Welcome to This Week’s [in]Security. Non-Compliance Lesson, DSSv4 related, Skimmers, Other Payments. New breaches: 7 breachers per capita, Shields &...
Welcome to This Week’s [in]Security. Trending: Coronavirus: Visualizing the spread. Infection and governments. Lockdown and reopening. Weird tech. Pool-noodle-hats. Vaccines, anti-bodies, treatments. More good, bad, and ugly. Masks, anti-maskers, and distancing. Confused AIs. PCI updated FAQs. The Unattributable 23M record breach. Celebrity law firm. 2nd grader pwns school board. More ransomware information sales. More contact tracing. Huawei export restrictions. Windows packet sniffer. Win-DoHs. Defcon & Blackhat cancelled. Thunderspy. Apples XML trouble. Ancient Windows bug. Attacking smart factories. Crypto-agility. Rash of supercomputer hacks. Exfiltrating over air gaps. New electronic warfare platform. Conspiracy theories. Election insecurity. And more.
Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.
Coronavirus updates. We recently change the way we report COVID articles to you so it is less overwhelming. Many COVID articles will appear within our normal blog section headings each with a sub-group dedicated to COVID-19. For example:
Our first regular reports on coronavirus can be found at https://controlgap.com/blog/this-weeks-insecurity-issue-147. And our first use of the trending topic section can be found https://controlgap.com/blog/this-weeks-insecurity-issue-149.
The spread and the curve:
Lockdown and reopening:
Treatments, Testing, Triage, and Trials, and things we learned:
Guidance, Response and Recovery:
Behaviour - the good, the bad, and the ugly:
Masks, anti-maskers, and distancing:
News and announcements relating to Payment Security, PCI, Card Brands, Payments, Payment Malware and Fraud.
Covering breaches, leaks, data exposures, ransomware (as potential breach), and their fallout.
Articles about privacy related news, risks, and trends.
COVID-19 Contact tracing:
News about laws, regulations, and standards affecting security, privacy, technology, and public interest.
Covering developments and opportunities that may help improve security.
Articles about newly discovered vulnerabilities and research.
News covering active trends and events.
COVID-19 Crime and Cybercrime:
Articles covering other types of risks.
COVID-19 Other risks and impact:
A variety of scientific, technical, historical, and more light-hearted news.
PCI DSS can be hard and not preparing for it just makes things harder. Following this advice is guaranteed to make it both more exciting and painful.