PCI Compliance in 60 days?

August 8th, 2007

Sounds too good to be true—is probably what some people are thinking. But that’s exactly what encryption vendor Ingrian Networks is offering to customers. With the rapid approach of the next PCI deadline on September 30, 2007, there has been a lot of discussion around compliance: what it really means to be compliant, what actions […]

TJX, Polo Data Surfaces In Another Credit Card Bust

July 10th, 2007

After more than $75 million in bogus credit card charges, several Cuban nationals in Florida have been arrested with more than 200,000 credit card account numbers, many of which came from the TJX and Polo Ralph Lauren data breaches, according to U.S. Secret Service officials, commenting on Monday’s announced arrests.
The numbers were sent to the […]

Many Retailers Taking Big Chances With Test Data

July 5th, 2007

Often transmitting unencrypted confidential customer data over weakly-protected connections, retailers risk privacy and create backdoors for cyber thieves. And yet, no one’s giving the merchants much of a choice.
When retailers make changes to any system that might impact credit-card processing—be it point-of-sale upgrades, OS patches, database changes, connection improvements, etc.—it needs to be tested.

For the […]

Inside Job? TJX cost of breach estimated at $1.6 billion

April 12th, 2007

Over the last couple of days there have been rumors whether the massive breach at TJX might have been an “inside-job”. This is probably fueled by the fact that the attacker apparently had access to the crypto keys within TJX’s data center. Whether it was an inside-job or not, doesn’t really matter at this point.

Protegrity […]

CERT takes a look at the insider threat

December 4th, 2006

CERT just posted this podcast that talks about the different type of attacks that come with insider threats. They break it down into three different kind of attacks:

Fraud
Identity Theft - Stealing Confidential Information
Sabotage
They also look at some of the specific attacks like setting up backdoor accounts or time and logic-bombs that […]

Escape from Patch Hell without patching - Blue Lane Technologies

November 30th, 2006

I’ve first learned about Blue Lane when they were still in stealth mode, they operated under a different company name first. Network Computing posted this Interview with Blue Lanes CEO Jeff Palmer. As he points out don’t confuse them with a patch management vendor.
I believe Blue Lane offers a very promising approach to solve […]

 
-->