---
title: Business Information Security News of the Week, November 6, 2020
description: Check out the latest news on Cybersecurity and Risk Management
image: https://blog.omnistruct.com/hubfs/Cybersecurity_News_That_Matters.png
---

<https://omnistruct.com/>![Omnistruct Logo1200px](https://blog.omnistruct.com/hs-fs/hubfs/Omnistruct%20Logo1200px.png?width=300&height=64&name=Omnistruct%20Logo1200px.png)<https://omnistruct.com/>

- [Omnistruct Home](https://omnistruct.com/)

- [Omnistruct Home](https://omnistruct.com/)

Search for:

[Home](https://omnistruct.com) / Business Information Security News of the Week, November 6, 2020

# Business Information Security News of the Week, November 6, 2020

Posted by [Omnistruct Marketing](https://blog.omnistruct.com/author/omnistruct-marketing) on Nov 6, 2020 11:01:47 AM

- [Tweet](https://twitter.com/share)

 

| **Omnistruct Webinar** **Staying In Business After Hackers Succeed** Date: Nov 19, 2020 at 01:00 PM in Pacific Time (US and Canada) Speaker: George Usi |
| --- |

| Learn More and Register Now!   |
| --- |

![CyberSecurity News that Matters (1)](https://blog.omnistruct.com/hs-fs/hubfs/CyberSecurity%20News%20that%20Matters%20(1).png?upscale=true&width=1116&upscale=true&name=CyberSecurity%20News%20that%20Matters%20(1).png)

 

**Top Stories for this Week**

 

## <https://apnews.com/article/fbi-warns-ransomware-healthcare-system-548634f03e71a830811d291401651610>[Ransomware Advisory](https://home.treasury.gov/policy-issues/financial-sanctions/recent-actions/20201001?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://apnews.com/article/fbi-warns-ransomware-healthcare-system-548634f03e71a830811d291401651610>

The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) is issuing an advisory to alert companies that engage with victims of ransomware attacks of the potential sanctions risks for facilitating ransomware payments. This advisory highlights OFAC’s designations of malicious cyber actors and those who facilitate ransomware transactions under its cyber-related sanctions program. By U.S Department of the Treasury I October 1, 2020

 

## <https://securityboulevard.com/2020/10/what-tech-companies-need-to-know-about-the-safe-data-act/>[Cybersecurity as we know it will be 'a thing of the past in the next decade,' says Cloudflare's COO, as security moves towards a 'water treatment' model](https://www.businessinsider.com/cloudflare-coo-michelle-zatlyn-cybersecurity-enterprisee-tech-transformers-2020-10?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://securityboulevard.com/2020/10/what-tech-companies-need-to-know-about-the-safe-data-act/>

In 10 years, cybersecurity as we know it will no longer exist, according to Cloudflare cofounder and COO Michelle Zatlyn, who spoke at Business Insider's inaugural roundtable conversation featuring five Enterprise Tech Transformers. By Rosalie Chan I October 30, 2020

 

---

# **New Known Breaches in the Past Week**

## <https://www.consumeraffairs.com/news/dickeys-bbq-data-breach-compromises-millions-of-credit-card-records-101620.html?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN><https://www.analyticsinsight.net/the-five-biggest-data-breaches-of-the-21st-century/>[Data breach reports were down 51% in the first three quarters of 2020](https://www.securitymagazine.com/articles/93800-data-breach-reports-were-down-51-in-the-first-three-quarters-of-2020?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://www.analyticsinsight.net/the-five-biggest-data-breaches-of-the-21st-century/><https://www.consumeraffairs.com/news/dickeys-bbq-data-breach-compromises-millions-of-credit-card-records-101620.html?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

Risk Based Security released their 2020 Q3 Data Breach QuickView Report, revealing that the number of records exposed has increased to a staggering 36 billion. There were 2,935 publicly reported breaches in the first three quarters of 2020, with the three months of Q3 adding an additional 8.3 billion records to what was already the “worst year on record.” By Security Magazine | November 2, 2020

 

## <https://www.msn.com/en-us/news/us/data-breaches-hit-thousands-of-k-12-students-federal-watchdog-reports/ar-BB1a4vzh?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN><https://insights.dice.com/2020/10/22/secops-struggles-as-data-breaches-and-security-threats-soar/>[Aetna, city of New Haven hit with OCR fines after data breach](https://www.healthcareitnews.com/news/aetna-city-new-haven-hit-ocr-fines-after-data-breach?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://insights.dice.com/2020/10/22/secops-struggles-as-data-breaches-and-security-threats-soar/><https://www.msn.com/en-us/news/us/data-breaches-hit-thousands-of-k-12-students-federal-watchdog-reports/ar-BB1a4vzh?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

