Clear Insights - Security News You Can Use

Sears.com Vulnerability Reinforces Need for Manual Testing

New vulnvulnerability in Sears.com website reinforces the need for manual pen testing.

PCI Auditor becomes PCI Defendant

An interesting twist in the legal battle regarding the breach at CardSystems now has the PCI auditor on trial.

Insecure SSL and How PCI “Nearly” gets it Right

Insecure ciphers and protocols are still supported on a very large percentage servers we assess. We strongly advocate removing all insecure ciphers and protocols. The PCI Council nearly made it a requirement to disable SSLv2 – In the words of Maxwell Smart, “They missed it by THAT much”.

Honey…What’s This Charge For?

New Payment Processor System Hacked