Carousel

Spoofed Trend Micro Email Leads to Malicious Site

November 23rd, 2009

 - Trend Micro threat analysts recently unearthed spammed messages that purported to have come from Trend Micro. Targeting trusted organizations is not an uncommon technique, used by cybercriminals when carrying out spam campaigns.  In (continue reading...)

This Halloween, Enjoy the Treats but Be Wary of Online Tricks

October 30th, 2009

 - We often associate Halloween with pumpkins and costumes but for cybercriminals it’s merely another avenue to exploit, steal, and trick users into giving away their personal identities. Treats are fun but we all need to (continue reading...)

Processor Best Practices You Can Use

October 29th, 2009

 - Visa just released its Cardholder Data Security Best Practices for VisaNet Processors. I think there are some things in this document that you as merchants can use, too. Here are a few (continue reading...)

Windows 7? No Problem for Trend Micro Users

October 23rd, 2009

 - Microsoft’s new OS, Windows 7, was made available to the general public earlier today. To say that this was eagerly anticipated is an understatement, however, as in the United Kingdom, pre-orders on Amazon for copies exceeded both (continue reading...)

Is Your Web App Secure? Really?

October 20th, 2009

 - The Web Application Security Consortium (WASC) today announced the findings of its WASC Web Application Security Statistics Project 2008. Their objective was to pool data from a number of sources to assess (continue reading...)

PCI Merchant Levels Cleared or Confused?

October 20th, 2009

 - Branden Williams writes that Visa and MasterCard have pulled the "reciprocity" from their merchant level definitions (see here). For those of you not up on all the details, I'll try and explain (continue reading...)

Your Campus Hotel and PCI

October 6th, 2009

 - I have been working with and talking to a number of schools recently that operate hotels on campus. These hotel operations face particular PCI compliance challenges due to the nature of the hotel business. (continue reading...)

Windows Live Hotmail User Information Leaked

October 6th, 2009

 - A quick heads-up to all users of Microsoft’s Windows Live Hotmail email service: a list of at least 10,000 user names (and the corresponding passwords) of the second-largest email service after (continue reading...)

POS PIN-entry Vulnerabilities

October 5th, 2009

 - Those of you with PIN-entry devices (PEDs) at your point of sale (POS) should take a look at Visa's POS PIN Entry Device Vulnerabilities white paper out today. Visa reports on the (continue reading...)

PCI Community Meeting – Day 2

September 24th, 2009

 - Day 2 of the PCI Community Meeting is just concluded. We heard from former Representative Tom Davis about the prospects for federal legislation addressing cyber security. My take from the presentation is (continue reading...)

PCI Community Meeting – Day 1 at The Listening Meeting

September 23rd, 2009

 - I'm here in Las Vegas with 650 of my closest PCI friends, including Tom Davis of Indiana Univeristy (For those of you who forgot, we represent NACUBO which is a Participating Organization). The PCI (continue reading...)

UPDATED: More on Choosing A QSA

September 10th, 2009

 - I previously referenced an article on how to select a QSA. Now there is another article (4 Ways to Get the Most From your PCI QSAs) at Computerworld with similarly good advice. (continue reading...)

Real Cost of a Security Breach?

September 7th, 2009

 - There is a standard benchmark used to calculate the cost of a security breach: about $200 per account compromised. But often the compromise is not based on, say, compromised payment cards. Sometimes (continue reading...)

I’m a QSA!

September 1st, 2009

 - OK, time for a little personal news here... Today it became official: I'm a QSA (Qualified Security Assessor). Until I joined 403 Labs, I could be a PCI consultant, but not a (continue reading...)

Bob Russo Comments on PCI and Recent Breaches

September 1st, 2009

 - The recent breaches and indictments have generated a lot of comments about PCI, many of them unfavorable. On one side are those that say they were "certified" as PCI compliant, but got breached anyway; (continue reading...)

Time to be Careful

August 28th, 2009

 - Today's required reading is an opinion piece in the New York Times "Time to be Afraid of theWeb" The article assesses the current state of Internet security and concludes that you don't have (continue reading...)

Keeping Informed on PCI Just Got Easier

August 27th, 2009

 - It can be really tough staying on top of developments in PCI DSS, card brand rules, risks, threats, and everything else we are supposed to know about but don't have the time to follow. (continue reading...)

Choosing a QSA…How Do YOU Do It?

August 26th, 2009

 - Nearly all schools validate their PCI compliance using a Self-Assessment Questionnaire (SAQ). Nevertheless, many schools also hire a QSA to help them in the process, either with training, conducting a PCI gap analysis, designing (continue reading...)

WALEDAC Celebrates Independence Day, Too

July 4th, 2009

 - Holidays are almost always the target of significant spam and malware attacks, and this Fourth of July is turning out to be little different. A new WALEDAC variant – detected as WORM_WALEDAC.DU – has (continue reading...)

Copyright © 2012 The Security Blog. All rights reserved.