controlgap.com

Posts about:

NIST (4)

This Week's [in]Security - Issue 190 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PIN Requirement Future Date Changes. FAQ Update. Magecart. Cardbreaches. New breaches. New Ransomware. Facial Recognition. Right to be forgotten. NIST. MFA. Deepfakes. @New Tools. Pluton. New free CA. Encrypt only. New browser. LidarPhone. Cyber AI. AWS. ICS. Cisco. Citrix. Oldies. Tesla. Fixes. Trends. Nation States. Legal actions. Health, Safety & Environment. Covid-19: Spread, Curves, Spikes, Waves, & reinfections. Contact Tracing. Vaccine Progress. And more.

Read More

This Week's [in]Security - Issue 189 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PTSv3 Expiry. POS malware. New breaches (150M+) New Ransomware. Zoom. NIST. Elections. DNS Cache Poisoning. Intel SGX. Chrome zero-days. Wordpress. Nation States. CyberSkils. Health, Safety & Environment. 30+ Hurricanes. Covid-19: Spread, Curves, Spikes, Waves, & reinfections. Contact Tracing. Vaccine Progress. And more.

Read More

This Week's [in]Security - Issue 182 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Draft DSS v4 RFC. Breach Reporting. New breaches: XP Source. Bing. Shopify. Spots. games. Airbnb. New Ransomware. Autonomous Indoor Drone? Facial Recognition. Taxing Tech. NIST Updates, Drafts & Workshops. YAYA and Chronicle Detect Threat Hunters. IoT. CBC Encryption. Russians hacking Russians. Arrests, Charges & Sentencings. Election Security. Phishing awareness fail. Homework fraud. Pastebin. Hurricane names. Medical AI. brain-computer interfaces. Near misses. Covid-19: Spread, Curves, Spikes, Waves, & reinfections. And more.

Read More

This Week's [in]Security - Issue 174 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Twitter Hack Week 3 arrests. Covid-19: Spread, Curves, Spikes & Waves. Lockdown, Reopening, & The New Normal. Vaccine Progress. More of the Good, Bad, and Ugly. DSSv4. CPoC and SPoC updates. SSF Update. POS Malware Alert. Mag-stripes. New breaches: Zello, LG, Xerox, Source Code Gigaleak. Ransomware: Garmin, Pivot Tech. HIBP gets 50M+ accounts. Breach costs. Contact tracing. Facial Recognition. GDPR. Stingray Drones. War on Crypto Updates. CitizenLab. Fair use. Forensic Software. Multiple NIST Updates. Blackberry. Big-tech Scrutiny. Quantum. Black Hat. Supply Chain Attack Survey. 0-day Root Causes & detection. BootHole. Wordpress RCE. Magneto RCE. Zoom. More ICS risk. Cisco bugs. Halt and catch fire for real. Tor. Multiple FBI warnings. IoT. Deepfake scam. Malware auction. Events-based Controls. Toronto. Fake News & Disinformation. Espionage. And more.

Read More

This Week’s [in]Security – Issue 159 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: COVID-19 update: stats live, Wuhan stats updated, infection hotspots, sewage early warning, reopening, conspiracies and threats, hacking researchers, virus sniffer dogs, vaccines including measles vs COVID. Surveillance law expired? Vulnerability Priority Rating vs CVSS. ISP BGP security. Zoom's DIY crypto. Rewards for cyber-spies. More zoom-bombing. Russia vs SFO. Domestic Terrorism. Opioid alternative. Hot Qubits. And more.

Read More

This Week’s [in]Security – Issue 157 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Trending: The great mask debate. Other PPE. The spread and curve. Projections. Responses. Behaviour - the good, the bad, and the ugly. Magecart. Breaches: Key Ring, Marriot (again), Dueling Network, Redis, Zoom. Equifax post-mortem. WFH and privacy. Zoom privacy. DHS biometric db. Meme privacy. EARN-IT. FISA abuse. Wi-Fi 6E. NIST updates and events. COVID Treatments, Innovation, Vaccines. In the water? Gearing up. More DoH. And More.

Read More

This Week’s [in]Security – Issue 148 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Recent Wawa breach hit 30M cards. PCI and NIST updates. Wuhan coronavirus updates and other diseases. The new ransomware. Breaches at Sprint, NEC, Trello, the UN, PIH, SpiceJet, and Cineplanet. The briefest leak. Equifax's $1B security bill. Collating Hacked Data. Modern Mass Surveillance. Privacy violations by Avast and Ring (nicky nicy nine trackers?). Facebook OS? Facial recognition and smart camera networks. Tool shows what third party sites tell Facebook. Data Privacy Day. $550M Facebook fine. Warrantless search law. Do PCI and CCPA align? War on encryption. Banning ransomware payouts? IoT Security Regs. NIST updates.Fighting ransomware. Firmware attacks and patches. Attacking factories. Airport insecurity. Sonos blinked. Hunting down ransom groups. NFL social media hijack. Sim Swapping Uping cyber-prosecutions. Fake news is very potent. Tech pushing Opiods. Audio deepfakes. Drones Border Security. And more.

Read More

This Week’s [in]Security - Issue 145 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Online Skimming and PCI. CheckPeople.com breach. Ransomware and Password Theft. DNA collection. Apple vs. FBI Round 2, NIST IoT, Password blocking. Correcting misinformation. Practical SHA-1 attack, Critical Firefox, Citrix ADC, WebEx, and CableHaunt. An ancient AV archive bug. ToTok controversy. Ontario Healthcare risks. Iranian malware and powergrids. Supply chain DoS. Tricky Phishing. Hacking laws with SQL. Ask Why! Another nuclear false alarm. Deepfakes and lies. Australian wildfires. Emoji liabilities. Measles deaths. Gaining Trust. Disturbing AI. And more.

Read More

This Week’s [in]Security – Issue 130 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: Big changes coming in PCI updates to DSS, P2PE PA-DSS/SSF. First PCI SPoC solutions. New Control Gap service offerings. New Magecart tactics. Breaches: 400M medical records, DoorDash. Breach updates on Dunkin, CafePress. 69K Facebook apps suspended. NIST privacy and zero trust. GDPR and Blockchain. California's privacy law. Right to be forgotten. Forensic transparency. Cost of fraud. Malicious RDP. Blocking malicious attachments. Ransomware tools. Pen-testers redirected to FBI site. Vaccines. Quantum milestone. Trade tools. Youtube 2FA bypassed. Visualizing an APT. New widespread SIM card attack. Fighting deep-fakes. And more.

Read More

This Week’s [in]Security – Issue 118

Welcome to This Week’s [in]Security. This week: Major update on PCI SSF and SLC standards, Magecart, POS malware, ATM shimmers, 300M EA Games breach, Attunity AWS breach, Desjardins insider breach, cloud breaches at PCM, Fujitsu, Tata, NTT Data, Dimension Data, CSC and DXC, 10 years breached Equifax CIO jailed, everyone's spying: NSA, MySpace, and Spanish Scoer League, ballot security, NIST IoT, NTS (Secure Time), DoH, Huawei full of holes, NASA Pi hack, 10 years vulnerable, multiple nation-state hacks, more ransomware, multiple crypto-currency frauds and hacks, USB-sniffing dogs, Perception gaps, Boeing's terrible week, logic puzzles, the world's largest human Maple Leaf, and more.

Read More