This Week's [in]Security - Issue 257
06 Mar 2022.
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: DSSv4 timelines. Training & events. New breaches: Conti Malware Group, Samsung, Nvidia, Robinhood, Lawyers. New Ransomware: Hive Decryption, Toyota, AON. Major outages: Semiconductors. Follow-ups & Fall-out. Privacy: DNA testing, AirTags. Laws & Regs - Canada: Lawful Access, Privacy Reform, CRTC. US: Cybersecurity law, SEC, Web-Scraping. World: Telcos, Crypto-Taxes. Standards: NSA, NIST. Defense. Vulnerabilities, Zerodays: Firefox, Other Vulnerabilities: Password Cracking, Credentials in Code, Linux, Samsung, Stalkerware, Medical IoT, Echo, Patching: CISA. Crypto-research: PQC-Hybrid. Cybercrime: Trends: APIs, DDoS, NVIDA certs, Sharkbot, SockDetour, Teabot. Nation States and mercenaries: Europe, China, Iran. Crime & Enforcement. Other Risks: Bulletproof TLS, Shadow IT. Democracy. Health, Safety & Environment. The Russia v. Ukraine war. Innovation and more.
Note: the volume and variety of Ukraine related articles makes it difficult to report these under specific sections, we will be reporting these in a dedicated section below.
PCI Compliance and Payments
News and announcements relating to Payment Security, PCI, Card Brands, Payments, Payment Malware and Fraud, and Payment Related Compliance.
-
PCI Updates:
- Updated summary of all PCI DSS v4 publications to finalized timelines https://controlgap.com/blog/PCI-DSSv4-is-Coming
-
Educational events, webinars, courses, etc:
- NICE Webinar: The NICE Framework at Work - Use Cases from Industry https://content.govdelivery.com/accounts/USNIST/bulletins/30b5e90
Breaches / Ransomware / Leaks
Covering breaches, leaks, data exposures, ransomware (as potential breach), and their fallout.
-
New Breaches:
- Conti cybergang gloated when leaking victims' data. Now the tables are turned https://arstechnica.com/information-technology/2022/03/conti-cybergang-gloated-when-leaking-victims-data-now-the-tables-are-turned/
- Conti Ransomware Group Diaries, Part I: Evasion https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-i-evasion/
- Conti Ransomware Group Diaries, Part II: The Office https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-ii-the-office/
- Conti Ransomware Group Diaries, Part III: Weaponry https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-iii-weaponry/
- Hackers leak 190GB of alleged Samsung data, source code https://www.bleepingcomputer.com/news/security/hackers-leak-190gb-of-alleged-samsung-data-source-code/
- Hackers Who Broke Into NVIDIA's Network Leak DLSS Source Code Online https://thehackernews.com/2022/03/hackers-who-broke-into-nvidias-network.html
- Hackers to NVIDIA: Remove mining cap or we leak hardware data https://www.bleepingcomputer.com/news/security/hackers-to-nvidia-remove-mining-cap-or-we-leak-hardware-data/
- NVIDIA - 71,335 breached accounts https://haveibeenpwned.com/PwnedWebsites#NVIDIA
- Robinhood - 5,003,937 breached accounts https://haveibeenpwned.com/PwnedWebsites#Robinhood
- Quarter of a million lawyer disciplinary records leak https://www.theregister.com/2022/02/28/ca_legal_leak/
- MacGeneration - 101,004 breached accounts https://haveibeenpwned.com/PwnedWebsites#MacGeneration
-
New Ransomware and "Incidents":
- Decrypting Hive Ransomware Data https://www.schneier.com/blog/archives/2022/03/decrypting-hive-ransomware-data.html
- Toyota halts production after reported cyberattack on supplier https://www.bleepingcomputer.com/news/security/toyota-halts-production-after-reported-cyberattack-on-supplier/
- Aon hit by cyber attack https://www.databreaches.net/aon-hit-by-cyber-attack/
- Swedish Security Solutions Provider Axis Hit by Cyberattack https://www.securityweek.com/swedish-security-solutions-provider-axis-hit-cyberattack
-
Major outages/downs:
- Massive blackout hits Taiwan, affecting 5 million households https://www.businessinsider.com/massive-blackout-hits-taiwan-affecting-households-2022-3
- Unplanned power outage at Taiwanese plant interrupts semiconductor production across the region https://www.techspot.com/news/93657-unplanned-power-outage-taiwanese-plant-interrupts-semiconductor-production.html
-
Follow-ups and fall-out:
- Breach Notification: Poor Transparency Complicates Response https://www.databreaches.net/breach-notification-poor-transparency-complicates-response/
- NY OAG warns T-Mobile data breach victims of identity theft risks https://www.bleepingcomputer.com/news/security/ny-oag-warns-t-mobile-data-breach-victims-of-identity-theft-risks/
Privacy
Articles about privacy related news, risks, and trends.
- Direct-to-Consumer DNA Testing: How protected is the genetic data you're submitting to these websites? https://www.comparitech.com/blog/information-security/dna-testing-privacy/
- Experts Create Apple AirTag Clone That Can Bypass Anti-Tracking Measures https://thehackernews.com/2022/02/experts-create-apple-airtag-clone-that.html
- AirTags are dangerous - here's how Apple could fix them https://www.theverge.com/2022/3/1/22947917/airtags-privacy-security-stalking-solutions
Laws, Regulations, Platforms, Standards, and Public Policy
News about laws, regulations, platform rules, and standards affecting security, privacy, technology, and public interest.
