Paul’s Security Weekly (Video)
Technology
Version 4.0 of the Payment Card Industry Data Security Standard (PCI DSS) puts greater emphasis on application security than did previous versions of the standard. It also adds a new “customized approach” option that allows merchants and other entities to come up with their own ways to comply with requirements, and which also has implications for application security. Specifically, PCI DSS 4.0 requires that by March 31, 2025, more testing of public-facing applications related to payment processing or other activities be considered “in scope” for compliance. Generally, any system that touches payment-card data is in scope for PCI DSS compliance, whether or not the system or function is public-facing. We'll talk through what organizations should have gotten done by March 31, 2024, and what needs to happen by March 31, 2025.
Segment Resources: https://info.obsglobal.com/pci-4.0-resources
Show Notes: https://securityweekly.com/psw-825
Authentication Vulnerabilities - PSW #720
Bypassing Biometrics, Hiding in Plain Sight, Hacker Cinema, & High Aspirations - PSW #720
Suing Satoshi, Trojans in IDA, FBI Spam, Beg Bounties, & UPNP Strikes Again - PSW #719
Skill Building: CTFs & Computer Fundamentals - Derek Rook - PSW #719
Building Vulnerable Docker Containers (On Purpose) - PSW #719
TIPC Kernel Vulns, SBDCs, Truckloads of GPUs, & Hardcoded SSH Keys - PSW #718
MAVSH - Sachin Mahajan - PSW #718
Stalkerware Capabilities in the Real World - Lodrina Cherne, Martijn Grooten - PSW #718
Shrootless Bug, Statistic Stats, Trojan Source, Fake Students, & Clippy Returns - PSW #717
Peel Back the Layers of Your Enterprise with Security Onion 2 - Doug Burks - PSW #717
Part 2: Scanning For Default Creds With Python - PSW #717
Iranian Gas, Smelly Towns, View Source Legality, EBCDIC & GDPR, & Unlocking Oculus Go - PSW #716
What Exactly Is an Incident Commander, Anyway - Matt Linton - PSW #716
Focusing on Preventing Ransomware - Roger Grimes - PSW #716
Wild Hippos, Chrome FTP, L0phtCrack Is Open-Source, Win 11 Pentium, & Legacy Systems - PSW #715
Scanning For Default Credentials With Python - PSW #715
Evolution & Maturity of the Cybersecurity Industry - Maxime Lamothe-Brassard - PSW #715
IoT Rickroll, Suing Over Disclosures, K-12 Cybersecurity Act, & SS7 Signaling - PSW #714
GraphQL - Sven Morgenroth - PSW #714
Open Source Endpoint Security with Osquery & Fleet - Zach Wasserman - PSW #714
Create your
podcast in
minutes
It is Free
Insight Story: Tech Trends Unpacked
Zero-Shot
Fast Forward by Tomorrow Unlocked: Tech past, tech future
Lex Fridman Podcast
Elliot in the Morning