techhub.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A hub primarily for passionate technologists, but everyone is welcome

Administered by:

Server stats:

5.4K
active users

#securityaudit

0 posts0 participants0 posts today

Passbolt partnered with Quarkslab to conduct a penetration test and assumed breach assessment of Passbolt Cloud solution.

What was tested?
Evaluated API security, backend controls, and safeguards against unauthorized actions.
Simulated an internal attack to assess resilience against an adversary with server access.

Read more on the blog article: hubs.li/Q039csDh0

PassboltPassbolt Clears Three Security and Compliance AuditsThis blog breaks down key findings from three independent assessments, reinforcing our commitment to strong security and compliance.

Over the last four months, passbolt underwent three independent assessments to evaluate and strengthen our security posture.

These assessments help us identify and address areas for improvement while confirming our existing security strengths.

Read more about the latest security reviews: hubs.li/Q039csDh0

See the findings in the thread.

PassboltPassbolt Clears Three Security and Compliance AuditsThis blog breaks down key findings from three independent assessments, reinforcing our commitment to strong security and compliance.

Don't miss out on the insights from FOSDEM'25! The recording of "How FreeBSD Security Audits Have Improved our Security Culture" is now available to watch online. Learn about Alpha-Omega's work with the FreeBSD Foundation, the vulnerabilities identified, and the future of security in FreeBSD.

Watch the video and download the slides here: buff.ly/42OoyTC #FreeBSD #SecurityAudit #OpenSource #FOSDEM25 #AlphaOmega #infosec

Oh boy. A simple #enumeration #attack could be used to read credit offers at #CHECK24 and #verivox, two big German portal offering a lot of things around comparing credit offers, insurance contracts and other things.

This is such a trivial mistake, it nearly feels deliberate. This should never ever happend. And for sure this should have be a red flag in any #securityaudit. I wonder how they can state "No indications of miss use.". #cybersecurity

Article in German:
correctiv.org/aktuelles/datens

correctiv.org · Kreditvermittlung bei Check24 und Verivox: kritische Datenlecks entdecktBy Jean Peters