< ciso
brief />
Tag Banner

All news with #encryption at rest tag

47 articles · page 2 of 3

Microsoft Provides BitLocker Keys to FBI Under Orders

🔐 Microsoft has the technical ability to release BitLocker recovery keys to the FBI when presented with appropriate court orders, a capability reportedly exercised roughly twenty times per year. While users can keep recovery keys only on their own devices, Microsoft advises storing them on its servers for convenience. That cloud backup simplifies recovery after lost credentials or device lockouts but also makes keys accessible to law enforcement through subpoenas or warrants.
read more →

Google Cloud Single-tenant Cloud HSM Now Generally Available

🔐 Single-tenant Cloud HSM is now generally available in the U.S. and EU, offering dedicated, hardware-enforced key isolation for regulated workloads. It provides FIPS 140-2 Level 3 validated Marvell LiquidSecurity HSMs, quorum-based administration, and the ability to revoke Google access to make keys unavailable. Google manages provisioning and high availability while customers retain root key control and can provision clusters in minutes using gcloud.
read more →

Update Server-Side Encryption Type for Amazon S3 Objects

🔒 You can now change the server-side encryption type of encrypted objects in Amazon S3 without moving data. Use the UpdateObjectEncryption API to atomically change encryption keys across any object size or storage class, and run it at scale with S3 Batch Operations to standardize entire buckets while preserving object properties and Lifecycle eligibility. The capability supports migrating from SSE-S3 to SSE-KMS, swapping customer-managed KMS keys, and enabling S3 Bucket Keys to reduce KMS requests. The API is available in all AWS Regions via the AWS Management Console and SDKs.
read more →

Microsoft Handed BitLocker Keys to US Law Enforcement

🔐 Microsoft complied with a US search warrant in early 2025 and provided BitLocker recovery keys stored on its servers to investigators probing alleged COVID unemployment fraud in Guam. Because many Windows installations back up recovery keys by default to Microsoft cloud services, those keys were retrievable when legally compelled. Experts stress this is a custody and governance issue rather than a cryptographic failure of BitLocker, and recommend restricting default cloud backups, enforcing strict admin controls, and redirecting keys to on‑premises or enterprise key vaults where possible.
read more →

EMR Serverless Supports AWS KMS Customer-Managed Keys

🔒 Amazon EMR Serverless now supports encrypting local disks with AWS KMS customer managed keys (CMKs), enabling customers to adopt CMKs instead of default AWS-owned keys for greater encryption control. You can use CMKs from the same account or from another account and apply them at the application level or per job run and interactive session. This capability is supported on new and existing EMR Serverless applications across all supported EMR release versions and is available in all Regions, including AWS GovCloud (US) and China.
read more →

Unencrypted TETRA Radio Leaves German Critical Sites Exposed

⚠️ Many German critical infrastructure organizations are transmitting over unencrypted digital radio, creating an easily exploitable interception vector. Wirtschaftswoche reports that prisons, airports and energy providers are operating TETRA networks without encryption—often citing cost reasons—while police networks remain multi-layer encrypted. AG Kritis calls the situation a security-policy disgrace, warning that a laptop, free software and modest technical skill are sufficient to eavesdrop and capture confidential information, potentially endangering supply security and lives.
read more →

Ransomhouse Upgrades: Dual-Encryption Attacks on VMware

🔒 Palo Alto Networks warns that the Jolly Scorpius group has significantly upgraded its Ransomhouse RaaS with a dual-key encryption trojan called Mario, combining a 32-byte primary key and an eight-byte secondary key that make recovery extremely difficult. Attack automation via MrAgent targets VMware ESXi hypervisors, enabling rapid cluster-wide encryption and firewall neutralization. The campaign primarily targets German companies; recommended mitigations include hardening virtual environments, immutable backups, and strict network segmentation.
read more →

Hardware-accelerated BitLocker arrives in Windows 11

🔒 Microsoft is rolling out hardware-accelerated BitLocker in Windows 11, offloading bulk cryptographic operations to SoC components with HSMs and TEEs to reduce CPU usage and improve I/O performance. The feature defaults to XTS-AES-256 on supported NVMe systems and initially appears on Intel Core Ultra Series 3 platforms. It’s available in Windows 11 24H2 (with September updates) and 25H2; verify mode with manage-bde -status.
read more →

Passwd: Google Workspace Password Manager Walkthrough

🔒 Passwd is a Google Workspace–focused password manager that emphasizes practical, business-oriented credential storage and seamless integration with Google Workspace. It uses client-side AES-256 encryption and a zero-knowledge design so only users can decrypt stored secrets, while SOC 2 and GDPR readiness support regulated environments. Administrators gain centralized controls, role-based permissions, audit logs, and scalable deployment options including hosting inside a customer Google Cloud project. Cross-platform access via web, browser extensions, and mobile apps plus autofill, password generation, and activity tracking make it a low-friction choice for teams committed to Google tools.
read more →

AWS Payment Cryptography Now Available in Hyderabad, Paris

🔐 AWS Payment Cryptography is now available in Asia Pacific (Hyderabad) and Europe (Paris), enabling customers with latency-sensitive payment applications to deploy or migrate cryptographic operations closer to their workloads. The fully managed service simplifies payment-specific cryptographic operations and key management, scales elastically, and is assessed for PCI PIN and PCI P2PE compliance. Organizations can reduce dependence on dedicated payment HSMs and use these regions for additional multi-region high availability.
read more →