-
Canada:
- The Law Bytes Podcast, Episode 119: Canada's Zombie Policy Proposal - Christopher Parsons on the Never-Ending Debate Over Lawful Access https://www.michaelgeist.ca/2022/02/law-bytes-podcast-episode-119/
- The Urgent Need for Privacy Reform: My Appearance Before the Standing Committee on Access to Information, Privacy and Ethics https://www.michaelgeist.ca/2022/03/the-urgent-need-for-privacy-reform-my-appearance-before-the-standing-committee-on-access-to-information-privacy-and-ethics/
- CRTC Calls for Increased Powers To Take a More "Interventionist" Approach on Internet Content https://www.michaelgeist.ca/2022/03/crtc-calls-for-more-powers-to-take-a-more-interventionist-approach-on-internet-content/
- Ontario extends anti-blockade police powers https://toronto.ctvnews.ca/ontario-extends-anti-blockade-police-powers-1.5799360
- Are you allowed to refuse to return to in-person work? A lawyer explains https://toronto.ctvnews.ca/are-you-allowed-to-refuse-to-return-to-in-person-work-a-lawyer-explains-1.5801466
- Canadians prepare to fight for Ukraine as security and legal concerns swirl https://globalnews.ca/news/8656035/canadians-fight-ukraine-security-legal-concerns/
-
US:
- Senate Unanimously Approves Cybersecurity Legislation https://www.pymnts.com/news/security-and-risk/2022/senate-unanimously-approves-cybersecurity-legislation/
- SEC: No Amnesty for Crypto Companies for Self-Reported Violations https://www.pymnts.com/cryptocurrency/2022/sec-no-amnesty-for-crypto-companies-for-self-reported-violations/
- Crypto's Impact on Russian Sanctions Could Lead to Tougher Regulation https://www.pymnts.com/cryptocurrency/2022/cryptos-impact-on-russian-sanctions-could-lead-to-tougher-regulation/
- U.S. Regulators Order Algorithm and Data Deletion in Settlement with Weight Watchers https://epic.org/u-s-regulators-order-algorithm-and-data-deletion-in-settlement-with-weight-watchers/
- TikTok Probed by State Attorneys General Over App's Impact on Children https://www.pymnts.com/legal/2022/tiktok-probed-by-state-attorneys-general-over-apps-impact-on-children/
- Utah on the Verge of Adopting Comprehensive Privacy Law https://www.pymnts.com/news/regulation/2022/utah-on-the-verge-of-adopting-comprehensive-privacy-law/
- Airline Sues to Stop Popular Web-Scraping Service-American Airlines v. The Points Guy https://www.databreaches.net/airline-sues-to-stop-popular-web-scraping-service-american-airlines-v-the-points-guy/
-
World:
- NIS 2.0-the EU looks to bolster its cybersecurity laws https://www.databreaches.net/nis-2-0-the-eu-looks-to-bolster-its-cybersecurity-laws/
- UK government starts public consultation on telco security https://www.theregister.com/2022/03/03/telco_security_regulations_dcms_consultation/
- Taxation May Be a Bigger Issue in Crypto Regulation Than Anticipated https://www.pymnts.com/cryptocurrency/2022/taxation-may-be-a-bigger-issue-in-crypto-regulation-than-anticipated/
- Barclays Faces $1M Penalty Over Payments Firm Collapse https://www.pymnts.com/news/international/2022/barclays-faces-1m-penalty-over-payments-firm-collapse/
- $90M Settlement in Facebook Tracking Case Would Force 'Complete Disgorgement' of Profits https://epic.org/90m-settlement-in-facebook-tracking-case-would-force-complete-disgorgement-of-profits/
-
Standards News:
- NSA Publishes Best Practices for Improving Network Defenses https://www.securityweek.com/nsa-publishes-best-practices-improving-network-defenses
- Final Ransomware Risk Management Cybersecurity Framework Profile & Quick Start Guide https://content.govdelivery.com/accounts/USNIST/bulletins/30bd30e
- Introduction to Cybersecurity for Commercial Satellite Operations: 2nd Draft of NISTIR 8270 is Available for Comment open through April 8 https://content.govdelivery.com/accounts/USNIST/bulletins/30cb849
- NCCoE Releases Draft Project Description for Manufacturing Sector Cybersecurity open for comment until April 14 https://content.govdelivery.com/accounts/USNIST/bulletins/30bef94
Defense / Techniques / Solutions
Covering developments and opportunities that may help improve security.
- Log4Shell Makes the Case for Runtime Application Self-Protection https://www.darkreading.com/application-security/log4shell-makes-the-case-for-runtime-application-self-protection
- Protecting Field Programmable Gate Arrays From Attacks https://www.darkreading.com/dr-tech/protecting-field-programmable-gate-arrays-from-attacks
- British Firm Tackles 'Harvest Now, Decrypt Later' Problem With Sharding Technology https://www.securityweek.com/british-firm-tackles-harvest-now-decrypt-later-problem-sharding-technology
- Companies Borrow Attack Technique to Watermark Machine Learning Models https://www.darkreading.com/threat-intelligence/companies-borrow-attack-technique-to-watermark-ml-models
- Stepping into a Hacker's Shoes: Why the Mainframe Needs Pentesting https://www.krisecurity.com/qa-with-a-pentester/
- Optimizing a smart contract fuzzer https://blog.trailofbits.com/2022/03/02/optimizing-a-smart-contract-fuzzer/
Bugs / Design Flaws / Vulnerabilities / Research
Articles about newly discovered vulnerabilities and research.
-
Zero-day news:
- Mozilla Firefox 97.0.2 fixes two actively exploited zero-day bugs https://www.bleepingcomputer.com/news/security/mozilla-firefox-9702-fixes-two-actively-exploited-zero-day-bugs/
-
Other Vulnerabilities:
- 8-Character Passwords Can Be Cracked in Less than 60 Minutes (MD5 vs both RTX3090 & Cloud) https://www.darkreading.com/attacks-breaches/8-character-passwords-can-be-cracked-in-less-than-60-minutes
- Companies' Code Leaking More Passwords and Secrets https://www.darkreading.com/application-security/companies-code-leaking-more-passwords-and-secrets
- New Linux Kernel cgroups Vulnerability Could Let Attackers Escape Container https://thehackernews.com/2022/03/new-linux-kernel-cgroups-vulnerability.html
- Samsung Encryption Flaw https://www.schneier.com/blog/archives/2022/03/samsung-encryption-flaw.html
- Vulnerability in Stalkerware Apps https://www.schneier.com/blog/archives/2022/03/vulnerability-in-stalkerware-apps.html
- Over 100,000 medical infusion pumps vulnerable to years old critical bug https://www.bleepingcomputer.com/news/security/over-100-000-medical-infusion-pumps-vulnerable-to-years-old-critical-bug/
- Critical Bugs Reported in Popular Open Source PJSIP SIP and Media Stack https://thehackernews.com/2022/03/critical-bugs-reported-in-popular-open.html
- Critical Vulnerabilities Impact Widely Used Printed Circuit Board File Viewer https://www.securityweek.com/critical-vulnerabilities-impact-widely-used-printed-circuit-board-file-viewer
- Most Cybersecurity Vendors at Risk Due to Internet-Exposed IT Assets https://www.darkreading.com/application-security/most-cybersecurity-vendors-at-risk-due-to-internet-exposed-it-assets
- The Truth About USB Device Serial Numbers - (and the lies your tools tell) https://www.sans.org/blog/the-truth-about-usb-device-serial-numbers
- These are the problems that cause headaches for bug bounty hunters https://www.zdnet.com/article/these-are-common-problems-that-cause-headaches-for-bug-bounty-participants
- Attackers can force Amazon Echos to hack themselves with self-issued commands https://arstechnica.com/information-technology/2022/03/attackers-can-force-amazon-echos-to-hack-themselves-with-self-issued-commands/
-
Patching:
- CISA warns organizations to patch 95 actively exploited bugs https://www.bleepingcomputer.com/news/security/cisa-warns-organizations-to-patch-95-actively-exploited-bugs/
- CISA Urges Organizations to Patch Actively Exploited Zimbra XSS Vulnerability https://www.securityweek.com/cisa-urges-organizations-patch-actively-exploited-zimbra-xss-vulnerability
-
Cryptography and Cryptographic Research:
- Soatok on The Controversy Surrounding (Post-Quantum) Hybrid Cryptography https://soatok.blog/2022/01/27/the-controversy-surrounding-hybrid-cryptography/
- Researchers Demonstrate New Side-Channel Attack on Homomorphic Encryption https://thehackernews.com/2022/03/researchers-demonstrate-new-side.html
Hacking / Malware / Cybercrime / Exploitation
News covering active trends, alerts, events.
