-
+25 +7
Malicious PyPI Package 'Pytoileur' Targets Windows and Leverages Stack Overflow for Distribution
Another day, another PyPI malware package. But this one has a new way to (try to) sneak into your computer.
-
+38 +2
OpenSSF Siren: Security for One, Security for All - DevOps.com
The OpenSSF Siren is a fresh, new take on ye old security mailing list.
-
+31 +4
Are all Linux vendor kernels insecure? A new study says yes, but there's a fix
All vendor kernels are plagued with security vulnerabilities, according to a CIQ whitepaper. Will the Linux community ever accept upstream stable kernels?
-
+39 +4
VFCFinder Highlights Security Patches in Open Source Software
VFCFinder analyzes commit histories to pinpoint the most likely commits associated with vulnerability fixes.
-
+39 +3
Everything you wanted to know about SELinux but were afraid to run
When you need to run Linux in an especially secure environment, SELinux is the answer. But getting SELinux up-and-running takes a lot of know how.
-
+31 +3
Three Reasons DevOps Should Consider Rocky Linux 9.4
The new version of Rocky Linux includes security improvements, better cloud images, and the latest developer tools.
-
+37 +5
Does More Money Improve Open Source Security?
It sounds simple: If you pay developers more money they'll improve the quality and security of their code. The evidence isn't so clear.
-
+39 +4
Update your Chrome browser ASAP. Google has confirmed a zero-day exploited in the wild
A new Chrome JavaScript security hole is nasty, so don't waste any time patching your systems.
-
+40 +4
What OpenTofu 1.7 Means for DevSecOps - DevOps.com
With built-in end-to-end encryption, OpenTofu is a natural DevSecOps fit.
-
+39 +2
CIQ Extends CentOS 7 Support with Bridge Service as its End-of-Life Approaches - Techstrong ITSM
The popular enterprise Linux CentOS 7 will soon cease to be supported, but its hundreds of thousands of users still need support.
-
+43 +4
If all kernel bugs are security bugs, how do you keep your Linux safe?
Since February, there've been 800 newly assigned CVEs. Your job? Update your main Linux distro more often.
-
+39 +6
Canonical Unveils 12 Years of Support for Ubuntu LTS
Want to keep running Ubuntu Linux for over a decade? Canonical can help.
-
+27 +5
Vulnerabilities for AI and ML Applications are Skyrocketing
In their haste to deploy LLM tools, organizations may overlook crucial security practices. The rise in threats like Remote Code Execution indicates an urgent need to improve security measures in AI development.
-
+35 +6
OpenSSF warns of Open Source Social Engineering Threats
What are the trust best practices? We honestly don't know yet. But, if we're to trust our open source projects, we must figure it out.
-
+42 +3
Meet the System Package Data Exchange: SPDX 3.0, with Profiles
The latest version of the newly renamed System Package Data Exchange (SPDX) was announced Tuesday at Open Source Summit North America.
-
+34 +2
Outlook is Microsoft’s new data collection service
The new Outlook now appears to be a data collection service for Microsoft’s 801 external partners for targeted advertising.
-
+25 +8
Roku: Credential Stuffing Attacks Affect 591,000 Accounts
Almost 600,000 Roku customers had their accounts hacked through two credential-stuffing attacks several weeks apart.
-
+18 +2
Locking down container security once and for all with Rust-based Edera
This new open-source project built on the Xen hypervisor will bring a new level of security to containers.
-
+40 +3
This backdoor almost infected Linux everywhere: The XZ Utils close call
For the first time, an open-source maintainer put malware into a key Linux utility. We're still not sure who or why - but here's what you can do about it.
-
+35 +4
Malicious Code in Linux xz Libraries Endangers SSH
Most users won't be affected by this malware, but if it had gone undetected for a few more months, everyone using Linux would have faced their biggest security disaster ever.
Submit a link
Start a discussion