Welcome to This Week’s [in]Security. Non-Compliance Lesson, DSSv4 related, Skimmers, Other Payments. New breaches: 7 breachers per capita, Shields &...
Welcome to This Week’s [in]Security. Big-Hacks: Exchange, SolarWinds, Ubiquiti. New breaches: Facebook, MobiKwik. New Ransomware: Molson Coors, Home Hardware. Follow-ups & Fall-out: 1000 Year Breach, Refunds? Privacy. Laws & Regs: web analytics, autodialers, backdooring Facebook. NIST Hospitality. Defense: Webinars. Girls and STEM. SSL and old TLS. CoinHive. Application Security. Vulnerabilities: QNAP ZeroDay, Firmware, WordPress, ICS, PHP/GitHub, Containers, Spectre. Cryptography: Homomorphic, Lightweight, and Post-Quantum. Cybercrime Trends: Bypassing Facial, Nation States. Crime: Utility Hack, Tatoos,. Lego? Other Risks: Facial Bias, Domains, Amber Alerts, Nuke Tweet, Shipping. Health, Safety & Environment: mRNA & saRNA. The problems with NFTs. Covid-19: Spread, Curves, Waves, and Variants. The Good, Bad, and Ugly (Behaviour). And more.
News and announcements relating to Payment Security, PCI, Card Brands, Payments, Payment Malware and Fraud.
Covering breaches, leaks, data exposures, ransomware (as potential breach), and their fallout.
New Ransomware and "Incidents":
Follow-ups and fall-out:
Articles about privacy related news, risks, and trends.
News about laws, regulations, platform rules, and standards affecting security, privacy, technology, and public interest.
Covering developments and opportunities that may help improve security.
Upcoming Webinars and Virtual Events:
Articles about newly discovered vulnerabilities and research.
New Security Signals study shows firmware attacks on the rise
News covering active trends, alerts, events.
Trends, Alerts, and Events (other than major Exchange, SolarWinds, F5, and Accellion):
Nation State Actors:
Crime & Arrests, etc.:
Articles covering other types of risks.
Health, Safety & Environment:
NFTs are supposed to be digitial-art with provenance on a blockchain, except they aren't. They're more like receipts for digital-art on a blockchain. The art isn't protected.
COVID related articles. We have been following coronavirus risks since https://controlgap.com/blog/this-weeks-insecurity-issue-147.
The spread, curves, spikes, waves, reinfection, and variant strains:
Guidance, Response, and Recovery:
Treatments, Testing, Triage, Trials, and things we Learned:
More of the good, the bad, and the ugly:
Masks, anti-maskers, distancing, compliance, and repercussions:
US govt warns that buying fake COVID-19 vaccine cards is a crime https://www.bleepingcomputer.com/news/security/us-govt-warns-that-buying-fake-covid-19-vaccine-cards-is-a-crime/
A variety of scientific, technical, historical, and more light-hearted news.
PCI DSS can be hard and not preparing for it just makes things harder. Following this advice is guaranteed to make it both more exciting and painful.