Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Microsoft has announced the availability of its Microsoft Edge Dev Channel for Linux. While Linux users can begin testing out Microsoft Edge on their systems, security researchers can begin searching for and submitting vulnerabilities to the company's new Microsoft Edge Bounty Program. . Earlier this year Microsoft brought its new Chromium-based Edge browser to macOS and now the company has announced the availability of the Microsoft Edge Dev Channel for Linux. With this release, the software giant's Edge browser is now available on all major platforms including Windows, macOS, Android, iOS and now Linux. This means that developers will be able to build and test their websites with the same web platform and tools available on macOS and Windows using their preferred environment. In its current form, Microsoft Edge for Linux supports a number of the most popular Linux distros including Ubuntu, Debian, Fedora and openSUSE. Going forward Microsoft plans to release weekly builds as it does for its other Dev Channel releases. . Microsoft has launched the Edge browser for Linux, a notable move for the open-source community, supporting major distros like Ubuntu and Fedora.. Microsoft Edge, Linux browser, software testing, Edge Dev Channel. . LinuxSecurity.com Team
Hackers are crawling all over the US Department of Defense’s websites. Don’t worry, though: they’re white hats, and DoD officials are quite happy about the whole thing. . Four years after it first invited white hat hackers to start hacking its systems, the Pentagon continues asking them to do their worst – and a report released this week says that they’re submitting more vulnerability reports than ever. The DoD’sDepartment of Defense Cyber Crime Center(DC3) handles cybersecurity for the DoD, and is responsible for tasks including cyber technical training and vulnerability sharing. It also runs the DoD’s Vulnerability Disclosure Program (VDP). The link for this article located at Naked Security is no longer available. . The collaboration with ethical hackers at the Pentagon has resulted in a notable rise in the number of vulnerability reports filed over the past four years.. White Hat Hacking, Pentagon Cybersecurity, Vulnerability Reporting. . Brittany Day
Want to help lock down Kubernetes and make some money while you're at it? The Cloud Native Computing Foundation has a new bug bounty program for you. . Kubernetes , the container orchestration program, has become hotter than hot. Everyone -- and I mean everyone -- is adopting it . But with quarterly major updates and everyone rushing to deploy it, security is a real worry. Thus, the Kubernetes Product Security Committee, funded by the Cloud Native Computing Foundation (CNCF) is launching a new bug bounty program to reward Kubernetes security bug hunters. The bug bounty program has been in a private beta release for several months now. Almost two years since the initial proposal, the program is now ready for all security researchers. The link for this article located at ZDNet is no longer available. . Participate in the exciting Kubernetes security initiative to enhance digital safety and receive incentives for your findings.. Kubernetes Bug Bounty, Container Security, Cloud Native Computing. . LinuxSecurity.com Team
Pinterest. The social networking site this week announced that it would begin paying cash rewards through its bug bounty program, upping the stakes from the T-shirt it originally offered last May when it kicked off the Bugcrowd-hosted initiative. The link for this article located at ThreatPost is no longer available. . The social networking site this week announced that it would begin paying cash rewards through its b. pinterest, social, networking, announced, would, begin, paying, rewards. . LinuxSecurity.com Team
It's bound to happen: you create a cool, forward looking incentive program designed to tap the "wisdom of the crowd" and help make your products better, only to find out that, in fact, the "crowd" isn't all that wise - and now wants you to pay cold, hard cash for their tepid ideas.. That's the experience that Google appears to have had since announcing that it would extend its bounty program for bugs from its Chromium platform to the various Web applications that the company owns in early November. In an updated blog post this week, the company said that it has already committed to some $20,000 in bounties, but also provided some "clarification" to the terms of the reward program, saying that - in essence - not all bugs are equal and that researchers dumping low priority vulns shouldn't expect to get much in return. The link for this article located at ThreatPost is no longer available. . The security initiative by Google encounters hurdles in managing minor vulnerability reports, while also outlining clearer criteria for compensation to contributors.. Google Bug Bounty, Vulnerability Rewards, Security Incentives. . LinuxSecurity.com Team
Taking a page from the Chrome playbook, Google has launched a program to encourage outsiders to find security vulnerabilities in its Web properties. Under the Chrome vulnerability-finding bounty program, the company already has been paying varying sums to those who locate holes in the browser. . Also part of the package has been mention on the Chromium security hall of fame and a public thank-you to those providing Google with sustained security help. The duplication of the initial program is geared to uncover "any serious bug which directly affects the confidentiality or integrity of user data," members of Google's security team said in a blog post yesterday. Payments are commensurate with the seriousness of the vulnerability and include $500, $1,000, $1,337, and $3,133.70 (that's "leet" and "eleet" for the leetspeak-impaired). The link for this article located at CNET Blogs is no longer available. . Also part of the package has been mention on the Chromium security hall of fame and a public thank-y. taking, chrome, playbook, google, launched, program, encourage, outsiders. . LinuxSecurity.com Team
The open-source Mozilla project has been offering cash bounties for security bugs for six years now, but often bug finders simply turn down the cash.. Between 10 percent and 15 percent of the serious security bugs reported since Mozilla launched its bug bounty program have been provided free of charge, according to Mozilla. "A lot of people would say, 'Don't worry about it. Donate it to the EFF [Electronic Frontier Foundation] or just send me a T-shirt,'" said Johnathan Nightingale, the director of Firefox development, in a recent interview. Mozilla was a pioneer in this area. It started offering a US$500 bounty for security bugs in August 2004. Since then, it's had more than 120 bugs reported by about 80 researchers. The project recently upped its bounty and is now paying out a maximum of $3,000 for critical security bugs. A few weeks later, Google announced that it, too, would pay up to $3,000 for security bugs reported in its products. The link for this article located at Network World is no longer available. . Between 10 percent and 15 percent of the serious security bugs reported since Mozilla launched its b. open-source, mozilla, project, offering, bounties, security, years. . LinuxSecurity.com Team
My last post Forget ROI and Risk. Consider Competitive Advantage seems to be attracting some good comments. I thought it might be useful to mention a variety of ways to justify a security program. I don't intend for readers to use all of these, or to even agree. However, you may find a handful that might have traction in your environment.. Crisis. Something bad happens. Although this is the worst way to justify a program, it is often very effective. Compliance. An external force compels a security program. This is also not a great way to justify a program, because resources are often misallocated. Competitiveness. Please see my previous blog post. Comparison. If your company security team is 10% the size of the average peer organization size, it's not going to look good when you have a breach and have to justify your decisions. Cost. It's likely that breaches are more expensive than defensive measures, but this can be difficult to capture. The link for this article located at taoSecurity is no longer available. . Crisis. Something bad happens. Although this is the worst way to justify a program, it is often very. forget, consider, competitive, advantage, seems, attracting. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.