U.K. electronics retailer Kitronik has told customers the Magecart gang managed to infiltrate the company’s payment system gaining access to some of their information.Attackers use POS malware to steal payment card data. The malware enabled some of 2013 and 2014's biggest breaches, including Target and Home Depot. Backoff and BlackPOS are two examples.The Register purportedly saw one of the emails Kitronik’s customer emails saying the malware was on the company website from August until mid-September and names, email addresses, card numbers, expiry dates, CVV codes and address were exposed.“Although we have a mechanism in place to alert us if the code on the website changes, this attack was very sophisticated and bypassed that code by making changes to the website database. The companies that take card payments on our behalf monitor trends and it was the payment gateway provider that notified us of a higher than normal amount of fraud, which triggered our investigation,” The Register quoted from the Kitronik email.
There are many ways to do DevSecOps, and each organization — each security team, even — uses a different approach. Questions such as how many environments you have and the frequency of deployment of those environments are important in understanding how to integrate a security scanner into your DevSecOps machinery. The ultimate goal is speed […]
It’s Cybersecurity Awareness Month, but security awareness is about much more than just dedicating a month to a few activities. Security awareness is a journey, requiring motivation along the way. And culture. Especially culture.That’s the point Proofpoint Cybersecurity Evangelist Brian Reed drove home in a recent appearance on Business Security Weekly.“If your security awareness program […]
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news