controlgap.com

Posts by:

CG Blogger

This Week’s [in]Security – Issue 163 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: Coronavirus: Visualizing the spread. Infection and governments. Lockdown and reopening. Weird tech. Pool-noodle-hats. Vaccines, anti-bodies, treatments. More good, bad, and ugly. Masks, anti-maskers, and distancing. Confused AIs. PCI updated FAQs. The Unattributable 23M record breach. Celebrity law firm. 2nd grader pwns school board. More ransomware information sales. More contact tracing. Huawei export restrictions. Windows packet sniffer. Win-DoHs. Defcon & Blackhat cancelled. Thunderspy. Apples XML trouble. Ancient Windows bug. Attacking smart factories. Crypto-agility. Rash of supercomputer hacks. Exfiltrating over air gaps. New electronic warfare platform. Conspiracy theories. Election insecurity. And more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 162 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Coronavirus update. COVID-19 hits 4M, subways, Russia & Brazil. Cats, ferrets, & Llamas. Reopening. Masks and anti-maskers. Magneto favicon skimmers. Fixing EU cookie policy. Mega-breach dumps and 10B (yes B) record breach. MFA or not. Password reuse. Power supplies and air-gaps. Azure-squatting. Remembering ILOVEYOU. Murder Hornets. Asteroid near miss. Where's the beef and other COVID fallout. And more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 161 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: Coronavirus: New Zealand, Canada, Brazil, Russia, Belgium, Mississippi. Vaccines, anti-bodies, treatments. Guidance, Response and Recovery. More good, the bad, and the ugly. Payments, PCI & Covid. Breaches & ransomware: Banco BCR (cards), GDPR site, Tokopedia (15M), 9M UK licence plate trip logs, TaiLieu(7M), LineageOS. How to respond to a breach tip. Contact tracing and privacy. Facebook settlement. Biometrics & De-anonymizing device IDs. Patents. NIST updates. Fuzzing Apple. Power Grid defense. Saving ".org". SQL on a firewall! OpenSSL, Teams, Wordpress, Saltstack, Magneto, Adobe, Belkin NetCams. Lock-picking. Shade ransomware keys released. Tricky phone scam. Deep-fakes and identity theft. COVID cabin fever. Trolling AI's. Ad more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 160 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: Coronavirus update. The spread, the curve, and aftermath. Guidance, Response and Recovery. The good, the bad, and the ugly. Peaking? Food processing crisis. Disinfectants. Antibody tests. Ingenuity and invention. Testing at scale. Payments and CPEs under lockdown. More PCI FAQ updates. Payment breaches at Paay and $2M in card details for sale. Breaches: Facebook (267M), Nintendo, gene lab, Vianet, WHO, Gates foundation, King Crimson distributor, CISI, Danish Agro. Privacy telehealth and contact tracing. Wi-Fi 6E. CFAA in Supreme Court. DoH-eh! Suing China. Scam defense. Disinformation and FB unfriends pseudoscience. Verified Advertisers. Windows broke Chrome. Vulnerabilities: iPhone email zero-day, OpenSSL, FGPAs, AV as weapon, Foxit & Phantom PDF, Bluetooth, and IBM flubs response. Zoom fixes. Wuhan hacked. Fraud and crisis. Cutting scientific corners. Negative oil. Meteorite death. Bulletproof breast? And more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 159 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: COVID-19 update: stats live, Wuhan stats updated, infection hotspots, sewage early warning, reopening, conspiracies and threats, hacking researchers, virus sniffer dogs, vaccines including measles vs COVID. Surveillance law expired? Vulnerability Priority Rating vs CVSS. ISP BGP security. Zoom's DIY crypto. Rewards for cyber-spies. More zoom-bombing. Russia vs SFO. Domestic Terrorism. Opioid alternative. Hot Qubits. And more.

Read More

This Week’s [in]Security – Issue 158 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: Coronavirus update. The spread, the curve, and aftermath. Guidance, Response and Recovery. The good, the bad, and the ugly. Immunity and knowledge. 12 PCI FAQ's. Mega breach. Fines deferred. COVID Contact tracing tech. Online voting is still a bad idea. Ventilators. Corp.com. Spam-spam-spam. MS Exchange, VMware, Zoom, Vehicles bugs. Breakable smart-lock. Fingerprint cloning. Zero-days. BGP hijacking. COVID hacking wave and other impacts. Faking AI. Krakatau again. And More.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 157 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: The great mask debate. Other PPE. The spread and curve. Projections. Responses. Behaviour - the good, the bad, and the ugly. Magecart. Breaches: Key Ring, Marriot (again), Dueling Network, Redis, Zoom. Equifax post-mortem. WFH and privacy. Zoom privacy. DHS biometric db. Meme privacy. EARN-IT. FISA abuse. Wi-Fi 6E. NIST updates and events. COVID Treatments, Innovation, Vaccines. In the water? Gearing up. More DoH. And More.

Read More

This Week’s [in]Security – Issue 156 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: Improved layout. COVID-19 update spread, impact, and behaviour. Extreme measures. Supplies. Masks. Tragedy. COVIDIOTS. Remote and Work from Home. Magecart. Carders smacked. Virus surveillance. Facial recognition gets scarier. Zoom privacy issues. Insurance and COVID. Internet and mail-in voting. NIST. Testing, treatments and trials. Industry steps up. 3D printers. ICS hacking. Reporting vulnerabilities isn't easy. Snail mail USB booby traps. Bypassing 2FA. And more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 155 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending:COVID-19 update: Spread, containment, Reactions, response, impact, Surveillance, Information, Tools, How much Toilet Paper, Extraordinary invention, Treatments, vaccines, Behaviours from just bad to evil. Magecart. POS Terminal sanitization. Breach responsibility. 3 Mega-breaches. Who Has Your Face. De-Googling. FIPS 140-3 and NIST. NIST Telework guidance and more. Password managers. Russian cyber-weapon breach. Security theatre. And more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More