Close Menu
    What's Hot

    Reversing Brexit Is Labour’s Best Hope by Anatole Kaletsky

    Opinion | JD Vance on the Morality of the Trump Administration

    Israel Stunned by Trump’s Iran Deal

    Facebook X (Twitter) Instagram
    Trending
    • Reversing Brexit Is Labour’s Best Hope by Anatole Kaletsky
    • Opinion | JD Vance on the Morality of the Trump Administration
    • Israel Stunned by Trump’s Iran Deal
    • World Cup 2026: Key takeaways from the opening group stage matches | World Cup 2026 News
    • Hegseth Berates NATO Allies for ‘Shameful’ Response to U.S. War in Iran
    • Afghanistan Issues Ban on Smartphones for Civil Servants and Military
    • Afghanistan Issues Ban on Smartphones for Civil Servants and Military
    • Warsh’s Hawkish Turn Has Scrambled the Math on Rates
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    The Scripts on Your Checkout Page Are Now a PCI DSS Problem

    adminBy adminJune 18, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    The Scripts on Your Checkout Page Are Now a PCI DSS Problem
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Hacker NewsJun 18, 2026Payment Security / Compliance

    The Scripts on Your Checkout Page Are Now a PCI DSS Problem

    An independent PCI assessor tested Reflectiz against the new PCI DSS rules. Here is the verdict: See the full QSA assessment here →

    When a customer types their card number into your checkout, their browser is running far more than your code. Analytics tags, a tag manager, a support widget, a payment iframe: a modern checkout loads dozens of third-party scripts, and any one of them can be turned into a skimmer.

    This is how Magecart works. Sansec has counted more than 100,000 sites hit by web skimming and supply-chain attacks. The 2018 British Airways breach alone exposed 380,000 transactions and a fine that started at £183 million.

    The dangerous part: the malicious code usually arrives through a script you already approved. Attackers compromise a third-party vendor, and the payload rides in on a script you have run for months. Nothing looks new. What changed is the script’s behavior, not its presence on the page.

    PCI DSS v4.0.1 closes that gap with two requirements, now fully in force. 6.4.3 says to inventory every payment-page script, authorize it, and prove its integrity. 11.6.1 says to detect tampering with page content and HTTP headers as the browser receives them. Done by hand, across hundreds of scripts that change constantly, this does not scale. Reflectiz data shows roughly 30% of payment-page scripts change within any two-week window.

    What the QSA Found

    Integrity360 Europe, a PCI Qualified Security Assessor and member of the PCI SSC Global Executive Assessor Roundtable, reviewed the Reflectiz PCI DSS Platform against both requirements and found it can effectively support compliance. Three things stood out:

    • It watches behavior, not just file hashes. A hash check misses a silent vendor-side swap. Reflectiz catches the script the moment it starts reaching for card data.
    • It deploys agentless. No code changes, no snippets, live in days, and it keeps working through refactors and CMS migrations.
    • It produces QSA-ready evidence in one click. Full audit trail per page, ready for assessment.

    The SAQ A Catch

    Since January 2025, merchants can drop 6.4.3 and 11.6.1 from SAQ A only if they confirm their site is not susceptible to script attacks. Full redirect to your processor? You are likely fine. Embed a payment iframe? A script on the parent page can still hijack the checkout before data reaches the secure frame, and you have to prove it cannot. PCI SSC FAQ #1588 points straight back to these same controls.

    Get the Full Assessment

    The complete Integrity360 Europe white paper breaks down both requirements line by line, the monitoring workflow, and exactly what SAQ A now demands of iframe merchants.

    Download the white paper →

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    Checkout DSS Page PCI problem scripts
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleWhy U.S. Sunscreens Are Finally About to Get a Lot Better
    Next Article Samsung The Frame Pro 2026 Review: Pricey But Worth It
    admin
    • Website

    Related Posts

    Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

    June 17, 2026

    Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments

    June 17, 2026

    Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went Offline

    June 17, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    Reversing Brexit Is Labour’s Best Hope by Anatole Kaletsky

    Opinion | JD Vance on the Morality of the Trump Administration

    Israel Stunned by Trump’s Iran Deal

    World Cup 2026: Key takeaways from the opening group stage matches | World Cup 2026 News

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by