Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
51 UPS Stores' Point-of-Sale Systems Breached
Threaded  |  Newest First  |  Oldest First
PaulH835
100%
0%
PaulH835,
User Rank: Apprentice
8/21/2014 | 12:58:34 PM
Resonsibility and Repercussions
When a company has an IT security breech the company replutation can be humilated, its stock impacted, and of course it can suffer business loss. But there does not seem to be any legal liability. If a public company errors in its financial reporting we now hold its significant officiers legally responsibile. That has created immense focus on many areas of security left neglected in the past. It seems we may need similar incentives to motivate focus on protecting customer personal information at any point it comes into contact with a company's systems. 
securityaffairs
100%
0%
securityaffairs,
User Rank: Ninja
8/21/2014 | 1:27:08 PM
Re: Resonsibility and Repercussions
It's time to change the approach to cyber security, retailers most of all are seriously exposed to the risk of hack.

Anyway it will be interesting if the threat actor behind the attack is the same of the popular data breaches suffered by Target and other retailers.

Another element of interest is the real dimension of this data breach, how many customers were involved. 
Stratustician
100%
0%
Stratustician,
User Rank: Moderator
8/21/2014 | 1:00:47 PM
POS security?
I have to be the first to ask, do any of these retailers ever stop to think that POS systems require their own security outside perimeter devices (Firewalls, IDS/IPS) which are protecting the overall network?  These sytems, while they might be limited in their overall functionality, are one of the most critical endpoints and need to be secured.  How many more of these breaches are required before POS systems become part of the overall security policy?
RoyKelly2
50%
50%
RoyKelly2,
User Rank: Apprentice
8/21/2014 | 8:34:01 PM
Re: POS security?
Excellent point!  Just as in any network, each device and application needs some form of security, even if it is encrypting the data being transmitted.  anyone with even the least bit of security training was taught this, but are retailers aware?  I think not.  It is up to us who work in the security field to train them.
Robert McDougal
50%
50%
Robert McDougal,
User Rank: Ninja
8/25/2014 | 11:21:38 PM
Re: POS security?
It is getting there, but it will take time for retailers to catch up.  Until the Target breach many retailers viewed their POS systems as unaffected by malware.  Now they have to play catchup, which will take several years.
MarkSitkowski
100%
0%
MarkSitkowski,
User Rank: Moderator
8/21/2014 | 6:53:55 PM
POS can be made hack proof
The trick to this, which few US retailers appear to have grasped, is to not have anything worth stealing on their systems. As long as there are card numbers and PIN's, hackers will find it rewarding to steal them. Although this article specifically refers to this week's other Great Breach, Supervalu, it is relevant to all POS systems. Take a look at Finextra article 'The Flaw in POS terminal security. Solved'
vnewman2
100%
0%
vnewman2,
User Rank: Strategist
8/21/2014 | 7:16:58 PM
Re: POS can be made hack proof
Wow.  Just wow. I don't think people are shocked to hear about data breaches - it's the price we pay for doing business the way we do. But, undetected for 8 months. Egad.

But kudos for them for being - let's say - "somewhat" proactive when they received the government bulletin and having an audit done.   Too bad the victims won't know they are victims until their own information get used against them!


COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7121
PUBLISHED: 2020-09-23
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the LLDP (Link Layer Discovery Protocol) process in the switch. This applies to f...
CVE-2020-7122
PUBLISHED: 2020-09-23
Two memory corruption vulnerabilities in the Aruba CX Switches Series 6200F, 6300, 6400, 8320, 8325, and 8400 have been found. Successful exploitation of these vulnerabilities could result in Local Denial of Service of the CDP (Cisco Discovery Protocol) process in the switch. This applies to firmwar...
CVE-2020-10687
PUBLISHED: 2020-09-23
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS att...
CVE-2020-10714
PUBLISHED: 2020-09-23
A flaw was found in WildFly Elytron version 1.11.3.Final and before. When using WildFly Elytron FORM authentication with a session ID in the URL, an attacker could perform a session fixation attack. The highest threat from this vulnerability is to data confidentiality and integrity as well as system...
CVE-2020-14365
PUBLISHED: 2020-09-23
A flaw was found in the Ansible Engine, in ansible-engine 2.8.x before 2.8.15 and ansible-engine 2.9.x before 2.9.13, when installing packages using the dnf module. GPG signatures are ignored during installation even when disable_gpg_check is set to False, which is the default behavior. This flaw le...