SSCC 159 – What can we learn from the “honeybot”? [PODCAST]

For your listening pleasure! Here’s this week’s episode of the Sophos Security Chet Chat podcast…

Bad passwords on PoS terminals leads to card stealing Backoff malware

More point of sale malware has been making the news, designed to steal credit card information as usual. This time the crooks are distributing the malware through remote control applications like Microsoft’s RDP. No exploits, no social engineering, just good old fashioned password guessing.

Remote access breach via POS system sparks yet more consumer data leak fears

A US supplier of point-of-sale (POS) equipment has informed its clients of a security breach in the remote access system it uses to log into clients’ networks, meaning hackers could have used the system to steal payment data.

Carwash POS systems hacked, credit card data drained

Police in the US state of Massachusetts have busted what they say is a gang of thieves who were buying stolen credit cards and using them to buy gift cards that were then sometimes exhausted of their balance, washed clean of data and reloaded with more stolen credit card data.

Data-drained Target hurries to adopt chip-and-PIN cards

The US has been dragging its heels on the expensive, laborious task of swapping its payment infrastructure for the more secure chip-and-PIN security used abroad. Still smarting from recent data theft, Target’s now apparently leading the way, promising the new cards in 2015.