Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

1/30/2019
12:00 PM
50%
50%

Discover Issues New Cards Following Data Breach

The credit card company reports Discover's card systems were not involved in the breach, discovered in August 2018.

Discover Financial Services has alerted cardholders to a data breach but has not disclosed the extent of personal information compromised or the number of individuals affected.

The incident was detected by Discover on August 13, 2018, when the company learned user accounts may have been affected in a data breach. It reports the breach did not involve any Discover systems but the company is aware of a possible merchant data breach.

Financial firms are common targets for cybercrime, but this marks the second time in 2018 that Discover reported a security incident affecting users' credit cards to the California Attorney General, BleepingComputer points out. State law mandates that businesses working with residents must inform the attorney general if a data breach affects users' information.

In this case, the report states, there were two separate sample breach notifications filed with the attorney general's office, indicating there could be two collections of credit card data discovered, or two types of cards affected in the attack. Not all affected cardholders were issued a new card and account number.

Read more details here.

Dark Reading's Quick Hits delivers a brief synopsis and summary of the significance of breaking news events. For more information from the original source of the news item, please follow the link provided in this article. View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
1/31/2019 | 9:56:04 AM
"Not all affected cardholders were issued a new card and account number."
"Not all affected cardholders were issued a new card and account number."

....why?
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
1/30/2019 | 12:33:43 PM
Not disclosed the extent
THAT is the key mistake ---- we found something bad, something got out but we're not telling you yet because either we don't know yet  --- improbable really --- or we have to check first with PR and Legal to see how we spin the story so we are not legally exposed.   All in all - more lies until the truth is forced out of their mouths. 
NSA Appoints Rob Joyce as Cyber Director
Dark Reading Staff 1/15/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-20949
PUBLISHED: 2021-01-20
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in STM32 cryptographic firmware library software expansion for STM32Cube (UM1924). The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vul...
CVE-2020-25683
PUBLISHED: 2021-01-20
A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. A remote attacker, who can create valid DNS replies, could use this flaw to cause an overflow in a heap-allocated memory. T...
CVE-2020-25684
PUBLISHED: 2021-01-20
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query,...
CVE-2020-25685
PUBLISHED: 2021-01-20
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSS...
CVE-2020-35271
PUBLISHED: 2021-01-20
Employee Performance Evaluation System in PHP/MySQLi with Source Code 1.0 is affected by cross-site scripting (XSS) in the Employees, First Name and Last Name fields.