controlgap.com

Posts about:

NIST (3)

This Week's [in]Security - Issue 219

Welcome to This Week’s [in]Security. e-commerce security: PCI, Magecart, & the DOM part 1. New breaches: Windows passwords, Pipeline#2, VW, EA games, Mc Donalds, Self-breached? New Ransomware: Exit plans & Lawyers. Major outages: Failing Fastly. Follow-ups & Fall-out: Infographic & analysis, Recouped Bitcoins, Humana suit, JBL meat pays out, MoviePass. Privacy: Cookie banners, Forget my face, Floc, Bitcoin Anon, Apple, WhatsApp. Laws & Regs - Canada: RCMP, More C-10. US: Tiktok, HIPPA, Disclosure, Hacking back. The world: Antitrust, Misuse. Standards: NIST OSCAL, drafts, extensions. Defense: Software Design, Supply Chain, Deepfakes, Slander, HIBP, Fellowships. Vulnerabilities: MS, IE RIP, Chrome, Intel, Adobe, Polkit, ALPACA, Bloodhound, Weapons, Quantum. Cybercrime - Trends: 5 Attacks, Nation States. The An0m sting, Crime. Misconduct, Tricky. Other Risks: Health, Safety & Environment: Alzheimer's, CO2. Covid-19: Spread, Curves, Waves, and Variants. Response, Immunity, Donating Vaccines, Learned, Impact, Covid Ugly. And more.

Read More

This Week's [in]Security - Issue 217 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI: SLC v1.1, Sunsetting P2PE v2 and PA-DSS. MasterCard resources. Control Gap SSA & SSLC. Magecart mobile, Carders. New breaches: Japanese Dating & government, Canada Post, Nukes, Dominos India, Hospitals, Compound redaction leak, New Ransomware: RCMP, Defensive shutdown. Privacy: Facial Recognition, Hiding controls. Laws & Regs - Canada: C-10 impact. US: Breach law. The world: Mass Surveillance, Data residency. Standards: NIST: Cloud, IoT/MuD. USB-C upgrade. Defense: Webinars, Webinars. Pipeline response, Cyber budgets, Unknown-unknowns, FBI supporting HIBP.

Read More

This Week's [in]Security - Issue 212 | insecurity | Control Gap

Welcome to This Week’s [in]Security. P2PE Solution Aid. More on 8-digit BINs. Supply-Chain Backdoors: CodeCov, Passwordstate, Solarwinds. New breaches: Facebook, Apple(?), ClearVoice. New Ransomware: Follow-ups & Fall-out: Privacy. Normalizing breaches. Floc Adverse. Laws & Regs: Canada: Bills C-10 & 11, regulating apps. US. UK, EU, HK. NIST iOT & ICS. CISv8. Defense: More Nation-State Patching, Moxie vs Cellebrite, Death to IoT, Passwordless, Mario and DevSecOps!? Vulnerabilities: Pulse, Chrome, SonicWall ZeroDays, Supply-chains, CyberGames, Clubhouse, Air-Drop, Docker Images, QNAP, Tesla. Updatable Encryption. Breaking Enigma. Cybercrime: Trends: TLS, QR, Sextortion, Ads, 7-Zip, ToxicEye, Pink, Fake DirectX12. Nation States. Crypto-skimming. Crime. Other Risks: Unethical patching, Social Media, Chips, Deepfake geography, Bounties, Resets, No bars! Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. Response. Immunity. Covid Ugly. Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 210 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI 3DS, New e-skimmers, Card breaches. EU's SCA. Big-Hacks: Facebook, Linkedin. New breaches: Clubhouse, Q Link Wireless. New Ransomware. Follow-ups & Fall-out. Privacy: Big Brother? Xcinex Venue. Laws & Regs: Bans, Breach law, Facial recognition, NIST & Hippa. Defense: Tools, Simplification, Resilience. Vulnerabilities: Cisco zeroday, Pwn2Own, SAP, Zoom, Carbon Black, Domain Time II, Moodle, medical devices, 802.11bf sensing. Cybercrime: Trends. Gigaset, Nation States. Cyber-war? Other Risks. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. The Good, Bad, and Ugly (Behaviour). And more.

