controlgap.com

Posts about:

IoT

This Week's [in]Security - Issue 253 | insecurity | Control Gap

Read More

This Week's [in]Security - Issue 244 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI and payments: Participating brands FAQ, and 8 updates. Magecart/skimmers, Brazil, Square. New breaches: Panasonic, Planned Parenthood. New Ransomware: Critical Infrastructure, Rideau Hall. Major outages, Follow-ups & Fall-out: Gravatar HIPB. Privacy: De-anonymization. Laws & Regs - Canada: health data, Huawei. US: FBI access, TSA, SEC, Biometrics. World: Product Security, Algorithm Transparency. Standards: NIST IoT, CISA mobile. Defense: Spam calls, AI understanding, Facial fuzz, attack maps, DRP, Old tech, Faraday cages. Vulnerabilities, Zerodays: Windows. Other Vulnerabilities: Printers, Routers, NSS Crypto, XS-Leaks, Passwords, zoom, Azure Sphere, Cloud Honeypot, CISA Hitachi & Zoho, Verizon. Cryptography HKDFs, PQC signatures & performance, Quantum Computing. Cybercrime: Trends, NABs, Trojans, AT&T, WRITE, Excel Addins. Nation States: diplomats, air-gaps, fake recruiters. Crime & Enforcement. Other Risks: Cyber-insurance exclusions, long game, China, misinformation, Meta/FB, amplification, shopping bots, Edge, Food, Hype? Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Learned; And more.

Read More

This Week's [in]Security - Issue 234 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI and payments: Remote assessments, magecart. New breaches: Thai visitors, Event Builder, Exchange. New Ransomware: Alert, Exabyte. Major outages: voip.ms, Trello. Follow-ups & Fall-out: Revil FBI Sting & backdoor cheat, Epik. Privacy: Amazon, Ant, creepy? QR, ewwww! Laws & Regs: Canada: US: Infrastructure, Facebook, Warrants. World: China bans crypto, Huawei, USB-C. Standards: CISA IPv6, NIST drafts. Defense: SSNs, AppSec, Quad, Ransomware action, Medical IoT, passwordless, tools, Cyber-insurance, Autodiscover, Bug bounties. Vulnerabilities, Zerodays: record zerodays, IoT, IoS, MacOS. Chrome. Other Vulnerabilities: OWASP update, API credentials, Ryzen, hack a mainframe demo, OpenOffice, Cisco, smartphones, Nagios, VMware. SonicWall, Routers, ROT13-NG. Cybercrime: Trends: Nation States. Crime: Mafia, DeFi, undone. Other Risks: Quantum Risk, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Impact; Covid Ugly; And more.

Read More

This Week's [in]Security - Issue 230 | insecurity | Control Gap

Welcome to This Week’s [in]Security. SSF faqs, firewalls, Storing CVV. New breaches: Microsoft Power Apps: IndiaMart, Imavex. New Ransomware: Ragnarok shutdown, FBI alerts. Major outages: Record DDoS, TSYS, OneDrive. Follow-ups & Fall-out: T-Mobile, Poly, SubaGames, Eatigo. Privacy: WFH surveillance. Laws & Regs: Canada: Online harms. US: non-competes. CSP troll, Chinese Tech. Standards: NIST. Defense: Webinars, Webinars. Supply-chain. Vulnerabilities: Unitrends zero-day, Medical IoT, Windows 10, F5 BIG-IP, SSL VPNs, OpenSSL, SNI, Cosmos DB, Confluence, Glowworm. Cybercrime: Trends: Nation States. Crime. Other Risks: Tech-hype, Voting Systems, Fooling AI. Health, Safety & Environment: Zoom fatigue. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Impact; Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 229 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Big-Hacks: T-Mobile. New breaches: Terrorist Watchlist, US census, Baby monitors and cams, Chase, HVAC as a vector, New Ransomware: State Department, Brazil. Major outages: Pakistan. Follow-ups & Fall-out: Colonial, Blackbaud, Pearson. Privacy: FB. Laws & Regs: Canada: Copyright. US: LEA data loss, Tesla. Standards: NIST CMVP. Defense: Hiring, ZeroTrust,, Tools. Vulnerabilities: more PrintNightmare, Apple photos, STARTTLS, Chrome, Cisco, Fortinet, LinkedIn Jobs, Wordpress, Realtek IoT Wi-Fi, Blackberry, DDoS. Cybercrime: Irony, Trends: HolesWarm. Phishing costs, QR malware, Nation States. Crime. Other Risks: Edge, IoT, Trolley problem, Windows 11, facial recognition. China, stunting. Health, Safety & Environment: Zombies, Haiti, EV fires, space junk, Whalesafe, Batteries. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Covid Ugly; And more.

