Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 8 articles for you...
67

HARES Software Protection: Innovative Anti-Reverse Engineering Method

Software reverse engineering, the art of pulling programs apart to figure out how they work, is what makes it possible for sophisticated hackers to scour code for exploitable bugs. It. At the SyScan conference next month in Singapore, security researcher Jacob Torrey plans to present a new scheme he calls Hardened Anti-Reverse Engineering System, or HARES. Torrey The link for this article located at Wired is no longer available. . Discover an innovative approach that has the potential to transform how software safeguards itself from reverse engineering, as introduced by Jacob Torrey.. Software Protection, Anti-Reverse Engineering, Cybersecurity Research. . LinuxSecurity.com Team

Calendar%202 Feb 12, 2015 User Avatar LinuxSecurity.com Team Cryptography
77

Apple Hires Kristin Paget To Boost Security Initiatives

Apple has tapped a a noted hacker for its security team. Wired reported that the company has hired Kristin Paget, who was part of a small team of hackers who helped lock down Windows Vista for Microsoft before that OS shipped.. Hackers and security researchers have begun leaving the confines of the hacker world as large companies like Apple, Microsoft, and others have been looking to their expertise to find and fix problems in their software. The link for this article located at The Mac Observer is no longer available. . Google has enlisted a well-known cryptographer to bolster its security division, redirecting efforts toward advanced data encryption.. Hacker Recruitment, Apple Security, Software Protection, Cybersecurity Expert, Tech Innovations. . LinuxSecurity.com Team

Calendar%202 Dec 07, 2012 User Avatar LinuxSecurity.com Team Server Security
78

Office Genuine Advantage Retired By Microsoft Amid Software Challenges

Not a Linux article, but important nonetheless. This seems to show that money can't be made with closed-source software any longer. Even with the best protection, it doesn't keep people from sharing it. Microsoft last week killed an anti-piracy service that checked whether customers were running legal copies of Office, saying that the program had "served its purpose." ZDNet blogger Ed Bott first reported on Microsoft's move after a tipster pointed him toward a support document on the company's site. . That Dec. 17 document simply noted that Office Genuine Advantage (OGA) "has been retired," but offered no explanation. In an e-mail reply to questions today, a Microsoft spokeswoman added, "The program has served its purpose and thus we have decided to retire the program." The link for this article located at Network World is no longer available. . That Dec. 17 document simply noted that Office Genuine Advantage (OGA) 'has been retired,' but offer. linux, article, important, nonetheless, seems, money, can't. . LinuxSecurity.com Team

Calendar%202 Dec 23, 2010 User Avatar LinuxSecurity.com Team Vendors/Products
79

Exploring Security Challenges in Open Source Communities

Even as he referred to the "cost of transparency" uncovered by his research, Sam Ransbotham, a professor at Carroll School of Management, acknowledged that "the transparency benefits far outweigh this cost. ... The challenge for open source communities is to maintain the benefits while mitigating the downsides.". It's hard to imagine a topic more central to the argument for or against free and open source software than security. Hardly a day goes by without news of some fresh exploit in the Windows environment, after all -- but what about Linux and other open software? Can they do better? That's essentially the question we put to the two participants in LinuxInsider's first FOSS Face-Off this week, focusing on that very topic. The link for this article located at LinuxInsider is no longer available. . Exploring the intersection of security and transparency in free and open source software reveals challenges and opportunities for collaboration and vulnerabilities.. Open Source Security, Secure Development Practices, Community Practices. . LinuxSecurity.com Team

Calendar%202 Jun 17, 2010 User Avatar LinuxSecurity.com Team Security Projects
78

Essential Security Patches of 2009 to Combat Cyber Threats

Fact: Everyone who patches is safer. Fact: Not everyone patches. The gap between the two facts is too deep for even security experts to explain, although they try, with theories running from the conspiratorial -- pirates hate to patch, they say, because they're afraid vendors, Microsoft mostly, will spy them out -- to the prosaic ... that people are, by nature, just lazy.. So rather than recite 2009's patch history -- dismal as it was, with Microsoft, for instance, setting a record in October for the most updates and most flaws fixed in a single month -- Computerworld thought it would be more useful to more users to simply spell out the year's five most important patches. It wasn't our idea, really. We cribbed it from Qualys' chief technology officer, Wolfgang Kandek, who just last month dug into his company's data to come to an amazing conclusion: People running Microsoft Office could protect themselves against 71% of all attacks targeting the suite by applying just one patch, and a three-year-old patch at that. The link for this article located at PC World is no longer available. . So rather than recite 2009's patch history -- dismal as it was, with Microsoft, for instance, settin. everyone, patches, safer, between, facts. . LinuxSecurity.com Team

