Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 2 articles for you...
83

Bit9 Breach Highlights Critical Security Flaws and Vendor Accountability

By confessing that its mistakes led to security breaches at three customers, Bit9 has sparked debate over whether the industry is ready to block hackers that see vendors as the door to other companies. . Bit9 disclosed last week that cybercriminals stole digital code-signing certificates from its computers and then used them to drop malware in the systems of three unidentified customers. The vendor acknowledged that the theft occurred on computers that it had failed to protect with its own product, which allows only software on a whitelist to run. The link for this article located at CSO is no longer available. . Bit9's revelation of a breach uncovers serious flaws in cybersecurity protocols and vendor responsibility.. Bit9 Breach, Cybercriminal Activity, Digital Certificates, Malware Incidents, Security Accountability. . LinuxSecurity.com Team

Calendar%202 Feb 12, 2013 User Avatar LinuxSecurity.com Team Hacks/Cracks
78

Examining Vendor Responsibilities in Security Bug Management

In last week. The reader wrote to say that his company often sits on security bugs until they are publicly announced or until at least one customer complaint is made. Before you start disagreeing with this policy, hear out the rest of his argument. The link for this article located at InfoWorld is no longer available. . Vendors delaying security bug fixes until public scrutiny poses ethical issues, prioritizing reputation over user safety and eroding trust in digital products. Vendor Accountability, Risk Management, Bug Fix Strategies. . LinuxSecurity.com Team

Calendar%202 May 14, 2007 User Avatar LinuxSecurity.com Team Vendors/Products
78

Bruce Schneier Advocates Software Vendor Accountability for Security

Software companies should be made liable for the security problems that arise in their products, according to security guru Bruce Schneier. In a presentation at the LinuxWorld OpenSolutions Summit, the BT Counterpane CEO said that this was the only way to help improve IT security, the effects of which were currently taken for granted. . By modifying the cost-benefit analysis and giving greater IT security responsibility to software companies through liability assignment, security could eventually be improved, he said. "All I need is for the cost of doing the bad [work] to increase. This is why I favor software liability because it raises the costs of bad software." The link for this article located at Techworld is no longer available. . Through a revision of the risk-reward evaluation, technology firms can be made responsible for deficiencies in information technology security.. Software Liability, Vendor Accountability, IT Security. . LinuxSecurity.com Team

Calendar%202 Feb 15, 2007 User Avatar LinuxSecurity.com Team Vendors/Products
78

Sun's Vendor Accountability Call for Enhanced Software Security

Sun's chief security officer last week said that vendors should bear legal responsibility for any security vulnerabilities found in their software, and should work harder to build more secure platforms and applications.. . .. Sun's chief security officer last week said that vendors should bear legal responsibility for any security vulnerabilities found in their software, and should work harder to build more secure platforms and applications. "Currently, it's a case of saying to firms, 'You pay, we promise you nothing, have fun.' But we need to put in place legal targets, perhaps for 2010 or 2015, and improve our methodology to provide much higher security standards if we are to accept liability," said Whitfield Diffie, Sun Microsystems chief security officer, speaking at the Information Security Solutions Europe (ISSE) event in Vienna last week. The call comes as a group of US users are proposing a class-action lawsuit against Microsoft because of Windows' vulnerability to computer viruses, which they claim could trigger "massive cascading failures" in global computer networks. Other experts at the event said that IT buyers share some responsibility for the increase in attacks via the internet. "Security has not had a big space in large companies in 2002 because it is difficult to make a clear business case to the chief finance officer for security, and that has to change," commented Michael Niebel, director general of the European Commission's information society, responsible for co-ordinating data security initiatives. The link for this article located at vnunet is no longer available. . The primary security officer at Sun highlights the vendors' obligation under the law to ensure their software is secure when dealing with weaknesses.. Software Liability, Vendor Accountability, IT Risk Management. . LinuxSecurity.com Team

