In-brief: The security firm Bluebox says the mobile applications used with Hello Barbie contain security flaws that could lead to the theft of passwords and other information. Update: this story was updated to include comment from Bluebox and ToyTalk. PFR 12/4/2015
Threats
Target agrees to pay $39m to Banks for Data Breach | Reuters
In-brief: Reuters reports today that Target Corp has agreed to pay $39.4 million to banks to resolve claims that said they lost money because of the retailer’s late 2013 data breach.
Toymaker Hack Highlights Dark Side of Tech Industry’s Data Obsession
In-brief: The hack of VTech, a maker of technology products for children, has exposed sensitive data on hundreds of thousands of children, the company acknowledged this week. Also exposed: the toy industry’s growing and unregulated appetite for information on the children who play with their toys.
Firm Finds Crypto Keys Recycled on Thousands of Devices
In-brief: Encryption keys used to secure data on- and communications between embedded devices are being recycled, creating a huge vulnerability that malicious hackers could exploit to snoop on sensitive communications or impersonate devices.
Experian: EMV Chips Won’t Stop Payment Breaches
In-brief: Experian, the credit monitoring firm, predicts in a new report that many merchants will continue to suffer payment-related breaches in 2016, despite the shift to EMV technology from older, magnetic stripe credit cards.