Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The Linux Foundation's OpenSSF is offering training courses to help keep the open source ecosystem secure by teaching DevOps professionals how to develop secure software. . Open Source Security Foundation (OpenSSF), hosted at the Linux Foundation, announced on Thursday that it is offering free training for developing secure software as well as adding a new certification and providing program and technical initiatives. OpenSSF is a cross-industry collaboration to secure the open source ecosystem. Open source software is available across all industries and making sure it is secure is more important than ever before. . The Open Source Security Foundation (OpenSSF), under the Linux Foundation, provides free educational programs aimed at improving secure coding skills for developers.. OpenSSF Training, Secure Software Development, Linux Foundation Programs. . Brittany Day
A nippy microkernel mathematically proven to be bug free*, and used to protect drones from hacking, will be released as open source tomorrow.. The formal-methods-based secure embedded L4 (seL4) microkernel was developed by Australian boffins at National ICT Australia (NICTA) and was part of the US Defense Advanced Research Projects Agency's High-Assurance Cyber Military Systems program hatched in 2012 to stop hackers knocking unmanned birds out of the sky. The link for this article located at The Register UK is no longer available. . The innovative seL4 microkernel, created by DARPA, is set to be made available as open-source software, providing a strong shield against digital security vulnerabilities.. seL4 Microkernel, Open Source Software, Secure Embedded Systems, Cyber Defense. . LinuxSecurity.com Team
Security has seldom been a priority in application development, but pressure from businesses stuck patching faulty software is having an impact on the industry.. Among the large software makers that have seen the light is Microsoft, which is pushing Windows developers to adopt a standard methodology and framework for building secure applications. The link for this article located at CSO Online is no longer available. . Influence from corporations is compelling software engineers to emphasize cybersecurity and embrace best practices.. Application Security, Secure Development Practices, Software Standards. . LinuxSecurity.com Team
Adobe has released the next-generation version of its Reader software that includes a protected mode to prevent attacks through PDF files. The release of Adobe Reader X on Windows follows closely behind Adobe Acrobat X.. Both products include the protected mode, which uses a sandbox approach to prevent hacker attacks and has been built with input from business users and from across the software industry, including Microsoft and Google. The security initiatives are aimed at reducing both the frequency and the impact of security vulnerabilities, said Adobe.. Adobe Acrobat Pro DC integrates an advanced safety feature employing isolation techniques to improve document protection for its users.. Adobe Reader X, Secure PDF, Sandbox Features, Enhanced Security. . LinuxSecurity.com Team
Just as software is everywhere, flaws in most of that software are everywhere too. Flaws in software can threaten the security and safety of the very systems on which they operate. The best way to prevent such vulnerabilities in software is to proactively incorporate security and other non-functional requirements into all phases of Software Development Lifecycle (SDLC).. Drawing on the best practices from our book Secure and Resilient Software Development this article summarizes some key activities required for integrating security into your SDLC and offers some recommendations and advice for implementing your own secure software development program. The link for this article located at CSO Online is no longer available. . Strengthen your Software Development Life Cycle (SDLC) by implementing secure software development best practices that proactively address vulnerabilities during development.. Secure Development, Security Integration, SDLC Best Practices. . LinuxSecurity.com Team
Secure Software announces the availability of CodeAssure(TM), a product suite for software developers and security professionals to pre-emptively find, prioritize and fix security flaws before they result in catastrophic breaches. . . .. WASHINGTON --(Business Wire)-- Nov. 8, 2004 -- Secure Software announces the availability of CodeAssure(TM), a product suite for software developers and security professionals to pre-emptively find, prioritize and fix security flaws before they result in catastrophic breaches. Security flaws and errors found in software are responsible for the exploits that lead to identity theft, unauthorized funds transfer, and fraud, costing the U.S. economy $59.5 billion per year (NIST estimate). The greatest challenge and greatest opportunity for Cyber Security Amit Yoran, former Director of the National Cyber Security Division stated, "The greatest challenge in cyber security exists in retrofitting security solutions on top of fundamentally flawed applications, protocols and platforms. And the greatest opportunity for improving our technology infrastructures exists in improving the quality and security of our software systems and applications. This must be done in both the technology development and security evaluation processes. Innovative and automated technologies and solutions, like those being developed by Secure Software, are pioneering ways to help companies develop more secure technology in house and better evaluate the security of those solutions they are procuring." The link for this article located at TMCNet is no longer available. . ProtectSoft unveils GuardCode(TM), empowering programmers to identify and address vulnerabilities swiftly and effectively.. CodeAssure, Security Flaws, Application Security, Code Quality. . LinuxSecurity.com Team
The author revisits a debate begun here recently on the nature of security in Open Source projects: do 'lots of eyeballs' insure secure code? It is a common misconception amongst users of Open Source software that it is a panacea when it comes to creating secure software.. . .. The author revisits a debate begun here recently on the nature of security in Open Source projects: do 'lots of eyeballs' insure secure code? It is a common misconception amongst users of Open Source software that it is a panacea when it comes to creating secure software. Although this belief is rarely grounded in fact, it has become a cliche that is used axiomatically by Open Source enthusiasts and pundits whenever they discuss security. The purpose of this article is to expose the fallacy of this kind of thinking and instead point to truer means of ensuring the quality of the security of a piece software is high. The link for this article located at Earthweb is no longer available. . In the world of open source, myths mislead users about security. Transparency can enhance security through community scrutiny, addressing vulnerabilities quickly.. Open Source Security, Secure Code Practices, Software Quality Assurance. . LinuxSecurity.com Team
This newly developed appliance consists of a 1U rackmount server with 64Mb of RAM and a 466Mhz Celeron processor and the popular NetMax Firewall product. "Today Impera Software Corp. announced a release of a secure network appliance based on the . . .. This newly developed appliance consists of a 1U rackmount server with 64Mb of RAM and a 466Mhz Celeron processor and the popular NetMax Firewall product. "Today Impera Software Corp. announced a release of a secure network appliance based on the popular Linux operating system. This newly developed appliance consists of a 1U rackmount server with 64Mb of RAM and a 466Mhz Celeron processor and the popular NetMax Firewall product." The link for this article located at LinuxPR is no longer available. . Nexus introduces a fortified network device powered by Unix, offering exceptional performance statistics aimed at improving cybersecurity.. secure Linux appliance, network security, Impera Software Corp, NetMax Firewall, rackmount server. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.