Welcome to This Week’s [in]Security. Trending: Coronavirus: New Zealand, Canada, Brazil, Russia, Belgium, Mississippi. Vaccines, anti-bodies, treatments. Guidance, Response and Recovery. More good, the bad, and the ugly. Payments, PCI & Covid. Breaches & ransomware: Banco BCR (cards), GDPR site, Tokopedia (15M), 9M UK licence plate trip logs, TaiLieu(7M), LineageOS. How to respond to a breach tip. Contact tracing and privacy. Facebook settlement. Biometrics & De-anonymizing device IDs. Patents. NIST updates. Fuzzing Apple. Power Grid defense. Saving ".org". SQL on a firewall! OpenSSL, Teams, Wordpress, Saltstack, Magneto, Adobe, Belkin NetCams. Lock-picking. Shade ransomware keys released. Tricky phone scam. Deep-fakes and identity theft. COVID cabin fever. Trolling AI's. Ad more.
Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.
Coronavirus updates. We recently change the way we report COVID articles to you so it is less overwhelming. Many COVID articles will appear within our normal blog section headings each with a sub-group dedicated to COVID-19. For example:
Our first regular reports on coronavirus can be found at https://controlgap.com/blog/this-weeks-insecurity-issue-147. And our first use of the trending topic section can be found https://controlgap.com/blog/this-weeks-insecurity-issue-149.
The spread, the curve, and aftermath:
Guidance, Response and Recovery:
Behaviour - the Good, the Bad, and the Ugly:
News and announcements relating to Payment Security, PCI, Card Brands, Payments, Payment Malware and Fraud.
COVID-19 Payments/PCI:
Covering breaches, leaks, data exposures, ransomware (as potential breach), and their fallout.
Articles about privacy related news, risks, and trends.
COVID-19 Contact tracing:
News about laws, regulations, and standards affecting security, privacy, technology, and public interest.
Covering developments and opportunities that may help improve security.
COVID-19 countermeasures:
Defending the power grid against supply chain attacks (long running series):
Articles about newly discovered vulnerabilities and research.
News covering active trends and events.
Articles covering other types of risks.
COVID-19 Other risks and impact:
A variety of scientific, technical, historical, and more light-hearted news.
For your COVID shelter-in-place cabin fever: