720-891-1663

March 31, 2023

  • Microsoft Says Outlook Zero-Day, Zero-Interaction Bug Has Been Exploited for a Year
  • Recent Uptick in “Free Gift” Spam
  • Microsoft Launches ChatGPT Based Tools for Its 365 Product Line
  • New Version of Microsoft Teams is Twice as Fast, Full Deployment by June
  • Apple Patches All iThings – iOS 15 Under Attack Now
  • As I Said, the AI Marketplace is Going to Run Circles Around the Law
  • Banning TikTok is Likely Unconstitutional and Will Hurt Americans More Than China
  • Law Firm Who Reps Breached Companies Gets Breached
  • Twitter Source Code Stolen
  • Multiple Louisiana Universities and Colleges Under Cyberattack
  • Puerto Rico’s Water Authority Hacked

Security News Bites for the Week Ending March 31st, 2023:

This week’s security news bites: Twitter to open-source recommendation algorithm, new
assistant Secretary of Defense for cyber won’t be proposed till year end, tis the time for IRS
email scams, Italy bans ChatGPT – at least temporarily and DEA paid US companies’
employees to steal data and open parcels. Read the details here.

Companies hire law firms from time to time. And, companies often share sensitive data
with them. Law firms are a hot target for hackers for that reason. Many law firms don’t
have great security practices. Have you risk-assessed the law firm you are considering
engaging? You might want to do that. I bet New York Presbyterian Hospital (see above)
wishes that they had done a risk assessment before hiring the law firm they hired. If your
law firm gets hacked, it is a double whammy. You get to pay them AND you get to deal
with the breach. Need help assessing a law firm? Please contact us.


Mitch

March 26, 2023

  • Xi, Putin Declare Plan to Rule AI and Infosec
  • FBI Releases This Year’s Internet Crime Report
  • Exploit Released for Veeam Bug Allowing Cleartext Credential Theft
  • WordPress FORCE PATCHES WooCommerce Plugin With a Half Million Installs
  • We Warned You
  • ‘Influencers’ Charged With Hawking Crypto Without Saying They Were Paid
  • Crypto Fugitive, Co-Founder of TerraForm Labs, Arrested in Montenegro
  • Congress is Shocked That 10 Year Olds Check the I Am Over 18 box Online
  • Oak RIdge, TN Hit by Ransomware Attack
  • Hacking the Hackers – BreachForums Shuts Down due to Fear They’ve Been Hacked by the Feds

Security News Bites for the Week Ending March 24th, 2023:

This week’s security news bites: Senators ask CISA to investigate DJI drones, hard-coded
secrets up 67%, threatens software supply chain, maybe Putin understands Apple better than
we do, I would side with the Justice Department in this case (says Google’s AI), Windows 11,
Tesla, Ubuntu and macOS hacked at Pwn2Own 2023 and Chinese suspected of signal jamming
passenger jets. Read the details here.

In light of recent class action lawsuits claiming that companies have been reckless,
negligent and careless in protecting your visitors’ data, companies need to prepare to
defend themselves from these claims. Could you successfully defend yourself? If you
need help protecting your data, please contact us.


Mitch

March 19, 2023

  • Google Finds 18 Vulnerabilities in Exynos Chips
  • NSA Offers New Tips on Zero Trust and Identity
  • Nothing is a Problem Until it Bothers Me
  • ChipMixer Crypto Mixer Shut Down (temporarily) After Laundering $3 Billion
  • US Demands TikTok Sells or be Banned
  • Medical Device IoT Maker Notifying 1 Million Wearable Defibrillators of Breach
  • Hacks of Virtual Money Continue
  • Top Aviation Company Safran Group Vulnerable for a Year
  • Pair Hacks Cops, Steals Cop-Data

Security News Bites for the Week Ending March 19th, 2023:


This week’s security news bites: Pornhub, OnlyFans and Meta join new sextortion prevention
platform, The Musk-eteer loses thousands of schematics to hacker, hacked Russian TV warns
of nuclear attack, DoJ charges Chinese billionaire with massive crypto fraud and this could be a
first – serving court papers by NFT. Read the details here.

Bring your own device policies are a problem for your security team. With the
vulnerabilities in the Exynos chipset and possibly others, the problem just became a lot
worse. If you need help protecting your data, please contact us.


Mitch

720-891-1663

March 12, 2023

  • Employees Feed Sensitive Corporate Data to ChatGPT, Effectively Making it Public
  • Murky Consent, An Approach to the Fictions of Consent in Privacy Law
  • OWASP May Implode – Open Letter Demands Changes
  • National Cybersecurity Strategy Wants Software Makers to be Liable for Vulnerabilities
  • Cops Fighting Street by Street to Take Down Cyberattacks
  • VW Refuses to Locate Carjacked Car for Police Until Owner Pays for the Service
  • UK Introduces its Own Flavor of GDPR, Giving UK Businesses Two Sets of Rules to Follow
  • IAB Rolls Out 2023 Priorities
  • Hackers Steal Gun Owners’ Data from Gun Auction Website
  • Acer Confirms Breach; Hackers Offers 160 Gig of Their Data for Sale

Security News Bites for the Week Ending March 10th, 2023:


This week’s security news bites: even the DoJ thinks John Deere should let farmers fix their
tractors, thousand of pro-Trump bots attacking DeSantis, Hayley and dems, Twitter has second
outage in a week, yet another government caught spying on its own people and hackers
targeting law firms with malware. Read the details here.


The national cybersecurity strategy could change the software business forever. If you
sell software and have been comforted that you are not liable for damages caused
when your software doesn’t work as expected, that may soon change. If that concerns
you, please contact us.


Mitch

720-891-1663

March 5, 2023

  • BlackLotus Bootkit Can Infect Fully Patched Windows 11 System
  • Microsoft Announces Release of Windows 11 Moments 2
  • GitHub Announces ‘Secrets’ Scanning Feature now Available for all Public Repositories
  • Microsoft Releases Confusing Set of Windows Patches for Intel CPU Flaws
  • Understanding the Consumer Review Fairness Act of 2016
  • CISA Shares Key FIndings to Improve Monitoring and Hardening of Networks
  • Dish Network has … Some kind of IT Something
  • Beeline, the ‘Contingent Workforce’ Management Company Hacked, Data Leaked
  • WSJ Parent Outfoxed by Intruders for Years
  • Vendor of European Hotel Chain Left ElasticSearch Database Unprotected; Did Not Respond to Emails

Security News Bites for the Week Ending March 3rd, 2023

This week’s security news bites: hackers claim they breached T-Mobile more than 100 times in
2022, Google accused of destroying evidence after promising to stop, Ford seeks patent on
tech to disable your car if you miss a payment, Russia bans Telegram and other chat apps and
wiper malware goes global, so does its destruction.

Read the details here.

If you allow your employees – and contractors – to use personally owned computing
devices, you could become the next LastPass. If that concerns you, please contact us.


Mitch
www.CyberCecurity.com
www.TurnkeyCybersecurityAndPrivacySolutions.com
Mitch@CyberCecurity.com

720-891-1663