Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Better support for Microsoft's NTFS file-system is coming to the Linux 5.15 kernel, along with some important process and security lessons for developers about how code submissions to the kernel should be made. . Linux creator Linus Torvalds has agreed to include Paragon Software's NTFS3 kernel driver, giving the Linux kernel 5.15 release improved support for Microsoft's NTFS file-system. But he also had some process and security lessons to offer developers about how code submissions to the kernel should be made. Paragon's NTFS driver will make working with Windows' NTFS drives in Linux an easier task — ending decades of difficulties with Microsoft's proprietary file system that succeeded FAT. . Linux boosts its NTFS capabilities with an upgraded driver, imparting crucial programming insights from Linus Torvalds.. NTFS Integration, Linux Kernel, Paragon Software, Code Submission Practices, File System Support. . LinuxSecurity.com Team
In August 2018, the US Department of Justice (DoJ) unsealed the indictment of a North Korean spy, Park Jin Hyok, whom they claim was behind the hack against Sony and the creation and distribution of the WannaCry ransomware. The 170-plus-page document was written by Nathan Shields of the FBI’s LA office and shows the careful sequence of forensic analysis they used to figure out how various attacks were conducted.. Security researchers have given Park’s organization various monikers, including the Lazarus Group, APT37, Lab 110, Group 123, Hidden Cobra, Nickel Academy and Reaper. Some are from the malware elements they created. That is the first thing that you will learn from the indictment: the North Koreans have been at the center of many different campaigns over the past six or so years. The link for this article located at CSO Online is no longer available. . Uncover vital insights from the indictment related to the Sony breach and enhance your cybersecurity measures to combat digital vulnerabilities.. Lazarus Group,Forensic Analysis,Cybersecurity Lessons,Ransomware Threat,North Korean Hackers. . LinuxSecurity.com Team
Though the second half of the year has been comparably calmer than the first half's excitement over database breaches at RSA, Sony, and Epsilon, the breach numbers continued to roll in -- especially at healthcare organizations, which made up a disproportionate number of exposed records. Here are some of the biggest breaches that went down in the second half of the year, along with a few database security lessons learned.. 1. The Breach Victim: Nemours Assets Stolen/Affected: Names, addresses, dates of birth, Social Security numbers, insurance data, medical treatment data, and bank account information for 1.6 million patients, vendors, and employees. Three unencrypted tapes containing a mother lode of personal information on patients, vendors, and employees were lost amid the dust of a facility remodel project when a cabinet that held them since 2004 went missing. The link for this article located at Dark Reading is no longer available. . 1. The Breach Victim: Nemours Assets Stolen/Affected: Names, addresses, dates of birth, Social Secur. though, second, comparably, calmer, first, half's, excitement. . LinuxSecurity.com Team
If Marcus Ranum were your CISO, this would be his resolution for 2011: To plan a "War Games" style exercise. "It's very enlightening for everybody," says Ranum, a noted security thought-leader, :and it actually helps a great deal in helping sell the need for security to the entire executive team.". In an exclusive interview on the 2011 information security outlook, as well as the biggest stories of 2010, Ranum discusses: The growing insider threat and how organizations must respond; Biggest lessons learned from 2010; Potential storylines of 2011. Ranum is CSO of Tenable Network Security. Since the late 1980s, he has designed a number of groundbreaking security products including the DEC SEAL, the TIS firewall toolkit, the Gauntlet firewall and NFR's Network Flight Recorder intrusion detection system. He has been involved in every level of operations of a security product business, from developer, to founder and CEO of NFR. Ranum has served as a consultant to many FORTUNE 500 firms and national governments, as well as serving as a guest lecturer and instructor at numerous high-tech conferences. In 2001, he was awarded the TISC "Clue" award for service to the security community, and also holds the ISSA lifetime achievement award. In 2005 he was awarded Security Professional of the Year by Techno Security Conference. The link for this article located at Government Info Security is no longer available. . In 2011, Marcus Ranum highlighted crucial security trends from 2010, urging organizations to reassess their security measures against evolving cyber threats. Marcus Ranum, Security Exercise, Insider Threat, Security Analysis, Information Security. . LinuxSecurity.com Team
A security researcher named Barnaby Jack amazed attendees at the Black Hat security conference by hacking ATM machines in a session titled "Jackpotting Automated Teller Machines Redux". There are some important lessons to be learned from the hacks Jack demonstrated, and they apply to more than just ATM machines.. Jack's exploits--one involving physical access to the ATM machine using a master key available online, and the other dialing in remotely to gain access--focused on ATM machines from Triton and Tranax. However, the issue is not necessarily limited to these two. Jack explained to his audience that he has yet to find an ATM machine that he couldn't crack and retrieve cash from. It's an impressive hack. Who wouldn't like to just walk up to an ATM machine and cause it to spew money as if you'd hit the jackpot on a Vegas slot machine? But, most businesses don't own ATM machines, so why should IT admins care about the ATM hack? The link for this article located at PC World is no longer available. . Uncover critical revelations from Barnaby Jack's ATM exploits presented at Black Hat, focusing on vulnerabilities and unauthorized access issues.. ATM Hacks, Security Lessons, Exploit Techniques, Black Hat, Cash Security. . Alex
