Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Gamers have been annoyed all day today as a hacker collective (or individual) known as the . American Airlines reacted to the threat immediately, diverting the plane to Phoenix and confirming it was for a security-related matter. SOE has come out with a statement that confirms that The link for this article located at Forbes is no longer available. . Delta Airlines rerouted a plane after receiving a bomb threat message from cybercriminals, prompting increased security protocols.. American Airlines Incident, Flight Diversion Incident, Bomb Threat Response. . LinuxSecurity.com Team
On Sunday morning, Nate Daiger, one of the owners of a small Los Angeles-based hosting company Chunk Host, received an odd email on his phone.. The email came from SendGrid, a company used by Chunk Host to send its email. SendGrid specializes in ensuring an organization's legitimate emails get through and aren't mistakenly picked off by spam filters. The link for this article located at IT World is no longer available. . The email came from SendGrid, a company used by Chunk Host to send its email. SendGrid specializes i. sunday, morning, daiger, owners, small, angeles-based, hosting, company, chunk. . LinuxSecurity.com Team
Hackers have broken into the cellphones of celebrities like Scarlett Johansson and Prince William. But what about the rest of us, who might not have particularly salacious photos or voice messages stored in our phones, but nonetheless have e-mails, credit card numbers and records of our locations?. A growing number of companies, including start-ups and big names in computer security like McAfee, Symantec, Sophos and AVG, see a business opportunity in mobile security The link for this article located at NY Times is no longer available. . As mobile devices grow central to our lives, their threat landscape widens, prompting cybersecurity firms to enhance protections against cybercriminals targeting them. Mobile Security Threats, Cybersecurity Solutions, Data Protection, Mobile Device Risks. . LinuxSecurity.com Team
The group responsible for coordinating U.S. responses to cyber threats is getting new digs. Department of Homeland Security (DHS) Secretary Janet Napolitano will cut the ribbon Friday at a new "unified operations center" in Arlington, Virginia, that will be home to the U.S. Computer Emergency Readiness Team (US-CERT). . It will also house the National Coordinating Center for Telecommunications (NCC), and the National Cyber Security Center (NCSC), which coordinates between three-letter government agencies such as the National Security Agency and the Federal Bureau of Investigation. The NCC monitors threats to the telecommunications system and coordinates its restoration in the event of an attack or a natural disaster. The three groups are being moved into one operations center in order to improve communications between the units, said Amy.Kudwa, a spokeswoman with the DHS. "The model of connecting the dots and sharing information and physically co-locating has been one of the most important lessons learned since 9/11," she said. "This is a similar model of collecting experts who are working on different aspects of a larger issue." The link for this article located at Network World is no longer available. . The Cybersecurity and Infrastructure Security Agency transforms into a central operations hub partnered with the National Cybersecurity Center to enhance responses to digital threats. Cybersecurity Hub, Threat Response, US-CERT, NCSC, NCC. . Anthony Pell
Two national task forces organized by the National Cyber Security Partnership called for a public awareness campaign, an early warning contact network and a national crisis coordination center to improve the nation's responses to cyber vulnerabilities, threats and incidents. Created last December at the National Cyber Security Summit, the task forces released their recommendations today for improving the nation's cybersecurity defenses. The National Cyber Security Partnership was formed to bring together private organizations and government agencies. . . .. Two national task forces organized by the National Cyber Security Partnership called for a public awareness campaign, an early warning contact network and a national crisis coordination center to improve the nation's responses to cyber vulnerabilities, threats and incidents. Created last December at the National Cyber Security Summit, the task forces released their recommendations today for improving the nation's cybersecurity defenses. The National Cyber Security Partnership was formed to bring together private organizations and government agencies. No price tag was attached to the task forces' suggestions, but establishing a national crisis coordination center by 2006 most likely would require legislation or an executive order. Guy Copeland, who led the Early Warning Task Force, said the center would coordinate threat analyses, warnings, research and responses for critical infrastructure-sector experts and federal, state and local officials. Copeland is vice president of information infrastructure advisory programs for Computer Sciences Corp.'s federal-sector business. The center would "bridge some cultural barriers that have hampered a true partnership in counterterrorism and cybersecurity," the task force report said. The early warning contact network, to be set up as early as December, would be a multichannel network housed and administered by the Homeland Security Department's U.S. Computer Emergency Readiness Team. Communication would occur primarilyvia the Internet, although task force leaders recommended having a backup means of communicating if the Internet goes down. Other recommendations of the task forces would be relatively inexpensive and easy to achieve. The Common Sense Guide to Cyber Security for Small Businesses, prepared by the Internet Security Alliance, is already available and free for downloading. The Awareness and Outreach Task Force has as one of its initial goals to reach 50 million households. Reaching home users will be accomplished largely through the cooperation of Internet service providers who would keep their customers informed of cybersecurity threats and attacks, task force leaders said. The link for this article located at fcw.com is no longer available. . A pair of federal committees advocates for the establishment of a centralized crisis management hub to enhance cybersecurity preparedness and reaction capabilities.. National Cyber Security, Crisis Management, Cyber Initiatives, Threat Analysis, Cyber Resilience. . Anthony Pell
