Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
209

Using Static Analysis for Continuous Assurance in Open Source Security

Open Source lends itself to a new way of certifying software: Continuous Assurance. In this approach, automated tools and processes ensure that, as code changes, it continually satisfies compliance, quality, and security requirements. "Continuous Assurance integrates directly into development and benefits from the always-up-to-date nature of cloud services, making it a perfect match for Open Source." . Sonatype’s 2020 State of the Software Supply Chain Report found that next generation cyber-attacks actively targeting open-source soft- ware projects increased 430% over the past 12 months. Industry and the Open Source communities recognize heightened security risks and are working to solve these. For example, in August 2020 the Linux Foundation launched the Open Source Security Foundation (OpenSSF), billing itself as “a cross-industry collaboration that brings together leaders to improve the security of open-source software.” The Foundation notes how pervasive open source has become, and how critical it is to bring together open-source security initiatives and those who support them to advance open-source security for all stakeholders. . Continuous Assurance and static analysis play crucial roles in enhancing open source security and ensuring compliance throughout the software development lifecycle. open source security, static analysis, cyber attacks, software compliance, Continuous Assurance. . Brittany Day

Calendar%202 Nov 04, 2020 User Avatar Brittany Day Security Trends
82

2007 DHS Budget: Enhancing Cybersecurity Through New Partnerships

Although President Bush's proposed budget for fiscal 2007 (starting Oct. 1, 2006) increases spending for key cybersecurity programs, it is not clear how that money would be spent, raising concerns in the information security industry. One of the biggest security-related boosts would be a $35 million infusion to the "critical infrastructure outreach and partnerships" initiative within the Department of Homeland Security. The goal of that effort is to increase cooperation and information sharing among DHS, state and local governments and infrastructure providers. Thirty million dollars of that allocation would go toward implementing partnership plans for private industry verticals like information technology, finance and electrical utilities. . The 2007 DHS budget also includes a $25 million increase for its National Cyber Security Division (NCSD), which is responsible for issues such as software assurance and computer security in federal agencies and, by extension, the private sector. John Sabo, director of security and privacy initiatives for Islandia, N.Y.-based vendor CA Inc. (Formerly Computer Associates International), said budget increases for cybersecurity and industry-specific partnerships are important. Sabo is the new chair of the Information Sharing and Analysis Centers Council, the umbrella organization that oversees a dozen vendor groups that advocate cooperation with DHS, including one for information technology firms. The link for this article located at SearchSecurity is no longer available. . The 2007 DHS budget also includes a $25 million increase for its National Cyber Security Division (N. although, president, bush's, proposed, budget, fiscal, (starting, 2006), increases, spending. . Brittany Day

Calendar%202 Mar 11, 2006 User Avatar Brittany Day Government
82

DHS Seeks Public Comment On Software Security Enhancement Initiatives

The Homeland Security Department wants public comment on two draft documents that are part of a federal program to improve software security, according to today's Federal Register. . The documents are part of the Software Assurance Program that DHS created as part of the National Strategy to Secure Cyberspace. The program is designed to reduce vulnerabilities and exploitation of weaknesses to improve software security, particularly in software that critical infrastructure uses. The link for this article located at FCW.com is no longer available. . The Department of Homeland Security invites community feedback on preliminary materials aimed at improving application security through the Software Assurance Initiative.. Software Assurance Program,Cybersecurity Measures,Critical Infrastructure. . Brittany Day

Calendar%202 Feb 03, 2006 User Avatar Brittany Day Government
77

NSA Initiative: New Center for Detecting Malware Backdoors

Declaring hidden malware to be "a growing threat," the National Security Agency's cybersecurity chief is calling on Congress to fund a new National Software Assurance Center dedicated to developing advanced techniques for detecting backdoors and logic bombs in large software applications. . . . . Declaring hidden malware to be "a growing threat," the National Security Agency's cybersecurity chief is calling on Congress to fund a new National Software Assurance Center dedicated to developing advanced techniques for detecting backdoors and logic bombs in large software applications. In prepared testimony before the House Select Committee on Homeland Security's cybersecurity subcommittee last month, NSA information assurance director Daniel Wolf bemoaned an absence of tools capable of scouring program source code and executables for evidence of tampering. "Beyond the matter of simply eliminating coding errors, this capability must find malicious software routines that are designed to morph and burrow into critical applications in an attempt to hide," said Wolf. The proposed solution: a federally funded think-tank that would include representatives from academia, industry, government, national laboratories and "the national security community," said Wolf, "all working together and sharing techniques." The link for this article located at SecurityFocus is no longer available. . The FBI advocates for an advanced facility to identify vulnerabilities in applications, recognizing concealed threats as an escalating concern.. Backdoor Detection, Malware Threat, Software Security, Cyber Defense, National Software Assurance. . LinuxSecurity.com Team

Calendar%202 Aug 11, 2003 User Avatar LinuxSecurity.com Team Server Security
81

NSA Security Initiatives: Insights From Michael Jacobs on Testing Programs

Interview with Michael Jacobs, information assurance director at the NSA. " ... to make sure commercial tools pass muster in terms of security, the NSA runs them through new software-testing programs. These programs, the Common Criteria Evaluation and Validation Scheme and the Cryptographic Module Validation Program, are part of the agency's National Information Assurance Partnership, a joint effort with the National Institute of Standards and Technology (), IT product vendors and users. . . .. Interview with Michael Jacobs, information assurance director at the NSA. " ... to make sure commercial tools pass muster in terms of security, the NSA runs them through new software-testing programs. These programs, the Common Criteria Evaluation and Validation Scheme and the Cryptographic Module Validation Program, are part of the agency's National Information Assurance Partnership, a joint effort with the National Institute of Standards and Technology (), IT product vendors and users. Products must pass rigorous testing before earning a Common Criteria security rating. The ratings were developed to help the Fort Meade, Md.-based NSA, but they're also available to private-sector users. And because testing standards are international, buyers of evaluated products can deploy them more easily across the globe. " The link for this article located at ComputerWorld is no longer available. . Interview with Michael Jacobs, information assurance director at the NSA. ' ... to make sure commerc. interview, michael, jacobs, information, assurance, director, commerc. . LinuxSecurity.com Team

Calendar%202 Jun 20, 2001 User Avatar LinuxSecurity.com Team Privacy
82

IRS Assurance: System Upgrade After Security Gaps Report

Despite a critical report revealing security gaps in the Internal Revenue Service's electronic filing system, the IRS is confident that the problems have been fixed, and the system is being upgraded. . Despite a critical report revealing security gaps in the Internal Revenue Service's electronic filing system, the IRS is confident that the problems have been fixed, and the system is being upgraded. The link for this article located at fcw.com is no longer available. . In light of a recent audit exposing vulnerabilities, the IRS pledges enhancements and solutions for their digital tax submission platform.. IRS Security, Electronic Filing System, System Upgrade, Security Fixes, Assurance. . Anthony Pell

Calendar%202 Mar 20, 2001 User Avatar Anthony Pell Government
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200