720-891-1663

Security News Update for the Week Ending April 19, 2024

Feds Give Another Chip Maker Subsidy to Build in US Last week the feds announced a subsidy to Taiwan Semi to build multiple chip plants (fabs) in Arizona. This week the feds announced, based on last year’s CHIPS Act, a subsidy to Samsung to build multiple plants in Texas. This creates a lot of construction […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Security News for the Week Ending December 10, 2021

NEW LOG4J JAVA LIBRARY ZERO-DAY IS BEING EXPLOITED IN THE WILD A proof of concept for a zero-day vulnerability in the very popular Apache Log4j Java library is being shared online. Log4j is used both in enterprises and in cloud services. Products from Apple, Amazon, Twitter and Steam, among others may be vulnerable to remote […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Verizon Loses Control of Customer Information

Different sources are reporting different numbers, but the personal information on between 6 million and 14 million Verizon Wireless customers has been exposed. The information includes name, address, phone number, general information on calls made to customer service and, in some cases, the user’s security PIN. The details of this are going to sound all […]

Continue reading → [DISPLAY_ACURAX_ICONS]

The Target Breach Story – How Did They Let This Out?

Krebs On Security has extensive reporting of an investigation by Verizon conducted starting a few days after the Target breach was announced. Target has refused to confirm or deny the report . One thing to consider.  We do not know how Brian (Krebs) got the report, so all we can do is speculate. This report, in […]

Continue reading → [DISPLAY_ACURAX_ICONS]

Verizon Customers Can Now Opt Out Of Supercookies

I have written before about Verizon (and AT&T) supercookies (see here and here, among others). Briefly, supercookies are tracking devices that Verizon adds to your web traffic from your phone after the traffic leaves your phone but before it reaches the intended web site. Verizon uses this traffic to figure out what sites you visit […]

Continue reading → [DISPLAY_ACURAX_ICONS]

PCI Compliance

Dark Reading reported on Verizon’s PCI compliance assessment and I think the numbers are interesting, but not terribly unexpected (see article).  The actual report, all 84 pages, is available here. Most of the time (maybe always), when a business has an assessment done by a third party assessor, that company will do an interim assessment […]

Continue reading → [DISPLAY_ACURAX_ICONS]