<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">
<channel>
<title>GovInfoSecurity.com  RSS Syndication</title>
<link>https://www.govinfosecurity.com/rssFeeds.php?type=main</link>
<description>GovInfoSecurity.com RSS News Feeds on government information security news, regulations, blogs and education</description>
<pubDate>Tue, 02 Mar 2021 08:32:37 -0500</pubDate>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/govinfosecurity/com" /><feedburner:info uri="govinfosecurity/com" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:browserFriendly></feedburner:browserFriendly><item>
			<title>Why This Facebook Privacy Settlement Is Unusual</title>
			<link>https://www.govinfosecurity.com/this-facebook-privacy-settlement-unusual-a-16086</link>
			<guid>https://www.govinfosecurity.com/this-facebook-privacy-settlement-unusual-a-16086</guid>
			<description>&lt;img src="https://130e178e8f8ba617604b-8aedd782b7d22cfe0d1146da69a52436.ssl.cf1.rackcdn.com/this-facebook-privacy-settlement-unusual-imageFile-2-a-16086.jpg" align=right hspace=4&gt;&lt;b&gt;$650 Million Settlement Reached Under Illinois' Groundbreaking Biometrics Privacy Law&lt;/b&gt;&lt;br&gt;Ending six years of litigation, a federal judge has signed off on a $650 million settlement of a class-action lawsuit against Facebook for violating Illinois' groundbreaking privacy law that restricts collecting biometrics data. Here's why this case is so unusual.</description>
			</item>
			<item>
			<title>Indian Vaccine Makers, Oxford Lab Reportedly Hacked</title>
			<link>https://www.govinfosecurity.com/indian-vaccine-makers-oxford-lab-reportedly-hacked-a-16084</link>
			<guid>https://www.govinfosecurity.com/indian-vaccine-makers-oxford-lab-reportedly-hacked-a-16084</guid>
			<description>&lt;img src="https://130e178e8f8ba617604b-8aedd782b7d22cfe0d1146da69a52436.ssl.cf1.rackcdn.com/indian-vaccine-makers-oxford-lab-reportedly-hacked-imageFile-8-a-16084.jpg" align=right hspace=4&gt;&lt;b&gt;Incidents Spotlight Growing COVID-19-Related Cyberthreats&lt;/b&gt;&lt;br&gt;Two Indian vaccine makers and an Oxford University lab are reportedly among the latest targets of hackers apparently seeking to steal COVID-19 research data.</description>
			</item>
			<item>
			<title>Rockwell Controllers Vulnerable</title>
			<link>https://www.govinfosecurity.com/rockwell-controllers-vulnerable-a-16083</link>
			<guid>https://www.govinfosecurity.com/rockwell-controllers-vulnerable-a-16083</guid>
			<description>&lt;img src="https://130e178e8f8ba617604b-8aedd782b7d22cfe0d1146da69a52436.ssl.cf1.rackcdn.com/rockwell-controllers-vulnerable-imageFile-4-a-16083.jpg" align=right hspace=4&gt;&lt;b&gt;Flaw Could Enable Access to Secret Encryption Key&lt;/b&gt;&lt;br&gt;A critical authentication bypass vulnerability could enable hackers to remotely compromise programmable logic controllers made by industrial automation giant Rockwell Automation, according to the cybersecurity company Claroty. Rockwell has issued mitigation recommendations.</description>
			</item>
			<item>
			<title>Equifax CISO Jamil Farshchi on SolarWinds and Supply Chains</title>
			<link>https://www.govinfosecurity.com/equifax-ciso-jamil-farshchi-on-solarwinds-supply-chains-a-16081</link>
			<guid>https://www.govinfosecurity.com/equifax-ciso-jamil-farshchi-on-solarwinds-supply-chains-a-16081</guid>
			<description>&lt;img src="https://130e178e8f8ba617604b-8aedd782b7d22cfe0d1146da69a52436.ssl.cf1.rackcdn.com/equifax-ciso-jamil-farschi-on-solarwinds-supply-chains-imageFile-3-a-16081.jpg" align=right hspace=4&gt;&lt;b&gt;‘Supply Chain Security Is Broken, and It’s Time for a Change’&lt;/b&gt;&lt;br&gt;Jamil Farshchi has been there. As CISO of Equifax, he knows what it’s like to be a victim of a high-profile cyberattack. And he knows breached companies have a choice: "Are they going to be a force for good by helping the rest of the industry learn from their experience?"</description>
			</item>
			<item>
			<title>DoD: Notice of Proposed Rulemaking on Privacy Training</title>
			<link>https://www.govinfosecurity.com/agency-releases/dod-notice-proposed-rulemaking-on-privacy-training-r-2575</link>
			<guid>https://www.govinfosecurity.com/agency-releases/dod-notice-proposed-rulemaking-on-privacy-training-r-2575</guid>
