Security News

Half of organizations do not audit SSH entitlements
2017-11-17 12:00

Cybercriminals, such as malicious insiders, use SSH keys to access systems from remote locations, evade security tools and escalate privileges, according to a study conducted by Dimensional...

OPM Contends 'Audit Fatigue' Hampers InfoSec Compliance
2017-11-07 22:03

IG Identifies Significant Deficiencies in Agency's IT Management StructureThe acting director of the U.S. Office of Personnel Management cites "audit fatigue" as a factor that explains why the...

HIPAA Compliance Audits: The Future Is Murky (InfoRiskToday)
2017-09-06 22:33

OCR Official Avoids Spelling Out Plans for the ProgramWill HHS, under the Trump administration, create a permanent HIPAA compliance audit program? And what's next for the ongoing second phase of...

TunnelBear VPN Audit Finds Few Vulnerabilities (Security Week)
2017-08-17 09:36

TunnelBear has commissioned a third-party audit of its virtual private network (VPN) application and only a few vulnerabilities have been found in recent versions of the product. read more

Uber to get privacy audit every two years (Help Net Security)
2017-08-16 15:35

Uber has agreed to implement a comprehensive privacy program and obtain regular, independent audits to settle Federal Trade Commission charges that they deceived consumers by failing to monitor...

OPM CIO Fires Back at GAO Over Cybersecurity Audit (InfoRiskToday)
2017-08-03 22:18

Auditors: Systems at 'Greater Risk' Till OPM Properly Implements All Security RequirementsOffice of Personnel Management Chief Information Officer David DeVries says negative aspects of a...

Mozilla Conducts Security Audit of Firefox Accounts (Security Week)
2017-07-19 13:09

Mozilla has asked Germany-based security firm Cure53 to conduct an audit of the Firefox Accounts system and researchers identified a total of 15 issues, including vulnerabilities rated critical...

Audit: OPM Struggles to Ensure IT Security (InfoRiskToday)
2017-07-12 16:48

IG Identifies Office of Personnel Management Problems In Assessing SecurityTwo years after a massive breach that exposed the personal information of some 21.5 million individuals, the U.S. Office...

UK Audit Office Says More Effort Needed to Combat Online Fraud (Security Week)
2017-07-03 11:37

UK's National Audit Office Says Online Fraud Needs to be Treated More Seriously by Government read more

Critical RCE Flaw Found in OpenVPN that Escaped Two Recent Security Audits (The Hackers News)
2017-06-22 01:08

A security researcher has found four vulnerabilities, including a critical remote code execution bug, in OpenVPN, those were not even caught in the two big security audits of the open source VPN...