Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
More than 40% of technology managers say security and compliance are an issue with open source. . How pervasive is open source software ? Extremely pervasive. Is it getting any easier to work with? Not much easier, sorry. That's the prognosis of a recent survey of 872 IT managers, which finds eight in 10 companies employ open source software. However, using freely available and low-cost or no-cost licensed software only solves part of the problem -- there is still the challenge of securing the software, as well as having the skills and support to maintain and run it effectively. . Uncover perspectives on the omnipresent role of open-source solutions and the related cybersecurity dilemmas facing IT administrators.. Open Source Usage, Technology Management, Security Compliance, IT Challenges. . Brittany Day
Open source may be the most viable option for most companies today but it comes with its own set of problems too. . Many people support the use of open source software (OSS). After all, why would we keep trying to build code that addresses issues that have already been resolved by others? Why not share the information and progressively and iteratively enhance the current open source solutions? These egalitarian values, however perhaps fundamental to civilization in general, not to mention software, nonetheless include conflicts that have been a problem for millennia. The problem with open source software security is that just because anyone can view the source code doesn’t imply they will. There are extensively used open-source projects that are only being maintained by a limited number of engineers. These engineers are unable to provide their time and effort completely voluntarily since they also need to pay their bills. . Explore the landscape of open-source vulnerabilities and the potential threats that modern organizations encounter when safeguarding essential software applications.. Open Source Software, Security Challenges, Software Maintenance. . Brittany Day
Imagine reading a headline in tomorrow’s news stating that your neighbor’s identity was stolen and their life savings cleaned out by criminals who entered through their ‘smart’ washing machine. Sound ridiculous? Well, have you checked your own home Wi-Fi network lately? . You might have several connected household gadgets and other internet of things (IoT) devices tethered wirelessly through a misconfigured router with no firewall settings. Is the firmware current? Are security patches up to date? Still not convinced this is a serious problem? Then consider this glaring example of how dangerous an outdated device can be. . With increasing smart devices at home, unsupported IoT risks rise. They lack updates, making them vulnerable to attacks and undermining network reliability.. IoT Devices, Cybersecurity Risk, Network Protection, Firmware Updates, Security Challenges. . Brittany Day
Hackers are turning coding languages such as Go, Rust, Nim and DLang into next-gen malware targeting Linux and Windows systems, enabling them to avoid signature detection and add layers of obfuscation. . Hackers are increasingly turning to relatively obscure programming languages when coding malware in a bid to avoid detection and pose greater challenges for the cyber security industry. Security professionals are coming across greater numbers of malware strains that are being written in ‘exotic’ languages such as coders are shifting to silicon valley backed programming languages , Rust, Nim, and DLang, according to researchers with Blackberry. Operators are even adopting these languages to rewrite existing malware families and create tools for new malware sets. . Cybercriminals are increasingly leveraging obscure coding languages to develop malicious software targeting both Linux and Windows, complicating the detection process.. malware Development, Cyber Threats, Exotic Languages, Linux Security. . LinuxSecurity.com Team
As the Linux Foundation's Zephyr Project celebrates its fifth anniversary, it has become apparent that addressing constrained device security challenges is more critical than ever. Luckily, the Zephyr Project is rising to meet these challenges. Learn how. . Noting nearly 1,000 contributors, 50,000 commits building advanced support for multiple architectures including ARC, Arm, Intel, Nios, RISC-V, SPARC and Tensilica, and more than 250 boards; the Zephyr Project is throwing a virtual party that will run from June 8 – 10 this year. The first-ever Zephyr Developer Summit is open to the public, free of charge, and full of Zephyr leaders from around the world presenting real-world use cases, best practices, mini-conferences, and more. . Celebrating its 5th anniversary, the Zephyr Project addresses IoT security challenges, empowering developers to enhance safety in resource-limited devices and applications. Zephyr Project, Constrained Device Security, Linux Foundation Events, Open Source Architecture. . LinuxSecurity.com Team
Microsoft is offering hackers up to $100,000 if they can break the security of the company’s custom Linux OS. The software giant built a compact and custom version of Linux last year for its Azure Sphere OS, which is designed to run on specialized chips for its Internet of Things (IoT) platform. The OS is purpose-built for this platform, ensuring basic services and apps run isolated in a sandbox for security purposes. . Microsoft now wants hackers to test the security of the Azure Sphere OS, paying up to $100,000 if the Pluton security subsystem or Secure World sandbox is breached. The bug bounty program is part of a three-month research challenge that runs from June 1st until August 31st. “We will award up to $100,000 bounty for specific scenarios in the Azure Sphere Security Research Challenge during the program period,” explains Sylvie Liu, a security program manager at Microsoft’s Security Response Center. . Google is providing $150,000 for evaluating the security of its Android platform, showcasing a significant initiative in enhancing cybersecurity.. Azure Sphere OS, Microsoft Security, bug bounty program, IoT security. . LinuxSecurity.com Team
Despite security coming a long way from warnings of the internet being able to be taken down in fewer than 30 minutes, it has “still got a long way to go.”. Reuniting six members of the L0pht hacker team at the DEFCON conference in Las Vegas, moderator Elinor Mills asked Dildog, Space Rogue, Mudge, John Tan, Weldpond and Kingpin, who used their hacker names as they had done 20 years ago when testifying to the US Senate and had done again when visiting again this year, whether they felt that the original testimony had worked. The link for this article located at InfoSecurity is no longer available. . Reuniting six members of the L0pht hacker team at the DEFCON conference in Las Vegas, moderator Elin. despite, security, coming, warnings, internet, being, taken. . Brittany Day
The annual Mobile Pwn2own competition, sponsored by Hewlett-Packard's Zero-Day Initiative (ZDI) and held in Tokyo on Nov. 12 and 13, yielded some surprising results.. The mobile version of the Pwn2own hacking challenge offers security researchers cash and prizes for successfully exploiting mobile devices. In the 2013 event, researchers exploited Android and iOS devices alike. The link for this article located at eWeek is no longer available. . The Cyber Assault Challenge showcased how cybercriminals took advantage of Wi-Fi and software vulnerabilities to win rewards in Berlin.. Mobile Exploitation, Pwn2own Challenge, NFC Attacks. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.