			<description>The Department of Defense and two other government agencies have issued a proposed rule designed to help ensure that government contractors provide adequate privacy training to their staff members.</description>
			</item>
			<item>
			<title>NIST SP 800-61 Revision 1: Computer Security Incident Handling Guide</title>
			<link>https://www.govinfosecurity.com/agency-releases/nist-sp-800-61-revision-1-computer-security-incident-handling-r-2383</link>
			<guid>https://www.govinfosecurity.com/agency-releases/nist-sp-800-61-revision-1-computer-security-incident-handling-r-2383</guid>
			<description>Guidance on establishing processes to rapidly detect and respond to cyber incidents.</description>
			</item>
			<item>
			<title>NIST FIPS PUB 201-2: Personal Identity Verification of Federal Employees and Contractors DRAFT</title>
			<link>https://www.govinfosecurity.com/agency-releases/nist-fips-pub-201-2-personal-identity-verification-federal-r-2379</link>
			<guid>https://www.govinfosecurity.com/agency-releases/nist-fips-pub-201-2-personal-identity-verification-federal-r-2379</guid>
			<description>Specifying architecture and technical requirements for a common identification standard for federal employees and contractors.</description>
			</item>
			<item>
			<title>NIST SP 800-39: Managing Information Security Risk</title>
			<link>https://www.govinfosecurity.com/agency-releases/nist-sp-800-39-managing-information-security-risk-r-2353</link>
			<guid>https://www.govinfosecurity.com/agency-releases/nist-sp-800-39-managing-information-security-risk-r-2353</guid>
			<description>Organization, Mission and Information System View</description>
			</item>
			<item>
			<title>Live Webinar: Going Passwordless and Beyond - The Future of Identity Management</title>
			<link>https://www.govinfosecurity.com/webinars/live-webinar-going-passwordless-beyond-future-identity-management-w-3004</link>
			<guid>https://www.govinfosecurity.com/webinars/live-webinar-going-passwordless-beyond-future-identity-management-w-3004</guid>
			<description />
			</item>
			<item>
			<title>Illumination Summit: Poker &amp; Cybersecurity: A Game of Skill, Not Luck</title>
			<link>https://www.govinfosecurity.com/webinars/illumination-summit-poker-cybersecurity-game-skill-luck-w-3001</link>
			<guid>https://www.govinfosecurity.com/webinars/illumination-summit-poker-cybersecurity-game-skill-luck-w-3001</guid>
			<description />
			</item>
			<item>
			<title>Live Webinar | The Path to Zero Trust with Least Privilege &amp; Secure Remote Access</title>
			<link>https://www.govinfosecurity.com/webinars/live-webinar-path-to-zero-trust-least-privilege-secure-remote-access-w-2998</link>
			<guid>https://www.govinfosecurity.com/webinars/live-webinar-path-to-zero-trust-least-privilege-secure-remote-access-w-2998</guid>
			<description />
			</item>
			<item>
			<title>Live Webinar | You Can’t Stop Human Attackers without Human Reporting and Analysis</title>
			<link>https://www.govinfosecurity.com/webinars/live-webinar-you-cant-stop-human-attackers-without-human-reporting-w-2997</link>
			<guid>https://www.govinfosecurity.com/webinars/live-webinar-you-cant-stop-human-attackers-without-human-reporting-w-2997</guid>
			<description />
			</item>
			<item>
			<title>Analysis: Feds Crack Down on Cryptocurrency Scams</title>
			<link>https://www.govinfosecurity.com/interviews/analysis-feds-crack-down-on-cryptocurrency-scams-i-4846</link>
			<guid>https://www.govinfosecurity.com/interviews/analysis-feds-crack-down-on-cryptocurrency-scams-i-4846</guid>
			<description>The latest edition of the ISMG Security Report features an analysis of a federal crackdown on ICO cryptocurrency scams. Also featured: An update on the SonicWall hack investigation and the use of digital IDs to verify COVID-19 testing.</description>
			</item>
			<item>
			<title>Secure Patient Access to Health Records: The Challenges</title>
			<link>https://www.govinfosecurity.com/interviews/secure-patient-access-to-health-records-challenges-i-4844</link>
			<guid>https://www.govinfosecurity.com/interviews/secure-patient-access-to-health-records-challenges-i-4844</guid>
