This Week's [in]Security - Issue 265

01 May 2022.

Welcome to This Week’s [in]Security. PCI and payments: PCI updates: SAQV4. Skimmers. Payments: New breaches: More GitHub, Coca-Cola. New Ransomware: trends, costs, BlackCat, Black Basta. Major outages: Record DDoS, fiber cable attacks. Follow-ups & Fall-out: 300K dbs, Smile, Aimware, fines, Blackbaud. Privacy: doxxing & right to be forgotten, warrantless searches, FAFSA (student aid) & Facebook. Laws & Regs - Canada: copyright, online harms, border rules. US: Fake EDRs, Patents, FOSTA, Drones. World: Open Internet, EU/India tech pact, EFF to the EU. Standards: security.txt, NIST OT & 5G. Defense - APIs, Google Docs. Tools: OpenSSF & malware packages. Vulnerabilities, Advisories: CISA. Zerodays: on the rise. Patching: Azure PostgreSQL. Other: CVE-like scores for Cloud, NPM, Nimbuspwn, NAS, Netatalk. Vulnerability research: Bug bounties, VirusTotal as vector. Crypto-research: PQC & agility. Cybercrime: Trends: Smishing, Malicious Tor, Onyx wiper, Bumblebee, Magniber. Crime & Enforcement: Child ID theft, Interpol. Sandworm, NFT theft, Nation States and mercenaries. China vs Russia, Journalists. Other. Playstore. Other Risks: General: Cloud, Bulletproof TLS, AI weirdness, Free speech, decoupling China. Health, Safety, Environment, Economy. Russia v. Ukraine. Innovation and more.

PCI Compliance and Payments

News and announcements relating to Payment Security, PCI, Card Brands, Payments, Payment Malware and Fraud, and Payment Related Compliance.

Breaches / Ransomware / Leaks

Covering breaches, leaks, data exposures, ransomware (as potential breach), and their fallout.

Privacy

Articles about privacy related news, risks, and trends.

Laws, Regulations, Platforms, Standards, and Public Policy

News about laws, regulations, platform rules, and standards affecting security, privacy, technology, and public interest.

Defense / Techniques / Solutions

Covering developments and opportunities that may help improve security.

Bugs / Design Flaws / Vulnerabilities / Research

Articles about newly discovered vulnerabilities and research.

Hacking / Malware / Cybercrime / Exploitation

News covering active trends, alerts, events.

Other Security / Risk

Articles covering other types of risks.

Russia v. Ukraine

News and announcements relating to Russia's invasion of Ukraine.

Off-Topic / Science & Tech / Lighter Side

A variety of scientific, technical, historical, and more light-hearted news.