Welcome to This Week’s [in]Security. Trending: Corona virus updates - individual guidance, spread, responses, security. PCI and COVID19. PCI SPOC update RFC. New breach guidance. Breach news on planes, trains, electric automobiles, spacecraft, phones, schools, and cruise lines. 200M property records. 25GB security data. PEI hit by breach-ware. Failure to test leads to breach. Geofence suspect. Facial recognition. Student privacy. Ex-marketer privacy advocate. Copyright vs GDPR. Cyber-law casebook. NIST updates. Software ingredients lists. CPU Vulnerabilities. Password reuse and credential stuffing. Failure to patch. The big Let's Encrypt revoke. Quantum enhanced weakness. SIM swapping threat. 1.2M Microsoft enterprise non-MFA accounts compromised. Homographs: tricky lookalike Domain Names. New ransomware. Election security. Crypto AG update. Mumps. Security dilemmas. And more.
Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.
New - Emerging Issues and Trending Stories
This special section is dedicated to emerging issues and trending stories that cross multiple of our regular news categories.
PCI Compliance and Payments
News and announcements relating to Payment Security, PCI, Card Brands, Payments, Payment Malware and Fraud.
Breaches / Ransomware / Leaks
Covering breaches, leaks, data exposures, ransomware (as potential breach), and their fallout.
- Cathay Pacific Airlines Fined Over Data Breach https://www.bankinfosecurity.com/cathay-pacific-airlines-fined-over-data-breach-a-13879
- British Rail Station Wi-Fi Provider Exposed Traveler Data https://www.bbc.com/news/technology-51682280
- Visser, a parts manufacturer for Tesla and SpaceX, confirms data breach https://techcrunch.com/2020/03/01/visser-breach/
- Telus-Owned Koodo Mobile Announces Data Breach, Stolen Info for Sale https://www.bleepingcomputer.com/news/security/telus-owned-koodo-mobile-announces-data-breach-stolen-info-for-sale/
- Like a Virgin, hacked for the very first time... UK broadband ISP spills 900,000 punters' records into wrong hands from insecure database https://www.theregister.co.uk/2020/03/05/virgin_media_subscriber_data_leak/
- Porn, gore, and gambling habits aired in Virgin Media breach https://arstechnica.com/information-technology/2020/03/virgin-media-breach-outs-some-customers-porn-gore-and-gambling-habits/
- Simon Fraser University reviewing security measures after data breach exposes personal information (Names, birthdays, email addresses) https://www.databreaches.net/ca-sfu-reviewing-security-measures-after-data-breach-exposes-personal-information/ and https://globalnews.ca/news/6620351/sfu-data-breach/ and https://bc.ctvnews.ca/personal-information-of-students-faculty-at-b-c-university-exposed-in-recent-data-breach-1.4835336
- Data Breach Affects Princess Cruises, Holland America Line Guests https://www.databreaches.net/data-breach-affects-princess-cruises-holland-america-line-guests/
- US property and demographic database of 200 million records leaked on the web https://www.databreaches.net/us-property-and-demographic-database-of-200-million-records-leaked-on-the-web/
- Brazilian security firm leaks more than 25 GB of client and staff data https://www.zdnet.com/article/brazilian-security-firm-exposes-more-than-25-gb-of-client-and-staff-data/
- AnimeGame - 1,431,378 breached accounts https://haveibeenpwned.com/PwnedWebsites#AnimeGame
- 266,000 Passwords Stolen in Trident Crypto Fund Data Breach https://www.databreaches.net/266000-passwords-stolen-in-trident-crypto-fund-data-breach/
- Walgreens Mobile App Exposed Health-Related Messages https://www.bankinfosecurity.com/walgreens-mobile-app-exposed-health-related-messages-a-13813
- MO: Detectives investigate data breach at Jefferson County School District https://www.databreaches.net/mo-detectives-investigate-data-breach-at-jefferson-county-school-district/
- Data Leak Compels Samsung To Activate Two-Factor Authentication https://www.pymnts.com/authentication/2020/data-leak-compels-samsung-to-activate-two-factor-authentication/
- Loyalty Cards Targeted in Tesco Clubcard Attack https://threatpost.com/tesco-clubcard-account-takeovers/153430/
- Hackers Compromise T-Mobile Employee' Email Accounts and Steal User' Data https://thehackernews.com/2020/03/hackers-compromise-t-mobile-employees.html
- Data breach follows P.E.I. ransomware attack https://www.thetelegram.com/news/canada/data-breach-follows-pei-ransomware-attack-418350/
- NZ: Tuia 250 privacy breach: Tech boss signed off on government website with no testing https://www.databreaches.net/nz-tuia-250-privacy-breach-tech-boss-signed-off-on-government-website-with-no-testing/
- NZ: Cyberattackers hack Wellington school’s computer system https://www.databreaches.net/nz-cyberattackers-hack-wellington-schools-computer-system/
- UK: Boots Advantage Card hit by cyber attack https://www.databreaches.net/uk-boots-advantage-card-hit-by-cyber-attack/
- Casinos in Las Vegas Hit by Suspected Ransomware Attack https://www.databreaches.net/casinos-in-las-vegas-hit-by-suspected-ransomware-attack/
- Legal services giant Epiq Global offline after ransomware attack https://www.databreaches.net/legal-services-giant-epiq-global-offline-after-ransomware-attack/
Privacy
Articles about privacy related news, risks, and trends.
Laws & Regulations / Standards
News about laws, regulations, and standards affecting security, privacy, technology, and public interest.
Defense / Techniques / Solutions
Covering developments and opportunities that may help improve security.
Bugs / Design Flaws / Vulnerabilities / Research
Articles about newly discovered vulnerabilities and research.
Hacking / Malware / Cybercrime / Exploitation
News covering active trends and events.
Other Security / Risk
Articles covering other types of risks.
Off-Topic / Science & Tech / Lighter Side
A variety of scientific, technical, historical, and more light-hearted news.