Security Audit Archives - 7ASecurity Blog https://7asecurity.com/blog/ Stay ahead with top security tips, tools, and insights from the official 7ASecurity blog. Learn more from 7ASecurity now. Tue, 15 Jul 2025 14:13:58 +0000 en-US hourly 1 https://7asecurity.com/blog/contents/uploads/2019/06/favicon.ico Security Audit Archives - 7ASecurity Blog https://7asecurity.com/blog/ 32 32 Conda-Forge Security Audit by 7ASecurity https://7asecurity.com/blog/2025/07/conda-forge-security-audit-by-7asecurity/ Tue, 15 Jul 2025 09:43:47 +0000 7ASecurity is proud to share the results of our security audit of conda-forge. conda-forge is a community-driven open source repository of conda package manager recipes. With the help of the Open Source Technology Improvement Fund and the Sovereign Tech Agency, this project has invested in its longevity and security health by hardening its resilience and …

The post Conda-Forge Security Audit by 7ASecurity appeared first on 7ASecurity Blog.

]]>
LinkerD Security Audit by 7ASecurity https://7asecurity.com/blog/2025/02/linkerd-security-audit-by-7asecurity/ Wed, 19 Feb 2025 08:31:19 +0000 7ASecurity is proud to share the results of a recent security audit of Linkerd. Linkerd is an open source service mesh for Kubernetes which prioritizes reliability, security, and simplicity. Thanks to the help of the Open Source Technology Improvement Fund (OSTIF) and the Cloud Native Computing Foundation, this project can continue to provide a lightweight …

The post LinkerD Security Audit by 7ASecurity appeared first on 7ASecurity Blog.

]]>
AmneziaVPN Security Audit by 7ASecurity https://7asecurity.com/blog/2024/12/amneziavpn-security-audit-by-7asecurity/ Sat, 14 Dec 2024 14:40:48 +0000 Our team of senior security experts recently completed another comprehensive security audit of AmneziaVPN. Over a 16-day period, we rigorously examined their Android, iOS, and Desktop clients, as well as their AmneziaWG and XRay services. Our goal was to identify any potential vulnerabilities and assess the overall security posture of their VPN solution. Key Findings: …

The post AmneziaVPN Security Audit by 7ASecurity appeared first on 7ASecurity Blog.

]]>
How Regular Pentesting Helps Maintain SOC 2 Compliance https://7asecurity.com/blog/2024/11/how-regular-pentesting-helps-maintain-soc-2-compliance/ Tue, 05 Nov 2024 09:45:55 +0000 Breaches that could have been prevented with pentesting. Achieving SOC 2 compliance is a big deal. It shows your clients that you take data security seriously. But getting certified is just the first step. Maintaining compliance and securing your systems requires ongoing effort, so SOC 2 pentesting is vital. Think of SOC 2 compliance as …

The post How Regular Pentesting Helps Maintain SOC 2 Compliance appeared first on 7ASecurity Blog.

]]>
SecureDrop Security Audit by 7ASecurity https://7asecurity.com/blog/2024/10/securedrop-security-audit/ Tue, 29 Oct 2024 08:29:07 +0000 About SecureDrop SecureDrop is an open source whistleblower submission system that media organizations and NGOs can install to accept anonymous, secure documents from sources. It receives documents via the Tor network (a distributed network of relays that help protect users" privacy), records only the date and time of the transfer, and enables recipients to view submissions in its …

The post SecureDrop Security Audit by 7ASecurity appeared first on 7ASecurity Blog.

]]>
7ASecurity Completes LitmusChaos Audit https://7asecurity.com/blog/2024/08/7asecurity-completes-litmuschaos-audit/ Mon, 26 Aug 2024 09:19:58 +0000 7ASecurity is proud to share the results of our security audit of LitmusChaos. LitmusChaos is an open source chaos engineering platform for a multitude of cloud platforms. With the help of the Open Source Technology Improvement Fund (OSTIF) and the Cloud Native Computing Foundation, this project can continue to provide secure chaos testing environments for …

The post 7ASecurity Completes LitmusChaos Audit appeared first on 7ASecurity Blog.

]]>
7ASecurity Completes V2Ray Security Audit https://7asecurity.com/blog/2024/07/7asecurity-completes-v2ray-security-audit/ Mon, 29 Jul 2024 11:00:31 +0000 About V2Ray is a versatile network utility that provides a platform for building proxies to bypass network restrictions—enabling users to access the internet safely and privately in restricted contexts where surveillance and censorship are prevalent. In addition to being open source, V2Ray is designed with encryption and obfuscation functions that make it harder for surveillance forces …

The post 7ASecurity Completes V2Ray Security Audit appeared first on 7ASecurity Blog.

]]>
7asecurity Completes OpenTelemetry Audit https://7asecurity.com/blog/2024/07/7asecurity-completes-opentelemetry-audit/ Sun, 21 Jul 2024 11:19:35 +0000 7ASecurity is proud to share the results of our security audit of OpenTelemetry. OpenTelemetry is an open source project for generating and collecting telemetry data for software analysis. With the help of the Open Source Technology Improvement Fund (OSTIF) and the Cloud Native Computing Foundation (CNCF), this project will experience strengthened security health as it moves to graduation status with the …

The post 7asecurity Completes OpenTelemetry Audit appeared first on 7ASecurity Blog.

]]>
7ASecurity completes CoverDrop Audit https://7asecurity.com/blog/2024/06/7asecurity-completes-coverdrop-audit/ Wed, 12 Jun 2024 09:46:20 +0000 About CoverDrop Whistleblowers need a secure method to initiate contact and build trust with journalists. Existing tools often cater to later-stage correspondence, leaving crucial, early touch-points vulnerable to surveillance. In addition, many of these tools are difficult to find on newspaper websites, hard to use securely, and offer insufficient user guidance. After conducting workshops with …

The post 7ASecurity completes CoverDrop Audit appeared first on 7ASecurity Blog.

]]>
7ASecurity Completes Opaque Security Audit https://7asecurity.com/blog/2024/03/7asecurity-completes-opaque-javascript-security-audit/ Mon, 11 Mar 2024 11:17:48 +0000 About Opaque Opaque is a JavaScript package to allow secure password-based, client-server authentication without the server ever obtaining knowledge of the password.  Audit Description Through OTF"s Red Team Lab, 7ASecurity conducted a penetration test and whitebox security review of Opaque. A whitebox review is a form of application testing that provides the tester with complete knowledge of the application …

The post 7ASecurity Completes Opaque Security Audit appeared first on 7ASecurity Blog.

]]>