controlgap.com
Posts about:
[in]security (6)
This Week's [in]Security - Issue 247 | insecurity | Control Gap
Welcome to This Week’s [in]Security. Big-Hacks: More log4shell. New breaches: Azure, Hellman. New Ransomware: terrorism? Inetum. Major outages: AWS. Follow-ups & Fall-out: HIPB adds near 1B passwords. Privacy: Eye-tracking. Laws & Regs - Canada: digital law, AI. US: tech lawsuits. World: Judgements & fines. Standards: NISTR draft. Defense: fighting scams, browser enhancements. Vulnerabilities, Other Vulnerabilities: Multiple-MS, WordPress plugin, VoIP backdoors, 7% pass, IoT honeypot, crypto-research. Cybercrime: Trends: top 5 scams, andrioid, powerpoint. Nation States: NSO group, Zoho. Crime & Enforcement: crypto returned, SEC filings. Other Risks: 5G & aircraft, Juice jacking, Human behavior. Innovations & Inventions: quantum, lickable screens. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Changing restrictions, Treatments; Rapid-Tests, Immunity; New Vaccine type. Learned; Omicon, Covid Ugly; Covid Compliance. And more.
This Week's [in]Security - Issue 246 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: FAQ, HSM. Magecart, Sportsgear, ATMs, PAX. Supply-Chain Backdoors: Log4J/Log4shell continues! Underfunding! New breaches: Scraping, Finite Recruitment, ProTemps, GumTree. New Ransomware: Kronos, Virginia, logistics, medical. Major outages: AWS. Follow-ups & Fall-out: schools, delays, Desjardins settles. Privacy: Staying signed in. Laws & Regs - Canada: Repair, Harms. US: Data Protection, National Security, Chinese Tech, Takedowns. World: trade disputes, Japan, UK, EU. Standards: NIST drafts. Defense: Webinars, bans, Bug bounties, Internet Hall-of-Fame. Vulnerabilities, Zerodays. Other Vulnerabilities: chips, Ubuntu, Dell, Firefox, Adobe, Apple, Chrome, and MS. ECDSA keys. Cybercrime: Trends, log-ins, Contact Forms, Anubis, Seedworm. Nation States. NSO, Huawei, Nobelium. Crime & Enforcement. Obit pirates, Arrests, Assassins. Other Risks: Data life cycles, AI diagnosis, Shadows, Printers, virtual assault, crypto currency. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Impact; Covid Ugly; And more.
This Week's [in]Security - Issue 245 | insecurity | Control Gap
Welcome to This Week’s [in]Security. Log4J/Log4shell! PCI and payments: PCI updates: PIN, SSF. Non-Compliance Lesson No.3. Magecart, Supply-Chain Backdoors: New breaches: Kafka. Volvo. New Ransomware: Follow-the-money, Cybercommand, Utilities, Healthcare, SPAR stores. Major outages: Amazon. Follow-ups & Fall-out. Privacy: Tor, surveillance capitalism, facial recognition. Alexa can you keep a secret? Laws & Regs - Canada: website blocking, JusTech. US: Copyright takedowns. World: Espionage tools, Botnet lawsuit, Assange. Cybercriminal Court? Standards: Cyber-resilience. testing. IPv6 transition. Defense: Cyber & the board, AI, Smishing, pirates. Vulnerabilities, Zerodays. Other Vulnerabilities: HTTP-no- S, Home grown, Chrome, Win/URI, WD SanDisk, SonicWall, MikroTik, Bluetooth, factoring. Cybercrime: Trends, Phising. WordPress, npm. Moobot. Nation States. Crime & Enforcement. Other Risks: AWS, Quantum, BurnOut, Tor, Kids, Cryptominers, AirTag abuse. Health, Safety & Environment. CO2 capture, batteries, nukes. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Impact; Covid Compliance. And more.
