Welcome to This Week’s [in]Security. This week: PCI is quite, ATM and payment app crime, record £183M GDPR fine for BA, massive smart home vendor records leak, de-anonymizing data, online fingerprinting , ISPs dislike DoH, secure power grid initiative, NIST VPN and TDEA/TDES updates, space tech risk, D-Link FTC settlement audits, Zipato’s smart hub IoT door lock failure, China puts secret app on tourist phones, Ubuntu hacked, Facebook account purge, push back and risk of Facebook's Libra Coin, Crypto-currency manipulation, courts and forensic firm hit by ransomware, ransomware firing, the strange case of Cisco gear with Huawei certificates, Blockchain hype, more evidence Blockchain is not eco-friendly, more Boeing pain, mushrooms and sleeping pill risks, and more.
Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.
PCI Compliance and Payments
News and announcements relating to Payment Security, Payments, PCI, and Card Brands.
Breaches / Leaks
Covering breaches, leaks, data exposures, and their fallout.
Privacy
Articles about privacy related news, risks, and trends.
Laws & Regulations / Standards
News about laws, regulations, and standards affecting security, privacy, technology, and public interest.
Defense / Techniques / Solutions
Covering developments and opportunities that may help improve security.
Bugs / Design Flaws / Vulnerabilities / Research
Articles about newly discovered vulnerabilities and research.
Hacking / Malware / Cybercrime / Exploitation
News covering active trends and events.
Other Security / Risk
Articles covering other types of risks.
- Consumer Data, Upcoming Elections Are at Risk, Black Hat Survey Says https://www.darkreading.com/consumer-data-upcoming-elections-are-at-risk-black-hat-survey-says/d/d-id/1335089
- So, you think you've spotted some 'fake news' — now what? https://www.cbc.ca/news/technology/fake-news-disinformation-propaganda-internet-1.5196964
- Analysis: The Real Threat From Facebook's Libra Coin is Identities https://www.forbes.com/sites/francescoppola/2019/06/30/the-real-threat-from-facebooks-libra-coin/
- We just got a clear sign that Facebook’s dodgy reputation means it has a massive struggle to persuade people to use its new cryptocurrency Libra We just got a clear sign that Facebook’s dodgy reputation means it has a massive struggle to persuade people to use its new cryptocurrency Libra https://www.businessinsider.com/facebook-people-libra-jefferies-trust-2019-7
- Seriously? Cisco put Huawei X.509 certificates and keys into its own switches https://www.zdnet.com/article/seriously-cisco-put-huawei-x-509-certificates-and-keys-into-its-own-switches/
- AT&T down: 911 calls failing to go through amid major carrier outage https://www.independent.co.uk/life-style/gadgets-and-tech/news/att-outage-911-calls-down-police-ambulance-latest-update-a8984316.html
- Cloudflare’s outage had widespread implications – incorrect Bitcoin prices, Down Detector unreachable and more https://metro.co.uk/2019/07/02/cloudflare-outage-means-websites-including-detector-10103471/
- Facebook says glitches involving WhatsApp, Instagram now resolved https://www.cbc.ca/news/technology/facebook-whatsapp-instagram-social-media-outage-1.5198656
- Facebook buildings evacuated in California after nerve agent scare https://www.cbc.ca/news/world/facebook-site-evacuated-mail-sarin-1.5196514
- ReactOS ‘a ripoff of the Windows Research Kernel’ claims Microsoft kernel engineer https://www.theregister.co.uk/2019/07/03/reactosaripoffofthewindowsresearchkernelclaimsmicrosoftkernel_engineer/
- A new, more user-friendly language for programming supercomputers https://techxplore.com/news/2019-07-user-friendly-language-supercomputers.html
- Apparently, IBM’s Blockchain Isn’t a Real Blockchain https://cointelegraph.com/news/why-ibms-blockchain-isnt-a-real-blockchain
- OK, we call BS. Article claiming Blockchain will stop breaches is long on hype, short on details, omits a massive amount of infrastructure and transformation, and ignores other technologies. “Cybersecurity Breach at Maryland Agency Spotlights Need for Blockchain www.ccn.com/op-ed/security-breach-at-maryland-agency-highlights-govt-need-for-blockchain/2019/07/06/” (If you must visit, you’ll have to cut and past the text link).
- ‘It’s very arbitrary’: People, mayors furious over Quebec’s updated flood maps https://globalnews.ca/news/5462671/people-mayors-furious-quebec-flood-maps/
- Boeing’s pain grows – loses big order for 737 Max aircraft https://www.bbc.com/news/business-48899588
- New Flaw In Boeing 737 Forewarns Emergency Procedure Bugs In Driverless Cars https://www.forbes.com/sites/lanceeliot/2019/07/03/new-flaw-in-boeing-737-forewarns-emergency-procedure-bugs-in-driverless-cars/
- SpaceX has Lost Contact With 3 of its Starlink Satellites https://www.universetoday.com/142733/spacex-has-lost-contact-with-3-of-its-starlink-satellites/
- Google tweaked algorithm after rise in US shootings https://www.theguardian.com/technology/2019/jul/02/google-tweaked-algorithm-after-rise-in-us-shootings
- Bitcoin's energy consumption 'equals that of Switzerland' https://www.bbc.co.uk/news/technology-48853230
- Toxic death cap mushroom spotted in Vancouver, health officials confirm https://globalnews.ca/news/5461798/death-cap-mushroom-vancouver/
- Risks of sleeping pills and planes: Embarrassing tales from 35,000 feet https://www.cnn.com/travel/article/planes-sleeping-pills/index.html
Off-Topic / Science & Tech / Lighter Side
A variety of scientific, technical, historical, and more light-hearted news.