Did you know that your router could be the biggest security hole in your network? . Many of the most popular home routers available to buy today feature a worrying number of security flaws and vulnerabilities, new research has found. A report from Fraunhofer Institute for Communication ( FKIE ) discovered that the firmware present in a large number of leading routers was susceptible to hugely damaging security issues. Many routers were found to never have received a single security firmware update in their lifetime, despite the risk that this could pose to users at home and at work, and were vulnerable to hundreds of well-known security issues. . Numerous widely-used residential routers contain significant vulnerabilities, putting both home and workplace users at risk.. Router Security, Home Network Risks, Firmware Vulnerabilities. . Brittany Day
When a security researcher finds a security bug, what do they do? Unfortunately, the answer sometimes is they search for the appropriate people to notify and, when they can’t be found, end up posting the vulnerability to public email lists, the GitHub project, or even Twitter. . This is the problem that security platform HackerOne and software supply chain management tool Sonatype have teamed up to solve with The Central Security Project, a new effort that “brings together the ethical hacker and open source communities to streamline the process for reporting and resolving vulnerabilities discovered in libraries housed in The Central Repository, the world’s largest collection of open source components,” according to a statement. The link for this article located at TheNewStack is no longer available. . GitHub partners with Snyk to enhance security audits for public Python packages, aiming to boost safety and reliability in the open source ecosystem. Vulnerability Reporting, Open Source Projects, Java Security, HackerOne Collaboration, Ethical Hacking. . LinuxSecurity.com Team
GitHub says its security scan for old vulnerabilities in JavaScript and Ruby libraries has turned up over four million bugs and sparked a major clean-up by project owners.. The massive bug find total was reached within a month of the initiative's launch in November when GitHub began scanning for known vulnerabilities in certain popular open-source libraries and notifying project owners that they should be using an updated version. . GitHub identified more than four million vulnerabilities in Java and Python packages, leading to necessary rectifications by developers.. Dependency Management, Library Security, Code Flaws, Security Issues. . LinuxSecurity.com Team
Who says hackers can't be nice? One group, MalSec, left a calling card on a security firm's website that decisively struck down its claim of being "the largest and most trusted full-service security and life-safety company in the Cayman Islands." But instead of rendering it useless, gave them pointers on how to fix their holes.. Hat tip to Ars Technica's Sean Gallagher for capturing a screengrab of MalSec's non-malevolent treatment of The Security Centre Ltd's vulnerabilities and its discovery of "previous security breaches." The link for this article located at MSNBC is no longer available. . SecWise's cooperative cyber defense strategy identifies weaknesses while offering constructive solutions for safety organizations.. Ethical Hacking, Website Vulnerabilities, Security Flaws, Bug Report, Security Advice. . LinuxSecurity.com Team
The US-CERT Cyber Security Bulletin provides a summary of new vulnerabilities that have been recorded by the National Institute of Standards and Technology (NIST) National Vulnerability Database (NVD) in the past week. The NVD is sponsored by the Department of Homeland Security (DHS) National Cyber Security Division (NCSD) / United States Computer Emergency Readiness Team (US-CERT). For modified or updated entries, please visit the NVD, which contains historical vulnerability information.. The vulnerabilities are based on the CVE vulnerability naming standard and are organized according to severity, determined by the Common Vulnerability Scoring System (CVSS) standard. The division of high, medium, and low severities correspond to the following scores: High - Vulnerabilities will be labeled High severity if they have a CVSS base score of 7.0 - 10.0 Medium - Vulnerabilities will be labeled Medium severity if they have a CVSS base score of 4.0 - 6.9 Low - Vulnerabilities will be labeled Low severity if they have a CVSS base score of 0.0 - 3.9 Entries may include additional information provided by organizations and efforts sponsored by US-CERT. This information may include identifying information, values, definitions, and related links. Patch information is provided when available. Please note that some of the information in the bulletins is compiled from external, open source reports and is not a direct result of US-CERT analysis. The link for this article located at US-CERT is no longer available. . NIST and US-CERT have identified various vulnerabilities across systems, each rated for severity to help organizations maintain security practices. Cyber Security Bulletin,NIST Vulnerability Database,US-CERT Reports. . Alex
Computer security is a precarious business both from a product development and administrative standpoint. Operating system vendors are forced to constantly patch their software to keep consumers protected from the latest digital threats. But which operating systems are the most secure? A recent report by Symantec hints that Windows currently presents fewer security holes than its commercial competitors. . . Computer security is a precarious business both from a product development and administrative standp. computer, security, precarious, business, product, development, administrative, standp. . LinuxSecurity.com Team
For the past four years the SANS Institute has partnered with the FBI's National Infrastructure Protection Center to compile and publish its list of the most commonly exploited IT security vulnerabilities. This list is regularly updated and revised. Earlier, I examined the latest Windows threats from the list. Now I'll cover the top 10 Linux/Unix threats. . . .. For the past four years the SANS Institute has partnered with the FBI's National Infrastructure Protection Center to compile and publish its list of the most commonly exploited IT security vulnerabilities. This list is regularly updated and revised. Earlier, I examined the latest Windows threats from the list. Now I'll cover the top 10 Linux/Unix threats. It's important to recall that, unlike the ever-growing list of new exploits found in operating systems and applications, the SANS-FBI list prioritizes them according to the actual number of attacks seen by the organizations surveyed. The link for this article located at John McCormick is no longer available. . Explore the SANS Institute’s latest findings on critical vulnerabilities affecting Linux and Unix systems. Examine the shifting threat landscape and strategies for protection. Linux Security Threats, IT Security Vulnerabilities, SANS Threats, UNIX Exploits. . Anthony Pell
Internet Security Systems Inc. last week unveiled its first Catastrophic Risk Index, a compilation of the 31 most serious current vulnerabilities and attacks. The index is designed to give administrators a constantly updated quick-reference list of the issues that should be their top priorities in protecting networks.. . .. Internet Security Systems Inc. last week unveiled its first Catastrophic Risk Index, a compilation of the 31 most serious current vulnerabilities and attacks. The index is designed to give administrators a constantly updated quick-reference list of the issues that should be their top priorities in protecting networks. Not surprisingly, all but two of the vulnerabilities on the list are some form of buffer overflow. Buffer overflows are far and away the most common security vulnerabilities plaguing commercial and open-source software. They come in many shapes and sizes and can be found in almost any kind of application, but the result is almost always the same: an attacker gets access to a critical application or server. The link for this article located at eWeek is no longer available. . Explore the newly released Peril Assessment Index from ISS showcasing essential cybersecurity threats for network managers.. Catastrophic Risk Index, Buffer Overflow, ISS, Network Protection, Vulnerability Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.