Welcome to This Week’s [in]Security. New breaches. Mega-breaches. New Ransomware. Facial Recognition. Surveillance Capitalism. NIST. Cybersecurity Awareness. No More FLASH. Supply Chain Security. Password Security. Ender's Game. MITRE Shield. e-voting. Windows 0-day. NSA Backdoors. Intel Firmware Signing Key. URLS. No MFA. DRM. Wordpress. IOT & ICS. BYOD. Nation States. Chekhov's Gun. Duct Cleaning. Legal actions. Unredacted. Election Security and Disinformation. AI fallibility. Health, Safety & Environment. Nurses. Covid-19: Spread, Curves, Spikes, Waves, & reinfections. Contact Tracing. Disinformation. And more.
PCI Compliance and Payments
News and announcements relating to Payment Security, PCI, Card Brands, Payments, Payment Malware and Fraud.
Breaches / Ransomware / Leaks
Covering breaches, leaks, data exposures, ransomware (as potential breach), and their fallout.
-
New breaches:
- Reincubate - 68,744,762 breached accounts https://haveibeenpwned.com/PwnedWebsites#Reincubate
- Massive Nitro credential breach impacts Microsoft, Google, Apple, more https://www.bleepingcomputer.com/news/security/massive-nitro-data-breach-impacts-microsoft-google-apple-more/
- Home Depot Confirms Data Breach in Order Confirmation SNAFU https://threatpost.com/home-depot-data-breach-order-confirmation/160728/
- Hackers rummaged about in Finnish psychotherapy clinic – now patients extorted with public data dump threats https://www.theregister.com/2020/10/26/finland_psychotherapy_clinic_ransom_attack/
- Personal data of 1.1 million RedMart user accounts stolen in Lazada breach and put up for sale https://www.databreaches.net/personal-data-of-1-1-million-redmart-user-accounts-stolen-in-lazada-breach-and-put-up-for-sale/
- Swedish Authorities, Banks Hit by Security Data Leak https://www.securityweek.com/swedish-authorities-banks-hit-security-data-leak-report
- Law Firm Says Google Employee Information Compromised in Data Breach https://www.securityweek.com/law-firm-says-google-employee-information-compromised-data-breach
- Has Guilford Technical Community College notified more than 43,000 students of data breach? https://www.databreaches.net/update-has-guilford-technical-community-college-notified-more-than-43000-students-of-data-breach/
- Eatigo reports data breach, personal data from customer accounts listed for sale online https://www.databreaches.net/eatigo-reports-data-breach-personal-data-from-customer-accounts-listed-for-sale-online/
- StarTribune - 2,192,857 breached accounts https://haveibeenpwned.com/PwnedWebsites#StarTribune
- Promofarma - 1,277,761 breached accounts https://haveibeenpwned.com/PwnedWebsites#Promofarma
- Data breach involving personal information reported at Rady Children’s Hospital https://www.databreaches.net/data-breach-involving-personal-information-reported-at-rady-childrens-hospital/
- Trump site hacked https://www.forbes.com/sites/rachelsandler/2020/10/27/trump-campaign-website-hacked-in-cryptocurrency-scam/, https://techcrunch.com/2020/10/27/trumps-campaign-website-hacked-by-cryptocurrency-scammers/, https://www.nbcnews.com/politics/2020-election/trump-campaign-website-hacked-n1245038, https://arstechnica.com/tech-policy/2020/10/trumps-website-defaced-with-claim-that-trump-admin-created-coronavirus/, and https://www.theregister.com/2020/10/28/trump_website_hacked/
- Compromised CMS Credentials Likely Used to Hack Trump Campaign Website https://www.securityweek.com/compromised-cms-credentials-likely-used-hack-trump-campaign-website
- New seller (?) offers 17 previously non-public databases for sale https://www.databreaches.net/new-seller-offers-17-previously-non-public-databases-for-sale/
-
New Ransomware:
-
Follow-ups and fall-out:
Privacy
Articles about privacy related news, risks, and trends.
Laws, Regulations, Standards, and Public Policy
News about laws, regulations, and standards affecting security, privacy, technology, and public interest.
Defense / Techniques / Solutions
Covering developments and opportunities that may help improve security.
Bugs / Design Flaws / Vulnerabilities / Research
Articles about newly discovered vulnerabilities and research.
Hacking / Malware / Cybercrime / Exploitation
News covering active trends, alerts, events.
Other Security / Risk
Articles covering other types of risks.
COVID-19 updates.
COVID related articles. We have been following coronavirus risks since https://controlgap.com/blog/this-weeks-insecurity-issue-147.
-
The spread, curves, spikes, and waves - now reinfection:
-
Contact Tracing:
-
Guidance, Response and Recovery:
-
Treatments, Testing, Triage, and Trials:
-
Things we learned:
-
Disinformation:
-
Masks, anti-maskers, distancing, compliance, and repercussions:
Off-Topic / Science & Tech / Lighter Side
A variety of scientific, technical, historical, and more light-hearted news.