The U.S. Department of Health and Human Services' Office for Civil Rights leveraged $1,000,000 in fines against Aetna Life Insurance Company and $202,400 against the city of New Haven, Connecticut, to settle potential HIPAA violations. By Kat Jercich I November 02, 2020

 

## <https://www.newswire.ca/news-releases/stelco-announces-cybersecurity-attack-896349927.html>[JM Bullion, the leading online bullion dealer in the United States, has disclosed a data breach, hackers stole customers’ credit card information.](https://securityaffairs.co/wordpress/110290/cyber-crime/jm-bullion-hacked.html?web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://www.newswire.ca/news-releases/stelco-announces-cybersecurity-attack-896349927.html>

JM Bullion, the online retailer of products made of precious metals (i.e. gold, silver, copper, platinum, and palladium) has disclosed a data breach. By Pierluigi Paganini I November 02, 2020

 

## <https://threatpost.com/broadvoice-leaks-350m-records-voicemail-transcripts/160158/?web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN><https://securityboulevard.com/2020/10/pfizer-suffers-huge-data-breach-on-unsecured-cloud-storage/>[Hackers Selling a Total of 34 Million User Records Stolen From 17 Companies](https://gbhackers.com/34-million-user-records/?web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://securityboulevard.com/2020/10/pfizer-suffers-huge-data-breach-on-unsecured-cloud-storage/><https://threatpost.com/broadvoice-leaks-350m-records-voicemail-transcripts/160158/?web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

A threat actor is selling account databases containing a total of 34 million user records that they claim were stolen from seventeen companies during data breaches. By GURUBARAN S I November 2, 2020

 

## [Financial institutions can sue Sonic as a class over data breach, judge rules](https://www.reuters.com/article/databreach-sonic/financial-institutions-can-sue-sonic-as-a-class-over-data-breach-judge-rules-idUSL1N2HP2AF?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU) <https://threatpost.com/broadvoice-leaks-350m-records-voicemail-transcripts/160158/?web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

An Ohio federal judge has certified a class of financial institutions in a lawsuit over Sonic Corp’s 2017 data breach that exposed customers’ payment card data from 325 of the fast-food chain’s drive-in locations. By Sara Merken I November 4, 2020

 

## [Data breach impacts Chesapeake Regional Healthcare](https://www.13newsnow.com/article/news/local/data-breach-impacts-chesapeake-regional-healthcare/291-60ddb8cc-d073-4650-8d48-afe72178acd9?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU) <https://threatpost.com/broadvoice-leaks-350m-records-voicemail-transcripts/160158/?web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

Chesapeake Regional Healthcare has released details about a data breach that affected one of its data hosting service vendors. By 13News Now Staff I November 3, 2020

 

## [Ransomware Gang Claims International Casino Equipment Supplier As Latest Victim](https://www.forbes.com/sites/leemathews/2020/10/31/ransomware-gang-claims-international-casino-equipment--supplier-as-latest-victim/?sh=5d0c37ef68b2&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU) <https://threatpost.com/broadvoice-leaks-350m-records-voicemail-transcripts/160158/?web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

The REvil ransomware crew has struck again. The same cybercriminals who breached Grubman, Shire, Meiselas & Sacks this spring has claimed Gaming Partners International as its latest victim. By Lee Mathews I October 31, 2020

 

---

# **General Cybersecurity News**

 

## <https://smallbiztrends.com/2020/10/teaching-kids-about-cybersecurity.html?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>[Cybersecurity threats to corporate America are present now ‘more than ever,’ SEC chair says](https://www.cnbc.com/2020/11/02/secs-jay-clayton-on-cybersecurity-threats-to-corporate-america.html?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU) <https://smallbiztrends.com/2020/10/teaching-kids-about-cybersecurity.html?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

Securities and Exchange Commission Chairman Jay Clayton is telling corporate America it needs to get much more vigilant on security. By CNBC I November 02, 2020

 

## <https://www.helpnetsecurity.com/2020/10/19/cybersecurity-automation-jobs/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN><https://news.cuna.org/articles/118620-compliance-cybersecurity-and-covid---ncuas-cybersecurity-briefing>[Small can be ugly when it comes to third-party cybersecurity](https://betanews.com/2020/11/02/small-ugly-third-party-cybersecurity/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://news.cuna.org/articles/118620-compliance-cybersecurity-and-covid---ncuas-cybersecurity-briefing><https://www.helpnetsecurity.com/2020/10/19/cybersecurity-automation-jobs/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

New research from CyberGRX, based on data collected from the third parties on its exchange, finds that company size correlates with the maturity of cybersecurity programs, more specifically, as companies get smaller, they have fewer controls in place and less mature programs. By Ian Barker I November 02, 2020

 

| [![Need help evaluating your supplier's risk?](https://no-cache.hubspot.com/cta/default/5223782/8ed335ee-99c3-4878-adb7-81c640ac5e4d.png)](https://cta-redirect.hubspot.com/cta/redirect/5223782/8ed335ee-99c3-4878-adb7-81c640ac5e4d) |
| --- |

---

**Small Business Cybersecurity Concerns**

 

## <https://smallbiztrends.com/2020/10/protect-your-files-3-tips-small-businesses.html?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>[Cisco Advances Effort to Simplify Security](https://securityboulevard.com/2020/11/cisco-advances-effort-to-simplify-security/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU) <https://smallbiztrends.com/2020/10/protect-your-files-3-tips-small-businesses.html?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

Cisco Systems has updated SecureX, a free console it provides for its portfolio of security offerings, to include sample extended detection and response (XDR) workflows along with additional analytics and a refreshed Ribbon interface through which security administrators can manage multiple tasks. By Michael Vizard I November 2, 2020

 

---

## **MSP News**

 

## <https://smallbiztrends.com/2020/10/protect-your-files-3-tips-small-businesses.html?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>[Managed Cloud-Native Services on the Rise](https://containerjournal.com/topics/container-management/managed-cloud-native-services-on-the-rise/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU) <https://smallbiztrends.com/2020/10/protect-your-files-3-tips-small-businesses.html?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

A report published by Information Services Group (ISG) suggests the complexity of cloud-native technologies such as Kubernetes and emerging service mesh platforms is driving more organizations toward consuming managed services delivered via the cloud versus deploying these technologies on their own. By Mike Vizard I November 3, 2020

 

|  |
| --- |

---

## **CVE Announcements This Week**

## <https://www.insurancebusinessmag.com/us/news/cyber/us-cyber-insurance-market-at-exciting-crossroad-236496.aspx?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>[Oracle publishes rare out-of-band security update for WebLogic servers](https://www.zdnet.com/article/oracle-publishes-rare-out-of-band-security-update-for-weblogic-servers/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU#ftag=RSSbaffb68?&web_view=true) <https://www.insurancebusinessmag.com/us/news/cyber/us-cyber-insurance-market-at-exciting-crossroad-236496.aspx?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

Oracle has published on Sunday a rare out-of-band security update to address an incomplete patch for a recently disclosed vulnerability in Oracle WebLogic servers that is currently being actively exploited in real-world attacks. By Catalin Cimpanu | November 3, 2020

 

## <https://www.insurancejournal.com/magazines/mag-features/2020/10/19/586866.htm?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN><https://www.insurancebusinessmag.com/us/news/cyber/patching-up-problems-with-innovative-cyber-solutions-237100.aspx>[Google patches second Chrome zero-day in two weeks](https://www.zdnet.com/article/google-patches-second-chrome-zero-day-in-two-weeks/?&web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://www.insurancebusinessmag.com/us/news/cyber/patching-up-problems-with-innovative-cyber-solutions-237100.aspx><https://securityboulevard.com/2020/10/types-of-cyber-attacks-a-closer-look-at-common-threats/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--bZS74_WZe1IDlpd0Z6DuKMLZcZmRMDuUWzB2uaX6wFusI-z5BS8N513GN3u_X92ecTCaX>

Google has released a security update today for its Chrome web browser that patches ten security bugs, including one zero-day vulnerability that is currently actively exploited in the wild. By Catalin Cimpanu | November 2, 2020

 

## <https://www.forbes.com/advisor/homeowners-insurance/scary-scams/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN><https://www.bizjournals.com/baltimore/news/2020/10/27/city-reup-20m-cyber-insurance-post-ransomware.html>[CNAs and CVEs – Can allowing vendors to assign their own vulnerability IDs actually hinder security?](https://portswigger.net/daily-swig/cnas-and-cves-can-allowing-vendors-to-assign-their-own-vulnerability-ids-actually-hinder-security?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://www.bizjournals.com/baltimore/news/2020/10/27/city-reup-20m-cyber-insurance-post-ransomware.html><https://www.forbes.com/advisor/homeowners-insurance/scary-scams/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