-
Trends, Alerts, and Events (other than major breaches):
- Attacks abusing programming APIs grew over 600% in 2021 https://www.bleepingcomputer.com/news/security/attacks-abusing-programming-apis-grew-over-600-percent-in-2021/
- Hackers Begin Weaponizing TCP Middlebox Reflection for Amplified DDoS Attacks https://thehackernews.com/2022/03/hackers-begin-weaponizing-tcp-middlebox.html
- Leaked stolen Nvidia cert can sign Windows malware https://www.theregister.com/2022/03/05/nvidia_stolen_certificate/
- SharkBot malware hides as Android antivirus in Google Play https://www.bleepingcomputer.com/news/security/sharkbot-malware-hides-as-android-antivirus-in-google-play/
- Stealthy 'SockDetour' Backdoor Used in Attacks on U.S. Defense Contractors https://www.securityweek.com/stealthy-sockdetour-backdoor-used-attacks-us-defense-contractors
- TeaBot Android Banking Malware Spreads Again Through Google Play Store Apps https://thehackernews.com/2022/03/teabot-android-banking-malware-spreads.html
- Log4shell exploits now used mostly for DDoS botnets, cryptominers https://www.bleepingcomputer.com/news/security/log4shell-exploits-now-used-mostly-for-ddos-botnets-cryptominers/
-
Nation State Actors:
- CISA and FBI warn of potential data wiping attacks spillover https://www.bleepingcomputer.com/news/security/cisa-and-fbi-warn-of-potential-data-wiping-attacks-spillover/
- Cyberattack Knocks Thousands Offline in Europe https://www.securityweek.com/cyberattack-knocks-thousands-offline-europe
- New Chinese Hacking Tool Found, Spurring U.S. To Warn Allies https://packetstormsecurity.com/news/view/33155/New-Chinese-Hacking-Tool-Found-Spurring-U.S.-To-Warn-Allies.html
- Researchers Warn of Stealthy Chinese Backdoor Targeting Multiple Foreign Agencies https://www.darkreading.com/endpoint/researchers-warn-of-stealthy-chinese-backdoor-targeting-multiple-foreign-agencies
- Iranian Hackers Using New Spying Malware That Abuses Telegram Messenger API https://thehackernews.com/2022/02/iranian-hackers-using-new-spying.html
-
Crime & Arrests, etc.:
- Beware of donation scams involving Ukraine https://toronto.ctvnews.ca/beware-of-donation-scams-involving-ukraine-1.5799910
- Be wary of scams, says RCMP, especially at tax time https://globalnews.ca/news/8661487/tax-scam-reminder-rcmp/
- 'It's a scam': Ontario warns residents not to click on link in licence plate refund text https://toronto.ctvnews.ca/it-s-a-scam-ontario-warns-residents-not-to-click-on-link-in-licence-plate-refund-text-1.5799250
- The Very Real Problem of Synthetic Identity Fraud https://www.pymnts.com/identity-theft/2022/the-very-real-problem-of-synthetic-identity-fraud/
Other Security / Risk
Articles covering other types of risks.
