Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
OpenSSF is excited to announce the Alpha-Omega Project to improve the security posture of open source software (OSS) through direct engagement of software security experts and automated security testing. Microsoft and Google are supporting the Alpha-Omega Project with an initial investment of $5 million. . Alan Shimel: Hey, everyone. Welcome to another segment for Techstrong TV. My guest today is Brian Behlendorf. Brian is with the Open Source Security Foundation – that’s the OSSF. The Open Source Security Foundation, of course, is part of the Linux Foundation and it was – it’s a relatively new organization. It was – was it announced at KubeCon – CNCFCon back in, I guess, September, was that, Brian? Brian Behlendorf: We announced kind of the second generation of the project in October. The project has been around for about a year longer than that – actually just over that as a collaboration between some things that Microsoft had started and Google had started. The Linux Foundation said, “Let’s put this in the same pod” and a tremendous community of volunteers stepped up to do all sorts of things and get plates spinning on top of poles. And then, around about October we realized, hey, there’s some places where spending some money would be helpful and here’s a whole bunch of companies willing to come in as sponsors and really fund some of that work. And so, that also freed me up to be able to focus full time on it as well. The link for this article located at Security Boulevard is no longer available. . The Open Source Security Foundation's Alpha-Omega Initiative is designed to bolster OSS protection through the involvement of specialists and thorough assessments.. OpenSSF, Open Source Security, Alpha-Omega Project, Software Security, Automated Testing. . Brittany Day
Following a meeting with government and industry leaders at the White House, OpenSSF is excited to announce the Alpha-Omega Project to improve the security posture of open source software (OSS) through direct engagement of software security experts and automated security testing. . Microsoft and Google are supporting the Alpha-Omega Project with an initial investment of $5 million . This builds on previous industry-wide investments into OpenSSF aiming to improve open source software security. Widely deployed OSS projects that are critical to global infrastructure and innovation have become top targets for adversarial attacks. Following new vulnerability disclosures, adversary attacks can be seen within hours. For example, recently discovered vulnerabilities in the widely deployed Log4j library forced many organizations into crisis as they raced to update applications using the popular library before adversaries could attack. . The OpenSSF collaborates with Google and Microsoft, investing $5 million to bolster the Alpha-Omega initiative, aimed at improving open-source software.. OSS Security, Alpha-Omega Project, Software Supply Chain, Security Testing, OpenSSF. . LinuxSecurity.com Team
Subscribers to organizations that sell exploits for vulnerabilities not yet known to software developers gain daily access to scores of flaws in the world's most popular technology, a study shows. . NSS Labs, which is in the business of testing security products for corporate subscribers, found that over the last three years, subscribers of two major vulnerability programs had access on any given day to at least 58 exploitable flaws in Microsoft, Apple, Oracle or Adobe products. The link for this article located at CSO Online is no longer available. . Recent findings from NSS Labs showcase the vast range of zero-day vulnerabilities accessible to those enrolled in their security initiative.. Zero-Day Exploits, Flaw Access, Security Analysis, Vulnerability Testing. . LinuxSecurity.com Team
The new Apple iPhone OS 3.1 software comes with a new anti-phishing feature for the Mobile Safari browser, but researchers say the filter doesn't work.. "I've not been able to get it to block anything," says Michael Sutton, vice president of research at Zscaler, who has been testing the mobile browser's security feature against several phishing sites identified on PhishTank. While Apple's Safari for the desktop blocks many of the sites, the iPhone's mobile version didn't block any that he tested. Sutton says it's either a bug in the OS 3.1 software, or the new iPhone software just runs a pared-down version of the Safari browser's security feature. "OS 3.1 has settings in the Safari browser for turning on and off phishing protection, but it's just not [working]," Sutton says. Apple had touted the new iPhone OS 3.0's anti-phishing feature, but Sutton says the feature was a no-show once the software was released in June, and he assumed the feature had just landed on the cutting floor. The link for this article located at Dark Reading is no longer available. . 'I've not been able to get it to block anything,' says Michael Sutton, vice president of research at. apple, iphone, software, comes, anti-phishing, feature, mobile, safari. . LinuxSecurity.com Team
