Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 28 articles for you...
79

Integrating GUAC: Enhancing Software Supply Chain Security Framework

Integrating the Graph for Understanding Artifact Composition (GUAC) in the open-source security framework has tremendous potential to improve software supply chain security . GUAC is an initiative introduced by Google, Kusari, Purdue University, and Citi that aggregates software security metadata into a high-fidelity graph database. . By joining the Open Source Security Foundation (OpenSSF) as an incubating project, GUAC aims to enhance existing tools for software security. It helps organizations understand their software supply chain by recognizing connections and enabling threat detection and response. What Is the Significance of GUAC in the Realm of Software Supply Chain Security? GUAC is experiencing growing adoption and maturity and is compatible with existing OpenSSF technologies. GUAC can consume SPDX SBOMs (Software Package Data Exchange), SLSA (Supply Chain Levels for Software Artifacts) attestation, and scorecard information about project dependencies. It enables organizations to analyze their dependencies easily, leading to more secure software. The implications of integrating GUAC into the software supply chain landscape are noteworthy. While SBOM capabilities have improved security, GUAC goes beyond generating SBOMs. It leverages metadata and documents across projects to provide insights and answer critical questions about the software supply chain. This approach allows for a better understanding of risks and highlights fleet-wide vulnerabilities. One intriguing aspect is GUAC's ability to perform graph analysis. GUAC provides a comprehensive view of the software supply chain by extracting additional insights from various datasets. This has long-term consequences, enabling security practitioners to focus their investments on improving application and dependency security. GUAC can ingest multiple types of security-related documents, such as VEX (Vulnerability Exploitability eXchange) statements and OSV vulnerability data, to better understand the connections between dataand assess risks efficiently. GUAC is currently in beta release. The project aims to reach its 1.0 release and create built-in dashboards with prioritized actionable items. This would facilitate organizations' understanding of their security posture and efficiently utilize the software supply chain knowledge graph. However, it is crucial to consider GUAC's evolution and how it adapts to emerging threats and technologies. From the perspective of Linux administrators, infosec professionals, internet security enthusiasts, and sysadmins, GUAC presents a valuable addition to its security toolkit. It brings together various sources of software security metadata, empowering practitioners to identify gaps in software supply chain data. This strengthens security practices and enables effective threat detection and response. Our Final Thoughts on the Implications of GUAC Integrating GUAC into the open-source security framework signifies a significant step in enhancing software supply chain security. It provides a valuable tool for security practitioners to understand their software dependencies better, analyze risks, and focus on improving application security. As GUAC continues to evolve, its potential to unlock a range of use cases and facilitate integration with other components will contribute to organizations' long-term security posture. . GUARD incorporates encryption details into software distribution scrutiny for improved safeguard and threat evaluation.. GUAC, Software Supply Chain, Security Framework, Risk Assessment. . Dave Wreski

Calendar%202 Mar 08, 2024 User Avatar Dave Wreski Security Projects
78

Kali Linux Purple: Innovative Defensive Security Framework Released

On the 13th of March, 2023, the Kali Linux team announced the availability of a new version of their security-focused Linux distribution, named “Kali Linux Purple”. The new distribution is aimed at defensive security. “Defensive” not in the sense of simply protecting your personal computer for anonymity like Qubes OS and Tails, but in the sense of protecting other machines or resources that you might own, just like an enterprise-level defensive system. . For so long, Kali Linux has been the de facto Linux distribution for penetration testing and other offensive security operations. Hackers, from all types of white, grey and black, used it to accomplish their quick-and-dirty tasks without a hassle. Today, the Kali Linux team with the release of Purple aims to expand their area of focus to include defensive security. That is, the aim is to provide a platform that users can utilize to protect key systems for whatever types of usage (personal, organization, enterprise…) they seek protection for. The new Linux distribution, Kali Linux Purple, simply comes with pre-installed tools to IDENTIFY, PROTECT, DETECT, RESPOND and RECOVER important data and resources. In case you were wondering why we wrote the preceding 5 words in a capital case, this is because these 5 stages are known as the “Five Framework”, which are the main stages a defensive cybersecurity strategy should take into account in order to be effective. It is part of both the US NIST and UK NCSC cybersecurity strategies. The link for this article located at Foss Post is no longer available. . Uncover the nuances of Kali Linux Purple, a cutting-edge security distribution designed specifically for defensive tactics and safeguarding data integrity.. Kali Linux Purple, Defensive Security, Cybersecurity Framework, Data Protection, Linux Tools. . LinuxSecurity.com Team

