Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
79

Key Elements for Cultivating a Successful Security Culture

When we were asked to keynote a recent CSO event, it was a pleasant surprise that the top concern of the CSOs was "security culture." From performing many security assessments and penetration tests, it is sadly obvious that even the best technical security efforts will fail if their company has a weak security culture. . It is heartwarming that CSOs are now moving past straight technological solutions and moving towards instilling a strong security culture as well. To determine the components of a truly successful security awareness program, we performed a study to identify critical success factors for building one. We interviewed security awareness practitioners at Fortune 500 companies and surveyed the security staff and general employees at the companies. Additionally, we validated the results and gathered additional information at a security executive event in the United Kingdom with more than 150 security executives participating. The link for this article located at CSO Online is no longer available. . Uncover essential components that fuel effective security awareness initiatives and enhance the security culture within organizations.. Security Culture, Awareness Program, Success Factors, Employee Training. . LinuxSecurity.com Team

Calendar%202 May 03, 2013 User Avatar LinuxSecurity.com Team Security Projects
79

Improving Security Culture Through Unconventional Practices

The lessons I learned letting my son break the rules hold true for security, too. Here's why sometimes breaking a rule leads to better compliance: 1. It creates an opportunity for an individual to practice autonomy, on the condition that they live with the consequences. This allows an individual to be recognized, and feel respected.. 2.The experience created a unique, shared context to discuss the reason for the rule. Generally this leads to a better understanding of the rule; sometimes, it actually creates a better understanding of why the rule needs to change. 3. It creates a better bond between people; individuals get closer to the consequences of their actions, and everyone improves their relationship. The link for this article located at CSO Online is no longer available. . Exploring the concept that challenging conventions can enhance protection measures and foster improved connections within groups.. Compliance Improvement,Risk Awareness,Security Culture. . LinuxSecurity.com Team

Calendar%202 Sep 17, 2012 User Avatar LinuxSecurity.com Team Security Projects
76

Celebrating 20 Years of DefCon: A Retrospective on Hackers and Security

In 1992, Jeff Moss (third from left in second row) invited a bunch of hacker friends to come to Las Vegas to party in the desert. Now in its 20th year, the DefCon hacker conference draws more than 7,000 hackers, security pros and undercover feds each year.. Dead Addict (center), a mainstay of DefCon, is one of the few hackers who has been with the conference from year one when he helped founder Jeff Moss organize the first gathering and secure the participation of Assistant US Attorney Gail Thackeray to speak to the hackers following her work on the notorious Operation Sun Dial case. The link for this article located at Wired is no longer available. . DefCon, a premier hacker conference, has shaped a global cybersecurity community for 20 years, evolving from a small meetup to a massive event where ideas flourish. DefCon 20, Hacker Culture, Cybersecurity Trends, Cybersecurity History, Hacker Events. . Dave Wreski

Calendar%202 Jun 22, 2012 User Avatar Dave Wreski Organizations/Events
74

Making Corporate Security Second Nature: A Collective Effort

Enterprise security executives need to make practices such as safe USB use and discreet handling of patient or customer data as commonplace as not accepting luggage from strangers in airports or wearing a seat belt when driving. . But they can't do it alone; it takes an entire organization to secure corporate assets, protect data from breaches and make sure enterprisewide risk remains low. "Security is everyone's responsibility," says John Kirkwood, vice president of Information Security Strategy at American Express, who spoke recently at a Boston seminar hosted by risk-management company Consul. Kirkwood, formerly chief information security officer at the financial services giant, says his role has evolved from security policy maker to enterprise risk-management evangelist. "Security has gone from being a server room concern to a boardroom type of issue," he says. The link for this article located at Network World is no longer available. . Comprehensive collaboration is vital for safeguarding company resources and maintaining robust information security.. Enterprise Security, Data Protection Strategies, Risk Management Strategies. . Brittany Day

