Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Payment Security Compliance Takes a Turn for the Worse
Newest First  |  Oldest First  |  Threaded View
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/27/2018 | 3:05:59 PM
IT 78%?
IT services had the highest levels of compliance (77.8%), Even IT is not enough in my view, this number should be way beyond 90% as they are supposed to know the trouble well enough.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/27/2018 | 3:03:58 PM
Re: financial services (47.9%)
So that fact that over 50% of them are failing to take best security practices towards compliance is a bit disheartening. As long as they protect themselves with an insurance they would not bother I would say.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/27/2018 | 3:02:55 PM
Re: financial services (47.9%)
These are the institutions that we trust to take care of our hard earned money. Yet they are the one not protecting it. The punishment may not be enough in my view.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/27/2018 | 3:01:35 PM
Re: financial services (47.9%)
However, what is alarming is how financial services is sitting below 50% for compliance. Yes that does not make sense at all. It should be cat higher than that.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
9/27/2018 | 3:00:31 PM
Worse?
I do not understand it could be worse first time in last six years, it was already worse, we keep hearing breached of credit cards.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
9/26/2018 | 9:59:15 AM
financial services (47.9%)
I am not surprised at the decline. The drop from 2016 to 2017 seems negligable. However, what is alarming is how financial services is sitting below 50% for compliance. These are the institutions that we trust to take care of our hard earned money. So that fact that over 50% of them are failing to take best security practices towards compliance is a bit disheartening.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Data Breaches Affect the Enterprise
Data breaches continue to cause negative outcomes for companies worldwide. However, many organizations report that major impacts have declined significantly compared with a year ago, suggesting that many have gotten better at containing breach fallout. Download Dark Reading's Report "How Data Breaches Affect the Enterprise" to delve more into this timely topic.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-43783
PUBLISHED: 2021-11-29
@backstage/plugin-scaffolder-backend is the backend for the default Backstage software templates. In affected versions a malicious actor with write access to a registered scaffolder template is able to manipulate the template in a way that writes files to arbitrary paths on the scaffolder-backend ho...
CVE-2021-43786
PUBLISHED: 2021-11-29
Nodebb is an open source Node.js based forum software. In affected versions incorrect logic present in the token verification step unintentionally allowed master token access to the API. The vulnerability has been patch as of v1.18.5. Users are advised to upgrade as soon as possible.
CVE-2021-43787
PUBLISHED: 2021-11-29
Nodebb is an open source Node.js based forum software. In affected versions a prototype pollution vulnerability in the uploader module allowed a malicious user to inject arbitrary data (i.e. javascript) into the DOM, theoretically allowing for an account takeover when used in conjunction with a path...
CVE-2021-43788
PUBLISHED: 2021-11-29
Nodebb is an open source Node.js based forum software. Prior to v1.18.5, a path traversal vulnerability was present that allowed users to access JSON files outside of the expected `languages/` directory. The vulnerability has been patched as of v1.18.5. Users are advised to upgrade as soon as possib...
CVE-2021-34800
PUBLISHED: 2021-11-29
Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147