product and service security within Europe. CRA mandates that security must be integrated into software design processes from their inception, and developers must be held responsible for vulnerability reporting and management services within their products. Also, transparent software dependency lists with SBOMs are an integral element. As a Linux security admin, your job extends far beyond protecting the infrastructure within which your systems reside. It involves ensuring all software running on them also complies with these new standards. This requires reassessing how software is sourced, developed, and maintained while emphasizing proactive security measures and thorough documentation. Enhancing Security Practices The requirements set out by CRA have fundamentally transformed how we approach system security. One key implication of their requirements is to incorporate security from the onset of software design -known as "security by design." This concept ensures that security considerations do not become an afterthought but are integrated into every stage of software creation. Linux security admins must work closely with development teams to ensure security protocols are strictly followed from the outset, including regular code reviews, threat modeling, and testing of security features as part of the development process. Taking an early detection and mitigation approach to vulnerabilities reduces risks associated with potential exploits. As soon as the CRA was implemented, its significance became even clearer. The upkeep of systems cannot be underestimated. Regular software patches and updates to address known vulnerabilities are imperative to creating resilient infrastructure. Tools and guidelines developed under the Linux Foundation Europe/OpenSSF initiative will also play a significant role in supporting enhanced security practices. Management of Software Bills of Materials (SBOMs) A core requirement of the CRA is transparency in software dependencies through SBOMs . An SBOM provides a detailed listing of components and dependencies within the software, making tracking vulnerabilities easier and ensuring compliance with regulations such as the CRA. Linux security administrators responsible for managing SBOMs must implement tools that automatically generate and maintain these inventories, track open-source components, evaluate their security posture, and promptly respond to vulnerabilities in software supply chains. Becoming proficient at managing SBOMs assists compliance and strengthens overall software supply chains. Compliance Tracking and Management Ensuring compliance with CRA standards requires constant oversight of all software and devices in your infrastructure, which makes compliance tracking essential. Compliance tracking involves keeping detailed records of security measures, software updates, vulnerability management activities, etc., demonstrating adherence to thesestandards. Administrators must establish efficient methods for documenting compliance activities and being ready for audits, including clear records of patch management, vulnerability assessments, and security testing results. Tools and guidelines created through Linux Foundation Europe and the OpenSSF initiative provide invaluable resources to aid administrators in streamlining these compliance tracking processes. Collaboration and Community Involvement Collaboration is at the core of open-source communities, and this initiative puts that strength to use to its maximum. The Linux Foundation Europe and OpenSSF are working with numerous stakeholders, including companies like ARM, Ericsson, GitHub, Kusari, OpenJS Foundation, and Red Hat Rust Foundation. Through such close cooperation, tools and guidelines that are comprehensive yet broadly applicable can be created. Engaging actively with the Linux security community is vital. Subscribing to industry newsletters and tracking updates on social channels will keep you abreast of recent events and developments. Contributing open source projects supporting this initiative also offers an invaluable opportunity to collectively share knowledge and enhance security practices. Education and Adaption With cybersecurity becoming ever-more dynamic, ongoing education and adaptation are critical. The initiative by Linux Foundation Europe and OpenSSF brings new tools, frameworks, or best practices that administrators must adopt. Keeping current with these resources and learning about emerging security threats is paramount to success. Furthermore, the advent of the CRA marks a growing global trend toward tightening security regulations by adapting proactively to this shift in policies and adapting their systems as necessary to comply with current requirements while being prepared for potential security threats in the future. Our Final Thoughts on This Security & Compliance Initiative The partnership between Linux Foundation Europe and OpenSource Security Foundation to implement the Cyber Resilience Act marks a historic moment in Linux security administration. This initiative emphasizes the necessity of enhanced security practices, rigorous compliance tracking, and effective management of SBOMs, fundamentally altering how we approach system security. Linux security administrators can benefit by accepting these changes, actively engaging with the open source community's efforts, and accepting tools and guidelines being developed to meet CRA requirements - ultimately increasing supply chain security. As the cybersecurity landscape transforms, staying informed, gaining new knowledge, and adapting to evolving regulations will become increasingly critical. This initiative offers an ideal way of strengthening security practices on Linux systems in response to emerging threats - providing increased resilience against them. . Adhering to GAAP regulations is essential for system administrators to safeguard data integrity and respond to changing legislation.. Cyber Resilience Act, compliance tracking, open source security, software dependencies, secure software design. . Brittany Day