This Week's [in]Security - Issue 244 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: Participating brands FAQ, and 8 updates. Magecart/skimmers, Brazil, Square. New breaches: Panasonic, Planned Parenthood. New Ransomware: Critical Infrastructure, Rideau Hall. Major outages, Follow-ups & Fall-out: Gravatar HIPB. Privacy: De-anonymization. Laws & Regs - Canada: health data, Huawei. US: FBI access, TSA, SEC, Biometrics. World: Product Security, Algorithm Transparency. Standards: NIST IoT, CISA mobile. Defense: Spam calls, AI understanding, Facial fuzz, attack maps, DRP, Old tech, Faraday cages. Vulnerabilities, Zerodays: Windows. Other Vulnerabilities: Printers, Routers, NSS Crypto, XS-Leaks, Passwords, zoom, Azure Sphere, Cloud Honeypot, CISA Hitachi & Zoho, Verizon. Cryptography HKDFs, PQC signatures & performance, Quantum Computing. Cybercrime: Trends, NABs, Trojans, AT&T, WRITE, Excel Addins. Nation States: diplomats, air-gaps, fake recruiters. Crime & Enforcement. Other Risks: Cyber-insurance exclusions, long game, China, misinformation, Meta/FB, amplification, shopping bots, Edge, Food, Hype? Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Learned; And more.
This Week's [in]Security - Issue 243 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: magecart, old school jackpot, processors, transit. Big-Hacks: 1M GoDaddy WordPress sites including SSL keys and credentials. New breaches: PNB, Millennium Bank, UHC, lessons learned. New Ransomware: Conti counterhack, IKEA, Vesta Turbines. Privacy: android settings. Laws & Regs - Canada: Misinformation vs. Freedom of Expression, Wills & social media. US: export ban, CISOs, federal privacy, Cryptocurrency, Apple vs. NSO. World: Israel Spy tech ban, UK default passwords, Aus limits anonymity. Standards: NIST Drafts, ICS/IOT defense. Defense: Webinars, Webinars. Cyber labeling, Metrics, Fake Apps, Trust Chains. Vulnerabilities, Zerodays: Windows Installer, Windows 10, Exchange. Other Vulnerabilities: Magento, BGP-IRR, Bad passwords, fingerprint bypass, medical devices, ICS Wi-Fi, passwordless Wi-Fi, open VPN, Virtual Box, Printjacking. Cybercrime: Trends, Infrastructure, Biomanufacturing, phone scams, CronRAT, email reply hijacking, JSWinRAT, Media-Tek DSP. Nation States: Crime: Interpol, Ukraine, holiday scams, and Ontario COVID arrest, flash mobs, RentAHitman? Other Risks: Facebook/Meta, unreal-estate, The Great Firewall, due diligence, quantum computing, Clearview AI, shipping, terminology, who me? Health, Safety & Environment. twindemic, plague, human error, exploding turkeys, insurance. flooding, Covid-19: Spread, Curves, Waves, and Variants; Omicron; Response; Treatments; Immunity; Learned; Impact; Covid Compliance. And more.
This Week's [in]Security - Issue 242 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: Magecart, Jackpot. New breaches: IAB's, Indian Securities Depository, Stripchat, RobinHood, RedDoorz, IDC, Ducks Unlimited, GitHub/Firefox-Linux. New Ransomware, holidays, trends, analysis, response. Major outages: Google, Tesla. Follow-ups & Fall-out: FBI emails. Privacy: CitzenLab reports, Amazon, phones, Microsoft(?) Camera detectors. Laws & Regs - Canada: C-10. digital IDs. US: attack reporting, hack-back, NSO, Right to repair, Ohio v. FaceBook. World: No-Hack pact, UK Cloud providers, lawsuits. Standards: Patch Management, password rules. Defense: Cell-spam, smartphones, Duck-Duck, SugarCoat, Deepfakes, rookies, misconfigurations. Vulnerabilities, Zerodays: FatPipe, Windows. Mac. Other Vulnerabilities: Canadian passwords, Chips & firmware, ICS, IoT, GitHub/NPM, Azure AD, Chrome, Windows, Apple patch lag, LibreCAD, Blacksmith/Rowhammer, ETW attack, TOR fingerprints. Cybercrime: Trends, Nation States: Belarus, Iran, North Korea. Crime: crypto-klepto, mixers, Revil, election hacking. Other Risks: Quantum update, supply chains, dystopia & harassment, insiders, Chatbots, NFTs. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Learned; Covid Ugly; And more.
