controlgap.com

Posts about:

[in]security (8)

This Week's [in]Security - Issue 228 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI SSF vs PA-DSS, Scoping Cloud, Cooperation, PCI Back to Basics Series, MageCart, Free Card Dump, No stripes. Big-Hacks: T-Mobile. New breaches: Accenture, Salesforce customers, Ford. New Ransomware. Follow-ups & Fall-out. Privacy: PGPP, Uber Surveillance, Politicians. Laws & Regs. Defense: Webinars, HTTPS first, Wiping Data, Passwordless Git, Fuzzing. Vulnerabilities: Windows, MS-ECC-spoofing, IoT non-randomness, Magento, 5G, Voting Machines, DNS. Cybercrime: Trends, Losses, Anti-AML, Office, Exchange, Flytrap, WordPress, Crypto heist? Nation States. Other Risks: Apple's Photo Scanning, Insiders, Disinformation, Bias, English to Code. Health, Safety & Environment: Covid election, Recalls, Wildfires, Heat, EV's. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Covid Ugly. And more.

Read More

This Week's [in]Security - Issue 227 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Community Meeting, Featured FAQs, PCI, MageCart, & JavaScript, Python PyPI library skimmer, Payment APIs. New Ransomware, Follow-ups & Fall-out. Privacy: Apple backdoor, Spotify, Facebook, Subscriptions. Laws & Regs: US: Repair, Stupid Patent, Copyright, Standards: 6 NIST announcements, Zero Trust, Cryptography, FIPS 198-1 HMAC, Retiring standards. Defense: Blackhat, Kubernetes, EU-Cybersecurity, Bitcoin monitoring, Vulnerabilities: Routers, IoT, Rust, HTTP/2, DNS, PwnedPiper, Blackhat, Hotels, VMWare. Cybercrime: Paragon, Pegasus, Word. Nation States: DeadRinger. Other Risks: Quantum simulation, Phishing AI, Handprints. Health, Safety & Environment: Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 225 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Card Production, Data Removal, Digesting PCI, Issuers. Fingerprint cards. New breaches: Saudi Aramco, Mexican voters, S3 service provider bucket, Denials and False breaches. New Ransomware: trains, suppliers, Major outages: Akamai. Follow-ups & Fall-out: Named and Shamed, Insurance restrictions, Audi, Kaseya, Privacy: Data brokers. Laws & Regs: Right to be Forgotten. Pipelines, Right-to-repair, Web-scraping. India's platforms, EU Crypto. Cybersecurity Career Awareness, AES Review, Lightweight Crypto Final, NIST. Defense: Backups, browsers, trackers, Tools, Russia's Firewall. Vulnerabilities: Print Drivers, SeriousSAM/HiveNightmare, PetitPotam, Linux "Sequoia", Telegram. Cybercrime: Pegasus Spyware, Trends: NPM Password Thief, MosaicLoader, Discord, Nation States: China, Crime. Homoglyphs, DNA, Swatter, Twitter, flattened-miners, ID Theft Scumbags. Other Risks: AI, Disinformation for Hire, Cloud ICS, Expired Domains, MLB Sign stealing. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Covid Ugly; Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 224 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Major-events: REvil goes dark, Kaseya. New breaches: Guess. New Ransomware: EA, D-Box, Campbell Conroy & O'Neil, Revelstoke. Follow-ups & Fall-out: Spin, Interpol, Tracking, Rebuilding. Privacy: Clearview AI, Scraping. Laws & Regs: Ransomware Response, Reward, Repair, Zero Day Hoarding. Defense: Tracker blocking, HTTPS-first, RDP, Talent, Quantum error correction & supremacy. Vulnerabilities: Browsers, SolarWinds, Commercial spyware, WordPress WooCommerce, Cloudflare, More Print Spooler, Windows Hello, D-Link, SonicWall, Elevators. Cybercrime: Trends. Nation States. Crime. Other Risks. Health, Safety & Environment. Ontario Tornados, Covid-19: Spread, Curves, Waves, and Variants. And more.

Read More

This Week's [in]Security - Issue 223 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Major incidents: Kaseya/REvil! New breaches: Morgan Stanley, CAN, Marsh McLennan, Mint Mobile, The GOP. New Ransomware: Iran. Follow-ups & Fall-out: Probes, Dumps, New fines, Settlements. Privacy: Alexa, Job Applications, SPAM. Laws & Regs - Canada: C-10, cyberlaw series. US: Right-to-repair. The world: EU Surveillance, China Privacy, Twitter liability, Legal Theater? Standards: NIST, FIDO. Defense: Webinars, 2020 attack methods, Internal threats, DoH-eh, database auditing. Vulnerabilities: PrintNightmare, Kaspersky Passwords, Sage X3, Quantum KD. Trends, Nation States, Crime, Other Risks: Chime Banking App, Windows 11. Health, Safety & Environment: Surfside, Heatdome. Covid-19: Spread, Curves, Waves, and Variants, Response, Immunity, Learned, Impact, And more.