Calendar%202 Apr 05, 2023 User Avatar LinuxSecurity.com Team Vendors/Products
76

OpenSSF Adopts Microsoft S2C2F Framework: Enhancing Supply Chain Security

Microsoft announced that its Secure Supply Chain Consumption Framework (S2C2F) has been adopted by the Linux Foundation’s Open Source Security Foundation (OpenSSF) in a move to improve “supply chain security for everyone,” according to Microsoft Azure CTO Mark Russinovich. . The OpenSSF’s adoption of the framework means “the community it serves can also now have a hand in growing and improving it,” Microsoft’s Principal Program Manager of Secure Software Supply Chain Adrian Diglio said. The No. 2 cloud giant has been using S2C2F in its own open source software ( OSS ) development processes for the past three years, and as “a massive consumer of and contributor to open source, Microsoft understands the importance of a robust strategy around securing how developers consume and manage OSS dependencies when building software,” Russinovich explained . . The recent implementation of the S2C2F framework by OpenSSF enhances cooperative efforts within the community to improve security across the supply chain.. Supply Chain Security, Open Source Framework, Microsoft Collaboration. . Brittany Day

Calendar%202 Jan 15, 2023 User Avatar Brittany Day Organizations/Events
209

Effective Security Management With The OWASP Top 10 Framework

What is the OWASP Top 10, and – just as important – what is it not? In this review, we look at how you can make this critical risk report work for you and your organization. . OWASP is the Open Web Application Security Project, an international non-profit organization dedicated to improving web application security. It operates on the core principle that all of its materials are freely available and easily accessible online, so that anyone anywhere can improve their own web app security. It offers a number of tools, videos, and forums to help you do this – but their best-known project is the OWASP Top 10. The link for this article located at The Hacker News is no longer available. . The OWASP stands for the Open Web Application Security Project, a vital entity dedicated to improving the security of web applications through essential guidelines and frameworks.. owasp top ten, application risks, security practices. . Brittany Day

Calendar%202 Oct 14, 2022 User Avatar Brittany Day Security Trends
76

SPDX Becomes ISO/IEC 5962:2021 Recognized Standard for Software Security

In use for a decade as the de facto standard for communicating software bills of materials, The Linux Foundation has announced that the Software Package Data Exchange (SPDX) specification has been published as ISO/IEC 5962:2021 and recognized as the open standard for security, license compliance and other software supply chain artifacts. . Software bills of materials are used to communicate information in policies or tools to ensure compliant, secure development across global software supply chains. "SPDX plays an important role in building more trust and transparency in how software is created, distributed and consumed throughout supply chains," said Jim Zemlin, executive director, the Linux Foundation, in a press release. "The transition from a de-facto industry standard to a formal ISO/IEC JTC 1 standard positions SPDX for dramatically increased adoption in the global arena. SPDX is now perfectly positioned to support international requirements for software security and integrity across the supply chain." . The ISO/IEC 5963:2021 standard has been adopted for SPDX, bolstering worldwide software compliance and security measures.. Software Package Data Exchange, ISO 5962, Security Compliance. . Brittany Day

Calendar%202 Sep 10, 2021 User Avatar Brittany Day Organizations/Events
79

Boosting Security Against Supply Chain Attacks With Google's SLSA Framework

To tackle the growing threat of attacks on the software supply chain, Google has proposed the Supply chain Levels for Software Artifacts framework, or SLSA which is pronounced "salsa". Can Google's 'salsa' make life harder for supply chain attackers? Comment below - we want to hear what you think! . Sophisticated attackers have figured out that the software supply chain is the soft underbelly of the software industry. Beyond the game-changing SolarWinds hack, Google points to the recent Codecov supply chain attack, which stung cybersecurity firm Rapid7 via a tainted Bash uploader. While supply chain attacks aren't new, Google notes they've escalated in the past year, and has shifted the focus from exploits for known or zero-day software vulnerabilities. . Advanced threat actors are targeting the software development pipeline; Google's SLSA initiative strengthens defenses against these vulnerabilities.. Software Supply Chain, Google Security, SLSA Framework, Software Attacks, Open Source Security. . LinuxSecurity.com Team

Calendar%202 Jun 17, 2021 User Avatar LinuxSecurity.com Team Security Projects
82

DHS Announces New National Cybersecurity Strategy For Risk Mitigation

The Department of Homeland Security (DHS) unveiled on Tuesday, 14 May, a new national strategy to be implemented to address evolving cybersecurity risks. The DHS strategy outlines strategic and operational goals and priorities to successfully execute the full range of the DHS secretary’s cybersecurity responsibilities.. “The strategy is built on the concepts of mitigating systemic risk and strengthening collective defense,” Homeland Security Secretary Kirstjen Nielsen said Tuesday as reported by The Hill. “Both will inform our approach to defending U.S. networks and supporting governments at all levels and the private sector in increasing the security and resilience of critical infrastructure.” The link for this article located at InfoSecurity is no longer available. . “The strategy is built on the concepts of mitigating systemic risk and strengthening collective de. department, homeland, security, (dhs), unveiled, tuesday, national, strategy. . Brittany Day

Calendar%202 May 17, 2018 User Avatar Brittany Day Government
79

Enhancing Security Effectiveness Through Proven Strategies

For the last few months, I. I The link for this article located at Newschool Security / Adam Shostack is no longer available. . IThe link for this article located at Newschool Security / Adam Shostack is no longer available.. months, article, located, newschool, security, shostack. . LinuxSecurity.com Team

Calendar%202 Jul 22, 2015 User Avatar LinuxSecurity.com Team Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200