Subscribe:
Showing posts with label internet-security. Show all posts
Showing posts with label internet-security. Show all posts

Wednesday, 7 September 2011

Century Payments Partners with Trustwave to Offer Merchants PCI Compliance Solutions



Century Payments, today selected Trustwave to provide Payment Card Industry Data Security Standard (PCI  DSS) compliance validation solutions to its Level 4 merchants. Trustwave is a leading provider of information security and compliance solutions.

The PCI DSS is the payment card industry security requirement for entities that store, process or transmit cardholder data, and has been endorsed by all the major card brands - Visa, MasterCard Worldwide, Discover Network, American Express and JCB.

In an effort to assist merchants with their compliance efforts, Century engaged Trustwave to provide its merchants access to TrustKeeper®, Trustwave's innovative security and compliance web portal.

Trustwave's TrustKeeper is a revolutionary web portal that supports merchants' compliance efforts, including moving merchants through the complex compliance process with greater ease and efficiency by making the tasks achievable by non-technical users. This helps facilitate PCI DSS compliance validation for merchants or acquirers, ISOs and processors with large merchant populations.

TrustKeeper features PCI Wizard, which simplifies the complex PCI DSS compliance process. Additionally, TrustKeeper Agent helps merchants identify if unencrypted cardholder data or track data is stored, thereby reducing the merchants' risk of card data theft. TrustKeeper also helps merchants complete required vulnerability scans and receive their PCI DSS compliance certificate.

"After careful consideration of other programs, we chose Trustwave because they most aligned with our goals and objectives around data security for our merchant portfolio," said Christopher Justice, president of Century Payments. "Trustwave's industry expertise and merchant compliance program will help our clients validate and maintain their PCI DSS compliance through easy-to-complete steps that any-sized merchant can understand."

"Trustwave is excited to partner with Century Payments, a leading payment processor, because they understand the importance of validating PCI DSS compliance across their merchant portfolio and are ready to provide the resources necessary to help manage the requirements," said Robert J. McCullen, chairman, CEO and president of Trustwave. "Our merchant compliance program provides Century Payments the necessary tools to help lead their merchants through the compliance process in a step-by-step program that translates the difficult tasks of compliance validation into a comprehensible language for merchants of any size."

About Century Payments
Century Payments, Inc. (centurypayments.com) is a nationally recognized leader in the electronic payment processing industry, dedicated to developing the most progressive, dynamic programs to benefit merchants, partners and agents alike. Through white label alliance programs, Century is the fastest growing electronic payments company having boarded over 50,000 merchants in the last three years and processing close to $10 billion in annual volume. In 2011, Century entered into an elite group recognized on the Inc. 500 list as one of the top 20 fastest growing, privately owned businesses for two consecutive years. The company is headquartered in Frisco, Texas.

About Trustwave
Trustwave (
trustwave.com) is a leading provider of on-demand and subscription-based information security and payment card industry compliance management solutions to businesses and government entities throughout the world. For organizations faced with today's challenging data security and compliance environment, Trustwave provides a unique approach with comprehensive solutions that include its flagship TrustKeeper PCI Compliance management software and other proprietary security solutions including SIEM, EV SSL certificates and secure digital certificates. Trustwave has helped hundreds  of thousands of organizations-ranging from Fortune 500 businesses and large financial institutions to small and medium-sized retailers-manage compliance and secure their network infrastructures, data communications and critical information assets. Trustwave is headquartered in Chicago with offices throughout North America, South America, Europe, Africa, Asia and Australia.


Wednesday, 3 August 2011

Global Cyber Attack Revealed by McAfee


(The Hosting News) – A new breach has been identified in the area of global cyber hacking. Recently internet security company McAfee detailed “Shady Rat,” a hacking operation that targeted 72 top worldwide entities. Such victims included various U.S. defense contractors, government agencies, top companies, the United Nations, and plenty more.

The operation occurred over five years. Although it mostly had U.S. targets, various other victims were based in countries such as Canada, South Korea, Taiwan, Switzerland, and the United Kingdom.

The security company’s analysis of the attack was based off of accessing the intruders’ “Command & Control server.” Despite the magnitude of the breach, McAfee says that most of the targets had already corrected problems caused by the infections.

According to the report, the operation relied on setting up a backdoor channel through malware. Concluding its findings, McAfee stated, “This is a problem of massive scale that affects nearly every industry and sector of the economies of numerous countries, and the only organizations that are exempt from this threat are those that don’t have anything valuable or interesting worth stealing.”

Although the source of the operation wasn’t revealed, many tech analysts have suspected China as the source of various recent cyber-attacks. Despite denying any involvement, the country was said to be the source of a recent high-profile attack on Google’s Gmail service.

Meanwhile, countries such as the United States have looked to increase their efforts against global cyber security threats by working with other nations, as well as developing new technology. Other recent global cyber-attacks have included a breach on defense contractor Lockheed-Martin and one involving the Pentagon (which the U.S. said likely originated from an unidentified nation state).

Besides these larger scale global breaches that seem more mysterious, this year has seen plenty of other attacks where individual hacking groups have openly taken credit for particular breaches.

