Guidance from CoalFire on the eSkimming Security requirements found in PCI DSS 4.0.
The most talked about and concerning new requirements in PCI DSS 4.0 fall under sections 6.4.3 and 11.6.1. For the first time, merchants are required to implement security controls to prevent eSkimming attacks. These new requirements require control of all scripts running on merchant eCommerce websites.
In this new whitepaper “A Holistic Approach to Protecting Credit Card Payment Flows,” CoalFire chimes in with background on the problem, guidance on scope, advice on how best to secure credit card data in eCommerce transactions, and a review of the Source Defense approach.
THE “PERFECT” MAGECART ATTACK: FAKE STRIPE FORM WITH ZERO EXTERNAL FOOTPRINT August 26, 2025 The Source Defense Research Team has observed a rare and highly
MAGECART ATTACK VIA 1X1 SVG & WEBSOCKETS August 12, 2025 The Source Defense Research Team has uncovered a new Magecart campaign impacting over 50 e-commerce websites,
When one magecart attack isn’t enough; three attacks, one website July 29, 2025 The Source Defense Research Team has uncovered a rare and dangerous scenario: