Archive Links

Consumer Archive
CU System Archive
Market Archive
Products Archive
Washington Archive

News Now

CU System
CMG Visa alert Hackers a risk to e-business systems
MADISON, Wis., and SAN FRANCISCO (2/5/08)--CUNA Mutual Group (CMG) issued a security alert yesterday morning identifying potential risks to financial institutions’ e-business systems after Visa told the company financial institutions are being targeted by hackers seeking cardholder information. Credit unions should use the alert to validate and confirm the security of their Web-facing systems, CMG said. CMG recommends that credit unions examine whether they have:
* Failed to use a network-based intrusion detection system; * Failed to use a host-based intrusion detection system; * Improperly segmented network environment; * Poorly configured ingress and egress firewall rules; and * Experienced structured query language (SQL) injection.
Visa also issued a second alert regarding SQL injection, stating it recently detected SQL attack methods targeted against websites and Web applications that were not properly designed or resided on unpatched systems. The latest SQL injection attacks pose serious additional risks to cardholder data stored or transmitted with systems and networks connected to the affected environment, the company said. Visa recommended that credit unions:
* Leverage an independent third party to conduct security assessments; * Assess and monitor the ongoing performance of security practices at key suppliers, especially those handling sensitive information; and * Develop a framework to assess partners, based on ISO-17799.
Credit unions also should validate and confirm Payment Card Industry Data Security Standards and Payment Card Industry Personal Identification Number Security Standards, CMG said in the alert. Credit unions that have experienced losses should contact CMG’s Credit Union Protection Response Center. For more information, use the links.
Other Resources

RSS





print
News Now LiveWire
Matz: Revised @TheNCUA #RBC rule for #creditunions 2 B unveiled 1/15/15, 90-day comment period to follow #newsnow http://t.co/qABhvghSTU
5 hours ago
Just announced: @TheNCUA board will consider a revised risk-based capital rule at its Jan 15 mtg. See #NewsNow Monday for more info.
6 hours ago
Nearing one-yr anniversary of data breach, @Target asks for class action suits to be dismissed via @BloombergNews http://t.co/kra6kupd35
7 hours ago
.@PeoplesTrustFCU has been recognized with the Juntos Avanzamos designation by @Cornerstone_CUL for its service to the Hispanic community
8 hours ago
#NewsNow: Rep. Hensarling names #HFSC subcommittee chairs. http://t.co/dXAMZdpn1p
8 hours ago