Security researchers have highlighted the potential pitfalls of allowing software vendors to assign their own vulnerability report IDs. By Jessica Haworth I November 03, 2020

 

## <https://portswigger.net/daily-swig/cnas-and-cves-can-allowing-vendors-to-assign-their-own-vulnerability-ids-actually-hinder-security?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU>[New RegretLocker ransomware targets Windows virtual machines](https://www.bleepingcomputer.com/news/security/new-regretlocker-ransomware-targets-windows-virtual-machines/?&web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://portswigger.net/daily-swig/cnas-and-cves-can-allowing-vendors-to-assign-their-own-vulnerability-ids-actually-hinder-security?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU><https://www.forbes.com/advisor/homeowners-insurance/scary-scams/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

A new ransomware called RegretLocker uses a variety of advanced features that allows it to encrypt virtual hard drives and close open files for encryption. By Lawrence Abrams I November 03, 2020

 

## <https://portswigger.net/daily-swig/cnas-and-cves-can-allowing-vendors-to-assign-their-own-vulnerability-ids-actually-hinder-security?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU>[Adobe Warns Windows, MacOS Users of Critical Acrobat and Reader Flaws](https://threatpost.com/adobe-windows-macos-critical-acrobat-reader-flaws/160903/?web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://portswigger.net/daily-swig/cnas-and-cves-can-allowing-vendors-to-assign-their-own-vulnerability-ids-actually-hinder-security?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU><https://www.forbes.com/advisor/homeowners-insurance/scary-scams/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>

Adobe has fixed critical-severity flaws tied to four CVEs in the Windows and macOS versions of its Acrobat and Reader family of application software services. The vulnerabilities could be exploited to execute arbitrary code on affected products. By Lindsey O'Donnell I November 03, 2020

 

---

## **MSP News**

## <https://www.itproportal.com/features/embracing-managed-service-providers-in-the-post-covid-19-world-transformation/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--KhWN0AG2UFGn-zb5wkDgUJZVJtmwO35BjfOnhLw19R9e7bo9dOkMt8V-6EWwsl8R4yDb9><https://eurowire.co/coronavirus/259124/managed-it-service-providers-market-increased-international-trade-opening-new-opportunities-2021/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN>[How MSPs are generating revenue in today’s marketplace](https://www.itproportal.com/features/how-msps-are-generating-revenue-in-todays-marketplace/)<https://eurowire.co/coronavirus/259124/managed-it-service-providers-market-increased-international-trade-opening-new-opportunities-2021/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN><https://www.openpr.com/news/2148389/cyber-insurance-market-next-big-thing-major-giants-american?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--bZS74_WZe1IDlpd0Z6DuKMLZcZmRMDuUWzB2uaX6wFusI-z5BS8N513GN3u_X92ecTCaX>

We’ve witnessed a major seismic shift in the managed services landscape following the disruptive coronavirus pandemic. It has spurred many companies worldwide to adopt remote operations in the face of unpredictable economic conditions. More than ever before, companies are relying on MSPs to maintain business operations. By Grady Gausman | October 27, 2020

[![Learn how Omnistruct can help build the right cybersecurity solution!](https://cta-image-cms2.hubspot.com/ctas/v2/public/cs/il/?pg=8a994d80-0bbf-4120-8ddd-5bda423f0efc&pid=5223782&ecid=&hseid=&hsic=)](https://cta-image-cms2.hubspot.com/ctas/v2/public/cs/ci/?pg=8a994d80-0bbf-4120-8ddd-5bda423f0efc&pid=5223782&ecid=&hseid=&hsic=)

---

## **Regulations, Frameworks, and Controls**

## <https://www.zdnet.com/article/microsoft-october-2020-patch-tuesday-fixes-87-vulnerabilities/?&web_view=true&utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--KhWN0AG2UFGn-zb5wkDgUJZVJtmwO35BjfOnhLw19R9e7bo9dOkMt8V-6EWwsl8R4yDb9><https://www.welivesecurity.com/2020/10/19/microsoft-issues-two-emergency-windows-patches/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN><https://thehackernews.com/2020/10/mobile-messaging-apps.html>[The Top 10 Things to Know About CMMC](https://securityboulevard.com/2020/11/the-top-10-things-to-know-about-cmmc/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://thehackernews.com/2020/10/mobile-messaging-apps.html><https://www.openpr.com/news/2148389/cyber-insurance-market-next-big-thing-major-giants-american?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--bZS74_WZe1IDlpd0Z6DuKMLZcZmRMDuUWzB2uaX6wFusI-z5BS8N513GN3u_X92ecTCaX>