- Global response to Russia's invasion should give China 'pause' over Taiwan: defence intel chief https://globalnews.ca/news/8655172/russia-invasion-ukraine-china-taiwan-plans/
- Bulletproof TLS #86, EU weakenes browser certificates/QWACs, fixes, BGO hijacking and certificates, hybrid encryption https://www.feistyduck.com/bulletproof-tls-newsletter/issue_86_eu_plans_to_mandate_less_secure_certificates_in_browsers
- Intel's 12th-gen Alder Lake processors will not include Microsoft's Pluton security https://www.theregister.com/2022/03/02/microsoft_pluton_chip/
- KnowBe4 Research: Half of Employees Use Unauthorized File Services to Complete Work https://www.darkreading.com/vulnerabilities-threats/knowbe4-research-half-of-employees-use-unauthorized-file-services-to-complete-work
- Large fines for exam cheating auditors - PwC Canada $950K last week https://www.complianceweek.com/regulatory-enforcement/pwc-canada-fined-950k-for-internal-training-exam-cheating/31405.article and KPMG $615K in 2021 https://www.afr.com/companies/professional-services/kpmg-fined-615-000-over-widespread-exam-cheating-20210915-p58rqp
- US fighter jet recovered from South China Sea https://www.bbc.co.uk/news/world-us-canada-60607784
- Disinformation and the Erosion of Democracy: Announcing Summit From the University of Chicago Institute of Politics and The Atlantic https://www.theatlantic.com/press-releases/archive/2022/02/announcing-summit-university-chicago-institute-politics-and-atlantic/622905/
- Anonymity in Crypto Raises Alarm https://www.nytimes.com/2022/03/02/technology/cryptocurrency-anonymity-alarm.html
- Bank of Canada raising key interest rate to 0.5 per cent https://www.ctvnews.ca/business/bank-of-canada-raising-key-interest-rate-to-0-5-per-cent-1.5802003
- Biden has pledged tax credits for electric vehicles. Here's what that means for Canada https://globalnews.ca/news/8655174/us-evs-tax-credit-canada-biden-speech/
-
Health, Safety & Environment:
- Face masks play a crucial role, new COVID research confirms https://scienmag.com/face-masks-play-a-crucial-role-new-covid-research-confirms/
- Magnets in newer portable electronic devices can interfere with implanted defibrillators https://scienmag.com/magnets-in-newer-portable-electronic-devices-can-interfere-with-implanted-defibrillators/
- Showing different types of COVID-19 data can directly influence behaviour during the pandemic https://scienmag.com/showing-different-types-of-covid-19-data-can-directly-influence-behaviour-during-the-pandemic/
- Belief in vaccination misinformation predicts attitudes toward vaccinating children https://scienmag.com/belief-in-vaccination-misinformation-predicts-attitudes-toward-vaccinating-children/
- A math model to predict COVID-19 vaccine efficacy https://scienmag.com/a-math-model-to-predict-covid-19-vaccine-efficacy/
- Another life-saving Covid drug identified https://www.bbc.co.uk/news/health-60601750
- Fighting COVID-19 with milk? https://scienmag.com/fighting-covid-19-with-milk/
- Making COVID Tests Better at Detecting Infectious People https://www.scientificamerican.com/article/making-covid-tests-better-at-detecting-infectious-people/
- COVID-19 hospitalizations in Ontario drop below 800 for first time since December https://toronto.ctvnews.ca/covid-19-hospitalizations-in-ontario-drop-below-800-for-first-time-since-december-1.5807042
- COVID-19: 3 deaths, jump in hospitalizations as N.B. scraps proof of vaccination https://globalnews.ca/news/8650664/nb-covid-19-feb-28-2022/
- Ontario lifts nearly all major COVID-19 restrictions https://toronto.ctvnews.ca/ontario-lifts-nearly-all-major-covid-19-restrictions-1.5800169
- Resistance exercise may be superior to aerobic exercise for getting better ZZZs https://scienmag.com/resistance-exercise-may-be-superior-to-aerobic-exercise-for-getting-better-zzzs/
- Scientists Identify The Optimal Number of Daily Steps For Longevity, And It's Not 10,000 https://www.sciencealert.com/huge-new-study-finds-the-optimal-number-of-daily-steps-is-far-less-than-we-re-told
- COVID-19 restrictions linked to nearly 750,000 fewer dengue cases in 2020 https://scienmag.com/covid-19-restrictions-linked-to-nearly-750000-fewer-dengue-cases-in-2020/
- Some places to keep checking for COVID-19 vaccine proof in Ontario https://globalnews.ca/news/8650417/some-places-maintain-covid-proof-vaccination-ontario/
- Toronto among several municipalities keeping mandatory vaccine policies for employees https://toronto.ctvnews.ca/toronto-among-several-municipalities-keeping-mandatory-vaccine-policies-for-employees-1.5802176
- A Tesla car came to a complete stop on an interstate, police say, causing a 3-car crash that killed the driver https://www.businessinsider.com/tesla-crash-driver-killed-after-car-stops-on-highway-2022-3
- Personal trainer dies from caffeine overdose after accidentally drinking the equivalent of 200 cups of coffee, reports say https://www.businessinsider.com/personal-trainer-dies-after-drinking-equivalent-of-200-cups-of-coffee-2022-3
- Scientists Uncover Largest Known Crater on Earth From The Last 100,000 Years https://www.sciencealert.com/scientists-uncover-the-largest-crater-on-earth-younger-than-100-000-years-old
- Last-Minute Defense Against an Asteroid That Could Obliterate it Before Impact https://www.universetoday.com/154759/last-minute-defense-against-an-asteroid-that-could-obliterate-it-before-impact/
- Clean energy broke records in 2021 but still can't catch up with oil and gas https://www.theverge.com/2022/3/3/22960195/clean-energy-records-2021-oil-gas-forecast
- New Nuclear Power Plants Are Unlikely to Stop the Climate Crisis https://www.scientificamerican.com/article/new-nuclear-power-plants-are-unlikely-to-stop-the-climate-crisis/
- The flat-pack water heater that fights climate change https://www.bbc.co.uk/news/stories-60617154
- First anti-aging, coral safe sunscreen with Methylene Blue hits the market https://scienmag.com/first-anti-aging-coral-safe-sunscreen-with-methylene-blue-hits-the-market/
- Corals can be "trained" to tolerate heat stress, study finds https://scienmag.com/corals-can-be-trained-to-tolerate-heat-stress-study-finds/
Russia v. Ukraine War
News and announcements relating to Russia's invasion of Ukraine.