This Week's [in]Security - Issue 241 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: CHD Truncation rules, Holiday warnings, Costco skimmer, Contactless. New breaches: Indian Securities, Robinhood. New Ransomware: WordPress Plugin, MediaMarkt, Ronmor, Queensland. Major outages: DDoS, Citrix, Google, Follow-ups & Fall-out: ICS & OT incident costs, NL Health, SolarWinds, Maxim Health, TTC. Privacy: Microsoft, Meta/FaceBook, PrivacyRaven, Rollercoaster. Laws & Regs - Canada: 5G. US: Crypto sanctions. Hack-back, NSO suit. World: No-hack pact. Defense: Webinars, Webinars. New certifications, Playbooks, Trojan Source, ClusterFuzzLite. Vulnerabilities, Zerodays: Other Vulnerabilities: Beg Bounties, AMD, Palo Alto, AWS, Siemens, BusyBox, Patch Tuesday, Zoho. Legacy MacOS, Web Cache Poisoning, Cybercrime: Trends: FBI email takeover, Initial Access Brokers, techniques, phones, gmail, HTML smuggling. Nation States: US accused, Iran, Korea. Crime: Big ransomware crackdown, Pegasus arrest, DNA and faces. Other Risks: Shadow IT, Azure mistakes, IT/OT, QRL-jacking, Biometrics, Pets, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; And more.
This Week's [in]Security - Issue 240 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: Non-Compliance Lesson #2, Big FAQ update, PAX/WorldPay/FBI update, magecart. New breaches: Waiting for QC, Shooting the messenger, Surveillance, VPN users. New Ransomware: Evolving tricks, NL Health. Follow-ups & Fall-out: Missouri. Privacy: Phone metadata, tappigraphy, Data Privacy Protocol, 1B deleted facial images. Laws & Regs - Canada: Bill C-10, Ontario utility data, Citizen Lab. US: FISA, LEA requests, Spyware sanctions, Bounties. World: Threatening open source, Toothless fines? Standards: EU-US. Cyber labelling, Critical Infrastructure. Defense: Pwn2Own & SANS CTF, Simulation Game. Cloud VA, Security MVP, Bloom Filter Searching, ZeroTrust. Vulnerabilities, Zerodays: Other Vulnerabilities: CISA 300 patch list, APIs, More on Trojan Source, Web Assembly, Github & NPM supply-chain - coa, rc, Cisco SSH key, non-enterprise IoT. Cybercrime: Trends: Rootkits, password spraying, GitLab, Office & Exchange. Nation States. Crime: Anti-ransomware actions, SIM & BEC arrests, Squid-scam, fraud. Other Risks: Trolls, Ethical AI, Skynet? buzzwords, meta-FOMO, Open Source Risks, Cert meltdowns, Yahoo leaves China, economy. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Covid Compliance. And more.
This Week's [in]Security - Issue 239 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PAX/WorldPay/FBI investigation, PCI updates, Mobile Wallets. Digital & Crypto. New breaches: Hotels, Locations, emails, Portpass, NRA. New Ransomware: Free Decryptors, key reuse, A/D, Conti, BlackMatter, SEO poisoning, REvil, TTC, Blue Shield. Major outages, Follow-ups & Fall-out. Privacy: smartglasses. Laws & Regs - Canada, US: Cell phone locations, Cybersecurity disclosures, Right to repair, Ransomware payoffs, National Security bans, Social Media hearings. World: Proton Mail, GDPR evasion, EU DSA, Online Harms. Standards: NSA/CISA 5G & Cloud. Security baseline. NVD API, NIST Supply Chains, Trusted cloud, Defense: Digital life, Attack Surface, Teams, SolarWinds, Twitter MFA, AWS. Vulnerabilities, Zerodays: Windows LPE, Chrome. Shrootless, Other Vulnerabilities: Hardware, Apache, Apple, Wordpress, XP's still around, Fuji, WinRaR, Trojan Source, War-driving. Cybercrime: Trends: NPM, Nation States. Crime. Other Risks: 2022, economy, Meta7FB, time. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Impact; Covid Ugly; And more.