Security rundown for week ending Aug. 12

12.08.2011

And in the strange-but-true category, it appears it's also possible for cybercriminals to control botnets through , at the Defcon conference.

News last week also focused on the Payment Card Industry (PCI) data-security standards, which are issued by the PCI Security Standards Council.

These influential standards are required to be used by any business accepting payment cards or processing them, and PCI has been a strong influence on network security in the past few years. However, it can cost a lot -- like more than half a million dollars -- to go through PCI validation for compliance each year through a special audit. Interestingly, it would waive the PCI validation requirement to qualified merchants that agree to install dual-use EMV point-of-sale devices that also support near-field communication (NFC), the technology for mobile payments in .

If Visa thinks the main incentive to get chip-based payment cards and NFC into the U.S. is by telling merchants they can wave goodbye to their annual PCI validation costs, is this a sign of the beginning of the end of the reign of PCI?

The PCI Security Standards Council would only comment, "Let's see what happens next," but they're still churning out security PCI guidelines, such as the one and how to use it to help with PCI compliance.