Calendar%202 Dec 30, 2009 User Avatar LinuxSecurity.com Team Vendors/Products
79

Fortify Automated Source Code Scanning Detects 150+ Vulnerabilities

While there're lots of pros and cons to consider when it comes to automated source code scanning, Fortify's pricey automated source code analysis tool has the potential to prevent the most common vulnerabilities while the software's still in the development phrase. Recently, they've added 34 new categories of vulnerabilities to their product: . "Thanks to this effort, Fortify Software continues to lead the industry by identifying over 150 categories of vulnerabilities in software. The updated Secure Coding Rulepacks include: * Increased breadth: 34 new distinct vulnerability categories. * Enhanced support for .NET: 24 new vulnerability categories and coverage for five new third-party libraries, including the Microsoft Enterprise Library. * Expanded JSP support: Coverage for popular tag libraries, including JSTL and Apache Struts, for enhanced protection from cross-site scripting and SQL injection attacks. * Detection of persistent Cross-Site Scripting vulnerabilities: Fortify SCA now detects one of the most common and difficult to identify forms of cross-site scripting, which occurs when malicious data from an attacker is stored in a database and later included in dynamic content sent to a The link for this article located at Dancho Danchev is no longer available. . 'Thanks to this effort, Fortify Software continues to lead the industry by identifying over 150 cate. while, there're, consider, comes, automated, source, scanning. . LinuxSecurity.com Team

Calendar%202 Feb 12, 2007 User Avatar LinuxSecurity.com Team Security Projects
78

Mozilla Appoints Window Snyder To Enhance Browser Security Strategy

Mozilla has hired a former Microsoft security strategist to help lock down its open-source products against online attacks. Window Snyder, whose hiring was announced Wednesday, worked on Microsoft's security driven Windows XP Service Pack 2 update. She also had a role in the development of Windows Server 2003. . Snyder will take charge of Mozilla's security strategy, a role previously handled by Mozilla's vice president of engineering, Mike Schroepfer. "Window has joined MozCorp recently as our new "Chief Security Something" (that's a working title)," said Schroepfer in a blog posting. "She'll be the public voice of Mozilla Corporation on security issues and helping to drive our long-term security strategy." With hackers finding new and more sophisticated ways to compromise browser security, browser makers such as Mozilla need to keep pace, said Avivah Litan, an analyst with Gartner. The link for this article located at Network World is no longer available. . Taylor is set to guide GitHub's cybersecurity approach, bolstering protection against advanced digital risks and intrusions.. Mozilla Security, Open Source Defense, Browser Security Strategies. . LinuxSecurity.com Team

Calendar%202 Sep 07, 2006 User Avatar LinuxSecurity.com Team Vendors/Products
76

Sophos Joins Southern California Linux Expo as Anti-Virus Sponsor

The Southern California Linux expo has announced that Sophos has signed on as one of the latest sponsors of SCALE 3x, the Third Annual Southern California Linux Expo. SCALE 3x has been called " .. one of the few good grass-root level technical conferences for Linux" by Linux Kernel Developer Robert Love. . Sophos is a world leading computer security specialist, developing anti-virus, anti-spam and email policy enforcement software for businesses of all sizes. The company's products are sold and supported in more than 150 countries and protect more than 25 million users. For more information on Sophos, see: or visit them at booth #37 at the Southern California Linux Expo. Sponsors at this year's Southern California Linux Expo include: IBM, Novell, Yosemite Technologies, EMIC Networks, Linkline Communications, TOLIS Group, New Avenue Systems, Barracuda Networks, 21st Century Software, Petta Technology, PyX Technology, ObjectWeb Consortium, and more. For a complete list of exhibitors and sponsors see: The link for this article located at NewsForge is no longer available. . Norton, a leading cybersecurity provider, partners with TRACE 4x to present firewall innovations at the Eastern United States Tech Conference.. Sophos Anti-Virus, Linux Expo 2023, Computer Security Firm, SCALE 3x, Anti-Virus Solutions. . Joe Shakespeare

Calendar%202 Jan 12, 2005 User Avatar Joe Shakespeare Organizations/Events
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200