controlgap.com
Posts about:
COVID-19
This Week's [in]Security - Issue 253 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: Target's anti-skimmer Merry Maker, Segway. Payments, Training & events. New breaches: Securitas (S3), News Corp, Whisper. New Ransomware: Changing tactics, Oiltanking, Kronos. Follow-ups & Fall-out: Equifax. Privacy: GPU-fingerprinting, Ungoogling yourself. Laws & Regs - Canada: C-11/streaming, Online harms, Digital Taxes. US: EARN IT, Cyber Review board, EFF. World: EU vs. US. Standards: NIST Software, IoT, &, Security Labeling. NVD API. Defense: volunteers, browsers. Vulnerabilities, Zerodays: Zimbra. Other Vulnerabilities: CISA alerts, Log4shell lives on, Firmware, Cisco, ESET, Supply chains, MSIX, Finding Open Source vulns, Walmart analyzes new ransomware. Patching: CISA must patch, Samba. Crypto-research. Cybercrime: Trends: Reverse proxy attacks, Nation States: taking down North Korea, China, more spyware, Ukraine. Crime & Enforcement; fraud & blackmail, big heists, drones, Other Risks: Automation. Banning ideas. App monopolies, too many secrets, Internet next, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Learned; Covid Ugly; Innovation and more.
This Week's [in]Security - Issue 250 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: Card Production. Carders. Training. New breaches, New Ransomware: bankruptcy, jail, DDoS. Major outages, Follow-ups & Fall-out: Lawyers vs Insurance, Accellion, Maryland. Privacy: Apple Private Relay. Laws & Regs - Canada: location data. US: DMCA, Carrier breach rules, DeFi, Facebook anti-trust, Celebrities sued. World: Europol, GDPR & Tech, China & tech. Standards: NIST drafts, Randomness. Defense: Protecting Open Source, Blocking stingray, ICS Security, C-Level, CSSLP. Vulnerabilities, Zerodays. Other Vulnerabilities: WordPress, React & NPM, MacOS, Defender, Patching: CISA must patch list, Adobe, AWS, Cisco. WordPress, L2TP. cryptography, Cybercrime: Trends: Self-inflicted, Multi-OS backdoor, Beware USB sticks. Nation States: Spyware for hire, Russia v Ukraine. Crime & Enforcement: Revil Arrests, Ukrainian arrests, Crypto theft. Other Risks: Great Resignation, QR fakes, Real war? Sowing division. Health, Safety & Environment: Tsunami, Tesla, Sharks, Wild-fires. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Innovation and more.
This Week's [in]Security - Issue 249
Welcome to This Week’s [in]Security. Skimmers, Training, Payments. Big-Hacks: Log4shell, EOL impediments, prevention, Log4-like vulns. New breaches: DatPiff, FlexBooker, Uscellular, McMenamins, healthcare. New Ransomware, Follow-ups & Fall-out. Privacy. Laws & Regs – US, World, Standards. Defense: cryptography, zero-day-repository, anti-extremism. Vulnerabilities, copied commands, Y2K22, android, vm ware, Bluetooth crypto. Cybercrime - Trends: Malsmoke, BadUSB, cyber-mercenaries, fake shut-downs. Supply chain sabotage. Nation States. Crime & Enforcement. Other Risks: Norton crypto-miner inside, Signal, AI & algorithms, false-positives. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Impact; Covid Compliance. Innovation and more.
This Week's [in]Security - Issue 248 | insecurity | Control Gap
Welcome to This Week’s [in]Security. Big-Hacks: Log4J, new RCE, the long road. New breaches: T-Mobile, Redline Stealer, Lastpass. New Ransomware: Saskatchewan, Norway, Shutterfly, Law Enforcement. Major outages: Backup Failure. Privacy: Spying toys, EFF's 2021. Laws & Regs - US: Missouri, Morgan Stanley. World: India. Defense: Krebs, TLS deprecates SHA1 & MD5. Vulnerabilities, Netgear, MS Exchange Y2K22 bug. Cybercrime: Trends: 2fa interception, Galaxy store, SSDs, Online courses. Nation States: Hackers-4-hire, Poland. Crime & Enforcement: Butter? Other Risks: Science, Cyber-due-diligence, ANOM, Blackberry EOL, Double Fake NFTs. Health, Safety & Environment: Alexa lethal challenge. Fireworks, winter driving, recall, 5G, Satellites. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Impact; Covid Compliance. And more.
This Week's [in]Security - Issue 247 | insecurity | Control Gap
Welcome to This Week’s [in]Security. Big-Hacks: More log4shell. New breaches: Azure, Hellman. New Ransomware: terrorism? Inetum. Major outages: AWS. Follow-ups & Fall-out: HIPB adds near 1B passwords. Privacy: Eye-tracking. Laws & Regs - Canada: digital law, AI. US: tech lawsuits. World: Judgements & fines. Standards: NISTR draft. Defense: fighting scams, browser enhancements. Vulnerabilities, Other Vulnerabilities: Multiple-MS, WordPress plugin, VoIP backdoors, 7% pass, IoT honeypot, crypto-research. Cybercrime: Trends: top 5 scams, andrioid, powerpoint. Nation States: NSO group, Zoho. Crime & Enforcement: crypto returned, SEC filings. Other Risks: 5G & aircraft, Juice jacking, Human behavior. Innovations & Inventions: quantum, lickable screens. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Changing restrictions, Treatments; Rapid-Tests, Immunity; New Vaccine type. Learned; Omicon, Covid Ugly; Covid Compliance. And more.
