Welcome to This Week’s [in]Security. PCI and payments: PCI updates: Call for Speakers, P2PE, 3DS, Card Production. Payments, Training & events. New breaches: Samsung, Mercado Libre, VirusTotal. New Ransomware: more Conti, Critical Infrastructure, Bridgestone, Ubisoft. Major outages: Fiji, Spotify & Discord. Follow-ups & Fall-out. Privacy: Trusting your phone, COVID passports, Radar & body language. Laws & Regs - Canada: Bill C-11, Competition Law. US: Incident reporting, Whistleblowers, ICE, Amazon, Weight Watchers, Utah, Location data. World: Clearview AI, cybercrime treaty, Spyware probe, Right to be Forgotten, Crypto regulations, cyber-flashing. Standards: NIST DevSecOps. Defense. CISA Exploit catalog, Defense in depth, Polls, Kali. Vulnerabilities, Zerodays: APC UPS, 0-clicks, Chrome, DDoS, Other Vulnerabilities: BGP crypto-heist, Ostriches, IoT & ATMs, More Specter, Azure, Linux. Defender, HP, Wordpress, Riverbed, password rules, Blockchain privacy, Proof-of-stake attacks. Patching: Microsoft, Firefox, Adobe, Siemens. Cybercrime: Trends: surging attacks, NVIDIA. Telegram, WhatsApp. Nation States and mercenaries: China, Iran. Crime & Enforcement: Zelle, Extraditions, Fresno, DoH! Other Risks: Alexa, Pluton, AI, Employment, Manufacturing, Gas, NFT myths. Health, Safety & Environment. Missiles, GPS, Meteors & asteroids. Russia v. Ukraine. Innovation and more.
PCI Compliance and Payments
News and announcements relating to Payment Security, PCI, Card Brands, Payments, Payment Malware and Fraud, and Payment Related Compliance.
Breaches / Ransomware / Leaks
Covering breaches, leaks, data exposures, ransomware (as potential breach), and their fallout.
Privacy
Articles about privacy related news, risks, and trends.
Laws, Regulations, Platforms, Standards, and Public Policy
News about laws, regulations, platform rules, and standards affecting security, privacy, technology, and public interest.
-
Canada:
-
US:
-
World:
-
Standards News:
Defense / Techniques / Solutions
Covering developments and opportunities that may help improve security.
Bugs / Design Flaws / Vulnerabilities / Research
Articles about newly discovered vulnerabilities and research.
-
Zero-day news:
-
Other Vulnerabilities:
-
Patching:
Hacking / Malware / Cybercrime / Exploitation
News covering active trends, alerts, events.
Other Security / Risk
Articles covering other types of risks.
Russia v. Ukraine
News and announcements relating to Russia's invasion of Ukraine.
-
The war:
-
Reaction and response:
-
Sanctions & economic Impact:
-
Cyber-attacks and the potential for cyber-war:
- Report: Recent 10x Increase in Cyberattacks on Ukraine https://krebsonsecurity.com/2022/03/report-recent-10x-increase-in-cyberattacks-on-ukraine/
- The secret US mission to bolster Ukraine's cyber defenses ahead of Russia's invasion https://arstechnica.com/information-technology/2022/03/the-secret-us-mission-to-bolster-ukraines-cyber-defences-ahead-of-russias-invasion/
- Where's the Russia-Ukraine Cyberwar? https://www.schneier.com/blog/archives/2022/03/wheres-the-russia-ukraine-cyberwar.html
- 'We Are Not Ready': A Cyber Expert On US Vulnerability To A Russian Attack https://packetstormsecurity.com/news/view/33202/We-Are-Not-Ready-A-Cyber-Expert-On-US-Vulnerability-To-A-Russian-Attack.html
- Crowd-sourced attacks present new risk of crisis escalation http://blog.talosintelligence.com/2022/03/ukraine-update.html
- Russia-Ukraine: Threat of Local Cyber Operations Escalating Into Global Cyberwar https://www.securityweek.com/russia-ukraine-threat-local-cyber-operations-escalating-global-cyberwar
- Ukrainian CERT Warns Citizens of Phishing Attacks Using Compromised Accounts https://thehackernews.com/2022/03/ukrainian-cert-warns-citizens-of.html
- Google: Russia, China, Belarus state hackers target Ukraine, Europe https://www.bleepingcomputer.com/news/security/google-russia-china-belarus-state-hackers-target-ukraine-europe/
- In Ukraine, hacktivists fight back with data leaks https://www.theverge.com/2022/3/11/22968049/anonymous-hacks-ukraine-russia-cybercrime-danger
- Malware Posing as Russia DDoS Tool Bites Pro-Ukraine Hackers https://threatpost.com/malware-posing-russia-ddos-tool-bites-pro-ukraine-hackers/178864/
- Internet Backbone Giant Lumen Shuns .RU https://krebsonsecurity.com/2022/03/internet-backbone-giant-lumen-shuns-ru/
- Russia, Blocked From the Global Internet, Plunges Into Digital Isolation https://www.nytimes.com/2022/03/07/technology/russia-ukraine-internet-isolation.html
- Russian Pushing New State-run TLS Certificate Authority to Deal With Sanctions https://thehackernews.com/2022/03/russian-pushing-its-new-state-run-tls.html
- Why Russia's “disconnection” from the Internet isn't amounting to much https://arstechnica.com/information-technology/2022/03/why-russias-disconnection-from-the-internet-isnt-amounting-to-much/
- US intelligence officials investigate satellite internet cyberattack in Ukraine, which took place on day Russia invaded, reports say https://www.businessinsider.com/ukraine-us-national-security-agency-cyberattack-satellite-internet-russia-invasion-2022-3
- Russian APTs Furiously Phish Ukraine – Google https://threatpost.com/russian-apts-phishing-ukraine-google/178819/
- Ukraine and US targeted by cybersecurity attacks in run-up to Russian invasion https://www.theverge.com/2022/3/8/22966892/ukraine-us-targeted-cyber-war-russia-invasion-google-phishing-energy
- New RURansom Wiper Targets Russia https://www.trendmicro.com/en_us/research/22/c/new-ruransom-wiper-targets-russia.html
- Russian defense firm Rostec shuts down website after DDoS attack https://www.bleepingcomputer.com/news/security/russian-defense-firm-rostec-shuts-down-website-after-ddos-attack/
- Russian government sites hacked in supply chain attack https://www.databreaches.net/russian-government-sites-hacked-in-supply-chain-attack/
- Belarus conducted widespread phishing campaigns against Ukraine, Poland, Google says https://www.databreaches.net/belarus-conducted-widespread-phishing-campaigns-against-ukraine-poland-google-says/
- Risky Business #657 -- Belarus targets refugee data https://risky.biz/RB657
-
Information, Disinformation, and Propaganda:
Off-Topic / Science & Tech / Lighter Side
A variety of scientific, technical, historical, and more light-hearted news.