Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
76

Linux Foundation Report on OSS Development Security Challenges

The Linux Foundation recently published a report titled Maintainer Perspectives on Open Source Software Security , which provides valuable insights into the perspectives, practices, and challenges faced by OSS maintainers and core contributors regarding open-source software security . The report highlights the importance of utilizing software composition analysis (SCA) and static application security testing (SAST) tools in evaluating the security of OSS packages. . It also emphasizes the need for automation and intelligent security tools to reduce developer fatigue and enhance threat detection. However, the report raises important questions about the limitations of existing security tools and the need for a better contextual understanding of vulnerabilities for effective risk mitigation. The report highlights the popularity and effectiveness of SCA and SAST tools in evaluating OSS security. However, there are valid concerns about the limitations of SCA tools, including license and vulnerability compliance challenges, Organizations may be overlooking other essential aspects of software security, such as selecting secure and high-quality dependencies and considering operational risk. These shortcomings could lead to an accumulation of technical and security debt, making it harder to address potential issues later. Furthermore, the report points out that SCA tools primarily track known vulnerabilities, excluding the rapidly increasing categories of attacks from malicious developers. This limitation highlights the need for security professionals to consider a holistic risk assessment approach that encompasses not only known vulnerabilities but also emerging threats. Additionally, the lack of contextual understanding of code usage and dependencies by SCA tools hinders effective vulnerability management. This raises questions about the ability of current tools to prioritize and allocate resources to address vulnerabilities accurately. Reducing developer fatigue and improving productivity in OSSdevelopment are critical. We encourage organizations to examine the process of selecting OSS dependencies to reduce long-term risk. This statement prompts us to consider how organizations can balance maintaining the speed and productivity enabled by OSS and ensuring adequate security measures. The issue of prioritizing security risks is also crucial, as developers waste significant amounts of time dealing with noisy application security alerts. Code and pipeline governance technologies are touted as solutions that can significantly reduce false positives compared to traditional SCA tools. What Are the Implications and Long-Term Consequences of These Findings? For Linux admins, infosec professionals, internet security enthusiasts, and sysadmins, this report presents crucial insights into the current state of software security practices in the OSS ecosystem. It raises questions about whether the existing security tools are sufficient to address the evolving threats and challenges faced by maintainers and contributors. The limitations highlighted in the report call for a deeper understanding of vulnerabilities, contextual risk analysis, and the development of more intelligent tools to provide better threat detection and response mechanisms. As a security practitioner, it is important to reflect on the implications of these findings. Are we relying too heavily on specific security tools without considering their limitations? How can we balance automation and manual code review to ensure comprehensive security practices? Are we effectively addressing both known vulnerabilities and emerging threats? Our Final Thoughts on Open-Source Software Security In conclusion, the Linux Foundation's report sheds light on the current state of OSS security practices and highlights key concerns and areas for improvement. It urges OSS community members to reconsider the effectiveness of existing security tools and embrace newer technologies that offer a more comprehensive understanding of code usage andvulnerabilities. This critical analysis and summary serve as a reminder to security practitioners to stay informed , adapt, and constantly assess the effectiveness of their security practices in the ever-evolving landscape of open source and Linux security. . Enhancing open source software development with structured protocols and security measures fosters trust and integrity among users and the community. Open Source Security, Development Tools, Risk Assessment, Security Best Practices. . Brittany Day

Calendar 2 Feb 05, 2024 User Avatar Brittany Day Organizations/Events
77

Exploring Red Hat's Approach To Linux Security Management

How does Red Hat go about building and developing a secure Linux operating system? That question was asked and answered at the Red Hat Summit this week by Josh Bressers, who heads the Red Hat Product Security Team.. Bressers explained that the security process involves both manual and automated activities for quality assurance. Linux is further reinforced with what Dan Walsh, senior principal software engineer at Red Hat called a "silver bullet" for Linux security -- SELinux. The link for this article located at eSecurity Planet is no longer available. . Red Hat strengthens Linux systems with careful manual and automated security measures, emphasizing SELinux for enforcing access controls and minimizing vulnerabilities. Red Hat Security, Linux Hardening, SELinux Implementation, Security Processes. . LinuxSecurity.com Team

Calendar 2 Jun 17, 2013 User Avatar LinuxSecurity.com Team Server Security
81

Fedora 14: OpenSCAP Tool for System Security Compliance and Automation

Security is always a primary concern for enterprise IT managers, with a constant need to ensure that systems are kept updated and properly configured to prevent exploits. A new tool debuting in the upcoming Red Hat-sponsored Fedora 14 Linux release could prove a key ingredient in enabling properly secured systems.. Fedora 14 is set to include a technology called OpenSCAP, an open source implementation of the Security Content Automation Protocol (SCAP) framework for creating a standardized approach for maintaining secure systems. The new system builds on numerous other technologies and systems in an effort to enable IT organizations to ensure a standardized approach to security. "There are lots of people focused on security, particularly in the U.S. government, that are worried about making sure that thousands of their systems are all up to date and aren't vulnerable to the different bugs and exploits that are out in the wild," Jared Smith, leader of the Fedora Project, told InternetNews.com. The link for this article located at Datamation is no longer available. . Fedora 14 is set to include a technology called OpenSCAP, an open source implementation of the Secur. security, always, primary, concern, enterprise, managers, constant, ensure. . LinuxSecurity.com Team