This Week's [in]Security - Issue 246 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: FAQ, HSM. Magecart, Sportsgear, ATMs, PAX. Supply-Chain Backdoors: Log4J/Log4shell continues! Underfunding! New breaches: Scraping, Finite Recruitment, ProTemps, GumTree. New Ransomware: Kronos, Virginia, logistics, medical. Major outages: AWS. Follow-ups & Fall-out: schools, delays, Desjardins settles. Privacy: Staying signed in. Laws & Regs - Canada: Repair, Harms. US: Data Protection, National Security, Chinese Tech, Takedowns. World: trade disputes, Japan, UK, EU. Standards: NIST drafts. Defense: Webinars, bans, Bug bounties, Internet Hall-of-Fame. Vulnerabilities, Zerodays. Other Vulnerabilities: chips, Ubuntu, Dell, Firefox, Adobe, Apple, Chrome, and MS. ECDSA keys. Cybercrime: Trends, log-ins, Contact Forms, Anubis, Seedworm. Nation States. NSO, Huawei, Nobelium. Crime & Enforcement. Obit pirates, Arrests, Assassins. Other Risks: Data life cycles, AI diagnosis, Shadows, Printers, virtual assault, crypto currency. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Impact; Covid Ugly; And more.
This Week's [in]Security - Issue 245 | insecurity | Control Gap
Welcome to This Week’s [in]Security. Log4J/Log4shell! PCI and payments: PCI updates: PIN, SSF. Non-Compliance Lesson No.3. Magecart, Supply-Chain Backdoors: New breaches: Kafka. Volvo. New Ransomware: Follow-the-money, Cybercommand, Utilities, Healthcare, SPAR stores. Major outages: Amazon. Follow-ups & Fall-out. Privacy: Tor, surveillance capitalism, facial recognition. Alexa can you keep a secret? Laws & Regs - Canada: website blocking, JusTech. US: Copyright takedowns. World: Espionage tools, Botnet lawsuit, Assange. Cybercriminal Court? Standards: Cyber-resilience. testing. IPv6 transition. Defense: Cyber & the board, AI, Smishing, pirates. Vulnerabilities, Zerodays. Other Vulnerabilities: HTTP-no- S, Home grown, Chrome, Win/URI, WD SanDisk, SonicWall, MikroTik, Bluetooth, factoring. Cybercrime: Trends, Phising. WordPress, npm. Moobot. Nation States. Crime & Enforcement. Other Risks: AWS, Quantum, BurnOut, Tor, Kids, Cryptominers, AirTag abuse. Health, Safety & Environment. CO2 capture, batteries, nukes. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Impact; Covid Compliance. And more.
This Week's [in]Security - Issue 242 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: Magecart, Jackpot. New breaches: IAB's, Indian Securities Depository, Stripchat, RobinHood, RedDoorz, IDC, Ducks Unlimited, GitHub/Firefox-Linux. New Ransomware, holidays, trends, analysis, response. Major outages: Google, Tesla. Follow-ups & Fall-out: FBI emails. Privacy: CitzenLab reports, Amazon, phones, Microsoft(?) Camera detectors. Laws & Regs - Canada: C-10. digital IDs. US: attack reporting, hack-back, NSO, Right to repair, Ohio v. FaceBook. World: No-Hack pact, UK Cloud providers, lawsuits. Standards: Patch Management, password rules. Defense: Cell-spam, smartphones, Duck-Duck, SugarCoat, Deepfakes, rookies, misconfigurations. Vulnerabilities, Zerodays: FatPipe, Windows. Mac. Other Vulnerabilities: Canadian passwords, Chips & firmware, ICS, IoT, GitHub/NPM, Azure AD, Chrome, Windows, Apple patch lag, LibreCAD, Blacksmith/Rowhammer, ETW attack, TOR fingerprints. Cybercrime: Trends, Nation States: Belarus, Iran, North Korea. Crime: crypto-klepto, mixers, Revil, election hacking. Other Risks: Quantum update, supply chains, dystopia & harassment, insiders, Chatbots, NFTs. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Learned; Covid Ugly; And more.
This Week's [in]Security - Issue 241 | insecurity | Control Gap
Welcome to This Week’s [in]Security. PCI and payments: CHD Truncation rules, Holiday warnings, Costco skimmer, Contactless. New breaches: Indian Securities, Robinhood. New Ransomware: WordPress Plugin, MediaMarkt, Ronmor, Queensland. Major outages: DDoS, Citrix, Google, Follow-ups & Fall-out: ICS & OT incident costs, NL Health, SolarWinds, Maxim Health, TTC. Privacy: Microsoft, Meta/FaceBook, PrivacyRaven, Rollercoaster. Laws & Regs - Canada: 5G. US: Crypto sanctions. Hack-back, NSO suit. World: No-hack pact. Defense: Webinars, Webinars. New certifications, Playbooks, Trojan Source, ClusterFuzzLite. Vulnerabilities, Zerodays: Other Vulnerabilities: Beg Bounties, AMD, Palo Alto, AWS, Siemens, BusyBox, Patch Tuesday, Zoho. Legacy MacOS, Web Cache Poisoning, Cybercrime: Trends: FBI email takeover, Initial Access Brokers, techniques, phones, gmail, HTML smuggling. Nation States: US accused, Iran, Korea. Crime: Big ransomware crackdown, Pegasus arrest, DNA and faces. Other Risks: Shadow IT, Azure mistakes, IT/OT, QRL-jacking, Biometrics, Pets, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; And more.