-
The war:
- Over 1 million Ukrainians have fled Russian invasion, UN says https://globalnews.ca/news/8655866/ukraine-refugees-1-million-russia-invasion/
- The Russia-Ukraine war could spawn an 'overwhelming' refugee crisis of up to 4 million people, UN warns https://www.businessinsider.com/united-nations-russia-ukraine-war-overwhelming-refugee-crisis-millions-2022-3
- 200,000 civilians remain trapped in the besieged Ukrainian city of Mariupol as the Russian cease-fire fails for a second time https://www.businessinsider.com/ukraine-russia-cease-fire-in-besieged-mariupol-fails-again-200000-trapped-2022-3
- Battle at Ukraine's largest nuclear power plant raises global alarm https://www.theverge.com/2022/3/4/22960816/ukraine-nuclear-power-plant-fire-russia-zaporizhzhia
- Shelling kills civilians, injures dozens in Kharkiv, says Ukrainian official https://globalnews.ca/news/8650101/ukraine-russia-war-kharkiv-shelling-civilians/
- Third round of Russia-Ukraine negotiations to take place next week https://globalnews.ca/news/8657424/ukraine-russia-negotiations/
- Satellite photos show Russian military convoy over 60km long headed toward Kyiv https://globalnews.ca/news/8651598/ukraine-russia-kyiv-convoy-photos/
- Telecoms blackout hits northeast Ukraine; large power outages also reported https://www.theverge.com/2022/3/3/22960374/telecoms-blackout-northeast-ukraine-power-outage-sumy
- Ukraine: Amateurs dig in to fight Russian troops from Kyiv forests https://www.bbc.co.uk/news/world-europe-60607649
- Ukraine: Estonian cargo ship sinks after blast in Black Sea https://www.bbc.co.uk/news/world-europe-60606515
- Russia's Initial Failures Don't Mean Ukraine Will Survive https://www.theatlantic.com/ideas/archive/2022/03/russian-military-power-weakness-ukraine/623323/
- Google disables Maps traffic data in Ukraine to protect citizens https://www.theverge.com/2022/2/28/22954426/google-disables-maps-traffic-data-in-ukraine-to-protect-citizens
- Snapchat turns off public 'heatmap' for Ukraine https://www.theverge.com/2022/3/4/22962384/snapchat-heatmap-ukraine-disabled-privacy-advertising
- Canada will send Ukraine anti-tank weapons, upgraded ammo: Trudeau https://globalnews.ca/news/8650978/canada-ukraine-lethal-aid-against-russia/
- Psaki rules out 'no-fly zone' over Ukraine because it could lead to war between the US and Russia https://www.businessinsider.com/psaki-rules-out-no-fly-zone-over-ukraine-2022-2
- Canadians urged to avoid non-essential travel to Russia amid Ukraine war https://globalnews.ca/news/8650187/canadians-russia-travel-advisory-ukraine-war/
- The war in Ukraine continues to weigh heavy on Ukrainian Canadians https://globalnews.ca/news/8655515/ukraine-russia-ukrainian-canadians-kingston/
- Putin's 'deeply irrational' nuclear threat must not deter West: Rae https://globalnews.ca/news/8650622/vladimir-putin-nuclear-threat-bob-rae/
- Ukraine conflict: What are the nuclear risks? https://www.bbc.co.uk/news/world-europe-60559574
- Pentagon seeks backchannels with Russian to prevent Ukraine invasion escalating to nuclear war, report says https://www.businessinsider.com/us-seeks-russia-backchannel-to-prevent-nuclear-escalation-report-2022-2
-
Reaction and response:
- International Criminal Court launches investigation of war crimes in Ukraine https://www.businessinsider.com/ukraine-international-criminal-court-begins-war-crimes-investigation-2022-3
- Russian oligarchs and lawmakers are speaking out against the invasion of Ukraine, an almost unheard-of sight in Putin's Russia https://www.businessinsider.com/russia-oligarchs-lawmakers-slam-ukraine-invasion-rare-rebuke-2022-3
- A Russian businessman has put a $1 million bounty on Vladimir Putin's head, calling for Russian military officers to arrest him as a war criminal https://www.businessinsider.com/russian-businessman-puts-1-million-bounty-on-putins-head-2022-3
- Ukraine to join NATO intel-sharing cyberdefense hub https://www.bleepingcomputer.com/news/government/ukraine-to-join-nato-intel-sharing-cyberdefense-hub/
- Last week's InSecurity issue covered the Russia-Ukraine invasion and related risks. We have created a separate special edition and added some links for those looking to help https://controlgap.com/blog/this-weeks-insecurity-issue-256-Ukraine
- How Ontarians can help the people of Ukraine as fighting with Russia intensifies https://globalnews.ca/news/8651679/ontario-help-ukraine-donations/
- Canada gives $100M in humanitarian aid for Ukraine, bars Russian ships from waters https://globalnews.ca/news/8652343/canada-humanitarian-aid-ships-russia-ukraine-war/
- Canada working to swiftly welcome Ukrainians fleeing Russian invasion: Trudeau https://globalnews.ca/news/8651596/russia-ukraine-war-canada-immigration/
- Canada calls for Russian INTERPOL membership to be suspended amid Ukraine invasion https://globalnews.ca/news/8656474/russia-ukraine-interpol-suspension-war-canada-trudeau/
- Russian airline Aeroflot violated Canada's ban on entering its airspace on Sunday, regulator says https://www.businessinsider.com/russian-airline-aeroflot-violated-canadas-airspace-ban-regulator-2022-2
- UK asks ports to block Russian ships, including any vessels 'owned, controlled, chartered, or operated by any person connected with Russia' https://www.businessinsider.com/uk-ports-block-russian-ships-tankers-yachts-2022-2
- Ukraine sanctions: UK dockers refuse tanker of Russian gas https://www.bbc.co.uk/news/uk-england-kent-60619112
- POLITICO: 'Big Tech' moves to defy Kremlin https://epic.org/politico-big-tech-moves-to-defy-kremlin/
- Ukraine asks ICANN to revoke Russian domains and shut down DNS root servers https://arstechnica.com/tech-policy/2022/03/ukraine-wants-russia-cut-off-from-core-internet-systems-experts-say-its-a-bad-idea/
- A Major Internet Backbone Company Cuts Off Russia https://www.wired.com/story/cogent-internet-backbone-cuts-off-russia-nvidia-ransomware-conti-security-news
- Switzerland breaks neutral status to sanction Russia over Ukraine invasion https://www.businessinsider.com/switzerland-sanctions-russia-breaks-neutral-status-ukraine-invasion-2022-2
- Finnish, Swedish citizens warming to NATO alliance amid Ukraine war, polls show https://globalnews.ca/news/8656956/finland-sweden-nato-russia-ukraine-war/