Calendar%202 Aug 05, 2006 User Avatar Brittany Day Network Security
74

Importance of Strong Password Policies in Corporate Security Practices

Failure to properly instil a culture of effective password management in a company could land its directors in jail, while wading through alternatives to "fatally flawed" passwords is a process mired in "fear, uncertainty and doubt" according to experts on all sides of the debate. The only given is that the need to get it right is now more pressing than ever, according to one top lawyer. David Naylor, partner at law firm Field Fisher Waterhouse, said companies need to ensure they have strict policies in place regarding password management and said best practice would be to incorporate these as requirements in the company's contractual arrangements with employees and third-parties with access to the company systems. . Naylor said: "Companies should make certain that employees and contractors are aware of the importance of maintaining systems security and the need to keep usernames and passwords secure and confidential. "If a company does not ensure security of its systems, any failure to maintain personal data securely may constitute an offence under the Data Protection Act 1998, opening the company to potential regulatory intervention and fines, and possibly civil and criminal liability." In addition to the legal risks, security breaches can lead to plenty of equally serious business and reputational damage. The link for this article located at silicon.com is no longer available. . Organizations need to implement robust password protocols to prevent potential legal repercussions and damage to their reputation.. Password Management, Corporate Security, Cybersecurity Culture. . Brittany Day

Calendar%202 May 16, 2006 User Avatar Brittany Day Network Security
77

Improving Business Resilience and Security Compliance Today

Companies are increasingly considering their security as world events cast doubt on their ability to deal with natural disaster, human error or malicious attack. Spending on security has reached record levels, and continues to climb as businesses seek to reassure shareholders . . . . Companies are increasingly considering their security as world events cast doubt on their ability to deal with natural disaster, human error or malicious attack. Spending on security has reached record levels, and continues to climb as businesses seek to reassure shareholders and comply with standards and changing legal requirements. However, being secure is about more than simply buying firewalls, antivirus software and login technology. "Good IT security is about good management. It's more important to maintain patches and to document systems and procedures than it is to install expensive new security devices," says Bart Vansevenant, director of European security strategies at security service provider Ubizen. "Secure environments are typically well-documented, with a procedure for regularly patching systems, good monitoring and control of servers, and where good security is part of a culture." The link for this article located at VNUNet is no longer available. . Companies are increasingly considering their security as world events cast doubt on their ability to. their, companies, increasingly, considering, security, world, events, doubt, ability. . LinuxSecurity.com Team

Calendar%202 Sep 25, 2003 User Avatar LinuxSecurity.com Team Server Security
83

Defcon 9: A Gathering of Hackers Celebrating Network Skills

A delegate hacked the conference network and was given an award. This is typical of the Defcon conference which attracts enthusiasts and saboteurs alike, says Simon Edwards. The crowds that descended on Las Vegas's casinos, strip clubs and all-you-can-eat restaurants last weekend were a little different from the norm. They were a little more troublesome, too.. . .. A delegate hacked the conference network and was given an award. This is typical of the Defcon conference which attracts enthusiasts and saboteurs alike, says Simon Edwards. The crowds that descended on Las Vegas's casinos, strip clubs and all-you-can-eat restaurants last weekend were a little different from the norm. They were a little more troublesome, too. For these thrill-seekers were computer hackers and security experts from all over the world - distinguishable from the general public thanks to vivid red and yellow entry passes, and occasional outlandish haircut and dress sense. They had gathered for the annual hacker conference known as Defcon. Now in its ninth year, it is claimed by the organisers to be the largest and most important computer "underground" meeting in the world. The estimated number of registered visitors ran to 4,500 this year. The link for this article located at The Guardian is no longer available. . An attendee breached the symposium's system and was celebrated at the exclusive Black Hat gathering renowned among tech enthusiasts.. Hacker Conference,Cybersecurity Culture,Defcon 9,Hacking Community,Network Security. . LinuxSecurity.com Team

Calendar%202 Jul 26, 2001 User Avatar LinuxSecurity.com Team Hacks/Cracks
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200