controlgap.com

Posts about:

COVID-19 (3)

This Week's [in]Security - Issue 225 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Card Production, Data Removal, Digesting PCI, Issuers. Fingerprint cards. New breaches: Saudi Aramco, Mexican voters, S3 service provider bucket, Denials and False breaches. New Ransomware: trains, suppliers, Major outages: Akamai. Follow-ups & Fall-out: Named and Shamed, Insurance restrictions, Audi, Kaseya, Privacy: Data brokers. Laws & Regs: Right to be Forgotten. Pipelines, Right-to-repair, Web-scraping. India's platforms, EU Crypto. Cybersecurity Career Awareness, AES Review, Lightweight Crypto Final, NIST. Defense: Backups, browsers, trackers, Tools, Russia's Firewall. Vulnerabilities: Print Drivers, SeriousSAM/HiveNightmare, PetitPotam, Linux "Sequoia", Telegram. Cybercrime: Pegasus Spyware, Trends: NPM Password Thief, MosaicLoader, Discord, Nation States: China, Crime. Homoglyphs, DNA, Swatter, Twitter, flattened-miners, ID Theft Scumbags. Other Risks: AI, Disinformation for Hire, Cloud ICS, Expired Domains, MLB Sign stealing. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Covid Ugly; Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 224 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Major-events: REvil goes dark, Kaseya. New breaches: Guess. New Ransomware: EA, D-Box, Campbell Conroy & O'Neil, Revelstoke. Follow-ups & Fall-out: Spin, Interpol, Tracking, Rebuilding. Privacy: Clearview AI, Scraping. Laws & Regs: Ransomware Response, Reward, Repair, Zero Day Hoarding. Defense: Tracker blocking, HTTPS-first, RDP, Talent, Quantum error correction & supremacy. Vulnerabilities: Browsers, SolarWinds, Commercial spyware, WordPress WooCommerce, Cloudflare, More Print Spooler, Windows Hello, D-Link, SonicWall, Elevators. Cybercrime: Trends. Nation States. Crime. Other Risks. Health, Safety & Environment. Ontario Tornados, Covid-19: Spread, Curves, Waves, and Variants. And more.

Read More

This Week's [in]Security - Issue 221 | insecurity | Control Gap

Welcome to This Week’s [in]Security. DSSv4 RFC, HSM RFC, WFH, Sunsets, 3DS, ATM vuln & Shimming. New breaches: Mercedes-Benz, APNIC. New Ransomware: FCUK. Follow-ups & Fall-out: Regulation & Breaches, SolarWinds, Colonial Pipeline. Privacy: Medical Data, Doorbells, Cookies/FLOC. Laws & Regs - Canada, US, The world, Standards. Defense: Webinars, Webinars. Einstein, D3FEND. Vulnerabilities: Stale Dependencies, Letting one slip by, DNS, BIOS, Vmware, Linux, SonicWall, Cybercrime - Trends: My Book, USB, Nation States. Crime. Most-Wanted. Other Risks: Job loss, Water Supplies, AI, Chips, Remote working, e-Proctoring, McAfee, Windows 11. Health, Safety & Environment: 751 more children, Condo Collapse. Covid-19: Spread, Curves, Waves, and Variants, Response, Immunity, Learned, Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 217 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI: SLC v1.1, Sunsetting P2PE v2 and PA-DSS. MasterCard resources. Control Gap SSA & SSLC. Magecart mobile, Carders. New breaches: Japanese Dating & government, Canada Post, Nukes, Dominos India, Hospitals, Compound redaction leak, New Ransomware: RCMP, Defensive shutdown. Privacy: Facial Recognition, Hiding controls. Laws & Regs - Canada: C-10 impact. US: Breach law. The world: Mass Surveillance, Data residency. Standards: NIST: Cloud, IoT/MuD. USB-C upgrade. Defense: Webinars, Webinars. Pipeline response, Cyber budgets, Unknown-unknowns, FBI supporting HIBP.

Read More

This Week's [in]Security - Issue 216 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI WFH FAQs, Standard updates, Mercari breach, Hashes Unsafe. New breaches: 23 Android Apps, Air India, Daily Quiz. New Ransomware: Banning payouts, Double Encryption. Follow-ups & Fall-out: SolarWinds, Codecov, Water Plant. Privacy: Apple, Cams, Health tools. Laws & Regs - Canada: C-10, Vaccine Patents. US: Pipeline Bills, IRS Crypto, Lawsuit backfires, Snapchat suit, Tesla review. UK, EU, HK: Facebook probe, WhatsApp, Sanctions, Crypto wars, USK MSP regs. Standards: Data Classification. Defense: ZeroDays, Phone numbers, Passwords, Simuland, Russian Keyboards, Explorer RIP. Vulnerabilities: Android, Windows RCE, Tool Abuse, Planes, (no trains), Automobiles. Cybercrime - Trends: Apple, Stuffing, Bizarro, Lazy Ransomware? Nation States. Crime. The2011 RSA Hack. Other Risks: Stress, Critical Infrastructure, Gig risgs, Busted for weak Wi-Fi? Just daft. Health, Safety & Environment: Covid-19: Spread, Curves, Waves, and Variants. Response. Immunity. Learned. Covid Ugly. Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 214 | insecurity | Control Gap

