Security News

'No Slowdown' for HIPAA Enforcement, But Audits Ending
2018-03-06 21:48

OCR Director Roger Severino Offers Update at HIMSS18 ConferenceHHS Office for Civil Rights Director Roger Severino told an audience at the HIMSS18 conference Tuesday that there will be "no...

Health Net Cited for Refusing a Security Audit
2018-02-22 21:18

Why Do Some Companies Reject Security Scrutiny?A government watchdog agency alleges that insurer Health Net of California has refused to cooperate in a security audit called for under a federal...

Facebook Increases Bug Bounty Payout After Audit
2018-02-09 19:00

Facebook decided to increase a researcher’s bug bounty payout after discovering that that a bug he reported could lead to account takeover.   read more

Half of organizations do not audit SSH entitlements
2017-11-17 12:00

Cybercriminals, such as malicious insiders, use SSH keys to access systems from remote locations, evade security tools and escalate privileges, according to a study conducted by Dimensional...

OPM Contends 'Audit Fatigue' Hampers InfoSec Compliance
2017-11-07 22:03

IG Identifies Significant Deficiencies in Agency's IT Management StructureThe acting director of the U.S. Office of Personnel Management cites "audit fatigue" as a factor that explains why the...

HIPAA Compliance Audits: The Future Is Murky (InfoRiskToday)
2017-09-06 22:33

OCR Official Avoids Spelling Out Plans for the ProgramWill HHS, under the Trump administration, create a permanent HIPAA compliance audit program? And what's next for the ongoing second phase of...

TunnelBear VPN Audit Finds Few Vulnerabilities (Security Week)
2017-08-17 09:36

TunnelBear has commissioned a third-party audit of its virtual private network (VPN) application and only a few vulnerabilities have been found in recent versions of the product. read more

Uber to get privacy audit every two years (Help Net Security)
2017-08-16 15:35

Uber has agreed to implement a comprehensive privacy program and obtain regular, independent audits to settle Federal Trade Commission charges that they deceived consumers by failing to monitor...

OPM CIO Fires Back at GAO Over Cybersecurity Audit (InfoRiskToday)
2017-08-03 22:18

Auditors: Systems at 'Greater Risk' Till OPM Properly Implements All Security RequirementsOffice of Personnel Management Chief Information Officer David DeVries says negative aspects of a...

Mozilla Conducts Security Audit of Firefox Accounts (Security Week)
2017-07-19 13:09

Mozilla has asked Germany-based security firm Cure53 to conduct an audit of the Firefox Accounts system and researchers identified a total of 15 issues, including vulnerabilities rated critical...