Paul’s Security Weekly (Video)
Technology
Version 4.0 of the Payment Card Industry Data Security Standard (PCI DSS) puts greater emphasis on application security than did previous versions of the standard. It also adds a new “customized approach” option that allows merchants and other entities to come up with their own ways to comply with requirements, and which also has implications for application security. Specifically, PCI DSS 4.0 requires that by March 31, 2025, more testing of public-facing applications related to payment processing or other activities be considered “in scope” for compliance. Generally, any system that touches payment-card data is in scope for PCI DSS compliance, whether or not the system or function is public-facing. We'll talk through what organizations should have gotten done by March 31, 2024, and what needs to happen by March 31, 2025.
Segment Resources: https://info.obsglobal.com/pci-4.0-resources
Show Notes: https://securityweekly.com/psw-825
LANtennas, ESXi & Python, Twitch Leaks, Facebook BGP, & iPhone Is Always On - PSW #713
Up & Running With Security Onion - PSW #713
Survey Says: Improve Your Security Posture by Purple Teaming - Dan DeCloss - PSW #713
Pickpocketing Apple Pay, Mandatory Breach Reporting, Huawei Fears, & Cyber Criminals - PSW #712
Defense Strategies to Combat Sophisticated Ransomware - Mehul Revankar - PSW #712
Renting Your Phone, Public-Key Explained, Toilet Identification, & AutoDiscover Bug - PSW #711
Nzyme - Paul Asadoorian & Larry Pesce - PSW #711
Velociraptor - Digging Deeper - Mike Cohen, Wes Lambert - PSW #711
Dubious Drones, NSO Group, Apple's Bug Bounties, Ghostscript 0-Day, & IBM Server Bugs - PSW #710
Brakeman - Justin Collins - PSW #710
The State of Network Security in 2021 - Sinan Eren - PSW #710
Iframe Security - Benjamin Daniel Mussler - PSW #709
Hacking Honda, Insider Threat Galore, ChaosDB, USB File Weight, & Linux 5.14 - PSW #709
Nmap Vulnerability Scanning/Flan Scan - PSW #709
Yard Sales, Bitcoin Thief Charged, Mouse Privilege Escalation, & LED Eavesdropping - PSW #708
Trends in Mac Malware & Apple Security - Patrick Wardle - PSW #708
Working With OpenVAS - PSW #708
Shifting Left Probably Left You Vulnerable, Here’s How To Make it Right - Sonali Shah - PSW #707
Sequoia: A Local Privilege Escalation Vulnerability in Linux’s Filesystem Layer - . Wheel - PSW #707
Tractorload of John Deere Vulns, T-Mobile Breach, Kalay IoT Hack, & HolesWarm - PSW #707
Create your
podcast in
minutes
It is Free
Insight Story: Tech Trends Unpacked
Zero-Shot
Fast Forward by Tomorrow Unlocked: Tech past, tech future
Lex Fridman Podcast
Elliot in the Morning