Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 7 articles for you...
82

Debian: Worries about EU Cyber Resilience Act and Its Effect on Open Source

The EU Cyber Resilience Act (CRA) and the Product Liability Directive (PLD) aim to introduce a set of cybersecurity and vulnerability handling requirements for manufacturers, with the intention to improve security. However, the Debian project has issued a statement raising concerns about the negative implications for the open-source community and contributors.. Key concerns for the open-source community are: Potential legal peril: The Debian project believes that the CRA's requirements could make redistributing Free Software legally risky, endangering their commitment to providing an integrated system without legal restrictions. Difficulty determining software's commercial status: Most Free Software projects, including Debian, cannot feasibly determine whether software is commercial or not, complicating compliance with the CRA. Increased security risks and effects on code availability: Fear of the CRA's financial consequences may lead upstream projects to stop making their code available, which could worsen system security. Discouragement of developers: The need for legal advice before contributing to Free Software projects may discourage developers who don't have organizational support. This could have broad implications on Debian's security practices, Challenges to responsible disclosure: The 24-hour mandatory reporting to European authorities could undermine the established responsible disclosure practices in the Free Software community. Centralized vulnerability reporting risks: Collecting all software vulnerabilities in one place increases the risk of leaking information to threat actors, putting users and privacy-focused initiatives at risk. Downplaying security issues: Legal implications may cause developers and companies to downplay security issues, leaving users more vulnerable. To mitigate these concerns, Debian's statement proposes: Exempting open development processes from CRA requirements: Just as software developed in private is not covered byCRA, open development should be exempt to maintain parity. Exempting small businesses and solo-entrepreneurs: To protect small projects and businesses that can't meet the CRA's requirements, an exemption should be introduced. Overall, the Debian project believes that the EU Cyber Resilience Act could have significant negative implications for the open-source community and its contributors, potentially stifling innovation and undermining security practices. . Debian voices worries regarding the EU Cyber Resilience Act, anticipating adverse effects on open source initiatives and potential legal complications.. EU Cyber Resilience Act, Debian Project, open source compliance. . Dave Wreski

Calendar%202 Dec 29, 2023 User Avatar Dave Wreski Government
82

Understanding The Cyber Resilience Act and Its Threat to Open Source

Society and governments are struggling to adapt to a world full of cybersecurity threats. Case in point: the EU CRA — Cyber Resilience Act — is a proposal by the European Commission to enact legislation with a noble goal: protect consumers from cybercrime by having security baked in during design. . Even if you don’t live in the EU, today’s global market ensures that if the European Parliament adopts this legislation, it will affect the products you buy and, possibly, the products you create. In a recent podcast , our own [Jonathan Bennett] and [Doc Searles] interview [Mike Milinkovich] from the Eclipse Foundation about the proposal and what they fear would be almost a death blow to open source software development. You can watch the podcast below. If you want some background, you can read the EU’s now closed request for comments and the blog post outlining the problems from opensource.org . At the heart of the issue is the need for organizations to self-certify their compliance with the act. Since open source is often maintained by a small loose-knit group of contributors, it is difficult to see how this will work. Here’s the concern in a nutshell. Suppose you write up a cool little C++ program for your own use. You aren’t a company, and you didn’t do it for profit. Wanting to share your work, you post your program on GitHub with an open source license. This happens all the time. Meanwhile, another developer of a large open source program — let’s say the fictitious open source GRID database server decides to incorporate your code. That’s allowed. In fact, it is even encouraged. That’s how open source works. . The Cyber Resilience Act will transform open source software development globally, enforcing stricter compliance and security measures that could challenge its decentralized ethos. Cyber Resilience Act, Open Source Compliance, EU Cybersecurity Legislation, Software Development Challenges. . Brittany Day

Calendar%202 Apr 23, 2023 User Avatar Brittany Day Government
209

Open Source Software Security Challenges: Survey Insights from IT Managers

More than 40% of technology managers say security and compliance are an issue with open source. . How pervasive is open source software ? Extremely pervasive. Is it getting any easier to work with? Not much easier, sorry. That's the prognosis of a recent survey of 872 IT managers, which finds eight in 10 companies employ open source software. However, using freely available and low-cost or no-cost licensed software only solves part of the problem -- there is still the challenge of securing the software, as well as having the skills and support to maintain and run it effectively. . Uncover perspectives on the omnipresent role of open-source solutions and the related cybersecurity dilemmas facing IT administrators.. Open Source Usage, Technology Management, Security Compliance, IT Challenges. . Brittany Day

