mastodon.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
The original server operated by the Mastodon gGmbH non-profit

Administered by:

Server stats:

360K
active users

#securityaudit

0 posts0 participants0 posts today

Alright, #infosec crew! ✌️

So, PCI DSS v4... that deadline's closing in fast, isn't it? 😳

A&F dropped some serious insights on this: We're talking Script Security, Change Detection, Vendor Risks... the whole shebang!

Look, CSP alone just ain't gonna cut it, sorry not sorry. 🤷‍♂️ Third-party vendors? They're often the number one back door. Gotta check those dependencies, seriously!

Compliance isn't a "set it and forget it" kind of deal. You need constant monitoring, folks! ☝️

And let's be real: Who here has actually mapped out their entire PCI DSS v4 plan? 🤔 Or are you still stuck playing Minesweeper? 😂

Passbolt partnered with Quarkslab to conduct a penetration test and assumed breach assessment of Passbolt Cloud solution.

What was tested?
Evaluated API security, backend controls, and safeguards against unauthorized actions.
Simulated an internal attack to assess resilience against an adversary with server access.

Read more on the blog article: hubs.li/Q039csDh0

PassboltPassbolt Clears Three Security and Compliance AuditsThis blog breaks down key findings from three independent assessments, reinforcing our commitment to strong security and compliance.

Over the last four months, passbolt underwent three independent assessments to evaluate and strengthen our security posture.

These assessments help us identify and address areas for improvement while confirming our existing security strengths.

Read more about the latest security reviews: hubs.li/Q039csDh0

See the findings in the thread.

PassboltPassbolt Clears Three Security and Compliance AuditsThis blog breaks down key findings from three independent assessments, reinforcing our commitment to strong security and compliance.

Oh boy. A simple could be used to read credit offers at and , two big German portal offering a lot of things around comparing credit offers, insurance contracts and other things.

This is such a trivial mistake, it nearly feels deliberate. This should never ever happend. And for sure this should have be a red flag in any . I wonder how they can state "No indications of miss use.".

Article in German:
correctiv.org/aktuelles/datens

correctiv.org · Kreditvermittlung bei Check24 und Verivox: Kritische Datenlecks entdecktBy Jean Peters