News & Commentary
Latest Content
Page 1 / 2   >   >>
The Real Reasons Why Users Stink At Passwords
News  |  9/28/2016  | 
Personality, denial, and authentication-overload are big factors, new study finds.
Hacking The Polls: Where US Voting Processes Fall Short
Commentary  |  9/28/2016  | 
The patchwork of 50 decentralized state electoral systems threatens to disrupt our national election through ransomware attacks, hijacked voter registration rolls, and altered voting results.
More Than Half Of IT Pros Employ Insecure Data Wiping Methods
News  |  9/28/2016  | 
Recent study shows most enterprise IT professionals incorrectly believe emptying a Recycle Bin or reformatting a computer drive permanently erases data.
Improving Security Savvy Of Execs And Board Room
Improving Security Savvy Of Execs And Board Room
Dark Reading Videos  |  9/28/2016  | 
Jeff Welgan describes how best to improve cybersecurity literacy throughout the C-suite.
SWIFT Toughens Customer Security With New Mandatory Rules
Quick Hits  |  9/28/2016  | 
Measures to include set of core safety standards and assurance framework requiring annual self-attestation by SWIFT members.
Beep Prepared: How Security Economics Can Help The Coyote Catch The Roadrunner
Partner Perspectives  |  9/28/2016  | 
The practice of security economics demonstrates how gaps in the security architecture impair business results.
FBI Probes Bid To Hack Democratic Party Officials Phones, Sources Say
Quick Hits  |  9/28/2016  | 
Russia-backed criminals again likely to be behind this hacking which, if proven, could involve theft of sensitive data, say the sources.
Improving The Security Conversation For CIOs, CISOs, & Board Members
News  |  9/28/2016  | 
Cybersecurity is a top priority among enterprise leaders, but it's difficult for them to communicate with IT and security teams if they lack an understanding of key security concepts.
Clinton, Trump Debate 'Twenty-First Century War' Of Cyberattacks
News  |  9/27/2016  | 
Lester Holt led with topic of cybersecurity as the first question on national security in Monday's Presidential debate.
5 Best Practices For Winning the IoT Security Arms Race
Commentary  |  9/27/2016  | 
By focusing on a pragmatic approach to security, its possible to develop IoT solutions that will reduce future risk without breaking the bank.
25 Emerging Security Vendors To Watch
Slideshows  |  9/27/2016  | 
A wave of companies is entering the security field armed with technologies to help businesses mitigate the next generation of cyberattacks. Who are these emerging vendors and what can they offer?
Yahoo Confirms August Data Dump Issue Unrelated To Breach Of 500 Million Users
Quick Hits  |  9/27/2016  | 
No 'connection' between August 2016 data dump claims and 2014 nation-state attack, company says.
Sharing Cybersecurity Threat Intelligence Is The Only Way We Win
Partner Perspectives  |  9/27/2016  | 
Security organizations must leverage each others information in order to better predict, prevent, detect, and respond to threats their customers and organizations face.
Yahoo Sued By User Over 2014 Hacking
Quick Hits  |  9/27/2016  | 
New Yorker files lawsuit against Yahoo for recklessness and delay in uncovering hack of half a billion accounts.
Yahoo Breach: US Senator Seeks SEC Role In Probe
Quick Hits  |  9/27/2016  | 
Democrat Mark Warner asks US Securities and Exchange Commission to investigate whether Yahoo completed obligations post breach discovery.
Mobile Fraud Changes Outlook for Multifactor Authentication
Commentary  |  9/27/2016  | 
SMS one-time passcodes just won't cut it anymore. We need new approaches that people will actually use.
Russian 'Fancy Bear' Hackers Hit Mac OS X With New Trojan
News  |  9/26/2016  | 
Aerospace victim hit by targeted attack that didn't even exploit a Mac vulnerability.
Ransomware: Coming To A Hospital Near You?
Partner Perspectives  |  9/26/2016  | 
10 ways to protect healthcare systems from ransomware and other malware infections.
Cyber Risk Among Top Concerns For Business Leaders: Study
News  |  9/26/2016  | 
More than 50% of business leaders surveyed in the Travelers Risk Index report cyber, computer, and technology risks are among their top concerns.
FBI Probes Dumping Of NSA Hack Tools On Public Site
Quick Hits  |  9/26/2016  | 
National Security Agency says tools left exposed by mistake - and dumping by presumably Russia-backed hackers Shadow Brokers.
Yahoo Breach Could Delay $4.8 Billion Verizon Takeover
Quick Hits  |  9/26/2016  | 
Verizon may revisit contract with Yahoo on doubts of vulnerabilities in the system after 500 million accounts were found hacked.
What The WADA Hack Proves About Today's Threat Landscape
Commentary  |  9/26/2016  | 
Fancy Bear's initial release of data on four top American athletes reminds us all to reassess our risks.
Microsoft Launches Windows Defender App Guard For Its Edge Browser
News  |  9/26/2016  | 
Microsoft debuts a new tool to strengthen security in its Edge browser for Windows Enterprise customers.
Adware Campaign Using Advanced Nation-State Obfuscation Techniques
News  |  9/26/2016  | 
New report from Carbon Black shows adware may be spreading ransomware, using similar tactics as Operation Aurora.
State Of The Exploit Kit
Slideshows  |  9/26/2016  | 
Exploit kit traffic is down considerably following the demise of Nuclear and Angler, but many researchers see it only as a temporary disruption.
7 New Rules For IoT Safety & Vuln Disclosure
Commentary  |  9/24/2016  | 
In the Internet of Things, even the lowliest smart device can be used for a malicious purpose. Manufacturers take heed!
