Securing PAN Using Keyed Cryptographic Hashing in PCI DSS v4.0.1
Securing PAN Using Keyed Cryptographic Hashing in PCI DSS v4.0.1
Posts about:
Securing PAN Using Keyed Cryptographic Hashing in PCI DSS v4.0.1
Welcome to This Week’s [in]Security. PCI and payments: Skimmers. Payments: New breaches: Anonymous, DeFi, Ikea. New Ransomware, Major outages, Follow-ups & Fall-out. Privacy: Health Canada, Facial recognition. Laws & Regs - Canada: Copyright. US: ISPs, Insurance. World: India. Standards: NIST, definitions. Defense - Training & events: space-cybersecurity. Password day. Kill-switch. Tools: MFA. Vulnerabilities, Advisories: Patching: F5, Cisco. Other: mental health apps, AV bugs, uClibc IoT, DNS poisoning, No MFA? Vulnerability research: Zero-Knowledge. Crypto-research: Quantum crypto. Cybercrime: Trends: Event log malware, Doh! Crime & Enforcement: BEC impact. Nation States and mercenaries. false-flags, sanctions, Spain & Pegasus, China. espionage, Other. Other Risks: General: Airtags, deepfakes, web3. Health, Safety, Environment, Disinformation, Economy. Russia v. Ukraine. NATO. Quantum computing, Innovation and more.
Welcome to This Week’s [in]Security. PCI and payments: PCI DSSv4 is live, Payments, New breaches: Ronin crypto, Globant, Lapsu$, Forged warrants, New Ransomware: Newfoundland, Conti. Major outages, DDoS. Follow-ups & Fall-out: Solarwinds, Royal Enfield. Atento, Privacy: Mystery Tracker, Never review patients! Laws & Regs - Canada: Online harms, Bill C-11. US: Facial recognition, Pro Codes Act, California. World: EU vs. Apple, crypto and. the other crypto. Standards: Hijacking standards. Defense: Chrome, Privid, IP reputation? Vulnerabilities, Zerodays: Chrome, Java Spring. Other: alerts, Pear PHP, 2FA bypass, GitLab, Defender IoT, Zlib, PLCs, Sandbox escape, Honda. Patching: CISA, Chrome, Edge, Sophos. Crypto-research: Proof-of-Stake. Cybercrime: Trends: Canada, NPM poisoning, Exchange. Nation States and mercenaries: FinFisher, Russia, China. Crime & Enforcement: identities, FBI, call centers. Other Risks: facebook, life-cycles, splinernet, spamming thyself. Disinformation, Health, Safety & Environment. 1 man 90 Jabs! Russia v. Ukraine. Quantum hype. Innovation and more.
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: Card Production. Carders. Training. New breaches, New Ransomware: bankruptcy, jail, DDoS. Major outages, Follow-ups & Fall-out: Lawyers vs Insurance, Accellion, Maryland. Privacy: Apple Private Relay. Laws & Regs - Canada: location data. US: DMCA, Carrier breach rules, DeFi, Facebook anti-trust, Celebrities sued. World: Europol, GDPR & Tech, China & tech. Standards: NIST drafts, Randomness. Defense: Protecting Open Source, Blocking stingray, ICS Security, C-Level, CSSLP. Vulnerabilities, Zerodays. Other Vulnerabilities: WordPress, React & NPM, MacOS, Defender, Patching: CISA must patch list, Adobe, AWS, Cisco. WordPress, L2TP. cryptography, Cybercrime: Trends: Self-inflicted, Multi-OS backdoor, Beware USB sticks. Nation States: Spyware for hire, Russia v Ukraine. Crime & Enforcement: Revil Arrests, Ukrainian arrests, Crypto theft. Other Risks: Great Resignation, QR fakes, Real war? Sowing division. Health, Safety & Environment: Tsunami, Tesla, Sharks, Wild-fires. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Innovation and more.
Welcome to This Week’s [in]Security. PCI and payments: PCI updates: FAQ, HSM. Magecart, Sportsgear, ATMs, PAX. Supply-Chain Backdoors: Log4J/Log4shell continues! Underfunding! New breaches: Scraping, Finite Recruitment, ProTemps, GumTree. New Ransomware: Kronos, Virginia, logistics, medical. Major outages: AWS. Follow-ups & Fall-out: schools, delays, Desjardins settles. Privacy: Staying signed in. Laws & Regs - Canada: Repair, Harms. US: Data Protection, National Security, Chinese Tech, Takedowns. World: trade disputes, Japan, UK, EU. Standards: NIST drafts. Defense: Webinars, bans, Bug bounties, Internet Hall-of-Fame. Vulnerabilities, Zerodays. Other Vulnerabilities: chips, Ubuntu, Dell, Firefox, Adobe, Apple, Chrome, and MS. ECDSA keys. Cybercrime: Trends, log-ins, Contact Forms, Anubis, Seedworm. Nation States. NSO, Huawei, Nobelium. Crime & Enforcement. Obit pirates, Arrests, Assassins. Other Risks: Data life cycles, AI diagnosis, Shadows, Printers, virtual assault, crypto currency. Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Learned; Impact; Covid Ugly; And more.