Welcome to This Week’s [in]Security. DSS v4.0 Summary, and Secure Payment Terminal Software. New breaches: Cookies, FermiLab, Glovo, Telestra, Twillo, Peleton, … New Ransomware: Pipeline Hack, Scripps, SmileDirect, Pirate, DDoS. Follow-ups & Fall-out: Apple, Ostriches, Lawyers, Therapy, and Disputes. Privacy: Facebook, Google, and EU Cloud. Laws & Regs - Canada: C-10. US: Scraping, CryptoEx, CFAA and the Cloud, Deplatforming, Astroturfing the FTC, Fines. Standards: Healthcare, Space-cyber. Defense: Kids, Buffs, Bounty, Containers, Tools, Doxing. Vulnerabilities: DNS, Spectre. Drone v. Telsla. Cybercrime - Trends: Nation States. Crime: Defogging BitCoin. Other Risks: Password Day, Missiles, TLDs. Exploit Ban, Tabs. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. Response. Immunity. Impact. Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 212 | insecurity | Control Gap

Welcome to This Week’s [in]Security. P2PE Solution Aid. More on 8-digit BINs. Supply-Chain Backdoors: CodeCov, Passwordstate, Solarwinds. New breaches: Facebook, Apple(?), ClearVoice. New Ransomware: Follow-ups & Fall-out: Privacy. Normalizing breaches. Floc Adverse. Laws & Regs: Canada: Bills C-10 & 11, regulating apps. US. UK, EU, HK. NIST iOT & ICS. CISv8. Defense: More Nation-State Patching, Moxie vs Cellebrite, Death to IoT, Passwordless, Mario and DevSecOps!? Vulnerabilities: Pulse, Chrome, SonicWall ZeroDays, Supply-chains, CyberGames, Clubhouse, Air-Drop, Docker Images, QNAP, Tesla. Updatable Encryption. Breaking Enigma. Cybercrime: Trends: TLS, QR, Sextortion, Ads, 7-Zip, ToxicEye, Pink, Fake DirectX12. Nation States. Crypto-skimming. Crime. Other Risks: Unethical patching, Social Media, Chips, Deepfake geography, Bounties, Resets, No bars! Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. Response. Immunity. Covid Ugly. Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 211 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI 3DS Updates. New breaches: ParkMobile, Codecov, Upstox, ClubHouse. New Ransomware: Follow-ups & Fall-out: Facebook. Breach spin and Greed. Privacy. Laws & Regs: Class Actions, Breach Notification, LEA requests. BYOD. IOT. Defense: Anti-Caller ID Spoofing, Rockets, Code, Coders, Free Course, Cyber Careers, Power Grid, FLoC off, OSCAL. Vulnerabilities: Browser ZeroDays, Faster Bug Disclosure, DNS, NAME:WRECKIoT, Un-awareness, Dependencies, Pwn2Own, Kubernetes, Juniper, Zoom, Crypto. Cybercrime: FBI Patching. Trends. Nation States. Crime. Other Risks. Child Abuse Images. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. The Good, Bad, and Ugly (Behaviour). And more.

Read More

This Week's [in]Security - Issue 210 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI 3DS, New e-skimmers, Card breaches. EU's SCA. Big-Hacks: Facebook, Linkedin. New breaches: Clubhouse, Q Link Wireless. New Ransomware. Follow-ups & Fall-out. Privacy: Big Brother? Xcinex Venue. Laws & Regs: Bans, Breach law, Facial recognition, NIST & Hippa. Defense: Tools, Simplification, Resilience. Vulnerabilities: Cisco zeroday, Pwn2Own, SAP, Zoom, Carbon Black, Domain Time II, Moodle, medical devices, 802.11bf sensing. Cybercrime: Trends. Gigaset, Nation States. Cyber-war? Other Risks. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. The Good, Bad, and Ugly (Behaviour). And more.

Read More

This Week's [in]Security - Issue 208 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI Updates: PTS FAQ, PIN 3.1, QSA Program. Big-Hacks: Exchange, SolarWinds, F5, Accellion. New breaches: New Ransomware: Follow-ups & Fall-out: Amazon sued. Privacy: Facial Recognition. Laws & Regs: Facebook sued, Section 230, Breach Disclosures, Location Tracking Guidelines, NIST. Defense: Isolate IoT, Tools, Browsers. Vulnerabilities: Android, iOS ZeroDay, Apple iOS. ColdFusion, NetMask code, Android, Wordpress. Arresting the messenger? Cybercrime: Trends. Account Takeovers. Other Risks: Disinformation, IoT Weapons, PII a Risk, Autopilot, Grid, Shipping, More NFTs, Win95, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. Immunity, Vaccines, and Vaccination. The Good, Bad, and Ugly (Behaviour). And more.

Read More