controlgap.com

Posts about:

Magecart (3)

This Week’s [in]Security – Issue 133 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: PCI more flexibility and staying ahead of threats. PCI and AWS. More Magecart. Carders take down carders. Mining social media. Canada Post resetting compromised passwords. ISO Privacy. China requiring facial scans for Internet access. Hiring Catch-22. Canada considering digital currency. MS Advanced Tamper Protection. Expanded bug bounties. Lots of patches. Biometric fails. More ransomware. IoT commodes - really. Bugs in cross platform code cause havoc. Playing with Trolls. Amazon says bye bye Larry. New Math. First all female spacewalk. And More.

Read More

This Week’s [in]Security – Issue 129 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: Big updates from the PCI Community meeting including DSS 4.0, P2PE 3.0, and Software Security. Lots of breaches. 8 cities via Click2Gov, Magecart revival and hotel booking sites. Equador (yes the country). Facebook suspends thousands of apps. FBI National Security letters and back-doors. New Mitre CWE top 25. Faster Wi-fi. Elections. AI fighting card fraud. Microsoft breaks defender. More bad Android apps. Fitbit catches up murder. Sentencing and sanctions. Russian's read FBI encrypted comms. Gene manipulation gone wrong. Crown Sterling demo flops. The climate , carbon footprints, and nukes. And more.

Read More

This Week’s [in]Security – Issue 118

Welcome to This Week’s [in]Security. This week: Major update on PCI SSF and SLC standards, Magecart, POS malware, ATM shimmers, 300M EA Games breach, Attunity AWS breach, Desjardins insider breach, cloud breaches at PCM, Fujitsu, Tata, NTT Data, Dimension Data, CSC and DXC, 10 years breached Equifax CIO jailed, everyone's spying: NSA, MySpace, and Spanish Scoer League, ballot security, NIST IoT, NTS (Secure Time), DoH, Huawei full of holes, NASA Pi hack, 10 years vulnerable, multiple nation-state hacks, more ransomware, multiple crypto-currency frauds and hacks, USB-sniffing dogs, Perception gaps, Boeing's terrible week, logic puzzles, the world's largest human Maple Leaf, and more.

Read More

This Week’s [in]Security – Issue 95 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: PCI's new Software Security Standard and PCI's new Software Security Framework, huge collection of compromised emails and passwords, using GDPR to go after tech companies, warrant needed to compel biometric access, hack a Telsa for profit, airline PNRs at risk, more IoT problems, even more Magecart, Payroll diversion BEC, $1.7M average breach cost, big game ransomware, DNA accuracy, proof AI can't solve everything, and three technologies to fight climate change.

Read More

This Week’s [in]Security – Issue 86 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: PCI compliance rates falling, DNA site breach of credentials, Jira AWS leak, IoT security regulation, problems with corporate auditing, DHS creates CISA, more Facebook fallout continues, new FACEbook security bug, ironic GPDR plugin compromised, Meltdown and Spectre-palooza, ATM hacking, a plague of  Magecart compromises,  new AWS security controls, browser add-ons and content security policies (CSP), swatter gets over 20 years, and ballot design issues.

Read More

This Week’s [in]Security – Issue 85 | insecurity | Control Gap

Welcome to This Week’s [in]Security. This week: breaches at FIFA, AMEX, Bankers Life, Ontario Cannabis Store/Canada Post, and HSBC,  warning about un-certified payment terminals, SEC has a new set of teeth, Stat's Canada data grab update, Consumer's Reports looks at IoT security, new laws in New Hampshire and Ohio, jailing CEOs, SSD encryption failure, more Magecart and other supply side scripting attacks, election security, and Remembrance Day.

Read More