Welcome to This Week’s [in]Security. PCI and payments: Participating brands FAQ, and 8 updates. Magecart/skimmers, Brazil, Square. New breaches: Panasonic, Planned Parenthood. New Ransomware: Critical Infrastructure, Rideau Hall. Major outages, Follow-ups & Fall-out: Gravatar HIPB. Privacy: De-anonymization. Laws & Regs - Canada: health data, Huawei. US: FBI access, TSA, SEC, Biometrics. World: Product Security, Algorithm Transparency. Standards: NIST IoT, CISA mobile. Defense: Spam calls, AI understanding, Facial fuzz, attack maps, DRP, Old tech, Faraday cages. Vulnerabilities, Zerodays: Windows. Other Vulnerabilities: Printers, Routers, NSS Crypto, XS-Leaks, Passwords, zoom, Azure Sphere, Cloud Honeypot, CISA Hitachi & Zoho, Verizon. Cryptography HKDFs, PQC signatures & performance, Quantum Computing. Cybercrime: Trends, NABs, Trojans, AT&T, WRITE, Excel Addins. Nation States: diplomats, air-gaps, fake recruiters. Crime & Enforcement. Other Risks: Cyber-insurance exclusions, long game, China, misinformation, Meta/FB, amplification, shopping bots, Edge, Food, Hype? Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Learned; And more.
Welcome to This Week’s [in]Security. PCI and payments: CHD Truncation rules, Holiday warnings, Costco skimmer, Contactless. New breaches: Indian Securities, Robinhood. New Ransomware: WordPress Plugin, MediaMarkt, Ronmor, Queensland. Major outages: DDoS, Citrix, Google, Follow-ups & Fall-out: ICS & OT incident costs, NL Health, SolarWinds, Maxim Health, TTC. Privacy: Microsoft, Meta/FaceBook, PrivacyRaven, Rollercoaster. Laws & Regs - Canada: 5G. US: Crypto sanctions. Hack-back, NSO suit. World: No-hack pact. Defense: Webinars, Webinars. New certifications, Playbooks, Trojan Source, ClusterFuzzLite. Vulnerabilities, Zerodays: Other Vulnerabilities: Beg Bounties, AMD, Palo Alto, AWS, Siemens, BusyBox, Patch Tuesday, Zoho. Legacy MacOS, Web Cache Poisoning, Cybercrime: Trends: FBI email takeover, Initial Access Brokers, techniques, phones, gmail, HTML smuggling. Nation States: US accused, Iran, Korea. Crime: Big ransomware crackdown, Pegasus arrest, DNA and faces. Other Risks: Shadow IT, Azure mistakes, IT/OT, QRL-jacking, Biometrics, Pets, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; And more.
Welcome to This Week’s [in]Security. PCI and payments: PCI & Ransomware, 3DS RFCs, PCI Halloween, AI shoulder surfing, Rapid Dispute, V-cards, UP Express. New breaches: Argentina!, CoinMarketCap, Durham police. New Ransomware: New Ransomware, Challenges, Revil (Strikeback), BlackMatter. Follow-ups & Fall-out. Privacy: ISPs, Alexa, Lunch Money. Laws & Regs - Canada, Online Harms. US: Export restrictions, Sanctions & Crypto, Notifications, Supplychains, Missouri, Facebook, World: GDPR bypass. Standards: NIST KDF, HTTPA. Defense: Detection, Blackhat, L0PHTcrack, Win11. Vulnerabilities, Zerodays: Apple. Other Vulnerabilities: Chrome, CVEs, MFA, Chinese hacking contest, Kerberos, DCOM, Gummy Browser attack, Tesla, Health Apps. Cybercrime: Trends: Fake pentest contracts, more fakes, Discord, Microsoft, Buggy malware, Obfuscation, NPM JavaScript, Youtube. Nation States. Crime: $35M deepfake heist, no honor among thieves, jail. Other Risks: IoT, third-parties, economic supply-chains, bias, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Treatments; Immunity; Covid Ugly; Covid Compliance. And more.
Welcome to This Week’s [in]Security. PCI and payments: Remote assessments, magecart. New breaches: Thai visitors, Event Builder, Exchange. New Ransomware: Alert, Exabyte. Major outages: voip.ms, Trello. Follow-ups & Fall-out: Revil FBI Sting & backdoor cheat, Epik. Privacy: Amazon, Ant, creepy? QR, ewwww! Laws & Regs: Canada: US: Infrastructure, Facebook, Warrants. World: China bans crypto, Huawei, USB-C. Standards: CISA IPv6, NIST drafts. Defense: SSNs, AppSec, Quad, Ransomware action, Medical IoT, passwordless, tools, Cyber-insurance, Autodiscover, Bug bounties. Vulnerabilities, Zerodays: record zerodays, IoT, IoS, MacOS. Chrome. Other Vulnerabilities: OWASP update, API credentials, Ryzen, hack a mainframe demo, OpenOffice, Cisco, smartphones, Nagios, VMware. SonicWall, Routers, ROT13-NG. Cybercrime: Trends: Nation States. Crime: Mafia, DeFi, undone. Other Risks: Quantum Risk, Health, Safety & Environment. Covid-19: Spread, Curves, Waves, and Variants; Response; Immunity; Impact; Covid Ugly; And more.