Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
209

How An Open Source Program Office Secures The Software Supply Chain

Learn how an open source program office (OSPO) - a bureau of open source experts within your organization dedicated to overseeing how your company uses, creates and contributes to free software - could helps secure your software supply chain. . It’s nearly impossible these days to build software without using open source code. But all that free software carries additional security risks. Organizations grapple with how best to secure their open source software supply chain . But there’s another problem: Many companies don’t even know how many open source applications they have — or what’s in them. The worst-case scenarios include debacles like 2021’s Log4j security vulnerability , or what happened with SolarWinds ’ proprietary Orion network monitoring product, which was infected with malware in 2020. . An open source program office (OSPO) enhances security in your software supply chain by standardizing evaluations and fostering security awareness among developers. Open Source Program Office, Software Security, Risk Management. . Brittany Day

Calendar%202 Mar 11, 2022 User Avatar Brittany Day Security Trends
78

Mozilla's Upcoming Ban On Obfuscated Code In Firefox Extensions

Mozilla announced plans today to ban Firefox extensions from its Add-ons portal if the extension contains obfuscated code. . The ban will enter into effect on June 10, at which point Mozilla plans to remove all Firefox extensions that don't meet this criteria and shoot down any future extension submissions that fail to provide full access to their source code. The link for this article located at ZDNet is no longer available. . Mozilla will enforce a ban on Firefox extensions with obfuscated code starting June 10, ensuring transparency.. Mozilla Firefox Extensions, Obfuscated Code Policy, Web Security Standards. . LinuxSecurity.com Team

Calendar%202 May 02, 2019 User Avatar LinuxSecurity.com Team Vendors/Products
79

Apache Traffic Server Joins Top-Level Project Status at Apache Foundation

The Apache Software Foundation runs its open source projects on a hierarchy of principally three levels, top-level projects (TLPs), sub-projects and incubated projects. Achieving the TLP status is a major milestone for an open source effort and this week Apache announced that six projects were being graduated to TLP status.. Among the six new TLPs, is the Apache Traffic Server, a project that was originally an incubated effort by Yahoo (NASDAQ: YHOO) in 2009. The Traffic Server is also being updated to version 2.0 this week as the technology continues to grow under the direction of the Apache model. "It's the fundamental goal of being in incubation that you succeed and graduate," Leif Hedstrom, Chairperson of the Apache Traffic Server project, told InternetNews.com. "It signifies that our community and software have been well-governed under the ASF's meritocratic, consensus-driven process and principles." In addition to the Traffic Server, five former sub-projects of existing TLPs have now moved up. Three of the new TLPs were formerly sub-projects of Apache Lucene. They include the Apache Mahout machine learning algorithms effort and Apache Tika which is a toolkit for content detection and analysis. The Apache Nutch Web search engine is also moving up to TLP status. Rounding out the list of new TLPs are a pair of Apache Hadoop sub-projects including the Avro data serialization project and the HBase distributed database. The link for this article located at ServerWatch is no longer available. . Uncover the ways in which Apache Traffic Server reaches premier project recognition and the implications this holds for the open-source ecosystem.. Apache Traffic Server, Open Source Governance, Top-Level Project. . LinuxSecurity.com Team

Calendar%202 May 05, 2010 User Avatar LinuxSecurity.com Team Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":2,"type":"x","order":2,"pct":66.67,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200