Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 3 articles for you...
76

OpenSSF Alpha-Omega Project for Improved Open Source Software Security

OpenSSF is excited to announce the Alpha-Omega Project to improve the security posture of open source software (OSS) through direct engagement of software security experts and automated security testing. Microsoft and Google are supporting the Alpha-Omega Project with an initial investment of $5 million. . Alan Shimel: Hey, everyone. Welcome to another segment for Techstrong TV. My guest today is Brian Behlendorf. Brian is with the Open Source Security Foundation – that’s the OSSF. The Open Source Security Foundation, of course, is part of the Linux Foundation and it was – it’s a relatively new organization. It was – was it announced at KubeCon – CNCFCon back in, I guess, September, was that, Brian? Brian Behlendorf: We announced kind of the second generation of the project in October. The project has been around for about a year longer than that – actually just over that as a collaboration between some things that Microsoft had started and Google had started. The Linux Foundation said, “Let’s put this in the same pod” and a tremendous community of volunteers stepped up to do all sorts of things and get plates spinning on top of poles. And then, around about October we realized, hey, there’s some places where spending some money would be helpful and here’s a whole bunch of companies willing to come in as sponsors and really fund some of that work. And so, that also freed me up to be able to focus full time on it as well. The link for this article located at Security Boulevard is no longer available. . The Open Source Security Foundation's Alpha-Omega Initiative is designed to bolster OSS protection through the involvement of specialists and thorough assessments.. OpenSSF, Open Source Security, Alpha-Omega Project, Software Security, Automated Testing. . Brittany Day

Calendar 2 Sep 11, 2022 User Avatar Brittany Day Organizations/Events
79

The Central Security Project: Streamlining Java Vulnerability Reporting

When a security researcher finds a security bug, what do they do? Unfortunately, the answer sometimes is they search for the appropriate people to notify and, when they can’t be found, end up posting the vulnerability to public email lists, the GitHub project, or even Twitter. . This is the problem that security platform HackerOne and software supply chain management tool Sonatype have teamed up to solve with The Central Security Project, a new effort that “brings together the ethical hacker and open source communities to streamline the process for reporting and resolving vulnerabilities discovered in libraries housed in The Central Repository, the world’s largest collection of open source components,” according to a statement. The link for this article located at TheNewStack is no longer available. . GitHub partners with Snyk to enhance security audits for public Python packages, aiming to boost safety and reliability in the open source ecosystem. Vulnerability Reporting, Open Source Projects, Java Security, HackerOne Collaboration, Ethical Hacking. . LinuxSecurity.com Team

Calendar 2 Mar 28, 2019 User Avatar LinuxSecurity.com Team Security Projects
67

OpenSSL Risks With Multiple Fix Projects That May Impact Security

Nobody questions that OpenSSL is a vital part of the Internet's infrastructure. So many fundamentals are built on top of it and in so many places. Too much is at stake for it to be vulnerable to yet another Heartbleed, the dangers of which may linger for some time in embedded and client devices.. That's why the efforts, plural, to fix OpenSSL and make it more maintainable are so heartening. But having three such projects in the works, all operating in parallel, may be the wrong kind of plurality. The link for this article located at InfoWorld is no longer available. . Worries grow regarding OpenSSL's oversight as several initiatives work on repairs at the same time; a threat to online safety.. OpenSSL Management, Cybersecurity Risks, Infrastructure Security, Project Coordination. . LinuxSecurity.com Team

Calendar 2 Jul 14, 2014 User Avatar LinuxSecurity.com Team Cryptography
81

Bandit Project Adds Role-Based Access To Identity Systems

No system works perfectly all the time, but for something as fundamental as being able to prove who you are and get access to what you. The Bandit project, led by Dale Olds from Novell, will add role-based authentication and auditing to identity systems, drawing on the Novell Directory Services, which Olds also worked on. He doesn't think this is an easy fix; indeed he admits The link for this article located at The Register is no longer available. . The Bandit project, led by Dale Olds from Novell, will add role-based authentication and auditing to. system, works, perfectly, something, fundamental, being, prove. . LinuxSecurity.com Team