Read More

This Week's [in]Security - Issue 208 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI Updates: PTS FAQ, PIN 3.1, QSA Program. Big-Hacks: Exchange, SolarWinds, F5, Accellion. New breaches: New Ransomware: Follow-ups & Fall-out: Amazon sued. Privacy: Facial Recognition. Laws & Regs: Facebook sued, Section 230, Breach Disclosures, Location Tracking Guidelines, NIST. Defense: Isolate IoT, Tools, Browsers. Vulnerabilities: Android, iOS ZeroDay, Apple iOS. ColdFusion, NetMask code, Android, Wordpress. Arresting the messenger? Cybercrime: Trends. Account Takeovers. Other Risks: Disinformation, IoT Weapons, PII a Risk, Autopilot, Grid, Shipping, More NFTs, Win95, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. Immunity, Vaccines, and Vaccination. The Good, Bad, and Ugly (Behaviour). And more.

Read More

This Week's [in]Security - Issue 203 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Texas Disaster. News/Link Taxing. More SolarWinds. SLC Update. PINs vs. Passwords. Skimmers. New breaches: CRA lockout. New Ransomware. Location. Tracker Pixels. NIST. Zero-Day. Routers. OpenSSL. Big Mac Attack. Trends. Buy-to-infect. Scams & Fraud. Nation States. Arrests, etc. AI. Misinformation. CRISPR. Quantum Fail. Serial Killers. Health, Safety & Environment. H5N8. Covid-19: Spread, Curves, Spikes, Waves, & reinfections. New Variants. Impact. Immunity, Vaccines, and Vaccination. Disinformation. The Good, Bad, and Ugly (Behaviour). And more.

Read More

This Week's [in]Security - Issue 202 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI HSM Update RFC. Vampire Skimmer. New breaches: New Ransomware. Encryption and Breaches. SolarWinds. NIST. Zero Days. Defender. Drivers. TCP Stacks. SAP. SonicWall. WordPress. SuperMicro. Trends. Water Plant Hack. Nation States. Supply-Chain Attack. Arrests, etc. SIM Swappers. AI Manipulators. Ambivalence. Health, Safety & Environment. Covid-19: Spread, Curves, Spikes, Waves, & reinfections. New Variants. Immunity, Vaccines, and Vaccination. The Good, Bad, and Ugly (Behaviour). And more.

Read More

This Week's [in]Security - Issue 201 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Magecart. New breaches: New Ransomware. Spotify. NIST. Attack the AI. Lego? Free book. Patching! Open Source. Easy Hacking. A year of zero-days. IoT. Libgcrypt. Chrome and Google's bad week. SolarWinds. Quantum. Wi-Fi. Trends. VMware. Supercomputers. Chrome. Perl. SonicWall. Infinite Coffee. Nation States. Arrests, etc. AI Job Screeners. Moderating Speech. US vs Hackers. Peloton. Capitol Tracking. Quantum. Election Security. Chucky Alert. Day Traders. Health, Safety & Environment. New Variants. Immunity, Vaccines, and Vaccination. And more.

Read More

This Week's [in]Security - Issue 200 | insecurity | Control Gap

Welcome to This Week’s [in]Security. SIGS. FAQ. New breaches: 220M, GOAT Breach? UScellular. EU. Mensa. New Ransomware. SkipTheDishes. Remote Proctoring. Facebook Oversight Board. catfishing. Credential Stuffing Liability. Crypto-wars. NIST&ISO. Pwn2Own. BlastDoor. Sudo. Flash Reflux?? Libgcrypt. WordPress Popup Builder. TikTok. Fuji HMI. ADT. Deepfakes. PrusaSlicer. NAT Slipstreaming. Trends. Ghost Accounts. Realtime Phishing. SolarWinds. Nation States. Arrests, etc. Netwalker. Disrupting Emotet. Influence Operations. Twice Victimized. Big Data. Bulletproof TLS. Health, Safety & Environment. GameStop. Covid-19: Spread, Curves, Spikes, Waves, & reinfections. New Variants. Impact. Immunity, Vaccines, and Vaccination. And more.

Read More

This Week's [in]Security - Issue 195 | insecurity | Control Gap

Welcome to This Week’s [in]Security. SolarWinds. Carders Shut. New breaches. New Ransomware. Contact tracing. Facial Recognition. NIST. APIs. Signal. Zero Days. DNS Poison. Quantum. Trends. Arrests, etc. Baloney Detection. Cheating. Deepfakes. Neurotech. Health, Safety & Environment. Covid-19: Spread, Curves, Spikes, Waves, & reinfections. Vaccine Updates. And more.

Read More