			<description>As the healthcare sector works to provide patients with secure access to their health information via smartphones and other devices, it must address critical identity and trust issues, says DirectTrust president and CEO Scott Stuewe.</description>
			</item>
			<item>
			<title>Analysis: Russia's Sandworm Hacking Campaign</title>
			<link>https://www.govinfosecurity.com/interviews/analysis-russias-sandworm-hacking-campaign-i-4842</link>
			<guid>https://www.govinfosecurity.com/interviews/analysis-russias-sandworm-hacking-campaign-i-4842</guid>
			<description>This edition of the ISMG Security Report features an analysis of the impact of a hacking campaign linked to Russia’s Sandworm that targeted companies using Centreon IT monitoring software. Also featured: a discussion of CIAM trends; a critique of Bloomberg's update on alleged Supermicro supply chain hack.</description>
			</item>
			<item>
			<title>Becoming a CISO: Many Paths to Success</title>
			<link>https://www.govinfosecurity.com/interviews/becoming-ciso-many-paths-to-success-i-4840</link>
			<guid>https://www.govinfosecurity.com/interviews/becoming-ciso-many-paths-to-success-i-4840</guid>
			<description>Mike Hamilton, founder and CISO of CI Security, followed an unusual path that led him to a career in cybersecurity. He says those who, like him, lack a formal education in security can build successful CISO careers.</description>
			</item>
			<item>
			<title>Not 'Above the Law' - Feds Target ICO Cryptocurrency Scams</title>
			<link>https://www.govinfosecurity.com/blogs/above-law-feds-target-ico-cryptocurrency-scams-p-3000</link>
			<guid>https://www.govinfosecurity.com/blogs/above-law-feds-target-ico-cryptocurrency-scams-p-3000</guid>
			<description>&lt;b&gt;$70 Million Allegedly Lost to Schemes Such as Bitcoiin2Gen Touted by Steven Seagal&lt;/b&gt;&lt;br /&gt;Authorities have accused Serbia-based scammers of capitalizing on the "initial coin offering" bubble that began in 2017, bilking global cryptocurrency investors out of $70 million via Bitcoiin2Gen and other supposed coins and hiring actor Steven Seagal to endorse them.</description>
			</item>
			<item>
			<title>SonicWall Was Hacked. Was It Also Extorted?</title>
			<link>https://www.govinfosecurity.com/blogs/sonicwall-was-hacked-was-also-extorted-p-2999</link>
			<guid>https://www.govinfosecurity.com/blogs/sonicwall-was-hacked-was-also-extorted-p-2999</guid>
			<description>&lt;b&gt;Hacker Claims SonicWall Paid Ransom; SonicWall Stays Silent&lt;/b&gt;&lt;br /&gt;SonicWall was recently attacked via a zero-day flaw in one of its own products. Curiously, SonicWall hasn't said much about the extent and damage of the breach since its announcement. But there are strong indications it may have been targeted by an extortion attempt.</description>
			</item>
			<item>
			<title>Data Breaches: ShinyHunters' Dominance Continues</title>
			<link>https://www.govinfosecurity.com/blogs/data-breaches-shinyhunters-dominance-continues-p-2998</link>
			<guid>https://www.govinfosecurity.com/blogs/data-breaches-shinyhunters-dominance-continues-p-2998</guid>
			<description>&lt;b&gt;Prolific Cybercrime Group Recently Tied to Breaches of E-Commerce and Dating Sites&lt;/b&gt;&lt;br /&gt;In 2020, a cybercrime operation known as ShinyHunters breached nearly 50 organizations, security researchers say. And this year, it shows no signs of slowing down - it's already hacked e-commerce site Bonobo and dating site MeetMindful.</description>
			</item>
			<item>
			<title>Bloomberg's Supermicro Follow-Up: Still No Chip</title>
			<link>https://www.govinfosecurity.com/blogs/bloombergs-supermicro-follow-up-still-no-chip-p-2997</link>
			<guid>https://www.govinfosecurity.com/blogs/bloombergs-supermicro-follow-up-still-no-chip-p-2997</guid>
			<description>&lt;b&gt;New Story Is Scant on Proof That China Implanted Chips on Motherboards&lt;/b&gt;&lt;br /&gt;Bloomberg has stood firm on its controversial story from two years ago asserting that China implanted a tiny chip on motherboards made by Supermicro. But rather than proving its contention in a follow-up, it may have inflicted more reputational damage upon itself.</description>
			</item></channel></rss>