Until recently, systems and security management have usually been seen as separate disciplines. While large framework vendors paid lip service in marketechture visions of deeply integrated security with the rest of systems and application management, this vision never materialized at a practical ops level.. . .. Until recently, systems and security management have usually been seen as separate disciplines. While large framework vendors paid lip service in marketechture visions of deeply integrated security with the rest of systems and application management, this vision never materialized at a practical ops level. Instead, security and systems management evolved into distinct areas with their own best of breed solutions that involved separate architectures, expertise, and consoles for management. Security focused on analysis while systems management gained prominence in operations. In most cases, security was considered secondary to maintaining performance and availability as companies pursued growth at all costs. New laws and regulations, highly visible worm and virus attacks, and 9/11, however, have transformed security from a back room to a boardroom issue. There are several areas where the convergence of systems and security management can make a big difference in improving efficiency and effectiveness across the enterprise. The link for this article located at SCMagazine is no longer available. . Until recently, systems and security management have usually been seen as separate disciplines. Whil. until, recently, systems, security, management, usually, separate, disciplines. . Anthony Pell
Microsoft's Security Response Center in Redmond, Wash., is the computing equivalent of a hospital emergency ward. When a problem comes in the door the center's director, Kevin Kean, and his staff must swiftly make an assessment: Is the security weakness detected in a Microsoft software product only minor?. . .. Microsoft's Security Response Center in Redmond, Wash., is the computing equivalent of a hospital emergency ward. When a problem comes in the door the center's director, Kevin Kean, and his staff must swiftly make an assessment: Is the security weakness detected in a Microsoft software product only minor? Or is it possibly so serious that, if exploited by a vandal's malicious code (as happened last month with the Blaster worm) it might crash computers and networks around the world? If the threat appears grave, the problem goes immediately into the center's emergency operating room, where it is attended to by a team of Microsoft engineers, working nearly round-the-clock to analyze the flawed code, anticipate paths of attack, devise a software patch to fix the defect and alert millions of customers of the problem and the patch. "It's triage and emergency response -- so it's a lot like an E.R. ward in that sense," Mr. Kean observed last week. The race to protect the computing patient has begun again. Site registration may be required. The link for this article located at NY Times is no longer available. . Microsoft's Security Response Center in Redmond, Wash., is the computing equivalent of a hospital em. microsoft's, security, response, center, redmond, computing, equivalent, hospital. . LinuxSecurity.com Team
Kevin Jurrens writes: Prentice Hall PTR and HP Books today announced the publication of "Halting the Hacker: A Practical Guide to Computer Security," Second Edition by Donald L. Pipkin, CISSP, Information Security Architect for the Internet Security Division of the Hewlett-Packard Company. "Halting the Hacker: A Practical Guide to Computer Security," Second Edition, combines unique insight into the mind of the hacker with practical, step-by-step countermeasures for protecting any HP-UX, Linux, or UNIX system.. . .. Kevin Jurrens writes: Prentice Hall PTR and HP Books today announced the publication of "Halting the Hacker: A Practical Guide to Computer Security," Second Edition by Donald L. Pipkin, CISSP, Information Security Architect for the Internet Security Division of the Hewlett-Packard Company. "Halting the Hacker: A Practical Guide to Computer Security," Second Edition, combines unique insight into the mind of the hacker with practical, step-by-step countermeasures for protecting any HP-UX, Linux, or UNIX system. Prentice Hall PTR and HP Books Publish Second Edition of Computer Security Bestseller "Halting the Hacker" Updated to Reflect Today's Most Critical Threats, Tools and Responses Upper Saddle River, NJ, Oct. 2, 2002 - Prentice Hall PTR and HP Books today announced the publication of "Halting the Hacker: A Practical Guide to Computer Security," Second Edition by Donald L. Pipkin, CISSP, Information Security Architect for the Internet Security Division of the Hewlett-Packard Company. "Halting the Hacker: A Practical Guide to Computer Security," Second Edition, combines unique insight into the mind of the hacker with practical, step-by-step countermeasures for protecting any HP-UX, Linux, or UNIX system. Top HP security architect Donald L. Pipkin has updated this global bestseller for today's most critical threats, tools, and responses. The book explores the processes hackers use to gain access, privileges, and control--showing readers exactly how hackers work and the best ways torespond to incidents. Using dozens of new examples, the book provides readers with the skills and mindset to protect themselves against any current hacking exploit--even attacks that haven't even been imagined yet. Halting the Hacker, Second Edition, covers: How hackers select targets, identify systems, gather information, gain access, acquire privileges, and avoid detection How multiple subsystems can be used in harmony to attack your computers and networks Specific steps to take immediately to improve the security of any HP-UX, Linux, or UNIX system How to build a secure UNIX system from scratch--with specifics for HP-UX and Red Hat Linux Systematic proactive, reactive, and preemptive security measures Security testing, ongoing monitoring, incident response, and recovery--in depth Legal recourse: What laws are being broken, what one needs to prosecute, and how to overcome the obstacles to successful prosecution The accompanying CD-ROM contains an extensive library of HP-UX and Linux software tools for detecting and eliminating security problems and a comprehensive information archive on security-related topics. About the Author... Donald L. Pipkin, CISSP, is an Information Security Architect for the Internet Security Division of HP who consults with many of HP's largest customers. An internationally renowned security expert with over 15 years of experience, Pipkin is a frequent speaker and presenter on security issues in regional, national, and international conferences. His areas of expertise include policy, procedures, and intrusion response. He is author of Information Security: Protecting the Global Enterprise. Halting the Hacker: A Practical Guide to Computer Security, Second Edition, Pipkin. Prentice Hall PTR/HP Books 2003. ISBN: 0-13-046416-3. 384 pp. $44.99 Editors and media: For complimentary review copies, permission for excerpts, art or interviews with the author, please contact Kevin Jurrens of Garfield Group PR at 215-867-8600 x273 or
Get the latest Linux and open source security news straight to your inbox.