This Week's [in]Security - Issue 220 | insecurity | Control Gap
Welcome to This Week’s [in]Security. DSSv4 timelines. Magecart. New breaches: CVS, Carnival...
6 min read
CG Blogger
:
Oct 15, 2018 12:00:00 AM
Welcome to This Week’s [in]Security. This week: a £120K USB stick, Google+ shuts down after breach, a very rare public admission of non-compliance with PCI, Facebook's troubles continue, outlawing weak passwords, controversial and conflicting stories about Chinese spy chips, shaming bad IoT, distrusting AIs, and creepy elevators.
Now here's this week’s selection of news, opinions, and research. Quickly skim annotated links organized by topic: compliance and payment security, breaches, regulation, bugs, privacy, hacking/malware, other security & risk, and more. We hope you enjoy and find them useful.
A very rare public admission of organizations failing PCI DSS https://www.cbc.ca/news/politics/security-data-shared-services-it-1.4848688
Facebook updates:
World's largest CCTV maker leaves at least 9 million cameras open to public viewing https://www.theregister.co.uk/2018/10/09/xiongmaicctvfail/
Magecart ecommerce skimmer injected into the “Shopper Approved” plugin https://www.theregister.co.uk/2018/10/09/magecartpaymentcard_malware/
Last week’s story about Chinese hardware implants story has generated a lot of follow-on and controversy
CG Blogger :
Jun 20, 2021 12:00:00 AM
Welcome to This Week’s [in]Security. DSSv4 timelines. Magecart. New breaches: CVS, Carnival...
CG Blogger :
Aug 15, 2021 12:00:00 AM
Welcome to This Week’s [in]Security. PCI SSF vs PA-DSS, Scoping Cloud, Cooperation, PCI Back to...
CG Blogger :
Oct 24, 2021 12:00:00 AM
Welcome to This Week’s [in]Security. PCI and payments: PCI & Ransomware, 3DS RFCs, PCI...