Cybersecurity is more essential than ever as threats grow more sophisticated and defenses continue to evolve. In 2025, businesses and individuals alike face unique challenges requiring innovative strategies. This overview dives into the key cybersecurity trends shaping our current reality and provides actionable insights to bolster your defenses. . Rise of AI and Machine Learning in Cybersecurity Artificial Intelligence (AI) and Machine Learning (ML) have already made significant strides in cybersecurity, but in 2025, these technologies will become even more integral to threat detection and response. AI-powered tools are increasingly adept at analyzing vast amounts of data in real-time, identifying patterns, and predicting potential threats more accurately. AI-driven Threat Detection: Traditional security measures often struggle to keep up with sophisticated and rapidly evolving threats. AI systems, however, can analyze network traffic, detect anomalies, and respond to threats faster than human teams. In 2025, we can expect AI to become even more advanced, with improvements in natural language processing and behavioral analytics enhancing threat detection capabilities. In particular, generative AI-powered attacks, such as custom phishing emails, have added new dimensions to the threat landscape. Automated Incident Response: AI-powered automation is expected to revolutionize incident response. Automated systems can detect threats and initiate responses, such as isolating affected systems or blocking malicious traffic, without human intervention. This rapid response can significantly reduce the damage caused by cyber incidents. The Critical Role of Open Source: The rise of Artificial Intelligence (AI) and Machine Learning (ML) in cybersecurity has been significantly propelled by the open-source movement. Open-source software and tools have democratized access to advanced AI and ML technologies, allowing researchers, developers, and cybersecurity professionals tocollaborate and innovate without the constraints of proprietary systems. This collaborative environment has accelerated the development and refinement of AI algorithms and ML models that are essential for identifying, analyzing, and responding to cyber threats with unprecedented speed and accuracy. By leveraging open-source platforms, cybersecurity solutions can rapidly evolve in response to new threats, benefiting from the collective expertise and contributions of a global community. This communal approach to development not only fosters innovation but also ensures a broader, more inclusive evolution of cybersecurity technologies that can adapt to the ever-changing landscape of cyber threats. Moreover, the transparency inherent in open-source initiatives allows for the rigorous examination and validation of AI and ML models by a wide array of experts, ensuring that these technologies are robust, secure, and without hidden vulnerabilities. In parallel, organizations are exploring post-quantum cryptography to prepare for quantum computing's future impact on encryption. This aspect is particularly pertinent, given the increasing sophistication of cyberattacks and the potential for AI-driven systems to be exploited if not properly scrutinized. Open Source also facilitates a more equitable distribution of cutting-edge cybersecurity tools, enabling organizations of all sizes to defend themselves effectively against cyber threats. This has the added advantage of raising the overall security posture of the digital ecosystem, as even smaller entities can deploy advanced AI-driven defense mechanisms. Increased Focus on Zero Trust Architecture The Zero Trust model has been gaining traction in recent years, and its adoption is set to accelerate in 2025. Zero Trust operates on the principle of “never trust, always verify,” meaning that no entity, whether inside or outside the network, is trusted by default. Instead, every access request must be continuously validated. Micro-Segmentation : ZeroTrust involves segmenting networks into smaller, more manageable segments. This micro-segmentation limits the lateral movement of attackers within the network, reducing the risk of widespread breaches. In 2025, organizations will increasingly implement micro-segmentation to enhance their security posture. Continuous Monitoring and Verification : Rather than relying on perimeter defenses, Zero Trust emphasizes continuous monitoring of user behavior and device health. This approach ensures that access is granted based on up-to-date assessments of risk and trustworthiness. Expansion of Cybersecurity for IoT Devices The Internet of Things (IoT) continues to proliferate, with over 25 billion connected devices entering homes and businesses. However, many IoT devices are notoriously vulnerable to cyberattacks due to inadequate security measures. Enhanced IoT Security Standards : In response to the growing threat, 2025 will see increased efforts to establish and enforce robust security standards for IoT devices . Manufacturers and regulatory bodies will work together to ensure that IoT devices are designed with security in mind, incorporating features such as encryption and secure authentication. Network Segmentation for IoT : To mitigate the risks associated with IoT devices, organizations will adopt network segmentation techniques to isolate these devices from critical systems. This approach limits the potential impact of a compromised IoT device on the broader network. Growth of Ransomware and New Mitigation Strategies Ransomware attacks have surged in recent years, and