- After Russia's invasion of Ukraine, Germany is making major moves to give its struggling military 'strength of our own' https://www.businessinsider.com/germany-moves-to-strengthen-military-after-russian-attack-on-ukraine-2022-3
- Ukraine conflict: Disney, Warner, Sony halt release of films in Russia https://www.bbc.co.uk/news/business-60566286
- Zara, Paypal and Samsung suspend business in Russia over Ukraine invasion https://www.bbc.co.uk/news/uk-60631835
- Russia and Belarus athletes banned from Winter Paralympics after team protests https://www.bbc.co.uk/sport/disability-sport/60599739
- German stakeholder in Nord Stream 1 natural gas pipeline rejects calls to shut it down in response to the Russian invasion of Ukraine https://www.businessinsider.com/nord-stream-1-eon-gas-pipeline-germany-gazprom-russia-ukraine-2022-2
-
Sanctions & economic Impact:
- Russia's invasion of Ukraine sends economic ripple across the globe https://globalnews.ca/news/8653967/russia-ukraine-invasion-economic-globe/
- Zelensky says he has officially applied to make Ukraine a member of the European Union https://www.businessinsider.com/zelensky-officially-applied-for-ukraine-to-join-european-union-2022-2
- The US, EU, and others have hit Russia with a pile of sanctions, but they still have more tools to hammer its economy https://www.businessinsider.com/russia-sanctions-ukraine-invasion-economic-damage-putin-russian-elites-banks-2022-2
- Russian billionaires' losses, now totaling $84 billion this year, have more than doubled since Russia invaded Ukraine less than a week ago https://www.businessinsider.com/russian-billionaires-wealth-lose-84-billion-dollars-under-a-week-2022-3
- Russia's central bank hikes interest rates to 20% and buys gold as the ruble crashes to a record low following tough Western sanctions https://markets.businessinsider.com/news/bonds/russia-ukraine-war-central-bank-ruble-dollar-gold-sanctions-economy-2022-2
- US Treasury Adds Crypto Rules to Russia Sanctions https://www.pymnts.com/cryptocurrency/2022/us-treasury-adds-crypto-rules-to-russia-sanctions/
- US KleptoCapture force to tackle cryptocurrency use in Russian sanction avoidance https://www.zdnet.com/article/us-govt-launches-kleptocapture-initiative-to-counter-crypto-use-in-avoiding-russian-sanctions
- Today in Crypto: Switzerland Freezes Russian Crypto Assets; China Continues Crypto Crackdown https://www.pymnts.com/cryptocurrency/2022/today-in-crypto-switzerland-freezes-russian-crypto-assets-china-continues-crypto-crackdown/
- France seizes Russian oligarch's super yacht https://www.bbc.co.uk/news/business-60604206
- Germany seized the world's largest mega-yacht worth $600 million belonging to Russian oligarch Alisher Usmanov, according to Forbes report https://www.businessinsider.com/germany-seizes-russian-billionaire-alisher-usmanovs-mega-yacht-forbes-2022-3
- Italy has reportedly seized $156 million in yachts and villas from sanctioned Russian oligarchs, including the country's richest man https://www.businessinsider.com/italy-seizes-yachts-villas-from-sanctioned-russian-oligarchs-ukraine-2022-3
- The Russian ruble is now worth less than 1 cent as Russia bombs Ukrainian cities and sanctions pile up https://markets.businessinsider.com/news/currencies/russian-ruble-worth-less-than-1-cent-ukraine-bombs-sanctions-2022-3
- The Kremlin says Russia's 'economic reality' has 'considerably changed' in the face of 'problematic' Western sanctions https://www.businessinsider.com/russia-ukraine-kremlin-western-sanctions-problematic-change-reality-economy-putin-2022-2
- International banking lobby has warned that it is 'extremely likely' Russia will default if the war in Ukraine escalates https://markets.businessinsider.com/news/bonds/russia-ukraine-bank-lobby-warning-default-crisis-markets-ruble-2022-3
- Russia could fall into a recession by summer, an economist says https://www.businessinsider.com/russia-recession-second-quarter-before-summer-economist-evgeny-nadorshin-2022-3
- Russia's central bank shuts the country's stock market for a 2nd day as analysts warn it is 'uninvestable' https://markets.businessinsider.com/news/stocks/russia-stock-market-closed-ukraine-conflict-sanctions-univestable-bonds-ruble-2022-3
- Russia's credit rating is cut to 'junk' by Moody's and Fitch as sanctions threaten to crush the country's economy https://markets.businessinsider.com/news/stocks/russia-ukraine-war-invasion-moodys-fitch-credit-rating-markets-economy-2022-3
- Russia's Looming Economic Collapse https://www.theatlantic.com/newsletters/archive/2022/03/vladimir-putin-economy-sanctions-swift-fallout/623330/
- Russia will ban Western companies from exiting investments as BP and others dash for the door https://markets.businessinsider.com/news/stocks/russia-ban-western-companies-exiting-investments-sanctions-swift-stocks-ruble-2022-3
- Russia's central bank has closed the country's stock market and instructed brokers to block foreign sales as losses mount https://markets.businessinsider.com/news/stocks/russia-closed-stock-market-blocks-foreigner-sales-central-bank-ukraine-2022-2
- As Payments Firms Disclose Russia Exposure, Wall Street Takes Stock https://www.pymnts.com/news/international/2022/as-payments-firms-disclose-russia-exposure-wall-street-takes-stock/
- Mastercard, Visa suspend operations in Russia over war in Ukraine https://globalnews.ca/news/8661576/visa-mastercard-suspended-russia-ukraine/
- Switzerland's SWIFT data centre under guard after Russian banks excluded https://www.theregister.com/2022/03/03/swift_data_centre_under_guard/
- Report: EU Considers SWIFT Ban for Belarus Banks https://www.pymnts.com/news/international/2022/report-eu-considers-swift-ban-for-belarus-banks/
- Canada announces trade action against Russia, more lethal aid and new immigration streams for Ukrainians https://www.ctvnews.ca/politics/canada-announces-trade-action-against-russia-more-lethal-aid-and-new-immigration-streams-for-ukrainians-1.5803845
- Canada to ban imports of crude oil from Russia https://www.bbc.co.uk/news/business-60564781
- Canadian banks are barred from transactions with Russian central bank: Trudeau https://globalnews.ca/news/8650244/russia-invasion-ukraine-canadian-banks-barred-from-business/
