controlgap.com
Posts about:
[in]security (5)
This Week's [in]Security - Issue 256 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: FAQs, Skimmers, Payments, Training & events. New breaches, New Ransomware: NVIDIA, Major outages: Follow-ups & Fall-out. Missouri surprise, Broward, Log4j. Privacy: browsing, facial recognition, boarder patrol, medical tests, AirTags. Laws & Regs - Canada: Financial surveillance, The Emergencies Act. US: Cyber-social contract, US data and consumer privacy, Board liability, Turbotax mass-arbitration. World: Crypto, UK misuse, EncroChat & NSO lawsuits. Standards: NIST, Federal ZeroTrust. Defense: Passwordless, GitHub SecDB, NY-SOC, Chips. Vulnerabilities, Other Vulnerabilities: NPM JS libraries, Cisco, SCADA, WordPress, Samsung, Horde, Zabbix, Zenly, Bugged. Crypto-research: HPKE & Post-quantum. Cybercrime: Trends: Trojan evolution, Docusign, MFA-bypass, Nation States and mercenaries: NSA backdoor, Firewall Botnet. Crime & Enforcement. Other Risks: AI bias, Open Source, Reset-failed, Untrained. Health, Safety & Environment. War: Russia vs Ukraine - hot war, sanctions, banking, investment & partnerships, products, ships, planes, and spacecraft, big tech, disinformation, alerts, actions, APTs & mercenaries. Innovation and more.
Update: 2022-03-03 This week we have a special edition covering the war in the Ukraine, international response, and other related risks https://controlgap.com/blog/this-weeks-insecurity-issue-256-Ukraine
This Week's [in]Security - Issue 256 - Ukraine
Welcome to this special edition of [in]Security. Our regular news update can be found https://controlgap.com/blog/this-weeks-insecurity-issue-256.
Much of the world was shocked at the Russian invasion of Ukraine. As the terrible cost of another war in Europe unfolds and the World rallies to help Ukraine and constrain Russia, the risk of escalation and overreaction go beyond the immediate battlefield with sanctions, bans, and cyber-mercenaries in play. Our sympathy and support goes out to the people of the Ukraine.
Update: 2022-03-03 Created as a standalone article with additions on how people can help. As events progress, we will continue to report on risks and events arising from this crisis in our regular issues under our usual topics.
This Week's [in]Security - Issue 255 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: Skimmers, Training & events. New breaches: credit freezes, insiders, Red Cross, GiveSendGo. New Ransomware: decryptor, access brokers. Major outages: Canadian banks, Coinbase, Doh! Privacy: IRS and dating apps, Otter.ai, Google Sandbox & Enhanced Safety. Laws & Regs - Canada: Crypto, Web3. US: SEC cyber, Trolls, Copyright, Missouri, Texas vs. Meta, Clearview lawsuits. World: Police access, Australia. Standards: NIST, Random Number Feedback. Defense: Free tools, Github Scanner, Cisco passwords, Remote work. Vulnerabilities, Other Vulnerabilities: More Magento, email appliances, Snap PM, Cassandra, Ice phishing. Unredacter, Patching: Forced patching, Intel Firmware, Magento. Crypto-research, SHA3. Cybercrime: Trends: BEC, Teams. Nation States and mercenaries. Crime & Enforcement; Cyber-policing, OpenSea NFTs. Other Risks: Cloud? Facebook, AI, DRM protected paper. Disinformation, follow the money, Canada. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Innovation and more.
This Week's [in]Security - Issue 254 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates, Skimmers, Carders, Payments, Training & events. New breaches, New Ransomware: insurance, decryptor, 49ers, Swissport. Major outages: Vodaphone. Follow-ups & Fall-out: IHS, Inmediata. Privacy: CIA, Canada, health sites, ID.me, AirTags. Laws & Regs - Canada: Bills C-11 & S-210. US: EARN IT, Facebook, Ohio. World: Cambridge, EU data sharing, Google Analytics, Consent spam, QWACs, Israel, Hacking Jamaica. Standards: NIST. Defense: 2FA, data retention liability, Shift-Left, trust, IoT audit, AI, Multiple Microsoft, deniable data! Vulnerabilities, Zerodays: Project Zero, Apple, Other Vulnerabilities: metrics, supply chains, Mozilla, PHP/Wordpress, Mazda, Bounties. Patching: 3 CISA alerts, android, Windows, SAP. Adobe, ECC vs quantum crypto. Cybercrime: Trends: IOCs, Modified Elephant, old tactics, Nation States and mercenaries. Crime & Enforcement; $4.5B, SIMs. romance, Other Risks: Spycraft, Chip errors, Chinese tech, Blockchain myths, Disinformation, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Covid Compliance. Innovation and more.
This Week's [in]Security - Issue 253 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: Target's anti-skimmer Merry Maker, Segway. Payments, Training & events. New breaches: Securitas (S3), News Corp, Whisper. New Ransomware: Changing tactics, Oiltanking, Kronos. Follow-ups & Fall-out: Equifax. Privacy: GPU-fingerprinting, Ungoogling yourself. Laws & Regs - Canada: C-11/streaming, Online harms, Digital Taxes. US: EARN IT, Cyber Review board, EFF. World: EU vs. US. Standards: NIST Software, IoT, &, Security Labeling. NVD API. Defense: volunteers, browsers. Vulnerabilities, Zerodays: Zimbra. Other Vulnerabilities: CISA alerts, Log4shell lives on, Firmware, Cisco, ESET, Supply chains, MSIX, Finding Open Source vulns, Walmart analyzes new ransomware. Patching: CISA must patch, Samba. Crypto-research. Cybercrime: Trends: Reverse proxy attacks, Nation States: taking down North Korea, China, more spyware, Ukraine. Crime & Enforcement; fraud & blackmail, big heists, drones, Other Risks: Automation. Banning ideas. App monopolies, too many secrets, Internet next, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Learned; Covid Ugly; Innovation and more.
