<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Malware dormant for 6 years (how does this happen?) in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80080#M4900</link>
    <description>&lt;P&gt;Yikes, it sounds like they were either concerned about processing the payments without concern for consumers, or some folks were sleeping on the job.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not my background, but a solution is spelled out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Supporting%20Document/Guidance-for-PCI-DSS-Requirements-6_4_3-and-11_6_1-r1.pdf" target="_blank" rel="noopener"&gt;Guidance-for-PCI-DSS-Requirements-6_4_3-and-11_6_1-r1.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 May 2025 15:14:41 GMT</pubDate>
    <dc:creator>ErikCamacho</dc:creator>
    <dc:date>2025-05-08T15:14:41Z</dc:date>
    <item>
      <title>Malware dormant for 6 years (how does this happen?)</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80042#M4897</link>
      <description>&lt;P&gt;I read this morning an article posted by TLDR that hundreds of e-commerce sites hacked in supply chain attack...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"The infections are the result of a supply-chain attack that compromised at least three software providers with malware that remained dormant for six years and became active only in the last few weeks."&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How does this happen?&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_screaming_in_fear:"&gt;😱&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source:&lt;/P&gt;&lt;P&gt;&lt;A href="https://arstechnica.com/security/2025/05/hundreds-of-e-commerce-sites-hacked-in-supply-chain-attack/?utm_source=tldrinfosec" target="_blank" rel="noopener"&gt;Hundreds of e-commerce sites hacked in supply-chain attack&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 01:10:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80042#M4897</guid>
      <dc:creator>ErikCamacho</dc:creator>
      <dc:date>2025-05-08T01:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: Malware dormant for 6 years (how does this happen?)</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80059#M4898</link>
      <description>&lt;P&gt;And this is why PCI DSS v4.0.1 has an additional control 11.6.1 for merchants to implement mechanisms to detect tampering to scripts that execute within customer browsers.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 09:08:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80059#M4898</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2025-05-08T09:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: Malware dormant for 6 years (how does this happen?)</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80080#M4900</link>
      <description>&lt;P&gt;Yikes, it sounds like they were either concerned about processing the payments without concern for consumers, or some folks were sleeping on the job.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is not my background, but a solution is spelled out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Supporting%20Document/Guidance-for-PCI-DSS-Requirements-6_4_3-and-11_6_1-r1.pdf" target="_blank" rel="noopener"&gt;Guidance-for-PCI-DSS-Requirements-6_4_3-and-11_6_1-r1.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 15:14:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80080#M4900</guid>
      <dc:creator>ErikCamacho</dc:creator>
      <dc:date>2025-05-08T15:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Malware dormant for 6 years (how does this happen?)</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80087#M4901</link>
      <description>&lt;P&gt;Unfortunately, malware being dormant is not new to the industry.&amp;nbsp; We have seen malware lie dormant waiting for a specific date or time, or even only being active on specific platforms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There is a lot of intelligence built into some malware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 May 2025 20:21:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80087#M4901</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2025-05-08T20:21:53Z</dc:date>
    </item>
    <item>
      <title>Re: Malware dormant for 6 years (how does this happen?)</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80856#M4960</link>
      <description>&lt;P&gt;That's a very patient logic bomb&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_open_mouth:"&gt;😮&lt;/span&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 28 May 2025 11:45:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80856#M4960</guid>
      <dc:creator>eclipse_8</dc:creator>
      <dc:date>2025-05-28T11:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Malware dormant for 6 years (how does this happen?)</title>
      <link>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80963#M4972</link>
      <description>&lt;P&gt;I hear that patience is a virtue&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt; maybe not so much here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 May 2025 00:49:01 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/Malware-dormant-for-6-years-how-does-this-happen/m-p/80963#M4972</guid>
      <dc:creator>ErikCamacho</dc:creator>
      <dc:date>2025-05-30T00:49:01Z</dc:date>
    </item>
  </channel>
</rss>