Calendar%202 Oct 14, 2003 User Avatar LinuxSecurity.com Team Vendors/Products
82

Department Of Energy Mandates Enhanced Oracle Database Security

The department of energy has done something unusual for a federal agency. It has become an example of excellent cyber-security practice. It has done this by pressuring Oracle to elevate security in its 9i database product--in the process, taking software out . . . . The department of energy has done something unusual for a federal agency. It has become an example of excellent cyber-security practice. It has done this by pressuring Oracle to elevate security in its 9i database product--in the process, taking software out of the shadows of "as is" licenses and putting it in the spotlight of a government procurement action. DOE's action could begin a process that improves the security of the technologies available to the public and private sectors alike. To win this open-ended deal, Oracle promised to deliver its database in a secure configuration and took responsibility for the security of the software going forward. Future patches must be delivered quickly and cannot create new problems or vulnerabilities if Oracle wants to continue getting paid. It's the kind of vendor commitment that every enterprise merits but that only the $59 billion IT buying power of the federal government can effect right now. The link for this article located at eWeek is no longer available. . The energy sector establishes a benchmark by insisting on advanced safety measures from Microsoft for fortified cloud infrastructure.. Database Protection, Cybersecurity Standards, Government Procurement, Vendor Accountability. . Anthony Pell

Calendar%202 Oct 07, 2003 User Avatar Anthony Pell Government
82

Clarke's Visit to MIT: Software Security and Vendor Guidance

After releasing a draft of the National Strategy to Secure Cyberspace for comment in September, Clarke has embarked on a cross-country tour, soliciting feedback on the document and stumping for passage of the bill that would create the Department of Homeland . . . . After releasing a draft of the National Strategy to Secure Cyberspace for comment in September, Clarke has embarked on a cross-country tour, soliciting feedback on the document and stumping for passage of the bill that would create the Department of Homeland Security. During his most recent stop, at the Massachusetts Institute of Technology, audience members gave Clarke a wide range of suggestions for the strategy, with many of them centering on the theme of vendor responsibility for insecure software. Many people asked Clarke, chairman of the President's Critical Infrastructure Protection Baord, to consider recommending some form of regulation for the software industry as a way to spur vendors into writing more secure applications. Clarke resisted the idea, as he has in the past, saying that he'd rather rely on market forces and customer demand to weed out the careless vendors. One area where Clarke agreed that new legislation might be in order is security research. One audience member complained that the Digital Millennium Copyright Act and anti-hacking laws are preventing legitimate security researchers from publishing information on new vulnerabilities. The link for this article located at eWeek is no longer available. . After releasing a draft of the National Strategy to Secure Cyberspace for comment in September, Clar. releasing, draft, national, strategy, secure, cyberspace, comment, september. . Anthony Pell

Calendar%202 Oct 17, 2002 User Avatar Anthony Pell Government
78

Enhancing Network Security: The Role Of Vendor Accountability

Network security is not a technological problem; it's a business problem. The only way to address it is to focus on business motivations. To improve the security of their products, companies - both vendors and users - must care; for companies to care, the problem must affect stock price. The way to make this happen is to start enforcing liabilities.. . .. Network security is not a technological problem; it's a business problem. The only way to address it is to focus on business motivations. To improve the security of their products, companies - both vendors and users - must care; for companies to care, the problem must affect stock price. The way to make this happen is to start enforcing liabilities. The only way to get many companies to spend significant resources to ensure the security of their customers' data is to hold them liable for misuse of this data. Similarly, the only way to get software vendors to reduce features, lengthen development cycles and invest in secure software development processes is to hold them liable for security vulnerabilities in their products. The link for this article located at NW Fusion / Schneier is no longer available. . Cybersecurity necessitates organizational responsibility to foster genuine transformation and enhance information safeguarding protocols.. Business Accountability, Software Liability, Security Measures. . LinuxSecurity.com Team

Calendar%202 Apr 25, 2002 User Avatar LinuxSecurity.com Team Vendors/Products
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200