the trend is expected to continue in 2025. Attackers are using increasingly sophisticated tactics, such as double extortion and even triple extortion, where attackers target victims' customers or partners to amplify pressure. Ransomware Preparedness : Organizations will need to bolster their ransomware preparedness by implementing comprehensive backup strategies, ensuring that backups are stored offline or in immutableformats. Regular testing of backup restoration processes will also become a standard practice. Ransomware Negotiation and Payment Policies : Companies are likely to develop clearer policies regarding ransomware negotiation and payment. Some organizations may choose to work with cybersecurity firms specializing in negotiating with attackers, while others may adopt a no-payment policy to discourage the criminal industry. Rise in Linux Ransomware: Due to its widespread deployment across servers and backend systems, Linux ransomware represents an alarming trend that threatens corporate and cloud environments alike. As hackers have realized Linux's significance to businesses, they have developed ransomware variants specifically tailored to exploit vulnerabilities in this popular OS. As such, researchers and developers from within the cybersecurity community have increased efforts to fortify Linux environments. Strategies include regularly applying updates and patches to address known vulnerabilities, employing enhanced monitoring tools that detect suspicious activities that indicate ransomware attacks, and investing in reliable backup solutions that allow rapid recovery without incurring ransomware payments. Additionally, the community supports and advocates for best practices such as least privilege principles and multi-factor authentication. Open-source initiatives play an integral role by developing tools and sharing knowledge to facilitate early detection and mitigation of threats—thus encouraging a proactive rather than reactive security posture. Increased Emphasis on Cybersecurity Skills and Training As cyber threats become more sophisticated, the demand for skilled cybersecurity professionals continues to outpace supply. In 2025, the focus will be on addressing this skills gap through enhanced training and development programs. Upskilling and Reskilling Initiatives : Organizations will invest in upskilling their existing IT staff and providing specialized training forcybersecurity roles. Partnerships with educational institutions and online training platforms will become more prevalent, aiming to build a pipeline of skilled cybersecurity professionals. A great example is the range of online IT courses that provide accessible and practical pathways into cybersecurity and other IT fields. Awareness and Training for Employees : Beyond specialized roles, all employees will need to be educated about cybersecurity best practices. Regular training on topics such as phishing awareness, password management, and safe internet usage will be critical in reducing the risk of human error. Strengthening Cybersecurity Regulations and Compliance Regulatory bodies continually update and expand cybersecurity regulations to address new threats and vulnerabilities. In 2025, we can expect a more stringent regulatory compliance environment with increased enforcement and compliance requirements. Global Data Protection Regulations: With the rise of data privacy concerns, global data protection regulations will become more comprehensive. Organizations will need to stay abreast of international regulations such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) , ensuring compliance to avoid hefty fines. New regulations such as the Digital Operational Resilience Act (DORA) in Europe are shaping how organizations must approach cybersecurity resilience. Industry-Specific Standards: Besides general data protection laws, industry-specific standards will gain prominence. Finance, healthcare, and critical infrastructure sectors will face more rigorous cybersecurity requirements tailored to their unique risks. Our Final Thoughts on 2024 Cybersecurity Trends Cybersecurity will be shaped by significant technological advancements, shifting threats, and tighter regulatory oversight. Staying informed about trends and adopting proactive measures will allow organizations and individuals to strengthen their defenses against cyberthreats. Key strategies include leveraging AI and machine learning, adopting Zero Trust principles, securing IoT devices, preparing for ransomware, investing in cybersecurity skills, and adhering to regulatory standards. Collaboration and vigilance are essential for maintaining a strong and adaptable cybersecurity posture in this dynamic environment. . Examine prominent cybersecurity developments in 2025, focusing on artificial intelligence, ransomware tactics, and Internet of Things vulnerabilities, to bolster your protective strategies.. Cybersecurity Trends, AI Tools, Ransomware Preparedness, IoT Security, Open Source Innovations. . Brittany Day
