News & Commentary
Latest Content
Page 1 / 2   >   >>
The Hidden Flaws Of Commercial Applications
News  |  5/2/2016  | 
Open source components in commercial applications are more plentiful than organizations think -- and they're full of long-standing vulnerabilities.
Ransomware Spikes, Tries New Tricks
News  |  5/2/2016  | 
Ransomware authors constantly upping their game, techniques, to stay ahead of security researchers.
Utility's Server Hacked, Infected With Ransomware
Quick Hits  |  5/2/2016  | 
Electricity, water supply uninterrupted while authorities work on solution to locked files.
Dental Association Unknowingly Sends Virus To Members
Quick Hits  |  5/2/2016  | 
American Dental Association (ADA) admits that some USB devices it mailed contain malware, advises caution.
Women In Security: What Are You Missing?
Partner Perspectives  |  5/2/2016  | 
For security jobs, men outnumber women by a long shot. It's time to start thinking and recruiting differently.
8 Microsoft Office 365 Security Tips To Reduce Data Loss
Slideshows  |  5/2/2016  | 
Even with a slew of new security tools and compliance guidance, there are still things you can do to protect this critical business system.
How To Succeed At Third-Party Cyber Risk Management: 10 Steps
Commentary  |  5/2/2016  | 
Organizations are failing -- and badly -- assessing the risk of attacks and data breaches from vendors and supply chains, according to a recent Ponemon Institute study. The solution starts at the top.
6 Steps for Responding to a Disruptive Attack
Slideshows  |  4/29/2016  | 
Today’s threat landscape dictates that companies must have a workable incident response plan.
Stop Building Silos. Security Is Everyone’s Problem
Commentary  |  4/29/2016  | 
Yes, it’s true that the speed of DevOps has made security more difficult. But that doesn’t mean accelerated release cycles and secure applications have to be mutually exclusive.
Symantec CEO Brown’s Exit Highlights Company’s Continuing Struggles
News  |  4/29/2016  | 
For the third time since 2012, Symantec is looking for a new CEO to help turn around the business.
Qatar National Bank Probes Possible Data Breach
Quick Hits  |  4/29/2016  | 
Bank details exposed include those of ruling family and defense officials, reports say.
San Bernardino iPhone Hack Tool Cost FBI ‘Under $1 Million’
Quick Hits  |  4/29/2016  | 
Agency now owns mechanism that can exploit unknown Apple security flaws.
Hacker Group Exploits 'Hot Patching' In Windows To Cloak Cyber Espionage
News  |  4/28/2016  | 
Group called Platinum employs spear phishing and malicious use of hot patching to steal information from government agencies in Asia.
Government Cybersecurity Performance, Confidence Bottoms Out
News  |  4/28/2016  | 
In the wake of OPM and other big gov breaches, government cybersecurity performance scores and employee confidence ratings sink through the floor.
The Morning After: What Happens to Data Post Breach?
Partner Perspectives  |  4/28/2016  | 
We need consumers and businesses to not simply shrug off data breaches but to take active measures to protect their data. We are hopeful that new insights will provide a compelling answer to the question “So what?”
How To Stay Secure At The Hotel On A Business Trip
News  |  4/28/2016  | 
As POS malware attacks on hotels increase and threat actors target executives, traveling for business puts company data at risk.
10 Newsmakers Who Shaped Security In the Past Decade
Slideshows  |  4/28/2016  | 
In celebration of Dark Reading’s 10th anniversary, we profile ten people whose actions influenced and shaped the trajectory of the industry – for better or for worse -- in the past ten years.
6 Reasons ISPs Must Step Up Defenses Against DDoS Attacks
Commentary  |  4/28/2016  | 
Conducting a DDoS attack used to require a significant amount of talent. But today, a high school student with basic hacking skills can access tools that will challenge even the most experienced ISP security teams.
German Nuclear Power Plant Infected With Malware
Quick Hits  |  4/28/2016  | 
Conficker, Ramnit malware found in Gundremmingen 'harmless' since the affected systems were not connected to the Internet.
Estonian Man Gets 7-Year Sentence For Clickjacking Attacks
Quick Hits  |  4/28/2016  | 
Cybercrime gang jailed for click-fraud scheme affecting 4 million computers in over 100 countries.
Pro-ISIS Hacking Groups Growing, Unifying, But Still Unskilled
News  |  4/28/2016  | 
Flashpoint report outlines the patchwork of hacking groups and the validity of their claims to fame.
4 Tips For Planning An Effective Security Budget
News  |  4/27/2016  | 
Security budgets start with managers assessing all of their resources and measuring the effectiveness of their security programs for strengths and weaknesses
PCI DSS 3.2: 3 Things You Need to Know
News  |  4/27/2016  | 
The latest round of upgrades are incremental yet necessary.
8 Signs Your Security Culture Lacks Consistency
Commentary  |  4/27/2016  | 
Organizations that practice what they preach and match their actions to their words do far better achieving their goals than those that do not. Here's why that matters.
10 Questions To Ask Yourself About Securing Big Data
Partner Perspectives  |  4/27/2016  | 
Big data introduces new wrinkles for managing data volume, workloads, and tools. Securing increasingly large amounts of data begins with a good governance model across the information life cycle. From there, you may need specific controls to address various vulnerabilities. Here are a set of questions to help ensure that you have everything covered.
