controlgap.com

Posts about:

[in]security (14)

This Week's [in]Security - Issue 168 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Fallout from US Unrest. Covid-19: Spread & Curve. Lockdown, Reopening, & The New Normal. More of the Good, Bad, and Ugly. Huge breach of dating apps. Web tracking breach. Contact tracing app problems. Implementing Privacy. Zoom blinks. NIST. DDoS. Expiring root Certificates followup. Anti-malware CPUs. Adobe, Windows 10 2004 bugs. Harvesting zero-days. Fake hacks. Crims using CAPTCHA. Vault 7 tools poorly secured. And more.

Read More

This Week's [in]Security - Issue 167 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Fallout from US Unrest. Covid-19: Spread & Curve. Lockdown, Reopening, & The New Normal. More of the Good, Bad, and Ugly. Magecart. Payment fraud and reserves. Key mismanagement. COVID related breaches. Contact tracing app problems. Facial recognition. Blaming users. Forensics survey. Fighting deepfakes. Lamphone eavesdropping attack. Lifespan of a Vulnerability. Bad GnuTLS bug. Intel side-channels. Magneto. IoT. Facebook Tails Exploit. Massive hacker for hire operation. Ransomware's hidden costs. Ransomware is fast. Root Certificate expiry will brick smart appliances. Zoom censorship. AI arms race simulations. And more.

Read More

This Week's [in]Security - Issue 166 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Fallout from US Unrest. Covid-19: Spread & Curve. Lockdown, Reopening, & The New Normal. Predicting outbreaks with social media. More of the Good, Bad, and Ugly. Medical research scandal. PCI SSF for Terminal Software. New FAQ. COVID related breaches. Another 100M breached credentials surface. Approximately 10M new. Contact tracing app problems. Google Incognito Lawsuit. Twitter War NIST key generation and IoT updates. Defending against future pandemics. e tu Password. Cybercrime prevention Homomorphic encryption tools. Shades of 'The Italian Job'. Air-gapped malware. e-Voting. Huawei 5G and the 5 Eyes. Zoom Encryption Controversy. And more.

Read More

This Week's [in]Security - Issue 165 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Covid-19: Spread & Curve Toronto COVID map & stats. Lockdown, Reopening, & The New Normal. More Good, Bad, and Ugly. Update on PCI DSS v4. COVID related breaches. A whopping 8B record giga-breach. 100M+ in smaller ones. Breach reports down? 5.5M older breaches added to HIBP. Ransomware's growth. Forensics report not 'protected' in lawsuit. Contact tracing app problems. Location tracking lawsuit. Twitter War. NIST monitoring, microservices, and crypto-agility. Doomsday Planning. Identifying fake photos. EXIM mail actively being exploited. Password reuse, SHA-1 login deprecated, 26 USB vulnerabilities. Bulletproof TLS #65. Random number security. Free ACM Digital Library Access. COVID Crimes. Scam anti-5G tech. Port-scanning customers without consent! UK 5G re-think. Rhyming AIs. We have liftoff. And more.

Read More

This Week’s [in]Security – Issue 164 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Covid19 passes 5M infected and nearly 100K US dead. Brazil, Russia. Leaked data on China's infections. Failed herd immunity. Misinformation. Distancing gimmicks. Isolation fatigue. New and updated PCI FAQs. PCI GEAR. Magecart evading scans. Verizon's annual breach report (DBIR). Breach notice speak. 116M+ breached records. COVID related breaches. Contact tracing APIs and apps. Deleting yourself from the Internet. Apple v FBI again. Security and memory safety. Dark Web checkup. Quantum computing update. COVID related fraud. Not invented here risk. Negative interest rates. Disturbing AI. Incels. Dust bowl 2.0. Hurricanes. The South Atlantic Anomaly. Recycling munitions. And more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 163 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: Coronavirus: Visualizing the spread. Infection and governments. Lockdown and reopening. Weird tech. Pool-noodle-hats. Vaccines, anti-bodies, treatments. More good, bad, and ugly. Masks, anti-maskers, and distancing. Confused AIs. PCI updated FAQs. The Unattributable 23M record breach. Celebrity law firm. 2nd grader pwns school board. More ransomware information sales. More contact tracing. Huawei export restrictions. Windows packet sniffer. Win-DoHs. Defcon & Blackhat cancelled. Thunderspy. Apples XML trouble. Ancient Windows bug. Attacking smart factories. Crypto-agility. Rash of supercomputer hacks. Exfiltrating over air gaps. New electronic warfare platform. Conspiracy theories. Election insecurity. And more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 162 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Coronavirus update. COVID-19 hits 4M, subways, Russia & Brazil. Cats, ferrets, & Llamas. Reopening. Masks and anti-maskers. Magneto favicon skimmers. Fixing EU cookie policy. Mega-breach dumps and 10B (yes B) record breach. MFA or not. Password reuse. Power supplies and air-gaps. Azure-squatting. Remembering ILOVEYOU. Murder Hornets. Asteroid near miss. Where's the beef and other COVID fallout. And more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 161 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: Coronavirus: New Zealand, Canada, Brazil, Russia, Belgium, Mississippi. Vaccines, anti-bodies, treatments. Guidance, Response and Recovery. More good, the bad, and the ugly. Payments, PCI & Covid. Breaches & ransomware: Banco BCR (cards), GDPR site, Tokopedia (15M), 9M UK licence plate trip logs, TaiLieu(7M), LineageOS. How to respond to a breach tip. Contact tracing and privacy. Facebook settlement. Biometrics & De-anonymizing device IDs. Patents. NIST updates. Fuzzing Apple. Power Grid defense. Saving ".org". SQL on a firewall! OpenSSL, Teams, Wordpress, Saltstack, Magneto, Adobe, Belkin NetCams. Lock-picking. Shade ransomware keys released. Tricky phone scam. Deep-fakes and identity theft. COVID cabin fever. Trolling AI's. Ad more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 160 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: Coronavirus update. The spread, the curve, and aftermath. Guidance, Response and Recovery. The good, the bad, and the ugly. Peaking? Food processing crisis. Disinfectants. Antibody tests. Ingenuity and invention. Testing at scale. Payments and CPEs under lockdown. More PCI FAQ updates. Payment breaches at Paay and $2M in card details for sale. Breaches: Facebook (267M), Nintendo, gene lab, Vianet, WHO, Gates foundation, King Crimson distributor, CISI, Danish Agro. Privacy telehealth and contact tracing. Wi-Fi 6E. CFAA in Supreme Court. DoH-eh! Suing China. Scam defense. Disinformation and FB unfriends pseudoscience. Verified Advertisers. Windows broke Chrome. Vulnerabilities: iPhone email zero-day, OpenSSL, FGPAs, AV as weapon, Foxit & Phantom PDF, Bluetooth, and IBM flubs response. Zoom fixes. Wuhan hacked. Fraud and crisis. Cutting scientific corners. Negative oil. Meteorite death. Bulletproof breast? And more.

Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.

Read More

This Week’s [in]Security – Issue 159 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: COVID-19 update: stats live, Wuhan stats updated, infection hotspots, sewage early warning, reopening, conspiracies and threats, hacking researchers, virus sniffer dogs, vaccines including measles vs COVID. Surveillance law expired? Vulnerability Priority Rating vs CVSS. ISP BGP security. Zoom's DIY crypto. Rewards for cyber-spies. More zoom-bombing. Russia vs SFO. Domestic Terrorism. Opioid alternative. Hot Qubits. And more.

Read More