Security News

Adlumin integrates with Google Workspace to give customers the ability to ingest crucial audit logs
2021-05-05 23:45

Adlumin announced that its platform will now integrate directly with Google Workspace, giving customers the ability to ingest crucial audit logs from their Google Workspace domains. Google Workspace is a suite of secure, cloud-native collaboration and productivity apps powered by Google AI and has become a viable competitor to Office365.

Sysdig adds detailed audit logs for runtime detection and response for AWS Fargate
2021-05-05 00:15

With the announcement today, Sysdig launched the first runtime security detection and response solution for AWS Fargate that provides detailed audit logs to respond to incidents. Sysdig's runtime detection for AWS Fargate is based on open source Falco, the runtime security tool created by Sysdig and contributed to the Cloud Native Computing Foundation.

Despite the pandemic, 85% of organizations completed their audits as planned
2021-04-28 03:00

85% of companies completed their audits as planned or with an extension, and 60% had no change to audit timing. Organizations conduct multiple audits as disjointed, redundant projects.

How to use Docker Bench for Security to audit your container deployments
2021-04-08 17:38

Docker Bench for Security is a simple way of checking for common best practices around your Docker deployments in production. One such tool is a pre-built container, called Docker Bench for Security-it does a great job of auditing your container host and the currently running deployments.

SecureDrop Workstation Gets Post-Audit Security Refresh
2021-04-02 15:45

The open-source SecureDrop Workstation has undergone a security makeover after a third-party security audit flagged multiple problems, including a high-risk bug that could allow an attacker to plant files on target machines. The SecureDrop Workstation audit, conducted by Trail of Bits and financed by the New York Times, warned that the high-risk directory traversal bug could be leveraged for code execution attacks.

Cloud technology adoption gap between internal audit and other enterprise functions to narrow
2021-04-01 03:00

Internal audit's ongoing digital transformation will rapidly accelerate in 2021, with 22% of respondents reporting that they will implement cloud-based technology this year, resulting in a majority of internal audit teams using a cloud-based audit management or GRC software solution for the first time, an AuditBoard survey reveals. "Many internal audit teams that have not yet shifted to a cloud approach are now set to reap the benefits of modernization - including gaining greater bandwidth for strategic, value-add activities - and will be better positioned to protect their organizations from new and emerging risks," said John Reese, AuditBoard's CMO. "They'll also get to equal footing with other functions within their organization who have already made the move to cloud-based solutions."

Leaders need to find ways to increase internal audit capacity without increasing budgets
2021-03-30 03:00

A study of 299 internal audit organizations showed that the function faced both declining budgets and a significantly expanded workload in 2020, according to Gartner. "For many heads of audit, it's not clear where the extra capacity is going to come from," said Margaret Moore Porter, managing vice president in the Gartner Audit practice.

Passing a compliance audit in the cloud doesn’t have to be hard
2021-03-11 05:30

Your company takes compliance and security very seriously, but you've no idea what or how to layer on top of AWS's existing security and compliance protocols to achieve levels necessary for compliance certification. In this case and others, passing a compliance audit may prove particularly problematic even though your company is committed to performing at or above baseline legal requirements.

Ongoing phishing attacks target US brokers with fake FINRA audits
2021-03-05 13:28

The US Financial Industry Regulatory Authority has issued a regulatory notice warning US brokerage firms and brokers of an ongoing phishing campaign using fake compliance audit alerts to harvest information. The domain used in these ongoing phishing attacks was registered just two days ago, on March 3rd, using the NameCheap domain name registrar.

How to Audit Password Changes in Active Directory
2021-02-04 03:28

Secondly, a given password might be somewhat easy to guess, despite existing password requirements. Password changes only occur via the user or Active Directory administrator.