- Russian companies sanctioned by Canada include big banks and a diamond mining giant https://www.ctvnews.ca/business/russian-companies-sanctioned-by-canada-include-big-banks-and-a-diamond-mining-giant-1.5799493
- Airbnb suspends all operations in Russia and Belarus https://www.theguardian.com/technology/2022/mar/04/airbnb-suspends-all-operations-in-russia-and-belarus
- Apple halts product sales in Russia https://www.theverge.com/2022/3/1/22957000/apple-russia-ukraine-invasion-halt-product-sales-app-store
- Bombardier, Canadian Tire suspend Russia-linked operations over Ukraine invasion https://globalnews.ca/news/8659795/bombardier-canadian-tire-suspend-russia-linked-operations-over-ukraine-invasion/
- Levi's and PwC among firms pulling back from Russia https://www.bbc.co.uk/news/business-60571133
- Magna idles Russian operations in response to Ukraine invasion https://globalnews.ca/news/8658662/magna-russia-operations-ukraine-war/
- Microsoft pulls the plug on 'new' sales of products and services in Russia https://www.theverge.com/2022/3/4/22961445/microsoft-russia-ukraine-sales-ban-xbox-azure-windows-office
- Netflix shuts down its services in Russia https://www.theverge.com/2022/3/6/22964565/netflix-shuts-down-services-russia-ukraine-invasion
- Oracle suspends operations in Russia, SAP pauses sales https://www.reuters.com/business/oracle-says-it-has-suspended-all-operations-russia-2022-03-02/
- Samsung has stopped shipping products to Russia https://www.theverge.com/2022/3/4/22962282/samsung-suspending-shipments-russia-smartphones-chips
- The world's largest airline ticket-booking service cuts ties with Russia's Aeroflot https://www.theverge.com/2022/3/3/22959816/sabre-cuts-ties-aeroflot-russian-invasion-ukraine
- World's biggest shipping company suspends container shipments to and from Russia https://www.businessinsider.com/maersk-pauses-russia-shipments-except-food-medical-humanitarian-aid-2022-3
- 2 China-based development banks have opted to suspend business with Russia https://www.businessinsider.com/2-china-based-development-banks-suspend-business-with-russia-2022-3
- Russian Companies Scramble to Open Chinese Bank Accounts https://www.pymnts.com/news/international/2022/russian-companies-scramble-to-open-chinese-bank-accounts/
- Aeroflot halts international flights as Russian sanctions increase risk of foreign-leased planes being impounded https://www.businessinsider.com/aeroflot-halts-international-flights-risk-foreign-planes-impounded-2022-3
- Russia axed joint experiments on the International Space Station in response to crippling sanctions for its invasion of Ukraine https://www.businessinsider.com/iss-russia-axes-joint-experiments-after-ukraine-invasion-sanctions-2022-3
- Russia holds OneWeb rocket launch hostage, issues conditional demands https://www.theverge.com/2022/3/2/22958082/russia-roscosmos-oneweb-soyuz-launch-demands-ukraine-invasion
- Russia's Space Isolation Grows as OneWeb Cancels Launch https://www.nytimes.com/2022/03/03/science/russia-oneweb-launch.html
-
Cyber-attacks and the potential for cyber-war:
- Cyberattacks are Prominent in the Russia-Ukraine Conflict https://www.trendmicro.com/en_us/research/22/c/cyberattacks-are-prominent-in-the-russia-ukraine-conflict.html
- Attack Matrices for Russian APT's (work in progress) https://github.com/NanoSecCo/RussianAPTMITRE
- Amazon: Charities, aid orgs in Ukraine attacked with malware https://www.bleepingcomputer.com/news/security/amazon-charities-aid-orgs-in-ukraine-attacked-with-malware/
- Canadian intelligence agency calls for ramped-up cyber defences after Russia invades Ukraine https://www.cbc.ca/news/politics/cyber-russia-cse-1.6362878
- Free decryptor released for HermeticRansom victims in Ukraine https://www.bleepingcomputer.com/news/security/free-decryptor-released-for-hermeticransom-victims-in-ukraine/
- Hacktivists Stoke Pandemonium Amid Russia's War in Ukraine https://www.wired.com/story/hacktivists-pandemonium-russia-war-ukraine
- Russia's cyber warfare is a problem for 'everyone,' experts warn https://globalnews.ca/news/8650575/russia-ukraine-canada-cyberattack-cyberspace-cybersecurity/
- Tech Companies Help Defend Ukraine Against Cyberattacks https://www.nytimes.com/2022/02/28/us/politics/ukraine-malware-microsoft.html
- Ukraine IT Army Targets Belarus Railway Network, Russian GPS https://packetstormsecurity.com/news/view/33171/Ukraine-IT-Army-Targets-Belarus-Railway-Network-Russian-GPS.html
- Ukraine says its 'IT Army' has taken down key Russian sites https://www.bleepingcomputer.com/news/security/ukraine-says-its-it-army-has-taken-down-key-russian-sites/
- Anonymous Hacker Group Targets Russian State Media https://www.securityweek.com/anonymous-hacker-group-targets-russian-state-media
- Hackers interrupt Catholic charity's online press conference on Ukraine https://www.databreaches.net/hackers-interrupt-catholic-charitys-online-press-conference-on-ukraine/
- HC3: Destructive Malware Targeting Organizations in Ukraine https://www.databreaches.net/hc3-destructive-malware-targeting-organizations-in-ukraine/
- Microsoft Finds FoxBlade Malware Hit Ukraine Hours Before Russian Invasion https://thehackernews.com/2022/03/microsoft-finds-foxblade-malware-hit.html
- Microsoft identifies and mitigates new malware targeting Ukraine "within 3 hours" https://arstechnica.com/gadgets/2022/03/microsoft-identifies-and-mitigates-new-malware-targeting-ukraine-within-3-hours/
- Second data-wiping malware found in Ukraine, says ESET https://www.theregister.com/2022/03/01/ukraine_wiper_apple_visa_mastercard/
- Ukraine security agencies warn of Ghostwriter threat activity, phishing campaigns https://www.zdnet.com/article/ukraine-security-agency-warns-of-ghostwriter-threat-group-activity-phishing-campaigns
- Ukrainian sites saw a 10x increase in attacks when invasion started https://www.bleepingcomputer.com/news/security/ukrainian-sites-saw-a-10x-increase-in-attacks-when-invasion-started/
- Russian space agency says hacking satellites is an act of war https://www.bleepingcomputer.com/news/security/russian-space-agency-says-hacking-satellites-is-an-act-of-war/
-
Information, Disinformation, and Propaganda:
- Risky Business #656 - We expected a cyberwar but got an infowar https://risky.biz/RB656
- The propaganda war has eclipsed cyberwar in Ukraine https://www.technologyreview.com/2022/03/02/1046646/the-propaganda-war-has-eclipsed-cyberwar-in-ukraine/