Advisory Body Calls For Stronger Cybersecurity Measures Across Airline Industry
News  |  9/23/2016  | 
Measures are designed to bolster operational security across all stakeholders in the aviation sector, Wall Street Journal says.
Spam Levels Spike, Thanks In Part To Ransomware
News  |  9/23/2016  | 
By shipping banking Trojans and ransomware that turn big profits fast, spammers can now afford the high overhead of high-volume spam campaigns.
7 Ways Cloud Alters The Security Equation
Slideshows  |  9/23/2016  | 
Would-be and existing customers must understand that security isn't set-and-forget just because it resides in the cloud.
An Open-Source Security Maturity Model
An Open-Source Security Maturity Model
Dark Reading Videos  |  9/23/2016  | 
Oh you don't run open-source code? Really? Christine Gadsby and Jake Kouns explain how to identify and secure all those open-source libraries and other third-party components lurking inside your applications, proprietary and otherwise.
D-FENSE! Using Research To Craft Effective Cyber Defenses
D-FENSE! Using Research To Craft Effective Cyber Defenses
Dark Reading Videos  |  9/23/2016  | 
A pair of experts from Imperva stops by the Dark Reading News Desk to chat.
On-Premises & In The Cloud: Making Sense Of Your Cybersecurity Ecosystem
Commentary  |  9/23/2016  | 
As enterprises continue to invest in hybrid cloud strategies, they need their fragmented security solutions to work together.
FTC Releases Video With Data Breach Recovery Advice
Quick Hits  |  9/23/2016  | 
The US Federal Trade Commission video has detailed instructions on what to do if personal data of a user is stolen and exposed.
Top Democrats Tell Putin To Halt Hacking Of US Political Parties
Quick Hits  |  9/23/2016  | 
Russia trying to influence November presidential elections, say Senator Dianne Feinstein and Rep. Adam Schiff.
Biometric Skimmers Pose Emerging Threat To ATMs
News  |  9/22/2016  | 
Even as financial institutions move to shore up ATM security with biometric mechanisms, cybercrooks are busy figuring out ways to beat them.
Yahoo Reveals Nation State-Borne Data Breach Affecting A Half-Billion Users
News  |  9/22/2016  | 
But still unconfirmed is whether the newly revealed attack is related to recently dumped Yahoo user credentials in an online cybercrime forum.
7 Factors That Make Security Organizations More Effective
News  |  9/22/2016  | 
(ISC)2 members have plenty of technical chops, but IANS research found they need to focus more on how infosec aligns with the business.
Snowden: Hollywood Highlights 2 Persistent Privacy Threats
Commentary  |  9/22/2016  | 
Oliver Stones movie shows us that while most of us have nothing to hide, we all have information worth protecting both technically and constitutionally.
10 Ways To Lock Down Third-Party Risk
Slideshows  |  9/22/2016  | 
Experts share ideas for closing potential security holes that leave organizations open to attack.
Even A False Positive Can Be Valuable
Commentary  |  9/22/2016  | 
Sharing information about cyberthreats is important for the financial services industry, even when threats turn out to be not-so-threatening.
SWIFT CISO: Cyber Threat 'Persistent'
Quick Hits  |  9/22/2016  | 
Alain Desausoi describes threat as persistent, and says there's been progress in combating it via new SWIFT initiatives.
NYSE Deals Blow To John McAfee's MGT Capital
Quick Hits  |  9/22/2016  | 
MGT searches for alternatives as share listing approval denied, causing deep plunge in share price.
Majority Of Major Corporations Have User Credentials Stolen And Exposed
News  |  9/21/2016  | 
Companies in the entertainment and technology sectors are far more exposed than others, Digital Shadows analysis shows.
National Health ISAC Calls For Collaborative Vuln Disclosure
News  |  9/21/2016  | 
St. Jude Medical to host upcoming workshop on medical device info sharing, convened by NH-ISAC and medical device security consortium.
How Cloud, Mobile Are Changing IT, Security Management: Study
News  |  9/21/2016  | 
The evolution of technology is changing the role of IT and security pros as more employees use cloud apps and connect personal devices to corporate networks.
How Windows 10 Stops Script-Based Attacks On The Fly
How Windows 10 Stops Script-Based Attacks On The Fly
Dark Reading Videos  |  9/21/2016  | 
Move over Apple 'Walled Garden.' Windows 10's new antimalware scan interface halts scripts by signing code on the fly... but does it work? Security researcher Nikhil Mittal takes a look.
A Twist On The Cyber Kill Chain: Defending Against A JavaScript Malware Attack
Commentary  |  9/21/2016  | 
This slightly modified model is a practical way to keep attackers out of your systems.
Rand Study: Average Data Breach Costs $200K, Not Millions
News  |  9/21/2016  | 
Rand taps multiple data sources to calculate that cyber incidents cost firms a scant 0.4% of annual revenues, on average.
Florida Man Charged With Hacking Linux Servers
Quick Hits  |  9/21/2016  | 
Donald Austin allegedly stole credentials of Linux employee to hack four company servers and install rootkit and Trojan software.
Chinese Researchers Hack Tesla S Models, Expose Bugs
Quick Hits  |  9/21/2016  | 
Automaker fixes security risks after Tencent Holdings uncover vulnerabilities in both parking and drive mode.
Page 1 / 2   >   >>


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I decided to treat the kiddos to a TV dinner tonight.
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Cybercrime has become a well-organized business, complete with job specialization, funding, and online customer service. Dark Reading editors speak to cybercrime experts on the evolution of the cybercrime economy and the nature of today's attackers.