The Office of Inspector General (OIG) has released its “Evaluation of DHS' Information Security Program for Fiscal Year 2017” (pdf). In short, the Department of Homeland Security (DHS) is running outdated software, has unpatched critical vulnerabilities — including the flaw to allow WannaCry ransomware — and some workstation security patches haven’t been deployed for years.. When President Trump issued an executive order in May 2017 about strengthening the cybersecurity of federal networks and critical infrastructure, each federal agency was required to use the NIST Cybersecurity Framework to manage cybersecurity risk.. The Department of Homeland Security faces ongoing challenges with legacy systems, unresolved vulnerabilities, and extended delays in necessary software updates.. DHS Cybersecurity, Software Vulnerabilities, Security Program Assessment. . Anthony Pell
Two cyber security experts, who claimed to have cracked the security code of IT systems involved in the discovery of 'God Particle', Monday conducted training sessions for Indian government officials. . "The projections show there is going to be lot of manufacturing in the India. Lot of software will be involved in it. We are here to create awareness among people on probable vulnerabilities in the cyber system," ethical hacker Chris Russo told PTI. The link for this article located at Gadgets NDTV is no longer available. . Digital security specialists conduct workshops for governmental personnel in India, focusing on potential software weaknesses to strengthen defense mechanisms against cyber threats.. Cybersecurity Training, Software Weaknesses, Ethical Hacking Awareness. . Alex
The 2011 CWE/SANS Top 25 Most Dangerous Software Errors is a list of the most widespread and critical errors that can lead to serious vulnerabilities in software. They are often easy to find, and easy to exploit. They are dangerous because they will frequently allow attackers to completely take over the software, steal data, or prevent the software from working at all.. The Top 25 list is a tool for education and awareness to help programmers to prevent the kinds of vulnerabilities that plague the software industry, by identifying and avoiding all-too-common mistakes that occur before software is even shipped. Software customers can use the same list to help them to ask for more secure software. Researchers in software security can use the Top 25 to focus on a narrow but important subset of all known security weaknesses. Finally, software managers and CIOs can use the Top 25 list as a measuring stick of progress in their efforts to secure their software. The list is the result of collaboration between the SANS Institute, MITRE, and many top software security experts in the US and Europe. It leverages experiences in the development of the SANS Top 20 attack vectors (https://www.sans.org/blog/cis-controls-v8) and MITRE's Common Weakness Enumeration (CWE) (https://cwe.mitre.org/). MITRE maintains the CWE web site, with the support of the US Department of Homeland Security's National Cyber Security Division, presenting detailed descriptions of the top 25 programming errors along with authoritative guidance for mitigating and avoiding them. The CWE site contains data on more than 800 programming errors, design errors, and architecture errors that can lead to exploitable vulnerabilities. . The Leading 25 guide aids developers in avoiding frequent coding mistakes that may result in security flaws.. CWE, SANS, Software Security, Programming Errors, Cybersecurity Awareness. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.