Showing posts with label GDPR. Show all posts
Showing posts with label GDPR. Show all posts

Saturday, December 7, 2019

Trend Micro reveals that Magecart group sets sights on Smith & Wesson, other high-profile stores

Trend Micro announced this week that the infamous credit card-skimming group Magecart has struck again. After incidents in the past few months that saw the threat actor go after customers of online shops and hotel chains, the group has set its sights on a new set of targets: high-profile stores, including firearms vendor Smith & Wesson (S&W).


According to security researcher, Willem de Groot of Sanguine Security, threat actors took advantage of the Black Friday rush by injecting credit card skimmers into the sites of a number of high-profile stores such as S&W. The group behind the attack injected the skimmer into S&W’s website on Nov. 27 — a couple of days before Black Friday, most likely in anticipation of the high volume of traffic going to the website. Note that the skimmer has been removed from the S&W store as of the time of writing.

The skimmer features an impressive list of capabilities, such as reverse engineering, a three-stage loader, and multiple layers of JavaScript obfuscation to hide its tracks. When a user visits the compromised website, the command-and-control (C&C) server initially sends harmless code — up until the actual payment process, when the skimmer begins its malicious routine. 


To make the skimming attack look more legitimate, a fake payment confirmation code is presented to the user. Behind the scenes, however, malicious code is already running, sneakily exfiltrating customer data such as payment information to the C&C server.

Sanguine Security notes that these attacks only worked for users which met various criteria, including using U.S.-based IP addresses, using non-Linux-based browsers, and not using the AWS platform.

The rise of Magecart highlights the need for vendors and other organizations to properly secure their websites and applications. Data theft via an attack such as the ones regularly performed by Magecart can mean monetary losses, not only for customers but also for the company whose website or application was compromised, especially given the potentially steep fines meted out to violators of data privacy laws such as the General Data Protection Regulation (GDPR).  


Organizations can minimize the chances of compromise by consistently applying the newest patches and updates to the software they use and by shoring up the authentication mechanisms provided to customers. Furthermore, it is recommended that IT and security teams proactively monitor their websites for any sign of malicious activities, such as unauthorized access or data exfiltration.

Thursday, December 5, 2019

Synack report showcases rapid growth, almost four times, in crowdsourced security testing for compliance

Synack released a new report Wednesday detailing a major cultural shift taking part among some of the world’s largest organizations and institutions. The 2020 State of Compliance and Security Testing Report reveals that a large percentage of organizations and institutions are moving toward a rigorous, continuous testing model to ensure compliance. 

As part of this shift toward continuous testing, organizations are utilizing crowdsourced security testing to achieve regulatory compliance and real security, with adoption expected to increase four-fold in 2020.

With new compliance frameworks such as GDPR and CCPA increasing the cost of a breach, organizations are racing to protect their data. In an increasingly connected, highly regulated and digital world, business leaders and decision makers are turning to outside vendors that can ramp up quickly in a cost effective manner. 


As a result, the crowdsourced security testing space--which has already gained credibility for its significantly better ROI than more traditional, less frequent, and less secure methods--has surpassed all estimates and will continue to do so in 2020 and beyond.

For the report, Synack surveyed leaders from more than 300 organizations representing a number of industries and verticals, including technology, government, healthcare, information technology, and financial services. 

In addition to helping identify a set of security and compliance best practices for a diverse set of industries, the report found security testing is becoming part of an organization’s normal routine rather than a once-a-year check of the box focused only on compliance. 


44 percent of organizations and institutions surveyed are performing security tests on a monthly or weekly basis, which suggests they are moving toward the more effective continuous model that crowdsourced solutions enable.

Other findings include 63 percent of organizations agree that the most common use case for external vendors is to identify and reduce vulnerabilities, which is encouraged by different compliance frameworks and best practice standards; 52 percent of organizations experience unwanted cost and complexity due to overlap in functionality from using multiple security vendors, which is caused by poor budget allocation and overlap in vendor capabilities; and 32 percent of compliance testing processes are expensive and difficult to scale, yet crowdsourced security testing solutions provide 147 percent higher ROI than a typical pen test and may decrease the burden of testing on organizations by reducing signal-noise ratio.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...