- 'Help Ukraine' crypto scams emerge as Ukraine raises over $37 million https://www.bleepingcomputer.com/news/security/help-ukraine-crypto-scams-emerge-as-ukraine-raises-over-37-million/
- Phishing attacks target countries aiding Ukrainian refugees https://www.bleepingcomputer.com/news/security/phishing-attacks-target-countries-aiding-ukrainian-refugees/
- Russia Leaks Data From a Thousand Cuts-Podcast https://threatpost.com/russia-leaks-data-thousand-cuts-podcast/178749/
- Teen who tracked Elon Musk's jet turns his attention to Russian oligarchs https://www.theguardian.com/technology/2022/mar/01/teen-tracks-russian-oligarchs-elon-musk
- Microsoft Accounts Targeted by Russian-Themed Credential Harvesting https://threatpost.com/microsoft-accounts-targeted-russian-credential-harvesting/178698/
- Hackers Try to Target European Officials to Get Info on Ukrainian Refugees, Supplies https://thehackernews.com/2022/03/hackers-try-to-hack-european-officials.html
- Why BBC Revived Shortwave Radio Dispatches in Ukraine https://www.nytimes.com/2022/03/03/business/media/bbc-shortwave-radio-ukraine.html
- BBC points Russians to the Tor version of itself https://www.theregister.com/2022/03/04/russia_splinternet_tor_rumours/
- Details of '120,000 Russian soldiers' leaked by Ukrainian media https://www.theregister.com/2022/03/02/russian_soldier_leaks/
- A Russia-linked hacking group broke into Facebook accounts and posted fake footage of Ukrainian soldiers surrendering, Meta says https://www.businessinsider.com/meta-russia-linked-hacking-group-fake-footage-ukraine-surrender-2022-2
- Ukraine invasion: Misleading claims continue to go viral https://www.bbc.co.uk/news/60554910
- Facebook removes Russian misinformation network pushing fake news about the war in Ukraine https://www.theverge.com/2022/2/28/22954451/facebook-twitter-remove-misinformation-network-russian-propaganda-ukraine-invasion
- Google has blocked Russian state media outlets RT and Sputnik from its app store in Europe https://www.businessinsider.com/google-blocks-russia-rt-sputnik-apps-play-store-europe-ukraine-2022-3
- Spotify removes Kremlin-backed content and closes Russia office https://www.theverge.com/2022/3/3/22959636/spotify-removes-rt-sputnik-russia-kremlin-ukraine-conflict
- TikTok Suspends Livestreaming and New Uploads From Russia https://www.nytimes.com/2022/03/06/technology/tiktok-russia-ukraine.html
- Wikimedia says it 'will not back down' after Russia threatens Wikipedia block https://www.theverge.com/2022/3/3/22960007/russia-wikipedia-wikimedia-foundation-censorship-demand
- YouTube blocks Russian news channels RT and Sputnik https://www.theverge.com/2022/3/1/22956114/youtube-blocks-russian-media-rt-russia-today-sputnik-europe
- Russia says it's blocking Facebook in alarming new censorship push https://www.theverge.com/2022/3/4/22960739/russia-internet-block-facebook-meta-roskomnadzor-ukraine
- Russia asks Google to end "misinformation" on "special op" in Ukraine https://www.bleepingcomputer.com/news/google/russia-asks-google-to-end-misinformation-on-special-op-in-ukraine/
- Facebook hits out at Russia blocking its platforms https://www.bbc.co.uk/news/technology-60626777
- Russian 'fake news' law could give offenders 15 years in prison https://www.theverge.com/2022/3/4/22961472/russia-fake-news-law-military-ukraine-invasion-casualties-jail-time
- BBC, CNN and others are suspending operations or halting their broadcast in Russia after Putin pushes 'fake news' law https://www.businessinsider.com/news-outlets-cnn-bloomberg-bbc-suspending-operations-russia-putin-law-2022-3
Off-Topic / Science & Tech / Lighter Side
A variety of scientific, technical, historical, and more light-hearted news.
-
Innovations & Inventions:
- A potential breakthrough for production of superior battery technology https://scienmag.com/a-potential-breakthrough-for-production-of-superior-battery-technology/
- MIT engineers created a material stronger than steel and as light as plastic https://www.businessinsider.com/mit-engineers-create-material-light-as-plastic-stronger-than-steel-2022-3
- Archeologists are Planning to Scan the Great Pyramid of Giza With Cosmic Rays With Such Detail, They Should see Every Hidden Chamber Inside https://www.universetoday.com/154689/archeologists-are-planning-to-scan-the-great-pyramid-of-giza-with-cosmic-rays-with-such-detail-they-should-see-every-hidden-chamber-inside/
-
Other:
- Out of Gas: A North Carolina Woman Can't Keep Her 'FART' License Plate https://www.mentalfloss.com/article/655803/north-carolina-woman-cant-keep-her-fart-license-plate
- Physics race pits Usain Bolt against Jurassic Park dinosaur https://scienmag.com/physics-race-pits-usain-bolt-against-jurassic-park-dinosaur/
- Wreckage of ship that sank in 1891 discovered in Lake Superior https://globalnews.ca/news/8658740/atlanta-ship-wreckage-lake-superior/
- A Huge Rotating Kilometer-Scale Space Station Could be Launched From a Single Rocket https://www.universetoday.com/154825/a-huge-rotating-kilometer-scale-space-station-could-be-launched-from-a-single-rocket/
- After mistaken identity and confusion, a piece of space junk slams into the Moon https://www.theverge.com/2022/3/4/22958705/chinese-rocket-space-debris-moon-collision-change-5-t1
- JWST update: All 18 eyes of the telescope now see a single, focused image! Kinda! https://www.syfy.com/syfy-wire/bad-astronomy-james-webb-space-telescope-milestone-as-mirrors-are-aligned
- Second-ever Earth Trojan asteroid found! https://www.syfy.com/syfy-wire/bad-astronomy-earth-trojan-asteroid-2020-xl5-confirmed
- Mars Explorers are Going to Need air, and Lots of it. Here's a Technology That Might Help Them Breath Easy https://www.universetoday.com/154809/mars-explorers-are-going-to-need-air-and-lots-of-it-heres-a-technology-that-might-help-them-breath-easy/
- This Mind-Bogglingly Gigantic Sunspot Is Roughly The Size of Our Entire Planet https://www.sciencealert.com/gaze-upon-the-magnificence-of-this-sunspot-the-size-of-earth
- Why Isn't Jupiter a Star? https://www.sciencealert.com/jupiter-is-bigger-than-some-stars-so-why-isn-t-it-one
- Closest black hole system found to contain no black hole https://scienmag.com/closest-black-hole-system-found-to-contain-no-black-hole/