“Most people do not listen with the intent to understand; they listen with the intent to reply.”

– Stephen Covey


Man pleads guilty to selling compromised POS systems, loading up Subway gift cards http://www.scmagazine.com/man-pleads-guilty-to-selling-compromised-pos-systems-loading-up-subway-gift-cards/article/347146/

http://www.securityweek.com/former-subway-franchise-owner-pleads-guilty-pos-system-hacking

C-IT Recommendation

  1. Use Strong password for Terminal log in accounts and change them regularly
  2. Keep POS operating systems and POS Software Applications updated with the latest patches:
  3. Install a Firewall
  4. Ensure a solid Antivirus solution is running on the PoS terminals
  5. Restrict Access to Internet. POS should not be allowed to access the internet
  6. Disallow Remote Access so
  7. Encrypt traffic between terminals, servers and payment card processor

Article Resources

US-CERT Malware Targeting Point of Sale Systems Advisory

https://www.us-cert.gov/ncas/alerts/TA14-002A

Protecting PoS Environments Against Multi-Stage Attacks

http://www.symantec.com/content/en/us/enterprise/white_papers/b-protecting-pos-environments-against-multi-stage-attacks-WP-21327754.pdf

Retailers join forces to share threat intelligence

http://www.scmagazine.com/retailers-join-forces-to-share-threat-intelligence/article/347215/

http://www.securityweek.com/retailers-share-cyber-threat-intelligence-through-new-retail-isac

http://www.csoonline.com/article/2156060/data-protection/how-retailers-can-boost-security-through-information-sharing.html

C-IT Recommendation

  1. Research security sharing communities your organization can participate in. Delegate someone from your organization to be a contributor and also a liason to the organization
  2. If no official organization exists, consider starting one of for your industry or your town’s key businesses to participate in.

Article Resources

Retail Cyber Intelligence Sharing Center

http://www.r-cisc.org/

Security for Business Innovation Council

http://www.emc.com/emc-plus/rsa-thought-leadership/sbic/index.htm


PayPal Fixes Vulnerabilities In MultiOrder Shipping Application http://www.securityweek.com/paypal-fixes-vulnerabilities-multiorder-shipping-application