Top 10 Web Hacking Techniques For 2015
Slideshows  |  4/27/2016  | 
The most influential research on vulnerabilities and exploits, as voted on by the security community.
SWIFT Issues Warning About Multiple Security Incidents
Quick Hits  |  4/27/2016  | 
Group releases new software update to help 'thwart' probable malware used in heists.
FBI Rules Out Disclosing iPhone Software Flaw
Quick Hits  |  4/27/2016  | 
Agency cites limited understanding of method used to crack San Bernardino iPhone.
'Dogspectus' Breaks New Ground For Android Ransomware
News  |  4/26/2016  | 
Blue Coat says it's the first Android ransomware that installs without user interaction
The Growing Sophistication Of Distributed Attacks
News  |  4/26/2016  | 
Botnet and DDoS attacks growing more advanced and more crucial than ever to cybercriminal's attack strategies.
Crowdsourcing The Dark Web: A One-Stop Ran$om Shop
Commentary  |  4/26/2016  | 
Say hello to Ran$umBin, a new kind of ransom market dedicated to criminals and victims alike.
Mexican Voter Database Exposed
Quick Hits  |  4/26/2016  | 
Unsecured database leads to 'leak' of private information of 87 million Mexican voters.
Extortionists Demand Ransom In 'Empty' DDoS Threats
Quick Hits  |  4/26/2016  | 
Gang of cybercriminals calling itself the Armada Collective threatens online businesses in return for Bitcoins.
Verizon DBIR: Over Half Of Data Breaches Exploited Legitimate Passwords In 2015
News  |  4/26/2016  | 
Financial sector suffered the most breaches last year, followed by the accommodation/hotel sector.
Malware At Root Of Bangladesh Bank Heist Lies To SWIFT Financial Platform
News  |  4/25/2016  | 
Customized malware hid $81 million of wire transfers until the money had been safely laundered.
Surviving InfoSec: Digital Crime And Emotional Grime
Commentary  |  4/25/2016  | 
The never ending stream of threats, vulnerabilities, and potential attacks can take its toll on the typical security professional. Here’s how to fight back against the pressure.
US Cyber Command Hacks ISIS
Quick Hits  |  4/25/2016  | 
'Cyber bombs' target ISIS online communications infrastructure.
Dark Reading Marks 10th Anniversary With Month Of Special Coverage
Commentary  |  4/25/2016  | 
Looking back at the decade in security.
Be Prepared: How Proactivity Improves Cybersecurity Defense
Commentary  |  4/23/2016  | 
These five strategies will help you achieve a state of readiness in a landscape of unpredictable risk.
10 Tips for Securing Your SAP Implementation
Slideshows  |  4/23/2016  | 
Without clear ownership of security for a critical business platform like SAP, it should come as no surprise that SAP cybersecurity continues to fall through the cracks among IT, admin, security and InfoSec teams.
Microsoft: Keep Calm But Vigilant About Ransomware
News  |  4/22/2016  | 
Though a growing problem, ransomware is still nowhere as prevalent as other threats, Microsoft says.
The Problem With Patching: 7 Top Complaints
Commentary  |  4/22/2016  | 
Is your security team suffering from patching fatigue? Check out these tips and eliminate critical vulnerabilities in your IT environment.
5 Features to Look For In A Next-Generation Firewall
Slideshows  |  4/22/2016  | 
When it comes to NGFWs, it’s the integration that counts.
SpyEye Creators Sentenced To Long Prison Terms
News  |  4/21/2016  | 
FBI found that arrest halted the release of nasty SpyEye 2.0.
Mea Culpa: Time To Build Security Into Connectivity
Commentary  |  4/21/2016  | 
How those of us who spent decades developing faster, easier, and more scalable networking technology have made the lives of our security counterparts a living hell.
Databases Remain Soft Underbelly Of Cybersecurity
News  |  4/21/2016  | 
Most enterprises still don't continuously monitor database activity.
Security Lessons from C-3PO, Former CSO of the Millennium Falcon
Commentary  |  4/21/2016  | 
The business will take risks. When and how to speak up.
The Perils Of Dynamically Pulling Dependencies
Partner Perspectives  |  4/21/2016  | 
The wide range of functions and broad availability of external packages is a tremendous boon to software development, but keep an eye on the security implications to manage your risk.
A Brief History Of Ransomware
Slideshows  |  4/21/2016  | 
A top ten chronicle of more than a decade of notable ransomware variants and trends.
How Best To Back Up Your Data In Case Of A Ransomware Attack
News  |  4/21/2016  | 
A ransomware attack could be around the corner, but there are some practical steps you can take to back up your data and deflect the attack.
Page 1 / 2   >   >>


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "He keeps trolling Tumblr by posting 'Yes, this is dog.'"
Current Issue
Understanding & Managing the Mobile Security Threat
Mobile devices are increasing IT security risk. Is your enterprise ready?
Flash Poll
10 Recommendations for Outsourcing Security
10 Recommendations for Outsourcing Security
Enterprises today have a wide range of third-party options to help improve their defenses, including MSSPs, auditing and penetration testing, and DDoS protection. But are there situations in which a service provider might actually increase risk?
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Join us as Dark Reading editors speak with IT security hiring experts about improving IT career prospects.