A reminder of how important these are came last week with a revelation from the Cold War era, contained in a new book by a senior US national security official. Thomas Reed's At The Abyss recounts how the United States exported control software that included a Trojan Horse, and used the software to detonate the Trans-Siberian gas pipeline in 1982. The Trojan ran a test on the pipeline that doubled the usual pressure, causing the explosion. Reed was Reagan's special assistant for National Security Policy at the time; he had also served as Secretary of the Air Force from 1966 to 1977 and was a former nuclear physicist at the Lawrence Livermore laboratory in California. The software subterfuge was so secret that Reed didn't know about it until he began researching the book, 20 years later. . . .. China has irked US wireless manufacturers by insisting that they conform to the PRC's encryption technology, we reported last week. Some commentators have castigated China for protecting its own fledgling tech industry. But that excludes the country's very understandable security concerns. A reminder of how important these are came last week with a revelation from the Cold War era, contained in a new book by a senior US national security official. Thomas Reed's At The Abyss recounts how the United States exported control software that included a Trojan Horse, and used the software to detonate the Trans-Siberian gas pipeline in 1982. The Trojan ran a test on the pipeline that doubled the usual pressure, causing the explosion. Reed was Reagan's special assistant for National Security Policy at the time; he had also served as Secretary of the Air Force from 1966 to 1977 and was a former nuclear physicist at the Lawrence Livermore laboratory in California. The software subterfuge was so secret that Reed didn't know about it until he began researching the book, 20 years later. The scheme to plant bugs in Soviet software was masterminded by Gus Weiss, who at the time was on the National Security Council and who died last year.Soviet agents had been so keen to acquire US technology, they didn't question its provenance. "[CIA Director] Bill Casey at Weiss at the NSC decided to help the Russians with their shopping. Every piece of sw would have an added ingredient," said Reed to NPR's Terry Gross last week. The software sabotage had two effects, explains Reed. The first was economic. By creating an explosion with the power of a three kiloton nuclear weapon, the US disrupted supplies of gas and consequential foreign currency earnings. But the project also had important psychological advantages in the battle between the two superpowers. "By implication, every cell of the Soviet leviathan might be infected," he writes. "They had no way of knowing which equipment was sound, which was bogus. All was suspect, which was the intended endgame for the entire operation." Tools you can trust The two great trading powers, China and the USA, are not currently engaged in a Cold War. But does that mean that the Cold War lessons are invalid? . Beijing's call for tighter encryption standards sparks fears over cybersecurity, reminiscent of Cold War tactics involving covert digital infiltration.. open source exporters,Trojan technology,Cold War secrets,software security,software sabotage. . Anthony Pell
After further review, security experts last week said enterprises can glean some new lessons from the Microsoft Corp. hacking saga. First and foremost, if you get hacked, don't do what Microsoft did. According to at least a dozen security experts contacted . . . . After further review, security experts last week said enterprises can glean some new lessons from the Microsoft Corp. hacking saga. First and foremost, if you get hacked, don't do what Microsoft did. According to at least a dozen security experts contacted last week by eWeek, Microsoft, which thwarts most hack attempts, did not know how to react to a successful hack. The Redmond, Wash., company's response was flawed in how it disseminated information about the security breach to its customers and in how it handled the intrusion once the company's in-house security experts recognized it. The link for this article located at ZDNet is no longer available. . After further review, security experts last week said enterprises can glean some new lessons from th. further, review, security, experts, enterprises, glean, lessons. . LinuxSecurity.com Team
When it comes to security, build for success, but plan for failure. eWEEK Labs' Openhack.com e-business site was built from the ground up with security in mind, and the site was co-designed and co-maintained by security company Guardent Inc. Yet Openhack . . . . When it comes to security, build for success, but plan for failure. eWEEK Labs' Openhack.com e-business site was built from the ground up with security in mind, and the site was co-designed and co-maintained by security company Guardent Inc. Yet Openhack was cracked--by two different people in less than one month. After we reported the hacks, a reader asked despairingly whether there was hope for anyone to stay secure. There is hope, but only for organizations that acknowledge the risk and work to manage it--constantly. The link for this article located at ZDNet is no longer available. . Discover valuable insights from Openhack on the essentials of creating robust e-commerce platforms and strategizing for security breaches.. E-Business Security, Risk Management, Cybersecurity Insights. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.