- PCI DSS 4.0: Who Really Owns Payment Security Risk?
When a payment page breach happens, who is actually accountable: the merchant, the processor, the PSP, or the vendor whose script got compromised? This episode brings together security leaders from across the payment chain to answer that question.
What's covered:
Where PCI DSS 4.0 succeeds and where it leaves gaps in payment security accountability.
How requirements 6.4.3 and 11.6.1 apply to real third-party script monitoring.
Why client-side vulnerabilities create cardholder data exposure that server-side controls miss.
How global retail, e-commerce, and payment processing teams are dividing payment security responsibility in practice.
What compliance teams should do differently once checking the PCI box is not enough.
Speakers: Una Dillon, Regional Director Europe, PCI Security Standards Council; Deepak Kumar, CISO, APEXX Global; Pete Chenery, Global Head of Cyber Security, Naked Wines; Mark Barry, Senior Security Operations Manager, Domino's Pizza; Leor Eliashiv, UK Regional Manager, Reflectiz.
Key terms: PCI DSS 4.0, payment security, client-side security, cardholder data protection, third-party risk, Magecart, checkout page security.
Explore Reflectiz's payment security resources and PCI compliance guides at reflectiz.com/demo. A good next step if you're mapping out where your own payment risk ownership breaks down.
E3 - 52m - Jul 23, 2026 - Magecart Detection: Can AI Code Review Tools Catch It?
Can AI-powered code security tools like Claude Code Security catch a live Magecart attack? This episode puts that question to the test using a real-world Magecart campaign that compromised a payment processing system.
What's covered:
Why static code analysis tools miss client-side threats that exploit runtime behavior in third-party scripts.
What Claude Code Security and similar AI code review tools can and cannot detect.
How a real Magecart campaign evaded development-time security checks.
Why payment page protection needs runtime visibility that static analysis cannot provide.
How to combine static analysis and runtime monitoring in a defense-in-depth strategy.
Speakers: Elan Hershcovitz, VP R&D, Reflectiz.
Key terms: Magecart, client-side security, runtime monitoring, static code analysis, third-party script risk, web supply chain security, payment page protection.
Download the CISO guide referenced in this episode at reflectiz.com/learning-hub/claude-code-security-guide. A useful companion if you're evaluating where AI code review fits in your security stack.
25m - Jul 23, 2026 - AI Supply Chain Attacks: The New Threat to Retail Security
Retailers are rolling out AI agents for procurement, inventory forecasting, and customer service, but few security teams have asked what happens when those agents get manipulated. This episode breaks down how attackers are already exploiting AI supply chains in retail.
What's covered:
How prompt injection lets attackers manipulate procurement AI systems without touching your codebase.
Why rogue suppliers can manipulate inventory forecasts through AI-driven procurement tools.
How attackers hijack trusted supplier identities to coordinate cartel-style attacks.
What it means when AI agents sit on payment pages and are trusted by default.
Practical steps for retail security teams to evaluate whether their AI systems are actually ready for this threat.
Speakers: Simon Arazi, VP Product, Reflectiz.
Key terms: client-side security, AI supply chain risk, third-party script risk, agentic AI security, payment page security, retail cybersecurity.
Watch the full webinar recording and explore Reflectiz's approach to AI-era retail security at reflectiz.com/demo. Worth a look if your team is rolling out AI procurement or forecasting tools without a clear security review process.
23m - Jul 23, 2026
