controlgap.com
Posts by:
CG Blogger
This Week's [in]Security - Issue 258 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: Call for Speakers, P2PE, 3DS, Card Production. Payments, Training & events. New breaches: Samsung, Mercado Libre, VirusTotal. New Ransomware: more Conti, Critical Infrastructure, Bridgestone, Ubisoft. Major outages: Fiji, Spotify & Discord. Follow-ups & Fall-out. Privacy: Trusting your phone, COVID passports, Radar & body language. Laws & Regs - Canada: Bill C-11, Competition Law. US: Incident reporting, Whistleblowers, ICE, Amazon, Weight Watchers, Utah, Location data. World: Clearview AI, cybercrime treaty, Spyware probe, Right to be Forgotten, Crypto regulations, cyber-flashing. Standards: NIST DevSecOps. Defense. CISA Exploit catalog, Defense in depth, Polls, Kali. Vulnerabilities, Zerodays: APC UPS, 0-clicks, Chrome, DDoS, Other Vulnerabilities: BGP crypto-heist, Ostriches, IoT & ATMs, More Specter, Azure, Linux. Defender, HP, Wordpress, Riverbed, password rules, Blockchain privacy, Proof-of-stake attacks. Patching: Microsoft, Firefox, Adobe, Siemens. Cybercrime: Trends: surging attacks, NVIDIA. Telegram, WhatsApp. Nation States and mercenaries: China, Iran. Crime & Enforcement: Zelle, Extraditions, Fresno, DoH! Other Risks: Alexa, Pluton, AI, Employment, Manufacturing, Gas, NFT myths. Health, Safety & Environment. Missiles, GPS, Meteors & asteroids. Russia v. Ukraine. Innovation and more.
This Week's [in]Security - Issue 257 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: DSSv4 timelines. Training & events. New breaches: Conti Malware Group, Samsung, Nvidia, Robinhood, Lawyers. New Ransomware: Hive Decryption, Toyota, AON. Major outages: Semiconductors. Follow-ups & Fall-out. Privacy: DNA testing, AirTags. Laws & Regs - Canada: Lawful Access, Privacy Reform, CRTC. US: Cybersecurity law, SEC, Web-Scraping. World: Telcos, Crypto-Taxes. Standards: NSA, NIST. Defense. Vulnerabilities, Zerodays: Firefox, Other Vulnerabilities: Password Cracking, Credentials in Code, Linux, Samsung, Stalkerware, Medical IoT, Echo, Patching: CISA. Crypto-research: PQC-Hybrid. Cybercrime: Trends: APIs, DDoS, NVIDIA certs, Sharkbot, SockDetour, Teabot. Nation States and mercenaries: Europe, China, Iran. Crime & Enforcement. Other Risks: Bulletproof TLS, Shadow IT. Democracy. Health, Safety & Environment. The Russia v. Ukraine war. Innovation and more.
Note: the volume and variety of Ukraine related articles makes it difficult to report these under specific sections, we will be reporting these in a dedicated section below.
This Week's [in]Security - Issue 256 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: FAQs, Skimmers, Payments, Training & events. New breaches, New Ransomware: NVIDIA, Major outages: Follow-ups & Fall-out. Missouri surprise, Broward, Log4j. Privacy: browsing, facial recognition, boarder patrol, medical tests, AirTags. Laws & Regs - Canada: Financial surveillance, The Emergencies Act. US: Cyber-social contract, US data and consumer privacy, Board liability, Turbotax mass-arbitration. World: Crypto, UK misuse, EncroChat & NSO lawsuits. Standards: NIST, Federal ZeroTrust. Defense: Passwordless, GitHub SecDB, NY-SOC, Chips. Vulnerabilities, Other Vulnerabilities: NPM JS libraries, Cisco, SCADA, WordPress, Samsung, Horde, Zabbix, Zenly, Bugged. Crypto-research: HPKE & Post-quantum. Cybercrime: Trends: Trojan evolution, Docusign, MFA-bypass, Nation States and mercenaries: NSA backdoor, Firewall Botnet. Crime & Enforcement. Other Risks: AI bias, Open Source, Reset-failed, Untrained. Health, Safety & Environment. War: Russia vs Ukraine - hot war, sanctions, banking, investment & partnerships, products, ships, planes, and spacecraft, big tech, disinformation, alerts, actions, APTs & mercenaries. Innovation and more.
