EGI CSIRT F2F meeting in CERN

The EGI CSIRT met in person for the first time in 2025 at CERN. Discussions focused on operational tasks such as monitoring, vulnerability management, etc., incident response, and the objectives for 2025. The focus will be on raising awareness of security through...

EGI CSIRT webinar on incidents in 2024

If you are interested in what kept us busy in 2024 and what we are planning for 2025, please join us for the next EGI webinar entitled “EGI IRTF 2024 in Review: Incidents, Learnings and Plans for 2025” which will take place on Wednesday 22 January 2025,...

Secure Login and Access

Securing access to your servers is critical because it is the first line of defence against unauthorised access and potential breaches. Most security incidents are caused by inadequate access controls, such as weak or default passwords, stolen credentials, and lack of...

Logging guidelines

Based on EGI Security Traceability and Logging Policy all certified EGI sites need to have a remote logging service in place. By storing logs remotely, you protect them from being tampered with or deleted by attackers who gain access to your systems. This ensures the...

Vulnerability in Slurm stepmgr subsystem CVE-2024-48936

Slurm version 24.05.4 was released, including a fix for a recently discovered security issue with the new stepmgr subsystem. A mistake in authentication handling in stepmgr could permit an attacker to execute processes under other users’ jobs. This is limited to...