Calendar%202 Feb 22, 2023 User Avatar Brittany Day Security Trends
76

SPDX Becomes ISO/IEC 5962:2021 Recognized Standard for Software Security

In use for a decade as the de facto standard for communicating software bills of materials, The Linux Foundation has announced that the Software Package Data Exchange (SPDX) specification has been published as ISO/IEC 5962:2021 and recognized as the open standard for security, license compliance and other software supply chain artifacts. . Software bills of materials are used to communicate information in policies or tools to ensure compliant, secure development across global software supply chains. "SPDX plays an important role in building more trust and transparency in how software is created, distributed and consumed throughout supply chains," said Jim Zemlin, executive director, the Linux Foundation, in a press release. "The transition from a de-facto industry standard to a formal ISO/IEC JTC 1 standard positions SPDX for dramatically increased adoption in the global arena. SPDX is now perfectly positioned to support international requirements for software security and integrity across the supply chain." . The ISO/IEC 5963:2021 standard has been adopted for SPDX, bolstering worldwide software compliance and security measures.. Software Package Data Exchange, ISO 5962, Security Compliance. . Brittany Day

Calendar%202 Sep 10, 2021 User Avatar Brittany Day Organizations/Events
82

Export Regulations Impacting Canadian Open Source Software Development

Canadian open source companies doing development in the U.S. are seldom aware of export regulations requiring encryption algorithms in the code to be filed with the U.S. Department of Commerce Bureau of Industry and Security (BIS). . Eran Strod, director of product marketing with Waltham, Mass.-based Black Duck Software Inc., said companies exporting code from the U.S. to other parts of the world must ensure compliance, yet that is a legal issue that developers are seldom aware of. "Engineering groups are really tasked with getting a product working, and policy compliance to them is not something that they are measured on," said Strod. "It's not something they are taught in school." The link for this article located at Network World is no longer available. . Gain insights into the export laws impacting Canadian open-source enterprises and the legal adherence they frequently neglect.. Open Source Compliance, Encryption Regulations, Canadian Software Development. . Alex

Calendar%202 Oct 30, 2009 User Avatar Alex Government
77

The Importance of Security Certifications in Open Source Growth

Only a few open-source vendors have borne the time and expense of having their software EAL-certified. Red Hat and Novell's SuSE Linux attained EAL3+ ratings in the last year, but many other vendors have yet to do the same. This raises a fundamental question: Does open-source software need security certifications to win global acceptance? . Open source is undeniably on the march. Linux continues to grow at a torrid pace -- now forecast by IDC to represent a US$35 billion market by 2008 -- though it has yet to significantly breach the desktop market. Mozilla's Firefox browser debuted with much fanfare recently, with over ten million downloads recorded in a single month. So far, open source has captured plenty of converts and customers, not to mention media attention and the ire of Microsoft (Nasdaq: MSFT) . Is there nothing to slow its mighty advance? The link for this article located at LinuxInsider.com is no longer available. . Open source is undeniably on the march. Linux continues to grow at a torrid pace -- now forecast by . open-source, vendors, borne, expense, having, their, software, eal-certifie. . LinuxSecurity.com Team

Calendar%202 Feb 02, 2005 User Avatar LinuxSecurity.com Team Server Security
78

Efficient Auditing Practices for Ensuring Open Source Software Compliance

Users of open source, even if not distributing modified GPL binaries, should routinely audit their servers and clients to determine what open source programs are being used and whether they are being used within the scope of their respective licenses. . . .. Users of open source, even if not distributing modified GPL binaries, should routinely audit their servers and clients to determine what open source programs are being used and whether they are being used within the scope of their respective licenses. Traditional software vendors need to recognize the shift taking place is driven not only by successful open source projects, but also by the rapid and broad adoption of open source in the customer marketplace. The numbers behind open source adoption are compelling. Linux in both the United States and Asia is the fastest growing operating system ever. As measured by hostnames, Netcraft reports that the Internet has grown 26.1 percent over the past 12 months, over 67% percent of it served up by open source Apache servers. The link for this article located at Newsforge is no longer available. . Open source enthusiasts should meticulously review software for adherence to licensing agreements; crucial for successful promotional approaches.. Open Source Strategy, Software Compliance, Marketing Tools. . LinuxSecurity.com Team

Calendar%202 Jul 13, 2004 User Avatar LinuxSecurity.com Team Vendors/Products
82

Federal Agencies Unite on IT Security Benchmarks for Procurement

A group of high-level IT officials in the federal government has begun collaborating on configuration benchmarks that government agencies could be required to use in future purchases of hardware and software. The development of the benchmarks is at once an indication . . . . A group of high-level IT officials in the federal government has begun collaborating on configuration benchmarks that government agencies could be required to use in future purchases of hardware and software. The development of the benchmarks is at once an indication of the growing importance of security in Washington and of the government's intention to use its purchasing power as an agent of change inside the Beltway and in the vendor community. "Yes, I believe the government is getting better at this," said Alan Paller, research director at The SANS Institute, based in Bethesda, Md., who has spoken with many of the federal CIOs involved in this effort. "This doesn't solve the entire problem, but it helps going forward. I believe a great deal of money was thrown away on reports that could've been spent on solving the problem." The link for this article located at EWeek is no longer available. . Top-tier government tech leaders unite to establish safety standards for acquiring hardware and software.. Security Benchmarks,Federal IT Collaboration,Government Standards. . Anthony Pell

Calendar%202 Dec 18, 2003 User Avatar Anthony Pell Government
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200