Calendar 2 Oct 05, 2010 User Avatar LinuxSecurity.com Team Privacy
79

Integrate OpenSCAP Framework for Efficient Security Automation

The OpenSCAP Project was created to provide an open-source framework to the community which enables integration with the Security Content Automation Protocol (SCAP) suite of standards and capabilities. It is the goal of OpenSCAP to provide a simple, easy to use set of interfaces to serve as the framework for community use of SCAP. SCAP is a line of standards managed by NIST. It was created to provide a standardized approach to maintaining the security of enterprise systems, such as automatically verifying the presence of patches, checking system security configuration settings, and examining systems for signs of compromise. The link for this article located at Darknet UK is no longer available. . OpenSCAP provides a free-to-use framework that facilitates the application of SCAP regulations, aiming to improve security automation processes.. OpenSCAP, SCAP Standards, Security Automation, NIST Compliance. . LinuxSecurity.com Team

Calendar 2 Jun 23, 2010 User Avatar LinuxSecurity.com Team Security Projects
79

Enhancing Security With OpenDNSSEC for Automated DNSSEC Implementation

Very cool. It would be really nice to see a review of this project, and follow it as it progresses. Is anyone interested in reviewing it and letting us know how you make out? A group of developers has released open-source software that gives administrators a hand in making the Internet's addressing system less vulnerable to hackers. . The software, called OpenDNSSEC, automates many tasks associated with implementing DNSSEC (Domain Name System Security Extensions), which is a set a set of protocols that allows DNS (Domain Name System) records to carry a digital signature, said John A. Dickinson, a DNS consultant working on the project. The link for this article located at Network World is no longer available. . DNSCurve integrates cryptography with DNS, providing protection against eavesdropping and manipulation.. OpenDNSSEC,DNS Security,Security Automation,DNS Protection,Internet Safety. . LinuxSecurity.com Team

Calendar 2 Jul 30, 2009 User Avatar LinuxSecurity.com Team Security Projects
74

Managing TCP/IP Connections With Cutter Tool On Linux Firewalls

Chris Lowth submits , Network security administrators sometimes need to be able to abort TCP/IP connections routed over their firewalls on demand. This would allow them to terminate connections such as SSH tunnels or VPNs left in place by employees over night, abort hacker attacks when they are detected, stop high bandwidth consuming downloads - etc. There are many potential applications.. . .. Chris Lowth submits , Network security administrators sometimes need to be able to abort TCP/IP connections routed over their firewalls on demand. This would allow them to terminate connections such as SSH tunnels or VPNs left in place by employees over night, abort hacker attacks when they are detected, stop high bandwidth consuming downloads - etc. There are many potential applications. This article describes how a Linux IPTables based firewall/router can be used to send the right combination of TCP/IP packets to both ends of a connection to cause them to abort the conversation. It describes the steps required to perform this task, and introduces a new open-source utility called "cutter" that automates the process. The link for this article located at Chris Lowth is no longer available. . The security personnel in charge of network systems can skillfully oversee TCP/IP sessions on Linux-based firewalls by utilizing a novel tool known as chopper.. Linux Firewall Management, TCP/IP Connection Termination, Open Source Tool. . Anthony Pell

Calendar 2 Jun 11, 2003 User Avatar Anthony Pell Network Security
79

Bastille Linux 1.2: Enhanced Usability And Security Features

"The Bastille Linux development team today announced the release of Bastille Linux 1.2, a hardening script for multiple Linux distributions. With this release, Bastille Linux delivers on the full promise of simplified, automated security administration for Linux systems.. . .. "The Bastille Linux development team today announced the release of Bastille Linux 1.2, a hardening script for multiple Linux distributions. With this release, Bastille Linux delivers on the full promise of simplified, automated security administration for Linux systems. "Version 1.2 of Bastille's usability and intelligence has made it a joy to use. MandrakeSoft's focus on usability has improved the Bastille front end tremendously," says Jay Beale, lead developer for the Bastille Linux Project. The Bastille Linux project is receiving assistance from Hewlett-Packard Company in developing Bastille functionality for HP-UX." The link for this article located at LinuxPR is no longer available. . 'The Bastille Linux development team today announced the release of Bastille Linux 1.2, a hardening . bastille, linux, development, today, announced, release, hardening. . LinuxSecurity.com Team

Calendar 2 Jun 16, 2001 User Avatar LinuxSecurity.com Team Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here