Canonical has launched Ubuntu Pro for Devices , a comprehensive offering emphasizing security and compliance for IoT device deployments. This initiative aims to provide 10 years of security maintenance for Ubuntu and thousands of open-source packages, along with device management capabilities through Landscape , a systems management tool by Canonical. Ubuntu Pro also ensures that IoT devices receive reliable security patches from a trusted source. . The Growing Importance of Security & Compliance in the Embedded Space This launch emphasizes the growing importance of open-source security and compliance, particularly in the embedded space. Canonical has collaborated with original device manufacturers (ODMs), including ADLINK, AAEON, Advantech, and DFI, showcasing a growing demand for open-source security and compliance in IoT deployments. Furthermore, this release underscores the evolving regulatory landscape and the growing need for reliable, long-term access to software security fixes. The EU Cyber Resilience Act and the U.S. Cyber Trust Mark raise questions about how these regulatory changes will impact IoT deployments and open-source software security in the long term. Timely CVE fixes are crucial for regulatory approval, reflecting the increasing necessity for secure and compliant software solutions. Thanks to Ubuntu Pro for Devices, this is now covered. Ubuntu Pro for Devices' cost-effective and convenient fleet management aspect should also be highlighted, particularly regarding remote device management for IoT. Integrating Landscape to manage devices and provide 10 years of security updates demonstrates a commitment to streamlined fleet maintenance. What Are the Security Implications of Ubuntu Pro for Devices? IoT security is paramount, given the increasing number of connected devices and their potential vulnerabilities. Admins must consider the security implications of Ubuntu Pro for Devices. This offering allows these professionals to enhance their IoT device security,compliance, and fleet management practices. It raises questions about the practicality and effectiveness of a 10-year security maintenance commitment in a rapidly evolving technological landscape. How will this offering impact the open-source community's approach to security and compliance in the long term? This offering significantly impacts IoT security practices, compliance, and effective fleet management, enabling admins and security professionals to adapt and evolve their security strategies. The inclusion of hardening profiles and compliance with standards such as FIPS , HIPAA , and PCI-DSS widens the scope for security practitioners to explore regulatory compliance within their respective regions and industries, sparking curiosity about how Ubuntu Pro for Devices can accommodate diverse compliance requirements internationally. Our Final Thoughts on the Launch of Ubuntu Pro for Devices The launch of Ubuntu Pro for Devices presents a significant development for security practitioners, especially within the IoT space. By extending security maintenance to 10 years, addressing regulatory compliance, and enhancing fleet management, this offering can influence long-term approaches to open-source security and compliance, prompting security practitioners to evaluate their strategies and adapt to evolving IoT security demands. . Explore the ways Ubuntu Pro for Devices elevates IoT security and adheres to compliance standards through comprehensive management solutions and extended support.. IoT Device Management, Open-Source Compliance, Fleet Maintenance, Embedded Security. . Anthony Pell
Are you a privacy advocate? Have you heard that global privacy regulators have announced an investigation into controversial facial recognition firm Clearview AI? . “The Office of the Australian Information Commissioner (OAIC) and the UK’s Information Commissioner’s Office (ICO) have opened a joint investigation into the personal information handling practices of Clearview AI Inc., focusing on the company’s use of ‘scraped’ data and biometrics of individuals,” a brief statement read. “The investigation highlights the importance of enforcement cooperation in protecting the personal information of Australian and UK citizens in a globalized data environment.” . International authorities are scrutinizing Clearview AI, particularly regarding its management of personal information and biometric data.. Privacy Investigation, Data Protection, Clearview AI, Biometric Data. . LinuxSecurity.com Team
The race to comply with the European Union's General Data Protection Regulation (GDPR) by the May 25 deadline is over, but data security and privacy is a marathon, not a sprint. If the ever-evolving regulatory compliance landscape is any indication, GDPR is just the first of many mandates to come.. Although it certainly has been a headache for many organizations — with large firms allocating an average of $20 million to $25 million to become GDPR compliant — the GDPR is the catalyst for a much-needed global, all-encompassing data security and privacy law. This is something we need sooner rather than later.. Although it certainly has been a headache for many organizations — with large firms allocating an . comply, european, union's, general, protection, regulation, (gdpr). . LinuxSecurity.com Team
Mobily, a Saudi Arabian telecommunications company with 4.8 million subscribers, is working on a way to intercept encrypted data sent over the Internet by Twitter, Viber, and other mobile apps, a security researcher said Monday.. Moxie Marlinspike, the pseudonymous cryptographer who has identified several security bugs in the secure sockets layer protocol used to protect website transactions, said he learned of the project after receiving an e-mail from company officials. Carrying the subject line "Solution for monitoring encrypted data on telecom," it said the project was required by "the regulator." Marlinspike believed this meant the government of Saudi Arabia.. A UAE-based telecommunications company investigates strategies to decrypt secure messages for adherence to legal standards.. Mobily Telecom, Encrypted Data, Telecom Monitoring, Encrypted Communications. . LinuxSecurity.com Team
AT&T continues to breach net-neutrality regulations despite an announcement that it would begin offering Apple. The nation The link for this article located at Wired is no longer available. . The nationThe link for this article located at Wired is no longer available.. at&, continues, breach, net-neutrality, regulations, despite, announcement, would, begin. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.