Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
74

Mozilla's 10-Day Critical Bug Patch Commitment Raises Security Standards

A Mozilla executive has vowed that his company can patch any critical vulnerability in its software within 10 days, a sign that Mozilla intends to step up its efforts to improve security. I found this to be a pretty bold claim. Does this have anything to do with the recent flood of Firefox security bugs? I really hope that Mozilla is able to stick with their claim of providing security fixes with-in 10 day. Could other software makers do the same thing? . Mozilla executive Mike Shaver backed up his claim by scrawling it on a business card at the Black Hat security conference in Las Vegas last week and handing it to Robert Hansen, CEO of SecTheory.com, who also runs the ha.ckers.org website. Hansen posted a photo of Shaver's business card, including the claim "Ten [expletive] days." The link for this article located at TechWorld is no longer available. . Mozilla executive Mike Shaver backed up his claim by scrawling it on a business card at the Black Ha. mozilla, executive, vowed, company, patch, critical, vulnerability, software. . Bill Locke

Calendar%202 Aug 06, 2007 User Avatar Bill Locke Network Security
82

Ounce Labs Initiatives for Security Standards in Code Development

The maker of a software security analysis tool is promoting quality assurance for outsourced code development. "We're going to help drive new behavior," said Jack Danahy, president and CEO of Ounce Labs Inc. of Waltham, Mass. . . .. The maker of a software security analysis tool is promoting quality assurance for outsourced code development. "We're going to help drive new behavior," said Jack Danahy, president and CEO of Ounce Labs Inc. of Waltham, Mass. Ounce Labs has published sample contract language for software development that sets specific security standards and requires a security audit of the source code. The language frees the buyer from having to pay for software that does not meet the standards. Danahy made no bones about the fact that adoption of the contract language could expand the market for his company's flagship analysis tool, Prexis. But outsiders, including at least one government IT administrator, also welcome the contract addendum. "It is incredibly significant," said Jamie Gateau, director of technology innovation for the Naval Network and Space Operations Command in Dahlgren, Va. Part of his job is overseeing software development, whether in-house or outsourced. Gateau can control the work in house, he said, "but when I'm dealing with contractors, we didn't have contract language to specify secure code. Now we finally have the beginnings of a language to talk about how we're going to hold people responsible for secure coding." The link for this article located at William Jackson is no longer available. . The maker of a software security analysis tool is promoting quality assurance for outsourced code de. maker, software, security, analysis, promoting, quality, assurance, outsourced. . Anthony Pell

Calendar%202 Sep 07, 2004 User Avatar Anthony Pell Government
76

Web Services Interoperability Challenges: WS-I Addresses Security Issues

A group working to ensure the compatibility of Web services software is preparing to tackle its biggest challenge yet: Security. The Web Services Interoperability organization (WS-I) was formed last year at the behest of companies including IBM and Microsoft to see to it that Web services products from different companies work together.. . .. A group working to ensure the compatibility of Web services software is preparing to tackle its biggest challenge yet: Security. The Web Services Interoperability organization (WS-I) was formed last year at the behest of companies including IBM and Microsoft to see to it that Web services products from different companies work together. The group now has approximately 160 members, including about 20 companies that are not information technology suppliers. Although businesses are forging ahead with Web services applications as a way of bridging differences between disparate systems, minor incompatibilities are surfacing. The WS-I's stated goal is to make sure gear from various IT suppliers is compatible and to help customers iron out any Web services glitches. So far, the group has delivered a draft specification of basic Web services protocols, which is set to be finalized in the second quarter. The link for this article located at ZDNet is no longer available. . A group working to ensure the compatibility of Web services software is preparing to tackle its bigg. group, working, ensure, compatibility, services, software, preparing, tackle. . Anthony Pell

Calendar%202 Feb 05, 2003 User Avatar Anthony Pell Organizations/Events
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200