This Week's [in]Security - Issue 252 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI updates: MPoC. Skimmers, Payments. New breaches, New Ransomware: insiders, Canada FA. Major outages: Record DDoS, Andorra, Tonga. Privacy: tracking censorship, FloC & Topics. Laws & Regs - Canada: CitizenLab on LawBytes. US: China Unicom ban, zero trust, too many laws, Google lawsuit, Cyber-insurance and ransomware, Metaverse-law. World: GDPR, autonomous car liability, China's Internet. Standards: FIPS, NIST, NICE. Defense: EU incident framework, source backup, test people too. Vulnerabilities, Zerodays: Centos 8 (EOL), Apple. Other Vulnerabilities: Disclosure, Polkit/PwnKit, Datacenter remote management, Cameras, mobile protocols. Patching: Windows, QNAP & the forced patch. The Quantum Apocalypse? Cybercrime: Trends: alerts, Revil, BlackCat, Oauth and MFA, BRATA, Dark Herring, BotenaGo/IoT exploit source, DazzleSpy, new tricks. Nation States: Pegasus, APTs. Crime & Enforcement; QR fraud, ID Theft, Rug-Pulls, Swatting. Other Risks: 2M certificates revoked, copywrongs, air tags, gaslighting, unrealestate, cloud costs, following the disinformation money. Russia-Ukraine, Belarus Rail, Health, Safety & Environment: snow, Bitcoin, Winter Olympics, nuclear. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Innovation and more.
This Week's [in]Security - Issue 251 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: PAN Truncation Simplified, DSSv4 preview, Payments, Training & events. New breaches: Crypto.com, Lympo, Multichain, WordPress supply chain, healthcare, Red Cross. New Ransomware, Major outages, Follow-ups & Fall-out: Leak Analysis, Open Subtitles. Upstox, Desjardins, C-Planet. Privacy: Duck Duck Bang, Meta gets creepy, Police & social media, PHAC, AirTag stalking. Laws & Regs - Canada: vaccine mandates. US: Restraining Tech, Anti-trust, DeFi, EFF, Pennsylvania, Missouri. World: UK crypto-wars, EU, Australia vs Google, China, Japan, Crypto mining, Standards: IPv6 Security. Defense: Supply Chains, Open Source, IRS, Excel macros, Chrome, Microsoft, Vulnerabilities, Zerodays: Zoom. Olympic App fail, Other Vulnerabilities: CISA warnings, Zero-click, Bug Bounty Markets, Likelihood of attack, Hospital IoT, Log4Shell, Cisco, Linux WCP, ManageEngine, McAfee, zombie Jquery, Box 2FA bypass, Security Devices. Dark Souls, Patching: Smart patching, Oracle, SAP, Windows emergency fixes, Zoho. Crypto-research. Cybercrime: Trends: Nation States: Crime & Enforcement. Other Risks: FAA vs FCC on 5G, Doomsday Clock, Russia-Ukraine, Drones, Disinformation, Economy. Health, Safety & Environment: Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Compliance. Innovation and more.
This Week's [in]Security - Issue 250 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: Card Production. Carders. Training. New breaches, New Ransomware: bankruptcy, jail, DDoS. Major outages, Follow-ups & Fall-out: Lawyers vs Insurance, Accellion, Maryland. Privacy: Apple Private Relay. Laws & Regs - Canada: location data. US: DMCA, Carrier breach rules, DeFi, Facebook anti-trust, Celebrities sued. World: Europol, GDPR & Tech, China & tech. Standards: NIST drafts, Randomness. Defense: Protecting Open Source, Blocking stingray, ICS Security, C-Level, CSSLP. Vulnerabilities, Zerodays. Other Vulnerabilities: WordPress, React & NPM, MacOS, Defender, Patching: CISA must patch list, Adobe, AWS, Cisco. WordPress, L2TP. cryptography, Cybercrime: Trends: Self-inflicted, Multi-OS backdoor, Beware USB sticks. Nation States: Spyware for hire, Russia v Ukraine. Crime & Enforcement: Revil Arrests, Ukrainian arrests, Crypto theft. Other Risks: Great Resignation, QR fakes, Real war? Sowing division. Health, Safety & Environment: Tsunami, Tesla, Sharks, Wild-fires. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Innovation and more.
This Week's [in]Security - Issue 249
Welcome to This Week’s [in]Security. Skimmers, Training, Payments. Big-Hacks: Log4shell, EOL impediments, prevention, Log4-like vulns. New breaches: DatPiff, FlexBooker, Uscellular, McMenamins, healthcare. New Ransomware, Follow-ups & Fall-out. Privacy. Laws & Regs – US, World, Standards. Defense: cryptography, zero-day-repository, anti-extremism. Vulnerabilities, copied commands, Y2K22, android, vm ware, Bluetooth crypto. Cybercrime - Trends: Malsmoke, BadUSB, cyber-mercenaries, fake shut-downs. Supply chain sabotage. Nation States. Crime & Enforcement. Other Risks: Norton crypto-miner inside, Signal, AI & algorithms, false-positives. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Impact; Covid Compliance. Innovation and more.