A cybersecurity task force recommended improvements today to a variety of technical standards and practices. Organized by the National Cyber Security Partnership, the task force issued a 104-page report with recommendations for the federal government and industry. The report is the last of five documents prepared by industry and academic experts on the President's National Strategy to Secure Cyberspace, a general blueprint for improving the nation's cybersecurity readiness. . . .. A cybersecurity task force recommended improvements today to a variety of technical standards and practices. Organized by the National Cyber Security Partnership, the task force issued a 104-page report with recommendations for the federal government and industry. The report is the last of five documents prepared by industry and academic experts on the President's National Strategy to Secure Cyberspace, a general blueprint for improving the nation's cybersecurity readiness. The task force members called for what they said were needed improvements to the consumer- and vendor-oriented software security testing program operated by the National Institute of Standards and Technology and the National Security Agency. The report recommends that NIST receive an initial $12 million in new appropriations and $6 million in following years for developing security requirements for specific classes of products such as intrusion-detection systems and virtual private networks. The link for this article located at fcw.com is no longer available. . A cybersecurity task force recommended improvements today to a variety of technical standards and pr. cybersecurity, force, recommended, improvements, today, variety, technical, standards. . Anthony Pell
The Defense Department's Biometrics Fusion Center soon will begin testing software on four types of biometric devices for use on its Common Access smart cards. DOD's Biometrics Management Office last week awarded a $915,000 contract to KPMG Consulting Inc. of . . . . The Defense Department's Biometrics Fusion Center soon will begin testing software on four types of biometric devices for use on its Common Access smart cards. DOD's Biometrics Management Office last week awarded a $915,000 contract to KPMG Consulting Inc. of McLean, Va., to conduct a 90-day test of biometric identifiers that could authenticate smart-card holders for building and network access. "We want to spend three weeks for a product assessment," said Paul Howe, director of the Biometrics Fusion Center in Bridgeport, W.Va. "We try to stay ahead of the marketing curve." Howe said the center's mission is to help DOD agencies become better buyers of biometrics. A separate facility in Bridgeport will host the tests for the Common Access program. KPMG's four subcontractors, known as the Smart Card Solution Team, will visit the fusion center to train workers in the vendors' enrollment and authentication applications with fingerprint readers as well as iris, voice and facial recognition devices. The subcontractors will demonstrate how a biometric identifier is stored and matched on a server, stored and matched on PCs, stored on a smart card and matched on a server, or stored and matched on smart cards. The link for this article located at GCN is no longer available. . The Defense Department's Biometrics Fusion Center soon will begin testing software on four types of . defense, department's, biometrics, fusion, center, begin, testing, software, types. . Anthony Pell
A group of open source developers dedicated to introducing an industry standard on security testing will be releasing the fruits of their labours later this month. Ideahamster.org started working on the Open Source Security Testing Methodology Manual (OSSTMM ) last year after becoming "sick of reading bland testing methodology descriptions".. . .. A group of open source developers dedicated to introducing an industry standard on security testing will be releasing the fruits of their labours later this month. Ideahamster.org started working on the Open Source Security Testing Methodology Manual (OSSTMM ) last year after becoming "sick of reading bland testing methodology descriptions". The group, which includes security experts and developers, claimed that the introduction of an industry standard on security testing would make it easier for users to judge security products. Security firms currently use a number of different methodologies for testing, often producing a variety of results. Be sure to read our interview with Pete Herzog, the creator of the project. The link for this article located at vnunet is no longer available. . A group of open source developers dedicated to introducing an industry standard on security testing . group, source, developers, dedicated, introducing, industry, standard, security, testing. . LinuxSecurity.com Team
Bruce Schneier's comments on a security Underwriters Laboratory. As always, a well-thought-out commentary well worth reading. " Second, network security is much too hard to test. Again, safes are easy. Breaking into them requires skill but is reasonably straightforward. Modern software . . . . Bruce Schneier's comments on a security Underwriters Laboratory. As always, a well-thought-out commentary well worth reading. " Second, network security is much too hard to test. Again, safes are easy. Breaking into them requires skill but is reasonably straightforward. Modern software is obscenely complex: There's an enormous number of features, configurations, implementations. And then there are interactions between different products, different vendors, and different networks. In the past, I've written extensively about complexity and the impossibility of testing security. For now, suffice it to say that testing any reasonably sized software product would cost millions of dollars and wouldn't guarantee anything at the end. And worse, if you updated the product you'd have to test it all over again." The link for this article located at ZDNet is no longer available. . Delving into Bruce Schneier's perspectives on the obstacles faced in evaluating network defense mechanisms and the intricacies of software systems.. Cybersecurity Risks, Network Security Testing, Software Assessment. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.