Read More

This Week's [in]Security - Issue 217 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI: SLC v1.1, Sunsetting P2PE v2 and PA-DSS. MasterCard resources. Control Gap SSA & SSLC. Magecart mobile, Carders. New breaches: Japanese Dating & government, Canada Post, Nukes, Dominos India, Hospitals, Compound redaction leak, New Ransomware: RCMP, Defensive shutdown. Privacy: Facial Recognition, Hiding controls. Laws & Regs - Canada: C-10 impact. US: Breach law. The world: Mass Surveillance, Data residency. Standards: NIST: Cloud, IoT/MuD. USB-C upgrade. Defense: Webinars, Webinars. Pipeline response, Cyber budgets, Unknown-unknowns, FBI supporting HIBP.

Read More

This Week's [in]Security - Issue 212 | insecurity | Control Gap

Welcome to This Week’s [in]Security. P2PE Solution Aid. More on 8-digit BINs. Supply-Chain Backdoors: CodeCov, Passwordstate, Solarwinds. New breaches: Facebook, Apple(?), ClearVoice. New Ransomware: Follow-ups & Fall-out: Privacy. Normalizing breaches. Floc Adverse. Laws & Regs: Canada: Bills C-10 & 11, regulating apps. US. UK, EU, HK. NIST iOT & ICS. CISv8. Defense: More Nation-State Patching, Moxie vs Cellebrite, Death to IoT, Passwordless, Mario and DevSecOps!? Vulnerabilities: Pulse, Chrome, SonicWall ZeroDays, Supply-chains, CyberGames, Clubhouse, Air-Drop, Docker Images, QNAP, Tesla. Updatable Encryption. Breaking Enigma. Cybercrime: Trends: TLS, QR, Sextortion, Ads, 7-Zip, ToxicEye, Pink, Fake DirectX12. Nation States. Crypto-skimming. Crime. Other Risks: Unethical patching, Social Media, Chips, Deepfake geography, Bounties, Resets, No bars! Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. Response. Immunity. Covid Ugly. Covid Compliance. And more.

Read More

This Week's [in]Security - Issue 211 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI 3DS Updates. New breaches: ParkMobile, Codecov, Upstox, ClubHouse. New Ransomware: Follow-ups & Fall-out: Facebook. Breach spin and Greed. Privacy. Laws & Regs: Class Actions, Breach Notification, LEA requests. BYOD. IOT. Defense: Anti-Caller ID Spoofing, Rockets, Code, Coders, Free Course, Cyber Careers, Power Grid, FLoC off, OSCAL. Vulnerabilities: Browser ZeroDays, Faster Bug Disclosure, DNS, NAME:WRECKIoT, Un-awareness, Dependencies, Pwn2Own, Kubernetes, Juniper, Zoom, Crypto. Cybercrime: FBI Patching. Trends. Nation States. Crime. Other Risks. Child Abuse Images. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. The Good, Bad, and Ugly (Behaviour). And more.

Read More

This Week's [in]Security - Issue 208 | insecurity | Control Gap

Welcome to This Week’s [in]Security. PCI Updates: PTS FAQ, PIN 3.1, QSA Program. Big-Hacks: Exchange, SolarWinds, F5, Accellion. New breaches: New Ransomware: Follow-ups & Fall-out: Amazon sued. Privacy: Facial Recognition. Laws & Regs: Facebook sued, Section 230, Breach Disclosures, Location Tracking Guidelines, NIST. Defense: Isolate IoT, Tools, Browsers. Vulnerabilities: Android, iOS ZeroDay, Apple iOS. ColdFusion, NetMask code, Android, Wordpress. Arresting the messenger? Cybercrime: Trends. Account Takeovers. Other Risks: Disinformation, IoT Weapons, PII a Risk, Autopilot, Grid, Shipping, More NFTs, Win95, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants. Immunity, Vaccines, and Vaccination. The Good, Bad, and Ugly (Behaviour). And more.

Read More

This Week's [in]Security - Issue 182 | insecurity | Control Gap

Welcome to This Week’s [in]Security. Draft DSS v4 RFC. Breach Reporting. New breaches: XP Source. Bing. Shopify. Spots. games. Airbnb. New Ransomware. Autonomous Indoor Drone? Facial Recognition. Taxing Tech. NIST Updates, Drafts & Workshops. YAYA and Chronicle Detect Threat Hunters. IoT. CBC Encryption. Russians hacking Russians. Arrests, Charges & Sentencings. Election Security. Phishing awareness fail. Homework fraud. Pastebin. Hurricane names. Medical AI. brain-computer interfaces. Near misses. Covid-19: Spread, Curves, Spikes, Waves, & reinfections. And more.

Read More