Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Uptycs - a leader in cloud-native security analytics - is helping organizations close security observability gaps across attack surfaces with its Uptycs Security Analytics Platform. Learn how Uptycs is helping a SaaS-based payment processing solution vendor automate their risk analysis and reduction strategy. . As a fast-growing organization processing billions of dollars in transactions, risk reduction is of paramount importance to this payment processing solution vendor. Download our case study to learn how this SaaS based company used the Uptycs Security Analytics Platform to secure over 2,000 macOS workstations and 15,000 Ubuntu Linux servers on AWS . With Uptycs, the company was able to achieve: Security observability at scale Analyze behavioral changes or anomalies Detection-as-code automation The link for this article located at Uptycs is no longer available. . Explore how a payment gateway enhanced its fraud detection by integrating automation with Uptycs Security Insights on Linux systems.. Cloud Native Security, Payment Processor Security, Risk Analysis Automation, Threat Detection, Security Analytics. . LinuxSecurity.com Team
Scorecards 2.0 , Google's new open-source security software program, can quickly tell you just how secure - or insecure - open-source software really is. . Some naive people may still think they're not using open-source software. They're wrong. Everyone does. According to the Synopsys Cybersecurity Research Center (CyRC) 2021 "Open Source Security and Risk Analysis" (OSSRA) report , 95% of all commercial programs contain open-source software. By CyRC's count, the vast majority of that code contains outdated or insecure code. But how can you tell which libraries and other components are safe without doing a deep code dive? Google and the Open Source Security Foundation (OSSF) have a quick and easy answer: The OpenSSF Security Scorecards . . Unveil Assessment Metrics 2.0, the latest feature by Google that rapidly and accurately evaluates the safety of publicly available software.. OpenSSF Scorecards, Google Security Assessment, Open Source Code Evaluation. . LinuxSecurity.com Team
A new report shows that stale open-source code is rampant in commercial software, and organizations in all industries are struggling to manage open source risk. "In 2020 the percentage of codebases containing high-risk vulnerabilities jumped from 49 to 60 percent. What was more disturbing is that several of the top 10 open source vulnerabilities found in 2019 codebases reappeared in the 2020 audits, all with significant percentage increases." . Organizations, regardless of industry, must do a better job maintaining open source components given their critical nature in software, according to this year’s risk analysis report by cybersecurity firm Synopsys . Open source software is now the foundation for the vast majority of applications across all industries. But many of those industries are struggling to manage open source risk. Synopsys released the 2021 Open Source Security and Risk Analysis (OSSRA) report on April 13. The report examines open source audit results, including usage trends and best practices across commercial applications. . Due to escalating dangers highlighted in recent evaluations, organizations need to enhance the management of open source elements.. Open Source Management, Software Security, Risk Analysis. . Brittany Day
Adopting open-source software and technology has the potential to improve an organizations' security posture if this technology is properly monitored and maintained. A new report from Synopsys indicates that many organizations are falling down on the job, resulting in serious security issues. . Outdated or abandoned open source components are persistent in practically all commercial software, putting enterprise and consumer applications at risk from security issues, license compliance violations, and operational threats, according to the Synopsys 2020 Open Source Security and Risk Analysis Report released Tuesday. Synopsys researchers analyzed more than 1,250 commercial code bases. The Synopsys Cybersecurity Research Center (CyRC) examined the code base audits performed by the Black Duck Audit Services team. The report highlights trends and patterns in open source usage within commercial applications. It provides insights and recommendations to help organizations better manage their software risk. . Neglected or obsolete open source libraries expose proprietary software to vulnerabilities, underscoring issues in oversight.. Open Source Management, Software Risk Analysis, Security Recommendations, Commercial Software Risk. . Brittany Day
Out of band authentication . But RSA's Anti-Fraud Command Center on Monday found and reported on a Trojan called Bugat that has been updated to hijack out-of-band authentication codes sent to bank customers via SMS. This doesn't mean out-of-band authentication via text messaging is useless, but it can be compromised using a dated, unsophisticated piece of malware. The link for this article located at American Banker is no longer available. . The Cybersecurity Agency warns of the Zett Malware intercepting mobile transaction confirmations, underlining the potential threat.. Bugat Trojan, SMS Authentication, Banking Malware, Trojan Risks, Out-of-Band Authentication. . LinuxSecurity.com Team
On Saturday, multimedia producer and Twitter user Daniel Dennis Jones . The link for this article located at Buzzfeed is no longer available. . A critical security flaw has been identified in Twitter, risking unauthorized access due to weak account recovery validation and enabling potential misuse of accounts. Twitter Security Flaw, Account Theft Risk, Cyber Threat Analysis. . LinuxSecurity.com Team
Understanding the business risk posed due to security threats is crucial for IT managers and security officers, two analysts have claimed. Addressing a media roundtable in Sydney at the Gartner Symposium, Andrew Walls and Rob McMillan said CIOs and CSOs must be abreast of their organisations. The link for this article located at Network World is no longer available. . The link for this article located at Network World is no longer available.. understanding, business, posed, security, threats, crucial, managers, securit. . Anthony Pell
Ross Anderson reports (via Bruce Schneier blog): Online transactions with credit cards or debit cards are increasingly verified using the 3D Secure system, which is branded as "Verified by VISA" and "MasterCard SecureCode". This is now the most widely-used single sign-on scheme ever, with over 200 million cardholders registered. It's getting hard to shop online without being forced to use it. . In a paper I'm presenting today at Financial Cryptography, Steven Murdoch and I analyse 3D Secure. From the engineering point of view, it does just about everything wrong, and it's becoming a fat target for phishing. So why did it succeed in the marketplace? Quite simply, it has strong incentives for adoption. Merchants who use it push liability for fraud back to banks, who in turn push it on to cardholders. Properly designed single sign-on systems, like OpenID and InfoCard, can't offer anything like this. So this is yet another case where security economics trumps security engineering, but in a predatory way that leaves cardholders less secure. We conclude with a suggestion on what bank regulators might do to fix the problem. The link for this article located at Bruce Schneier is no longer available. . In a paper I'm presenting today at Financial Cryptography, Steven Murdoch and I analyse 3D Secure. F. anderson, reports, bruce, schneier, blog), online, transactions, credit, cards, debit. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.