Calendar 2 Sep 15, 2006 User Avatar LinuxSecurity.com Team Privacy
79

DARPA Sardonix Project Faces Challenges In Attracting Auditors

Two years after its hopeful launch, a U.S.-backed research project aimed at drawing skilled eyeballs to the thankless task of open-source security auditing is prepared to throw in the towel. Initially funded by a research grant from the Pentagon's Defense Advanced Research Projects Agency (DARPA), the Sardonix project aspired to replace the loosely-structured Linux security review process with a public website that meticulously tracks which code has been audited for security holes, and by whom. . . .. Two years after its hopeful launch, a U.S.-backed research project aimed at drawing skilled eyeballs to the thankless task of open-source security auditing is prepared to throw in the towel. Initially funded by a research grant from the Pentagon's Defense Advanced Research Projects Agency (DARPA), the Sardonix project aspired to replace the loosely-structured Linux security review process with a public website that meticulously tracks which code has been audited for security holes, and by whom. As conceived by Oregon-based computer scientist Crispin Cowan, Sardonix was to attract volunteer auditors by automatically ranking them according to the amount of code they've examined, and the number of security holes they've found. Auditors would lose points if a subsequent audit by someone else turned up bugs they missed. Cowen hoped that the system would produce the same cocktail of goodwill and computer-judged competition that fuels other successful geeky endeavors, from the distributed computing effort that recognizes top producers in the search for new prime numbers, to the "karma" points awarded highly-rated posters on the news-for-nerds site Slashdot. In the end, though, nobody showed up. "I got a great deal of participation from people who had opinions on how the studliness ranking should work, and then squat from anybody actually reviewing code," says Cowan, chief research scientist at WireX Communications. . Two years after its hopeful launch, a U.S.-backed research project aimed at drawing skilled eyeballs.years, hopeful, launch, -backed, research, project, aimed, drawing, skilled, eyeballs. . LinuxSecurity.com Team

Calendar 2 Feb 02, 2004 User Avatar LinuxSecurity.com Team Security Projects
79

OWASP CodeSeeker: Open Source Firewall and IDS for Enhanced Security

The Open Web Application Security Project (OWASP) are pleased to annouce the imminent availability of CodeSeeker, an Application Level Firewall and Intrusion Detection System (AFWIDS) for Linux, Win32 and Solaris.. . .. The Open Web Application Security Project (OWASP) are pleased to annouce the imminent availability of CodeSeeker, an Application Level Firewall and Intrusion Detection System (AFWIDS) for Linux, Win32 and Solaris. CodeSeeker was donated to OWASP on November 19th by Butterfly Security. The Butterfly Security team will be continuing to manage this project and developing and enhancing Codeseeker as a community effort at OWASP. CodeSeeker is GPL and copyrighted to the FreeSoftware Foundation ensuring that it will always remain truly open source and free to everyone. This is a truly altruistic donation by Butterfly Security and we can¢t thank them all enough. CodeSeeker is written in Java and C/C++. It intercepts HTTP traffic off the stack (immediately after its been decrypted by SSL if its HTTPS), and applies a set of security rules to determine if the traffic is legitimate or malicious. CodeSeeker can either sit in a passive mode simply alerting your console of attacks (IDS) or in an active mode blocking traffic (firewall). You can see screenshots at Version 1.0 beta will be made available to developers and beta testers in December. If you are interested in joining this project as a developer and have Java or C skills then please join the CodeSeeker mailing list and introduce yourself. owasp-codeseeker List Signup and Options The link for this article located at OWASP is no longer available. . The OWASP Foundation unveils CodeSeeker, an all-encompassing application firewall and intrusion detection system aimed at bolstering security measures.. Application Layer Firewall, Open Source Protection, Network Security. . LinuxSecurity.com Team

Calendar 2 Nov 25, 2002 User Avatar LinuxSecurity.com Team Security Projects
79

PHP Audit Project: Enhancing Interpreter Security For OpenBSD

Because PHP is a critical piece of the hosting service puzzle, the PHP audit project was started in order to harden the PHP interpreter against known and unknown vunlerabilities. We are also trying to add some enhancements for the OpenBSD operating . . . . Because PHP is a critical piece of the hosting service puzzle, the PHP audit project was started in order to harden the PHP interpreter against known and unknown vunlerabilities. We are also trying to add some enhancements for the OpenBSD operating system, without breaking the portability to other systems. The idea was born on the misc@ mailing-list. We are currently working on PHP 4.1.2 . The link for this article located at PHP Audit Project is no longer available. . The JavaScript enhancement initiative is designed to bolster the JS runtime by tackling both identified and unrecognized vulnerabilities.. PHP Hardening, OpenBSD Project, Security Enhancements. . LinuxSecurity.com Team