Groups LulzSec and Anonymous have recently dominated the headlines. LulzSec has been responsible for attacks on sites belonging to Sony, PBS, the U.S. Senate, the CIA, and more while Anonymous has recently targeted the likes of U.S. defense contractor Booz Allen Hamilton and Monsanto, an agricultural company. Fighting back, authorities in various countries have recently arrested people suspected of involvement in the organizations.

Even with all the bad news recently regarding cyber breaches, hopefully such developments have spread awareness and pushed entities to increase their protection against large cyber threats.

You can access the entire report by McAfee in PDF format here: http://www.mcafee.com/us/resources/white-papers/wp-operation-shady-rat.pdf

Monday, 25 July 2011

10 Points to keep your network secure and safe from hackers and viruses


If you’re connected to the Internet (especially with an always on Connection Search as cable or DSL), you’re at risk for intrusion from hackers or from infection with a virus or spyware. This can happen without your knowledge. You can be browsing, logging on and off various web sites, etc., and be compromised. However, you can protect yourself from this type of intrusion by following a few simple steps.

first. Use a firewall to block all incoming connections from the Internet to services that should not be Publicly Available. By default, you should deny all incoming connections and only allow services you want to Explicitly offer to the outside world.

second. Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to Prevent or limit damage when a computer is compromised.
3rd. Ensure that programs and users of the computer use the lowest level of privileges Necessary to complete a task. When prompted for a root or UAC password, Ensure that the program asking for administration-level access is a legitimate application.

4th. Disable AutoPlay to Prevent the automatic launching of executable files on network and removable drives, and disconnect the drives when not required. If write access is not required fifth, enable read-only mode if the option is available.

. Turn off file sharing if not needed. If file sharing is required, use ACLs and password protection to limit access. Disable anonymous access to shared folders. Grant access only to user accounts with strong passwords to folders that must be shared.

6th. Turn off and remove unnecessary services. By default, many operating systems install auxiliary services that are not critical. These services are avenues of attack. If they are removed, threats have less avenues of attack.

7th. If a threat exploits one or more network services, disable, or block access to, those services until a patch is applied.

8th. Configure your email server to block or remove email that contains file attachments that are commonly used to spread threats, such as. Vbs,. Bat. Exe,. Pif and. Scr files.

9th. Isolate compromised computers quickly to Prevent threats from spreading further. Perform a forensic analysis and restore the computers using trusted media.

10th. Train employees not to open attachments unless they are expecting them. So, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

When it comes to doing business online, security is a two-way street. Safe online transactions demand smart behavior on the part of consumers and proactive security policies and procedures on the part of Web sites.

Businesses that sell goods or services online then have a responsibility to keep their transactions secure and private. And the more current sites to know about e-commerce security threats, the better job they can do at protecting their transactions. Your browser should comply with industry security standards, as searchable SSL Certificate. SSL (Secure Socket Layer) is a security protocol.

Friday, 22 July 2011

Google malware warning system alerts users about infections


Hillary O’Rourke, Contributor
Published: 21 Jul 2011


Google is instituting a new malware warning system to alert users that their computer may be infected with malware.  
We hope that by taking steps to notify users ... we can help them update their antivirus software and remove the infections

Damien Menscher, Google security engineer.
The new feature was implemented after Google detected an issue on its servers related to multiple malware infections.The new Google malware system displays a message to users at the top of the Google search results page when it detects possible issue.
The search engine giant decided to take action after discovering unusual search traffic while performing routine maintenance on one of their data centers, according to Damien Menscher, a Google security engineer.
“This particular malware causes infected computers to send traffic to Google through a small number of intermediary servers called ‘proxies,’” Menscher wrote in a blog post announcing the new Google malware warning feature.

The malware only affects computers running Microsoft Windows. When detected by Google’s system, it is likely that the computer is, or was previously, infected with the malicious software, Menscher wrote.
Some malware may alter the victim’s computer settings, redirect some traffic to a malicious server controlled by the attacker and can taint search results, according to Menscher. Tainted search results can lead people to malicious webpages and trick users into downloading rogue antivirus software.

The move is reportedly the first time Google is taking proactive measures to detect and warn users about malware infections. Microsoft is advocating a plan to get ISPs to be more proactive in scanning and alerting users to infections.
Trustworthy Computing Vice President  Scott Charney advocated for more proactive measures at his RSA Conference keynote in March. In his keynote he said ISPs should use more aggressive network access control measures for inspecting and cleaning computers before allowing them onto the Internet.

Google will not block infected users from accessing its search function. The company will provide recommendations to users for scanning systems for malware, how to remove infections, and information about why the victim may have been infected in a Google Help Center document.

 “We hope that by taking steps to notify users whose traffic is coming through these proxies, we can help them update their antivirus software and remove the infections,” Menscher wrote.
Republised By:-
TheSSLstore.com is the platinum partner authority of major SSL certificates such as VeriSign, GeoTrust, RapidSSL, and Thawte on Global Scale. Being Pioneer in SSL security certificate solutions for Standard SSL Certificates, High Assurance Certificates, Wildcard SSL Certificates, SAN Certificates, SGC Certificates, EV SSL Certificates, and Code Signing Certificates, TheSSLstore provides RapidSSL Wildcard, Thawte SSL123, and GeoTrust QuickSSL Premium SSL Certificates at the lowest price to secure ecommerce Community globally.