Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Exciting news has just reached the open-source community: OpenStack , now known as OpenInfra Foundation , is joining forces with the Linux Foundation . This significant move promises greater collaboration and operational efficiency throughout the community. . Linux security admins now have new opportunities to leverage advanced security practices supported by the extensive resources of the Linux Foundation, with improved integration and compliance with global security standards. In addition, this partnership underscores the significance of secure infrastructure in supporting cutting-edge technologies like AI . By aligning these two powerful organizations, their combined expertise and governance should strengthen security protocols further, making collaborative efforts more robust and streamlined. Let's examine the significance of this partnership and its potential benefits for open-source security/ Strengthening Open-source Collaboration The open-source community thrives on cooperation, as evidenced by the recent merger between OpenInfra Foundation (formerly OpenStack) and the Linux Foundation. By joining forces, these two powerhouses aim to amp up their impact in areas critical for modern infrastructure; not simply pooling resources but creating synergies that strengthen robustness, security, scalability, and longevity of open-source projects. This is particularly beneficial for Linux security administrators hoping this alliance will bring new methodologies and tools to make their tasks more efficient and effective. OpenInfra's decision to collaborate with the Linux Foundation is wise. Although its governance will remain unchanged, collaboration unlocks unrivaled expertise and resources within both organizations. Thanks to their long history of nurturing innovative projects, this relationship provides fertile ground for OpenInfra to expand and improve initiatives, providing security admins access to improved tools and practices without disrupting current governance structures. Enhancing Security Practices One of the main benefits of this merger is its potential to strengthen security practices across both organizations' projects. The Linux Foundation has an impressive record of creating and enforcing security standards that should now extend into OpenInfra's tools and frameworks. This cross-pollination should lead to more resilient and secure open-source infrastructures. As Linux security administrators, integration means having more structured and well-maintained security protocols. The Linux Foundation's Core Infrastructure Initiative and Open Source Security Foundation aim to identify and mitigate vulnerabilities early. With more deeply embedded OpenInfra projects providing a stronger basis on which to build secure environments, fewer vulnerabilities will slip through cracks. Operational Efficiency and Governance Aligning with the Linux Foundation offers another great advantage in terms of operational efficiency. The organization boasts a well-tested governance model, which helps projects run smoothly and scale. OpenInfra's adherence to this model will mean adopting best practices in project management that streamline development cycles and lead to faster implementation of security features. We security administrators will benefit from this governance model in two ways. Integration of new features and updates should become simpler within your systems. More predictable release cycles and documentation will reduce the overhead of keeping systems secure and up-to-date , potentially decreasing the patching frenzy that typically follows less structured release cycles. Supporting Cutting-edge Technologies Ensuring a secure foundational infrastructure is necessary at the forefront of cutting-edge technologies. With their complex computational demands, Artificial Intelligence (AI) and Machine Learning (ML) necessitate a secure yet scalable infrastructure. OpenInfra and the Linux Foundation's partnership strives to support this by making sure open-source toolsused for AI/ML are not only robust but also safe. AI applications often involve sensitive data that requires stringent security measures to safeguard against breaches. As OpenInfra projects align closer with Linux Foundation's standards, these security measures for such applications will strengthen AI/ML solutions providers' confidence that their infrastructure's security can meet these requirements head-on. Better Integration with Global Security Standards The Linux Foundation's dedication to upholding global security standards is another hallmark of its collaboration. Projects under its umbrella are known for complying with these standards, making regulatory requirements easier for organizations to meet. With OpenInfra now part of this ecosystem, organizations can expect improved alignment with international security regulations such as GDPR and HIPAA. Linux security administrators working in regulated industries know firsthand that assuring compliance is often time-consuming. Thanks to increased adherence to security protocols and standards introduced by this merger, this process will become streamlined, reducing administrative burden and mitigating risk from noncompliance penalties. Leveraging Expertise and Resources One key advantage of joining forces is access to available expertise and resources. The Linux Foundation houses numerous projects and working groups specializing in technology and security, which OpenInfra projects can now leverage by joining forces. For us admins, this means having access to an expansive community of security experts who can offer insights and assistance with specific security challenges. Leveraging collective knowledge through forums, working groups, or direct collaboration can significantly boost your capabilities and security strategies, creating an ecosystem designed for continuous learning and improvement that keeps you at the forefront of security practices. Final Thoughts & Looking Ahead OpenInfra's integration into the Linux Foundationmarks an exciting step forward for open-source projects, especially those focused on security. Collaboration, robust security practices, operational efficiency, and compliance with global standards will likely all improve over time, setting new benchmarks for creating and maintaining these projects. This merger marks an exciting time in our community as the OpenInfra Foundation and Linux Foundation join forces to advance infrastructure security and efficiency. Stay engaged, stay secure, and embrace what this game-changing collaboration will offer! . Linux cybersecurity professionals can now benefit from improved protective strategies, resulting from a partnership with the Linux Foundation.. OpenInfra, Linux Foundation, Open Source Security, Security Practices, Compliance Standards. . Brittany Day