Calendar 2 Mar 10, 2002 User Avatar LinuxSecurity.com Team Security Projects
79

Kernel Auditing Project: Securing Linux Through Comprehensive Reviews

Brian Paxton writes, "It's an attempt to audit the linux kernel for any security vulnerabilities and/or holes and/or possible vulnerabilities and/or possible holes, and of course without adding more bugs or drawbacks to the existing kernels. The suggested kernels to be audited are 2.0.x kernel series , 2.2.x kernel series, and the 2.3.x/2.4.x kernel series. The group and it's work shall be dealt and worked with via a mailing list." . Brian Paxton writes, "It's an attempt to audit the linux kernel for any security vulnerabilities and/or holes and/or possible vulnerabilities and/or possible holes, and of course without adding more bugs or drawbacks to the existing kernels. The suggested kernels to be audited are 2.0.x kernel series , 2.2.x kernel series, and the 2.3.x/2.4.x kernel series. The group and it's work shall be dealt and worked with via a mailing list." ############## kernel auditing project ################ This is a mission statement for a project under way and ready to get going. The Linux kernel auditing project(LKAP). The purpose of this project is self-explanatory. It's an attempt to audit the linux kernel for any security vulnerabilities and/or holes and/or possible vulnerabilities and/or possible holes, and of course without adding more bugs or drawbacks to the existing kernels. The suggested kernels to be audited are 2.0.x kernel series , 2.2.x kernel series, and the 2.3.x/2.4.x kernel series. The group and it's work shall be dealt and worked with via a mailing list. How to subscribe: echo subscribe kernel-audit | mail This email address is being protected from spambots. You need JavaScript enabled to view it. I feel that this project should have been done a long time ago, not to imply that the linux kernel is insecure, but for example the setuid() hole found on June 7 which affected all 2.2.x kernels. This bug was patched in a matter of hours (isn't open source great!). But here's the point, the flaw/function/hole should _NOT_ have existed in the first place. Which is where this project comes into place. There's a few things that differ from thisproject compared to a few others that are similar. 1) To audit the kernel src code without affecting/breaking/disrupting any other part of the kernel. These will not be additional patches you can downloads (add-ons). This auditing is dealing with the current code in the src, not adding or implementing new functions. 2) To educate kernel developers/hackers on how to securely write code. It is my hopes that kernel developers/hackers new and old will subscribe and post to this mailing list with questions and share information, and to simply get help with their code(e.g.: Could this function() cause a possible security hole or lead to an exploit ?"), this is the true power of open source and GNU/Linux 3) To be ahead of the game... A perfect example of this are certain proprietary Operating Systems who sit around and wait for a security bug to come to them and not go to bug themselves. Of course this needs no explanation as to why this never works. I feel that kernel developers/hackers are down to earth and pretty logical people and realize that Linux is _NOT_ perfect, that a lot of the code they write, submit, and gets plugged into the kernel is not flawless and more than likely could be improved for security reasons. 4) To provide an operating system to the public. I want to see a linux where the sysadmin doesn't have to watch his back all the time in fear of say some new knfsd exploit or a way to fork()bomb his/her router via a simple mistake in buffer.c 5) To provide a safe linux to the end-user.. Linux is slowly but surely becoming a choice for the desktop user. Most of these users are walking into linux with no knowledge of what potential dangers lie at their finger tips and in their hard drive. Linux has proven to be one of the most secure operating systems, but I feel as linux becomes more popular with the general public this will change, that more kernel security holes and exploits will arise from nowhere and give us a very unpleasant reality check. And at last, this will be no easy project,security auditing never is. It takes man power, skill, and just plain aching time. But I believe if the community of gets together on this one, nothing will stop us and Linux will go on to become the #1 security wise operating system to do this date. Sincerely Bryan Paxton How to subscribe: echo subscribe kernel-audit | mail This email address is being protected from spambots. You need JavaScript enabled to view it.. Evaluating the Linux kernel seeks to uncover possible vulnerabilities while ensuring no additional problems are introduced. Be part of the initiative!. Linux Auditing, Kernel Security, Open Source Initiative. . LinuxSecurity.com Team

Calendar 2 Jun 09, 2000 User Avatar LinuxSecurity.com Team Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here