In recent years, the DoD has undergone a series of bold cybersecurity initiatives, from embracing responsible vulnerability disclosure to the trailblazing Hack the Pentagon initiative. Now, the DoD has a new risk in its sights: defense contractors. By Jacqueline von Ogden I November 3, 2020

## <https://www.bleepingcomputer.com/news/security/us-cyber-command-patch-windows-bad-neighbor-tcp-ip-bug-now/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--KhWN0AG2UFGn-zb5wkDgUJZVJtmwO35BjfOnhLw19R9e7bo9dOkMt8V-6EWwsl8R4yDb9><https://www.infosecurity-magazine.com/news/government-spooks-urge-firms-patch/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-8fsDeaDJXWhOIF7z7KPYs4pJcQE6jS2bSHDiAa8qxCzqgLEJsbp867yYzGBk85k-1aCHdN><https://cyware.com/news/malware-authors-leveraging-telegram-based-command-and-control-7010f17b>[6 Reasons to Increase Your Compliance Budget in 2021](https://securityboulevard.com/2020/11/6-reasons-to-increase-your-compliance-budget-in-2021/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz-_XrPXN6TbtNHZUleFtqz4RMO3UloYIuOmlsm1ssfbAJX8ribvor-63v9sHMoBA7i4O_DpU)<https://cyware.com/news/malware-authors-leveraging-telegram-based-command-and-control-7010f17b><https://www.bleepingcomputer.com/news/security/us-cyber-command-patch-windows-bad-neighbor-tcp-ip-bug-now/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--KhWN0AG2UFGn-zb5wkDgUJZVJtmwO35BjfOnhLw19R9e7bo9dOkMt8V-6EWwsl8R4yDb9>

Risk management and compliance are critical business capabilities that deserve adequate attention and resources in the current climate. An organization with weak risk management and compliance capabilities invites risks and regulatory trouble, but a strong compliance program can help a business thrive. By Jingcong Zhao I November 3, 2020

 

---

[![Would you like to learn more?](https://no-cache.hubspot.com/cta/default/5223782/03c006cc-7176-47cd-8bdc-5834c22e7c11.png)](https://cta-redirect.hubspot.com/cta/redirect/5223782/03c006cc-7176-47cd-8bdc-5834c22e7c11)

 

| Sincerely, **Omnistruct Marketing** 866-683-8827 [www.omnistruct.com](https://omnistruct.com/?utm_campaign=Cybersecurity%20News&utm_source=hs_email&utm_medium=email&_hsenc=p2ANqtz--bZS74_WZe1IDlpd0Z6DuKMLZcZmRMDuUWzB2uaX6wFusI-z5BS8N513GN3u_X92ecTCaX) --- Omnistruct, 2740 Fulton Avenue #101-02, Sacramento, CA 95821, USA, (866) 683-8827 [Unsubscribe                  ](https://email.omnistruct.com/business-information-security-news-october-9-2020#)[Manage preferences](https://email.omnistruct.com/business-information-security-news-october-9-2020#) |
| --- |

 Topics: [Omnistruct Newsletter](https://blog.omnistruct.com/tag/omnistruct-newsletter)

### Recent Posts

- [Cyber Security Programs](https://omnistruct.com/)
- [Why NIST CSF?](https://omnistruct.com/why-nist-csf/)
- [Pricing By Outcome](https://omnistruct.com/by-outcome/)
- [Pricing By Service](https://omnistruct.com/by-service/)
- [About](https://omnistruct.com/company/)
- [Contact](https://omnistruct.com/contact/)
- [Blog](https://omnistruct.com/blog/)
- [Partners](https://omnistruct.com/partners/)
- [News](https://omnistruct.com/news/)

![Omnistruct](https://blog.omnistruct.com/hubfs/Omnistruct_July2019%20/Images/Omnistruct1%20(1).png)

#### Get Social

<https://twitter.com/Omnistruct> <https://www.linkedin.com/company/omnistruct/>

Omnistruct Inc® - Copyright 2019 - Terms of Use - Privacy Policy