Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
Newest First  |  Oldest First  |  Threaded View
Angelshab
50%
50%
Angelshab,
User Rank: Apprentice
2/22/2014 | 7:45:01 AM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
Very interesting article about Point-to-Sale system (POS System) in that I have seen plenty of these systems from Mall retailers and still using Lotus Notes.

Relevant URL (s) : http://www.cybernetman.com/en/...
mufidmmn
50%
50%
mufidmmn,
User Rank: Apprentice
2/18/2014 | 7:02:41 PM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
halu
larsamund
50%
50%
larsamund,
User Rank: Apprentice
2/13/2014 | 11:29:01 PM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
And of all those 40 business that were notified, nobody, customers, employees etc. has come forth with any information? Sounds a bit strange.
larsamund
50%
50%
larsamund,
User Rank: Apprentice
2/13/2014 | 11:26:16 PM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
Darn good point.
anon5511426393
50%
50%
anon5511426393,
User Rank: Apprentice
2/13/2014 | 11:00:44 PM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
LOL - does anyone else see the word "RSA" in there, and choose not to bother reading past it? Who cares what they "found" - we already know they themselves sell backdoors in their crypto to anyone with a spare $10M to pay. They violated the trust of the entire internet (then lied about it, badly, when we found out) - who could possibly be left that trusts them enough to still read anything they've got to say?
kjhiggins
50%
50%
kjhiggins,
User Rank: Strategist
1/31/2014 | 8:19:06 PM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
Correct.
TwistedBitLogic
50%
50%
TwistedBitLogic,
User Rank: Apprentice
1/31/2014 | 6:22:01 PM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
I'm assuming how this works is they notify the businesses and each business is responsible for the disclosure of the breach. It's not the researchers breach so they have no right or responsibility to disclose the information.
jwaters974
50%
50%
jwaters974,
User Rank: Apprentice
1/31/2014 | 4:37:13 PM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
Isn't it irresponsible to not say who the 40 retailers are? If I get hit, and you knew it would happen - you are an accomplice - if not a co-conspirator looking to have a big breach to enhance the security business. Unjust enrichment of RSA isn't it?
kjhiggins
50%
50%
kjhiggins,
User Rank: Strategist
1/31/2014 | 2:50:22 PM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
jwilfong300 RSA FirstWatch is not naming the companies publicly--they have notified them.
jwilfong300
50%
50%
jwilfong300,
User Rank: Apprentice
1/31/2014 | 2:29:05 PM
re: Point-Of-Sale System Attack Campaign Hits More Than 40 Retailers
What are the 40 companies?


News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23347
PUBLISHED: 2021-03-03
The package github.com/argoproj/argo-cd/cmd before 1.7.13, from 1.8.0 and before 1.8.6 are vulnerable to Cross-site Scripting (XSS) the SSO provider connected to Argo CD would have to send back a malicious error message containing JavaScript to the user.
CVE-2021-25315
PUBLISHED: 2021-03-03
A Incorrect Implementation of Authentication Algorithm vulnerability in of SUSE SUSE Linux Enterprise Server 15 SP 3; openSUSE Tumbleweed allows local attackers to execute arbitrary code via salt without the need to specify valid credentials. This issue affects: SUSE SUSE Linux Enterprise Server 15 ...
CVE-2021-27921
PUBLISHED: 2021-03-03
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
CVE-2021-27922
PUBLISHED: 2021-03-03
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation can be very large.
CVE-2021-27923
PUBLISHED: 2021-03-03
Pillow before 8.1.1 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation can be very large.