Update: 2022-03-03 This week we have a special edition covering the war in the Ukraine, international response, and other related risks https://controlgap.com/blog/this-weeks-insecurity-issue-256-Ukraine
This Week's [in]Security - Issue 256 - Ukraine
Welcome to this special edition of [in]Security. Our regular news update can be found https://controlgap.com/blog/this-weeks-insecurity-issue-256.
Much of the world was shocked at the Russian invasion of Ukraine. As the terrible cost of another war in Europe unfolds and the World rallies to help Ukraine and constrain Russia, the risk of escalation and overreaction go beyond the immediate battlefield with sanctions, bans, and cyber-mercenaries in play. Our sympathy and support goes out to the people of the Ukraine.
Update: 2022-03-03 Created as a standalone article with additions on how people can help. As events progress, we will continue to report on risks and events arising from this crisis in our regular issues under our usual topics.
This Week's [in]Security - Issue 255 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: Skimmers, Training & events. New breaches: credit freezes, insiders, Red Cross, GiveSendGo. New Ransomware: decryptor, access brokers. Major outages: Canadian banks, Coinbase, Doh! Privacy: IRS and dating apps, Otter.ai, Google Sandbox & Enhanced Safety. Laws & Regs - Canada: Crypto, Web3. US: SEC cyber, Trolls, Copyright, Missouri, Texas vs. Meta, Clearview lawsuits. World: Police access, Australia. Standards: NIST, Random Number Feedback. Defense: Free tools, Github Scanner, Cisco passwords, Remote work. Vulnerabilities, Other Vulnerabilities: More Magento, email appliances, Snap PM, Cassandra, Ice phishing. Unredacter, Patching: Forced patching, Intel Firmware, Magento. Crypto-research, SHA3. Cybercrime: Trends: BEC, Teams. Nation States and mercenaries. Crime & Enforcement; Cyber-policing, OpenSea NFTs. Other Risks: Cloud? Facebook, AI, DRM protected paper. Disinformation, follow the money, Canada. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Innovation and more.
This Week's [in]Security - Issue 254 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates, Skimmers, Carders, Payments, Training & events. New breaches, New Ransomware: insurance, decryptor, 49ers, Swissport. Major outages: Vodaphone. Follow-ups & Fall-out: IHS, Inmediata. Privacy: CIA, Canada, health sites, ID.me, AirTags. Laws & Regs - Canada: Bills C-11 & S-210. US: EARN IT, Facebook, Ohio. World: Cambridge, EU data sharing, Google Analytics, Consent spam, QWACs, Israel, Hacking Jamaica. Standards: NIST. Defense: 2FA, data retention liability, Shift-Left, trust, IoT audit, AI, Multiple Microsoft, deniable data! Vulnerabilities, Zerodays: Project Zero, Apple, Other Vulnerabilities: metrics, supply chains, Mozilla, PHP/Wordpress, Mazda, Bounties. Patching: 3 CISA alerts, android, Windows, SAP. Adobe, ECC vs quantum crypto. Cybercrime: Trends: IOCs, Modified Elephant, old tactics, Nation States and mercenaries. Crime & Enforcement; $4.5B, SIMs. romance, Other Risks: Spycraft, Chip errors, Chinese tech, Blockchain myths, Disinformation, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Covid Compliance. Innovation and more.
