Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Visa: EMV Cards Drove 70% Decline in Fraud
Threaded  |  Newest First  |  Oldest First
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/25/2018 | 9:33:52 PM
EMV
Expect this figure to spike back up once there is broader use/acceptance/deployment of EMV tech. Hackers and attackers go for low-hanging fruit -- but EMV is hardly an impenetrable technology, security-wise.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 8:01:21 PM
Re: EMV
Expect this figure to spike back up once there is broader use/acceptance/deployment of EMV tech. That is my hope too, they need to stop providing magnetic cards to speed this adaption.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
2/26/2018 | 9:28:03 PM
Re: EMV
@Dr.T: Why do you hope this?

What I'm trying to communicate is that EMV is not invulnerable and bears its own vulnerabilty issues and potential exploits. Once you have much more broader penetration of EMV overall, you'll start seeing a greater focus on EMV attacks.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 7:59:31 PM
chip cards
Glad to hear chip card utilization going up in US, we are way behind Europe on this.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
2/26/2018 | 8:04:46 PM
96%?
Nearly all (96%) of US payments in December were done with EMV chip cards. 96% is a surprisingly high. Some of these cards have both magnetic strip and chip, they may still be using swipe.
Joe Stanganelli
0%
100%
Joe Stanganelli,
User Rank: Ninja
2/26/2018 | 9:30:22 PM
Re: 96%?
@Dr.T: Because (1) many consumers are still confused about EMV technology and (2) the processing of EMV chips takes much longer than standard swipe-card technology, many retailers have purposely declined to activate their EMV setups so as to keep their business moving more smoothly and more quickly. Even some major retailers purposely delayed their rollouts until such a time as consumers became more used to chip-insertion, letting consumers figure things out and scratch their heads on other retailers' time.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises Are Assessing Cybersecurity Risk in Today's Environment
The adoption of cloud services spurred by the COVID-19 pandemic has resulted in pressure on cyber-risk professionals to focus on vulnerabilities and new exposures that stem from pandemic-driven changes. Many cybersecurity pros expect fundamental, long-term changes to their organization's computing and data security due to the shift to more remote work and accelerated cloud adoption. Download this report from Dark Reading to learn more about their challenges and concerns.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-23258
PUBLISHED: 2022-01-25
Microsoft Edge for Android Spoofing Vulnerability.
CVE-2021-43799
PUBLISHED: 2022-01-25
Zulip is an open-source team collaboration tool. Zulip Server installs RabbitMQ for internal message passing. In versions of Zulip Server prior to 4.9, the initial installation (until first reboot, or restart of RabbitMQ) does not successfully limit the default ports which RabbitMQ opens; this inclu...
CVE-2022-23031
PUBLISHED: 2022-01-25
On BIG-IP FPS, ASM, and Advanced WAF versions 16.1.x before 16.1.1, 15.1.x before 15.1.4, and 14.1.x before 14.1.4.4, an XML External Entity (XXE) vulnerability exists in an undisclosed page of the F5 Advanced Web Application Firewall (Advanced WAF) and BIG-IP ASM Traffic Management User Interface (...
CVE-2022-23032
PUBLISHED: 2022-01-25
In all versions before 7.2.1.4, when proxy settings are configured in the network access resource of a BIG-IP APM system, connecting BIG-IP Edge Client on Mac and Windows is vulnerable to a DNS rebinding attack. Note: Software versions which have reached End of Technical Support (EoTS) are not evalu...
CVE-2022-23008
PUBLISHED: 2022-01-25
On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. No...