Open Source vulnerabilities rose by nearly 50 percent in 2019 over the previous year, based on a report released Thursday. . Common vulnerabilities rated as high or critical severity were found in all of the most popular open source projects, according to the WhiteSource 2020 annual report, "The State of Open Source Security Vulnerabilities." The vulnerability rate is expected to continue rising. As open source usage continues to grow, so does the number of eyes focused on open source security research. This resulted in a record-breaking number of published open source security vulnerabilities last year, according to the report. . Numerous significant weaknesses categorized as high or critical risk have been identified across all leading open source software initiatives.. open source vulnerabilities, security risks, threat analysis. . Brittany Day
Requests from governments worldwide for user information have more than doubled since three years ago. Worse still, says Google, is what the US won't let us tell you.. The US government is on a data-gathering spree at Google, new data from the search giant reveals. Between January and June 2013, the US government issued nearly 11,000 requests to Google asking for user information, or about 42 percent of the global total. India was second with nearly 2,700 government requests. The link for this article located at CNET is no longer available. . Facebook highlights an increase in international demands for user information, shedding light on evolving issues in privacy and data security.. User Data Requests, Government Regulations, Data Privacy, Google User Data, Surveillance Trends. . LinuxSecurity.com Team
A security testing firm today said a recent report that named Google's Chrome as the most secured browser was flawed -- and part of a campaign by Google to undermine Mozilla's Firefox.. The work done by Denver-based security consultancy Accuvant, which released a report last week naming Chrome as more secured than either Firefox or Microsoft's Internet Explorer (IE), was paid for by Google. That raised the hackles of NSS Labs, a California company that tests browser security and antivirus software. The link for this article located at Network World is no longer available. . The latest study from SecureNet on web browser vulnerabilities has ignited claims suggesting that Microsoft is attempting to weaken Chrome's standing.. Browser Security, Firefox Tension, Google Accusations, Chrome Security, Security Testing. . LinuxSecurity.com Team
The number of companies reporting a spyware infestation has increased by almost half in the past 12 months, according to a new survey. In addition, 17 percent of companies with more than 100 employees have spyware such as a keylogger on their networks, said the authors of the annual Websense Web@Work survey, published on Tuesday. "This is almost 50 percent growth in the instances of keyloggers that organizations are reporting back," said Joel Camissar, a manager for Internet security specialist Websense. . "Despite the organizations' having a 'best of breed' antivirus, anti-spyware and firewall, we are still detecting a huge amount of back-channel spyware communication." Spyware is seen as an increasingly serious security problem, and the U.S. Federal Trade Commission has pledged to take action against companies that distribute it. The software is installed on machines without the owner's knowledge to track their online habits, sometimes via a keylogger, which records the user's keystrokes. . Rising usage of malware, such as screen capture tools, intensifies threats as organizations disclose severe breaches. Learn more.. Spyware Threats, Keylogger Incidents, Network Monitoring Tools. . LinuxSecurity.com Team
After three years of modest or no gains, the number of publicly reported vulnerabilities jumped in 2005, boosted by easy-to-find bugs in web applications. Yet, questions remain about the value of analyzing current databases, whose data rarely correlates easily. A survey of four major vulnerability databases found that the number of flaws counted by each in the past five years differed significantly. However, three of the four databases exhibited a relative plateau in the number of flaws publicly disclosed in 2002 through 2004. And, every database saw a significant increase in their count of the flaws disclosed in 2005. . A few common themes emerged from the data as well. In 2005, easy-to-find flaws in web applications were likely responsible for the majority of the increase, the database managers said in interviews with SecurityFocus. However, some of the increase came from a doubling in the number of flaws released by large software companies. The link for this article located at TheRegister.co.uk is no longer available. . The rising number of documented flaws underscores patterns in software security gaps following an extended period of consistency.. Public Vulnerabilities Trends, Web Application Bugs, Vulnerability Data Analysis. . LinuxSecurity.com Team
Five working groups formed at the National Cyber Security Summit released initial reports that focus on delivering concrete results within a year, task force leaders said Thursday.. . .. Five working groups formed at the National Cyber Security Summit released initial reports that focus on delivering concrete results within a year, task force leaders said Thursday. The working groups have pledged to release white papers by March 1, 2004, that outline their recommendations for securing businesses and consumers and creating more secure software. The next meeting, tentatively set for September 2004, will be the deadline for each group to deliver at least some results. "A concern is that if we were to meet in (a year), can we show progress?" said Mary Ann Davidson, chief security officer at database maker Oracle and the co-chair of the Technical Standards and Common Criteria Task Force, one of the five working groups. "Even if we make recommendations, we should prioritize, and one of the priorities should be showing results in a year or less." The link for this article located at CNET is no longer available. . At the Tech Innovation Forum, six collaborative teams were established to prioritize practical outcomes and hardware security strategies.. Task Force, Cybersecurity, Software Security, Result-Oriented. . LinuxSecurity.com Team
A UK based security firm claimed today that digital attacks on Web sites using the Linux operating system have reached an all-time high over the last three months. British firm mi2g claimed that Windows based servers were more resilient from March . . . . A UK based security firm claimed today that digital attacks on Web sites using the Linux operating system have reached an all-time high over the last three months. British firm mi2g claimed that Windows based servers were more resilient from March to May for corporate and government systems. It issued figures saying that the reason for the vulnerabilities was down to improperly configured systems, lack of a "trustworthy" computing initiative, and corporations choosing Linux because of its cost but not costing in technical support overheads. The link for this article located at The Inquirer is no longer available. . Cyber intrusions targeting Linux-endowed web platforms have escalated dramatically in the past few weeks, hitting unprecedented heights as reported by a cybersecurity company.. Linux Server Security, Digital Attack Trends, Security Breach Reports. . LinuxSecurity.com Team
The report entitled "Security and Privacy for the Citizen in the Post-September 11 Digital Age: A Prospective Overview" focuses on the potential threats to security and privacy of three particular technologies. They are identity management, such as on-line services that require . . . . The report entitled "Security and Privacy for the Citizen in the Post-September 11 Digital Age: A Prospective Overview" focuses on the potential threats to security and privacy of three particular technologies. They are identity management, such as on-line services that require the identification of the user; location-based services focused on the positioning and tracking the user; and "smart" and mobile devices connected to user homes, offices and cars. The link for this article located at ElectricNews.net is no longer available. . In our digital world, the blend of identity management and location tracking poses serious privacy threats, risking identity theft and unwanted surveillance by corporations and governments. Privacy Threats, Identity Management, Location Services, Digital Security, Security Report. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.