This Week's [in]Security - Issue 253 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: Target's anti-skimmer Merry Maker, Segway. Payments, Training & events. New breaches: Securitas (S3), News Corp, Whisper. New Ransomware: Changing tactics, Oiltanking, Kronos. Follow-ups & Fall-out: Equifax. Privacy: GPU-fingerprinting, Ungoogling yourself. Laws & Regs - Canada: C-11/streaming, Online harms, Digital Taxes. US: EARN IT, Cyber Review board, EFF. World: EU vs. US. Standards: NIST Software, IoT, &, Security Labeling. NVD API. Defense: volunteers, browsers. Vulnerabilities, Zerodays: Zimbra. Other Vulnerabilities: CISA alerts, Log4shell lives on, Firmware, Cisco, ESET, Supply chains, MSIX, Finding Open Source vulns, Walmart analyzes new ransomware. Patching: CISA must patch, Samba. Crypto-research. Cybercrime: Trends: Reverse proxy attacks, Nation States: taking down North Korea, China, more spyware, Ukraine. Crime & Enforcement; fraud & blackmail, big heists, drones, Other Risks: Automation. Banning ideas. App monopolies, too many secrets, Internet next, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Learned; Covid Ugly; Innovation and more.
This Week's [in]Security - Issue 252 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI updates: MPoC. Skimmers, Payments. New breaches, New Ransomware: insiders, Canada FA. Major outages: Record DDoS, Andorra, Tonga. Privacy: tracking censorship, FloC & Topics. Laws & Regs - Canada: CitizenLab on LawBytes. US: China Unicom ban, zero trust, too many laws, Google lawsuit, Cyber-insurance and ransomware, Metaverse-law. World: GDPR, autonomous car liability, China's Internet. Standards: FIPS, NIST, NICE. Defense: EU incident framework, source backup, test people too. Vulnerabilities, Zerodays: Centos 8 (EOL), Apple. Other Vulnerabilities: Disclosure, Polkit/PwnKit, Datacenter remote management, Cameras, mobile protocols. Patching: Windows, QNAP & the forced patch. The Quantum Apocalypse? Cybercrime: Trends: alerts, Revil, BlackCat, Oauth and MFA, BRATA, Dark Herring, BotenaGo/IoT exploit source, DazzleSpy, new tricks. Nation States: Pegasus, APTs. Crime & Enforcement; QR fraud, ID Theft, Rug-Pulls, Swatting. Other Risks: 2M certificates revoked, copywrongs, air tags, gaslighting, unrealestate, cloud costs, following the disinformation money. Russia-Ukraine, Belarus Rail, Health, Safety & Environment: snow, Bitcoin, Winter Olympics, nuclear. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Innovation and more.
This Week's [in]Security - Issue 251 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: PAN Truncation Simplified, DSSv4 preview, Payments, Training & events. New breaches: Crypto.com, Lympo, Multichain, WordPress supply chain, healthcare, Red Cross. New Ransomware, Major outages, Follow-ups & Fall-out: Leak Analysis, Open Subtitles. Upstox, Desjardins, C-Planet. Privacy: Duck Duck Bang, Meta gets creepy, Police & social media, PHAC, AirTag stalking. Laws & Regs - Canada: vaccine mandates. US: Restraining Tech, Anti-trust, DeFi, EFF, Pennsylvania, Missouri. World: UK crypto-wars, EU, Australia vs Google, China, Japan, Crypto mining, Standards: IPv6 Security. Defense: Supply Chains, Open Source, IRS, Excel macros, Chrome, Microsoft, Vulnerabilities, Zerodays: Zoom. Olympic App fail, Other Vulnerabilities: CISA warnings, Zero-click, Bug Bounty Markets, Likelihood of attack, Hospital IoT, Log4Shell, Cisco, Linux WCP, ManageEngine, McAfee, zombie Jquery, Box 2FA bypass, Security Devices. Dark Souls, Patching: Smart patching, Oracle, SAP, Windows emergency fixes, Zoho. Crypto-research. Cybercrime: Trends: Nation States: Crime & Enforcement. Other Risks: FAA vs FCC on 5G, Doomsday Clock, Russia-Ukraine, Drones, Disinformation, Economy. Health, Safety & Environment: Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Compliance. Innovation and more.