Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Federal legislators have begun the process of better securing the open-source software used by government agencies with a new bill titled “Securing Open Source Software Act of 2022.” . Sens. Gary Peters, D-Mich., and Rob Portman, R-Ohio, introduced the legislation that seeks to address open source software risks in government. The proposed Bill, S. 4913, now awaits action by the Committee on Homeland Security and Governmental Affairs. The legislation comes after a hearing Peters and Portman convened on Feb. 2 to investigate the Log4j incident that was discovered in December 2021. It directs the Cybersecurity and Infrastructure Security Agency (CISA) to help ensure that open-source software is used safely and securely by the federal government, critical infrastructure, and others. . Senators Tina Smith and Mike Lee proposed a bill aimed at improving the safety of open-source applications across federal departments.. Open Source Software, Cybersecurity Act, Government Security, Software Risks. . Brittany Day
Total vulnerabilities in OSS more than doubled in 2019 - suggesting that while open-source code is often considered more secure than commercial software, OSS vulnerabilities are on the rise and may be a blindspot for many organizations. . The study also revealed that it takes a very long time for OSS vulnerabilities to be added to the National Vulnerability Database ( NVD ), averaging 54 days between public disclosure and inclusion in the NVD. This delay can cause organizations to remain exposed to serious application security risks for almost two months. These very long lags were seen across all severities including vulnerabilities rated as ‘Critical’ and those that were weaponized, meaning those where an exploit is present in the wild. . The rise of open-source flaws peaked in 2019, exposing critical security weaknesses and prolonged response times to emerging threats.. Open Source Security, Vulnerabilities Trends, Application Security Risks, National Vulnerability Database. . Brittany Day
The value of OSS is undeniable. OSS offers organisations greater flexibility and cost savings. However, it needs to be understood that no software is completely bullet proof and OSS shares the same inherent risks as traditional software. . The rapid pace of modern software development has allowed businesses to transform the way they run – yielding superior customer experiences, greater efficiencies, faster time to market and better cost optimisation. Software has enabled companies to disrupt their business environments by leveraging the agility and speed of change that only software can deliver. The companies that thrive today are those that realize that software innovation can drive agility, create differentiation and provide competitive advantages. With software so predominant, the use of Open Source Software (OSS) has grown in popularity over the last few years. The enticement of OSS is undeniable, and the vibrant open source community has rallied, resulting in significant contributions to the open source movement. As a result, developers are increasingly turning to OSS to aid their organization’s transformation. The link for this article located at Science Direct is no longer available. . Open source software (OSS) offers numerous advantages and challenges for organizations, enhancing transparency while introducing vulnerabilities that require careful management. Open Source Software, OSS Security Risks, Business Transformation, Software Development Challenges. . Brittany Day
A preliminary study released February 18, which we directed alongside the Linux Foundation, numerous troubling trends in open source security underscore the importance of understanding where open source is most used and could be vulnerable to attack. . Commonly used free and open source software (FOSS) is one of the most significant technological trends of the decade. After all, 80-90 percent of a typical application contains FOSS components (pdf) . And that trend is only increasing with its use in smart phones, cars, the Internet of Things, and numerous pieces of critical infrastructure. But without appropriate investment and maintenance, that widespread adoption has the potential to become a liability. The link for this article located at Harvard Business School is no longer available. . Widely utilized free and open source software (FOSS) highlights notable security patterns and possible vulnerabilities.. Open Source Vulnerabilities, FOSS Security Risks, Software Supply Chain, Open Source Software Challenges. . Brittany Day
Open-source software and components are critical to many of the online services we use today. Companies, ranging from the most well-known technology giants to SMBs, will often use open-source technologies to improve their own business processes and access useful software libraries.. Open-source components can be used in everything from security to Big Data analysis and communications platforms, but companies are failing to keep track of what open-source projects they rely on -- as well as keep these systems secure. The link for this article located at ZDNet is no longer available. . Open-source components can be used in everything from security to Big Data analysis and communicatio. open-source, software, components, critical, online, services, today, compan. . Brittany Day
The number of software vulnerabilities fell overall in 2009, but the number of bugs in document readers and multimedia applications increased by 50 percent, according to IBM's annual X-Force Trend and Risk Report.. IBM's X-Force research and development team studies vulnerability disclosures and collects other data on Web-based attacks. In 2009, the team recorded 6,601 new vulnerabilities, which is 11 percent less than in 2008. But IBM said the number of vulnerability disclosures for document readers, editors and multimedia applications rose by 50 percent. IBM classifies those as client-side vulnerabilities, which also include vulnerabilities affecting browsers and operating systems. Of the five most prevalent Web site exploits, three involved PDF (Portable Document Format) files. Attackers have had much success in finding vulnerabilities in Adobe's PDF software and conduct attacks through spam campaigns and malicious Web sites. "There's definitely a group of bad guys out there that are targeting that piece of software," said Tom Cross, IBM X-Force research manager. The link for this article located at PC World is no longer available. . The Symantec security team noted a decrease in malware exploits, yet phishing attempts have risen dramatically.. IBM X-Force, Document Reader Risks, Software Security. . LinuxSecurity.com Team
Security breaches in software applications and networks are one of the biggest threats organizations currently face. But unless you pack your computers into boxes and go back to pencils, paper, and typewriters, being mindful of electronic security is an unavoidable reality and business expense. Because security vulnerabilities are such a high stakes issue, the subject has become a political hot potato between open source and commercial software advocates, with each pointing a finger at the other. Some commercial software vendors claim that their model promotes security while the open source model weakens it; some open source developers claim the exact opposite. . For organization making the decisions, however, blanket generalizations are best avoided. The link for this article located at ServerWatch is no longer available. . Entities encounter substantial risks stemming from cybersecurity incidents within applications and digital frameworks. Grasp the repercussions.. Open Source Security, Network Risks, Software Security, Risks Management. . LinuxSecurity.com Team
Microsoft Office XP and Internet Explorer version 5 and later are configured to request to send debugging information to Microsoft in the event of a program crash. The debugging information includes a memory dump which may contain all or part of . . . . Microsoft Office XP and Internet Explorer version 5 and later are configured to request to send debugging information to Microsoft in the event of a program crash. The debugging information includes a memory dump which may contain all or part of the document being viewed or edited. This debug message potentially could contain sensitive, private information. The link for this article located at CIAC is no longer available. . Outdated software like Microsoft Office 2003 and old web browsers may unintentionally expose sensitive information during crashes, creating privacy risks. Sensitive Documents, Data Privacy, Software Risks, Office XP Issues. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.