Vulnerabilities / Threats //

Vulnerability Management

11/19/2018
11:30 AM
Steve Zurier
Steve Zurier
Slideshows
Connect Directly
Twitter
RSS
E-Mail
50%
50%

7 Holiday Security Tips for Retailers

It's the most wonderful time of the year - and hackers are ready to pounce. Here's how to prevent them from wreaking holiday havoc.
Previous
1 of 8
Next

Image Source: Pixabay

Image Source: Pixabay

Black Friday and Cyber Monday are at hand, which means retailers have been working extra hard behind the scenes to ensure their websites and security-savvy customers are well-protected from the cyber Grinches.

Indeed, 50% of 2,011 US consumers recently surveyed by Sophos said they are very concerned about getting hacked and would not buy from a retailer that has been in the news for not protecting personal information either online or in-store. Another 32% said they are somewhat concerned and would consider an alternative company to buy from instead.

"First and foremost, retailers have to help their customers not become victims," says Chet Wisnieswki, principal research scientist at Sophos. "They have to understand that there are criminals out there trying to impersonate their company."

What can retailers do to keep their customers and themselves safe this holiday season? For the answers, we turned to Wisniewski, along with Russell Schrader, executive director of the National Cyber Security Alliance, and Adam Isles, a principal at The Chertoff Group.

 

Steve Zurier has more than 30 years of journalism and publishing experience, most of the last 24 of which were spent covering networking and security technology. Steve is based in Columbia, Md. View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PaulChau
50%
50%
PaulChau,
User Rank: Apprentice
12/27/2018 | 9:14:02 AM
Security lax
It is important to note that if we have not been hit before by online attacks, that does not mean that we will never get hit. It is important to still implement these security tips and guidelines if we want our business to prevail even after the holidays. It might just be too late if we think that we are safe and there is no lax in our systems.
MarkSindone
50%
50%
MarkSindone,
User Rank: Apprentice
12/22/2018 | 12:53:41 AM
Brand versus no brand
I don't know why people would go to a website that wasn't guaranteed to be a legitimate one, even over the holiday periods. I mean, I can get cheap China knock-offs, but if things are already on sale at a reputable branded place, that's what getting a good deal is about right?
High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writer,  2/14/2019
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
Making the Case for a Cybersecurity Moon Shot
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  2/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-15380
PUBLISHED: 2019-02-20
A vulnerability in the cluster service manager of Cisco HyperFlex Software could allow an unauthenticated, adjacent attacker to execute commands as the root user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by connecting to the cluster serv...
CVE-2019-3474
PUBLISHED: 2019-02-20
A path traversal vulnerability in the web application component of Micro Focus Filr 3.x allows a remote attacker authenticated as a low privilege user to download arbitrary files from the Filr server. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.
CVE-2019-3475
PUBLISHED: 2019-02-20
A local privilege escalation vulnerability in the famtd component of Micro Focus Filr 3.0 allows a local attacker authenticated as a low privilege user to escalate to root. This vulnerability affects all versions of Filr 3.x prior to Security Update 6.
CVE-2019-10030
PUBLISHED: 2019-02-20
A sandbox bypass vulnerability exists in Jenkins Script Security Plugin 1.52 and earlier in RejectASTTransformsCustomizer.java that allows attackers with Overall/Read permission to provide a Groovy script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.
CVE-2019-10030
PUBLISHED: 2019-02-20
A exposure of sensitive information vulnerability exists in Jenkins Cloud Foundry Plugin 2.3.1 and earlier in AbstractCloudFoundryPushDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through anoth...