Passwork 7: Self-hosted Password and Secrets Manager

🔐 Passwork 7 is a self-hosted password and secrets manager designed for enterprise teams, combining a user-facing password vault with a programmatic secrets management system. It introduces a flexible vault architecture (user, company, and custom vault types), granular RBAC, secure internal and external sharing, and comprehensive audit trails. The platform supports SSO/LDAP, an API-first model with a Python connector, CLI and Docker deployment, and a zero-knowledge encryption mode to keep data encrypted client-side. Passwork 7 targets organizations seeking unified human and machine credential governance with self-hosting and compliance controls.
read more →

Amazon Aurora adds PostgreSQL minor versions and DDM

🔒 Amazon Aurora PostgreSQL-Compatible Edition now supports minor PostgreSQL releases 17.6, 16.10, 15.14, 14.19, and 13.22. The update introduces Dynamic Data Masking (DDM) for versions 16.10 and 17.6, masking column values at query time via role-based policies without changing stored data. It also adds a shared plan cache and delivers improved performance, faster RTO, and better Global Database switchover behavior. These versions are available in all commercial AWS Regions and AWS GovCloud (US); you can create new clusters or upgrade existing databases through the RDS console.
read more →

Amazon Aurora PostgreSQL Adds Dynamic Data Masking

🔒 Amazon Aurora PostgreSQL-Compatible Edition now supports dynamic data masking using the new pg_columnmask extension, enabling column-level protection at query time. The extension complements PostgreSQL row-level security and column grants by letting administrators define SQL-based masking policies that alter how data appears to users without changing stored values. Policies can use built-in or user-defined functions to hide, partially mask, or transform data, and multiple policies can be applied with weighted precedence. pg_columnmask protects results across WHERE, JOIN, ORDER BY, and GROUP BY clauses and is available for Aurora PostgreSQL 16.10+ and 17.6+ in all regions.
read more →

AWS S3 bucket-level setting to standardize encryption

🔒 Amazon S3 now provides a bucket-level default encryption configuration to enforce SSE-S3 or SSE-KMS for all write requests, allowing organizations to standardize server-side encryption types across buckets. The PutBucketEncryption API update lets you disable SSE-C on specific buckets or in CloudFormation templates. This capability is available in all AWS Regions and configurable via Console, SDK, API, or CLI. It helps simplify compliance and reduce misconfiguration risk.
read more →

Google Announces Private AI Compute for Cloud Privacy

🔒 Google on Tuesday introduced Private AI Compute, a cloud privacy capability that aims to deliver on-device-level assurances while harnessing the scale of Gemini models. The service uses Trillium TPUs and Titanium Intelligence Enclaves (TIE) and relies on an AMD-based Trusted Execution Environment to encrypt and isolate memory on trusted nodes. Workloads are mutually attested, cryptographically validated, and ephemeral so inputs and inferences are discarded after each session, with Google stating data remains private to the user — 'not even Google.' An external assessment by NCC Group flagged a low-risk timing side channel in the IP-blinding relay and three attestation implementation issues that Google is mitigating.
read more →

Proving Data Sovereignty: Controls, Keys, and Audits

🔒 The article argues that data sovereignty commitments like Project Texas must be supported by auditable, technical evidence rather than marketing promises. It prescribes five concrete, testable controls — brokered zero‑trust access, in‑region HSM keys, immutable WORM logs, continuous validation, and third‑party attestation — plus measurable metrics to prove compliance. A 90‑day blueprint and emerging AI automation are offered to operationalize verification and produce regulator‑ready, reproducible evidence.
read more →

FinWise Breach Highlights Encryption and Insider Risk

🔒 The FinWise data breach involved a former employee who retained credentials and accessed systems on May 31, 2024, exposing personal records for 689,000 American First Finance customers. The intrusion remained undetected until June 18, 2025, prompting lawsuits alleging inadequate encryption and weak security governance. Experts say robust protection requires not only encryption but effective key management, strict access controls, and proactive monitoring. Vendor solutions such as D.AMO are presented as integrated platforms combining encryption, an isolated KMS, and centralized control to mitigate insider risk.
read more →

Amazon RDS for SQL Server: KMS Encryption for Native Backups

🔐 Amazon RDS for SQL Server now supports encrypting native backup files (.bak) stored in Amazon S3 using server-side encryption with AWS KMS keys (SSE-KMS). By default, native backups remain encrypted with Amazon S3-managed keys (SSE-S3), and customers can opt to apply their own KMS key for additional protection and key control. To enable the feature, update the KMS key policy to grant the RDS backup service access and specify the parameter @enable_bucket_default_encryption in the native backup stored procedure. This capability is available in all AWS Regions where Amazon RDS for SQL Server is offered.
read more →

Google transitions to cryptographic media sanitization

🔐 Google will transition in November 2025 from overwrite-based media sanitization to cryptographic erasure, using default encryption to render data unrecoverable by securely deleting encryption keys rather than overwriting drives. Recognized in NIST SP 800-88, this method is faster and better suited to modern storage technologies. Google says it will apply a layered, defense-in-depth model with independent verification, key rotations, and protections for device secrets to maintain strong safeguards.
read more →

Amazon SNS Adds FIPS 140-3 Endpoints in US and Canada

🛡️ Amazon Simple Notification Service (Amazon SNS) now supports additional FIPS 140-3 validated endpoints across several AWS Regions in the United States and Canada. These FIPS-compliant endpoints allow organizations, including federal contractors, to meet requirements to use validated cryptographic modules when encrypting sensitive data. The new endpoints support requests over dual-stack public and VPC endpoints and are available in US East (N. Virginia and Ohio), US West (N. California and Oregon), Canada (Central and Calgary) and AWS GovCloud (US). Customers can use these endpoints to run SNS workloads that require FIPS 140-3 validated cryptography within the listed regions.
read more →