RedHat's acquisition of StackRox underscores the growing significance of DevSecOps. "DevSecOps, the best of DevOps and security operations, is becoming a top priority for enterprise customers. StackRox, with its integration with existing DevOps and CI/CD tools, delivers seamless DevSecOps for Kubernetes." . Last week, Red Hat announced that it’s acquiring StackRox, a California-based Kubernetes security company founded in 2014. This is one of the most strategic acquisitions for Red Hat, which is squarely focused on increasing the enterprise infrastructure market share. StackRox complements Red Hat’s current portfolio by bringing critical security capabilities missing from its infrastructure and platform offerings. The founders of StackRox, Ali Goshan and Wei Lien Dang, have a strong security background. Ali worked at Microsoft and PwC as a security researcher while Wei led secure product initiatives at CoreOS, AWS, Splunk, and Bracket Computing. In 2018, StackRox appointed Kamal Shah, an industry veteran, and an investor, as the president and CEO. The link for this article located at Forbes is no longer available. . The purchase of StackRox by Red Hat underscores the vital importance of integrating security within the development and operations phases of cloud environments and organizational frameworks.. DevSecOps, Kubernetes Security, Cloud Innovations. . Brittany Day
Sir Tim Berners-Lee has defended his decision not to build in security at the onset of the world wide web. It. The link for this article located at The Register UK is no longer available. . Tim Berners-Lee articulates the rationale behind his decision to forgo the implementation of initial security measures on the web.. Web Security, Tim Berners-Lee, Internet Design, HTTP Protocol. . Alex
A new week, a new rash of attacks against security vendors, email marketers and banks. It would be easy to point fingers and laugh at the irony, especially in the case of security vendors, but that would be both petty and shortsighted.. The stark reality is that security breaches can, will and do happen to everyone. For every security control and process we put in place, somewhere else there's a vulnerability, a weakness, an untrained employee or a path of least resistance for an attack. All the point solutions in the world are not going to make us any more secure. What we desperately need is a new model for integrating security solutions across vendors, across devices, across operating systems and across the globe. Companies today are faced with a fundamental security conundrum. Their networks, applications and end-user devices are made up of a patchwork of dozens if not hundreds of vendor solutions. Each vendor may offer security features in their apps, security appliances, or even an entire range of security solutions. None of them really interoperate with any of the other vendors' security solutions (not unless you consider LDAP and syslog to be interoperability). None of them work on other vendor network devices. The link for this article located at Network World is no longer available. . Cyber threats are an ongoing challenge for all suppliers. It's essential to implement protective measures across systems seamlessly.. Security Integration, Cyber Attacks, Vendor Security Solutions, Network Protection. . LinuxSecurity.com Team
VMware plans to open its hypervisor to security vendors with a set of APIs that make it easier to protect virtual machines from threats including viruses, Trojans and keyloggers. Without these APIs, security vendors building antivirus and firewall tools for virtual servers are removed from the hypervisor by several layers and therefore cannot see everything that happens within the virtual environment, according to Yankee Group Analyst Phil Hochmuth. So what do you do when critical vulnerabilities are found in your virtual machines? Open-source to the rescue - read on for an interesting account of VMsafe, a set of APIs which should allow for better security through more isolation of virtual machines. Do you see any real improvements in security with VMsafe?. The link for this article located at Network World is no longer available. . The link for this article located at Network World is no longer available.. vmware, plans, hypervisor, security, vendors, easier. . LinuxSecurity.com Team
A survey by the National Association of State Chief Information Officers shows that state governments are paying more attention to information security, hiring chief information security officers and giving them defined budgets and enforcement authority. . NASCIO The link for this article located at Government Computer News is no longer available. . NASCIOThe link for this article located at Government Computer News is no longer available.. state, survey, national, association, chief, information, officers, shows, government. . Brittany Day
The folks running the annual RSA Conference here this week will tell you that the show is bigger than ever and security is at the top of every CIO's list of concerns. And while all of that may well be true, if heavyweights such as Sun Microsystems, Cisco Systems and Microsoft have their way, enterprises soon will have little use for the wares that most of the security vendors here are hawking. . It's rare that those three vendors would all agree on anything, but in speeches and interviews this week, executives from all of them have said that it's time to build security into hardware and software from the ground up and stop trying to fix problems after the fact. The link for this article located at eWeek is no longer available. . Top executives advocate for unified safety measures within hardware and software to address urgent security challenges.. Security Integration, Enterprise Security, RSA Conference 2023. . LinuxSecurity.com Team
Fresh off record third-quarter growth, Juniper Networks on Wednesday outlined its strategy for the next 12 months, including plans to move to integrated security and to secure the Infranet, a profitable public IP network. . . .. Fresh off record third-quarter growth, Juniper Networks on Wednesday outlined its strategy for the next 12 months, including plans to move to integrated security and to secure the Infranet, a profitable public IP network. At Juniper's annual analyst meeting, CEO Scott Kriens and other company executives discussed the road ahead for the Sunnyvale, Calif.-based vendor, stating flatly that channel partners would play a key role. "We only successfully see the way to grow this business by connecting to partners," Kriens said. The link for this article located at Matt Villano is no longer available. . After impressive development in the third quarter, Juniper Networks outlined its plan to enhance comprehensive security for the Infranet.. Infranet Security, Juniper Strategy, Integrated Security, Network Solutions, Public Network Growth. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.