Read More

This Week's [in]Security - Issue 222 | insecurity | Control Gap

Welcome to This Week’s [in]Security. DSSv4 RFC, PINv3 FAQ. New breaches: AIG, Raychat, LimeVPN. New Ransomware: Kaseya! Follow-ups & Fall-out: Linkedin Scraping, Microsoft, Capital One. Privacy: Inuit, Used IoT, Facial Recognition, Laws & Regs - Canada: C-10, New Ontario Privacy Law, Cyberlaw. US: Census Privacy, Secret Orders, Crypto proposal, Legal search. The world, Standards: NIST. Defense: Vulnerabilities: ZeroDay: WD My Book, PrintNightmare. Netgear, Adobe, ICS, Edge, Powershell, KVM breakout, Cloud Hijack. Cybercrime - Trends: Nation States. Crime. Other Risks: cyber-insurance, Stunt driving, Residential Schools, Win11. Health, Safety & Environment: Cholera, Malaria, sleep apnoea, back pain, heatwave, accessible EVs? Covid-19: Spread, Curves, Waves, and Variants, Response, Immunity, Learned, Impact, And more.

Read More

This Week's [in]Security - Issue 221 | insecurity | Control Gap

Welcome to This Week’s [in]Security. DSSv4 RFC, HSM RFC, WFH, Sunsets, 3DS, ATM vuln & Shimming. New breaches: Mercedes-Benz, APNIC. New Ransomware: FCUK. Follow-ups & Fall-out: Regulation & Breaches, SolarWinds, Colonial Pipeline. Privacy: Medical Data, Doorbells, Cookies/FLOC. Laws & Regs - Canada, US, The world, Standards. Defense: Webinars, Webinars. Einstein, D3FEND. Vulnerabilities: Stale Dependencies, Letting one slip by, DNS, BIOS, Vmware, Linux, SonicWall, Cybercrime - Trends: My Book, USB, Nation States. Crime. Most-Wanted. Other Risks: Job loss, Water Supplies, AI, Chips, Remote working, e-Proctoring, McAfee, Windows 11. Health, Safety & Environment: 751 more children, Condo Collapse. Covid-19: Spread, Curves, Waves, and Variants, Response, Immunity, Learned, Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 220 | insecurity | Control Gap

Welcome to This Week’s [in]Security. DSSv4 timelines. Magecart. New breaches: CVS, Carnival Cruises, Wegmans. New Ransomware: G7 vs. Russia, Bitcoin?, ICS Software, Nukes, source released. Major outages: Puerto Rico, Follow-ups & Fall-out: Avaddon quits, 5B records, Lessons learned, US fines. Privacy: Trusting VPN providers, Pseudonymity, Phones, Cartoon App. Laws & Regs - Canada: Copyright. US: Web Scraping, DPA, Facial recognition, Section 230, Massachusetts and Google app installation. The world: Crypto-wars, USA-EU, Compelling Passwords, Apple-EU. Standards: NIST & NSA. Defense: MFA list, Supply chain, ScriptWatch, Free book. Vulnerabilities: Chrome & Apple ZD, Utility Sector, Cisco, Linux, Defibrillators, Peleton. FPE weaker, 2G/GPRS backdoor. Cybercrime - Trends: Vigilante malware? PDFs, SEO poison, Google Docs, Fake cryptocurrency devices, Ransomware ops, Nation States. Crime. Other Risks: Undersea cables, email risks, BadBots, Win10 EOS, Mainframes. Health, Safety & Environment: Bio-labs, Makeup, Pollution, More mRNA, Smart meters, Tesla crashes, Extremism. Covid-19: Spread, Curves, Waves, and Variants. Response, Vaccine passports, Borders, Immunity, Delta & Gamma, Canada, Learned, Covid Ugly. And more.

Read More

This Week's [in]Security - Issue 219

Welcome to This Week’s [in]Security. e-commerce security: PCI, Magecart, & the DOM part 1. New breaches: Windows passwords, Pipeline#2, VW, EA games, Mc Donalds, Self-breached? New Ransomware: Exit plans & Lawyers. Major outages: Failing Fastly. Follow-ups & Fall-out: Infographic & analysis, Recouped Bitcoins, Humana suit, JBL meat pays out, MoviePass. Privacy: Cookie banners, Forget my face, Floc, Bitcoin Anon, Apple, WhatsApp. Laws & Regs - Canada: RCMP, More C-10. US: Tiktok, HIPPA, Disclosure, Hacking back. The world: Antitrust, Misuse. Standards: NIST OSCAL, drafts, extensions. Defense: Software Design, Supply Chain, Deepfakes, Slander, HIBP, Fellowships. Vulnerabilities: MS, IE RIP, Chrome, Intel, Adobe, Polkit, ALPACA, Bloodhound, Weapons, Quantum. Cybercrime - Trends: 5 Attacks, Nation States. The An0m sting, Crime. Misconduct, Tricky. Other Risks: Health, Safety & Environment: Alzheimer's, CO2. Covid-19: Spread, Curves, Waves, and Variants. Response, Immunity, Donating Vaccines, Learned, Impact, Covid Ugly. And more.

Read More