Cybersecurity Lawyer

128 Followers
174 Following
618 Posts
Lawyer focused on Cybersecurity and Privacy Regulation
http://linkedin.com/in/cybersecuritylawyer

A ruling in the U.S. Securities and Exchange Commission action against SolarWinds swept away much of the basis that the SEC relied upon in its amended complaint. Practically speaking, the focus by companies (public and private) on public security statements goes up, and those statements may become few and far between. Also, securities lawyers will be able to continue tried and true practices on cybersecurity securities disclosure. And, the focus on enhanced disclosure controls during an incident continues.

https://technologylaw.fkks.com:443/post/102je3h/sec-receives-major-blow-in-solarwinds-case?LinkSource=PassleApp

SEC Receives Major Blow in SolarWinds Case (via Passle)

On July 18, in a devastating opinion, a federal judge in the Southern District of New York dismissed the bulk of the claims the Securities and Exchange ...

Passle

As Genetic testing provider 23andMe faces multiple lawsuits for an October credential stuffing attack that led to the theft of customer data, the company has modified its Terms of Use to make it harder to sue the company.

https://www.bleepingcomputer.com/news/security/23andme-updates-terms-of-use-to-prevent-data-breach-lawsuits/

23andMe updates Terms of Use to prevent data breach lawsuits

As Genetic testing provider 23andMe faces multiple lawsuits for an October credential stuffing attack that led to the theft of customer data, the company has modified its Terms of Use to make it harder to sue the company.

BleepingComputer
Nissan Australia and New Zealand are dealing with a “cyber incident”, which likely translates as ‘paying the ransom with the help of the Australian government’. https://www.nissan.com.au/ #threatintel
Clop gang exploiting SolarWinds Serv-U flaw in ransomware attacks

The Clop ransomware gang, also tracked as TA505 and FIN11, is exploiting a SolarWinds Serv-U vulnerability to breach corporate networks and ultimately encrypt its devices.

BleepingComputer
Days after a data breach allowed hackers to steal 6.9 million 23andMe users' personal details, the genetic testing company changed its terms of service to prevent customers from suing the firm or pursuing class-action lawsuits against it. https://t.co/8R8Fa5kAgw
23andMe changes terms of service amid legal fallout from data breach

Its new terms of service may prevent customer from taking the company to court.

Axios
This is a longish read but I really go all in on what I think about the ransomware situation and what CitrixBleed signifies in this: https://doublepulsar.com/what-it-means-citrixbleed-ransom-group-woes-grow-as-over-60-credit-unions-hospitals-47766a091d4f

When the U.S. Securities and Exchange Commission filed a complaint against SolarWinds, they used a security statement from their website to make claims of securities fraud. The implications are concerning. #sec #cybersecurity

https://technologylaw.fkks.com/post/102iu09/the-sec-turns-false-marketing-into-securities-fraud

The SEC Turns False Marketing Into Securities Fraud (via Passle)

Between January, 2019, and December 2020, SolarWinds experienced one of the worst cybersecurity incidents in history. The SUNBURST supply chain cyberatt...

Passle
California is poised to issue the most sweeping cybersecurity regulation in the US and maybe the world. They are doing it through audit requirements. #cybersecurity #regulation #CCPA #audit https://technologylaw.fkks.com:443/post/102is68/cppa-draft-cybersecurity-audit-regulation-revisions-3-takeaways?LinkSource=PassleApp
CPPA Draft Cybersecurity Audit Regulation Revisions - 3 Takeaways (via Passle)

In advance of their December 8, 2023 meeting, the CPPA released additional revisions to the draft Cyberseurity Audit Regulations.  For a more complete d...

Passle

👀 ”Extremists keep trying to trigger mass blackouts — & that’s not even the scariest part
…exposing the reporting gaps between the state and federal agencies that oversee its security.”

…Law enforcement officials have blamed much of the rise in grid assaults on white nationalist and far-right extremists, who they say are using online forums to spread tactical advice on how to shut down the power supply.” https://www.politico.com/news/2023/09/10/power-grid-attacks-00114563

Extremists keep trying to trigger mass blackouts — and that’s not even the scariest part

Extremist groups are among those targeting the electricity network, exposing the reporting gaps between the state and federal agencies that oversee its security.

POLITICO
The Comedy of Errors That Let China-Backed Hackers Steal Microsoft’s Signing Key https://www.wired.com/story/china-backed-hackers-steal-microsofts-signing-key-post-mortem/
The Comedy of Errors That Let China-Backed Hackers Steal Microsoft’s Signing Key

After leaving many questions unanswered, Microsoft explains in a new postmortem the series of slipups that allowed attackers to steal and abuse a valuable cryptographic key.

WIRED