News & Commentary
Latest Content
Page 1 / 2   >   >>
New Cybersecurity Regulations Begin Today For NY Banks
News  |  3/1/2017  | 
New York's new security regulations for financial industry viewed as potential model for other states.
Best Practices for Lowering Ransomware Risk
Commentary  |  3/1/2017  | 
The first step is to avoid falling prey in the first place. That means teaching your entire organization - from IT staff to executive management - how not to be a victim.
Hacked Robots Present a New Insider Threat
News  |  3/1/2017  | 
Robots and their control software are rife with critical and painfully obvious security flaws that make them easily hackable, new research shows.
DNSSEC: Why Do We Need It?
Partner Perspectives  |  3/1/2017  | 
The number of signed domain names has grown considerably over the past two and a half years but some sectors are heavily lagging behind.
Insider Sabotage among Top 3 Threats CISOs Cant yet Handle
Partner Perspectives  |  3/1/2017  | 
These five steps can help your organizations limit the risks from disgruntled employees and user errors.
Trump Names New Head of Economic Council for Cybersecurity, Technology
Quick Hits  |  3/1/2017  | 
Grace Koh will be special assistant to the President for technology, telecom, and cybersecurity.
Palo Alto Networks Acquires LightCyber
Quick Hits  |  3/1/2017  | 
Company will integrate LightCyber technology into its Next-Generation Security Platform.
Massive Necurs Spam Botnet Now Equipped to Launch DDoS Attacks
News  |  2/28/2017  | 
With more than one million active bots at any time, a Necurs-enabled DDoS attack could dwarf such an attack by the Mirai botnet.
Report: Only 2 in 3 Cyber Attacks Can Be Stopped with Current Defenses
Partner Perspectives  |  2/28/2017  | 
A recent Bitdefender survey of 250 US IT execs in companies with 1000 or more PCs paints a disturbing picture of cybersecurity preparedness in the enterprise.
How Security Pros Can Bridge The Skills Shortage
Commentary  |  2/28/2017  | 
By paying it forward, we can help address the industrys exploding need for talent.
Mac Malware Reaches New Highs
Partner Perspectives  |  2/28/2017  | 
Two new malware threats in a week this past month, plus others in January, brings the 2017 Mac malware count up to 6 and growing.
Zones of Trust: A New Way of Thinking about IoT Security
Commentary  |  2/28/2017  | 
Recent attacks have focused attention on how to safely add "things"to enterprise networks, a topic that straddles IT and physical security. A zones-of-trust approach may be the answer.
Microsoft Opens Cybersecurity Center in Mexico
Quick Hits  |  2/28/2017  | 
Microsoft launches a Mexican cybersecurity center and signs a Government Security Program to promote IT security research.
Kaspersky Lab Expert's Treason Charge Linked To 2010 Complaint
Quick Hits  |  2/28/2017  | 
A Russian businessman accused Kaspersky Lab security expert Ruslan Stoyanov, and Russian security officers, of leaking confidential data to US firms in 2010.
Apparel, Food Delivery Hardest Hit by Online Fraud Attacks
News  |  2/28/2017  | 
New Forter-Merchant Research Council report confirms that EMV chips have moved fraudsters away from point-of-sale to online.
Google's Ease-of-Use Email Encryption Project Goes Open Source
News  |  2/27/2017  | 
E2Email, together with open source Key Transparency project, are meant to take on the challenges that have dogged end-to-end email encryption adoption for decades.
Microsoft Adds Technical Updates to SDL Site
Quick Hits  |  2/27/2017  | 
Microsoft releases a new round of updates and technical content additions to its Security Development Lifecycle website.
Today on Dark Reading: Your Costs, Risks & Metrics Questions Answered
Commentary  |  2/27/2017  | 
First up on the Dark Reading upcoming events calendar is our Dark Reading Virtual Event Tuesday, Feb. 28.
20 Questions for SecOps Platform Providers
Commentary  |  2/27/2017  | 
Security operations capabilities for the masses is long overdue. Heres how to find a solution that meets your budget and resources.
Two Charged In Gas Station Card-Skimming Scheme
Quick Hits  |  2/27/2017  | 
Two individuals face federal charges for skimming debit card information from gas station pumps across multiple states.
In Cybersecurity, Language Is a Source of Misunderstandings
Commentary  |  2/27/2017  | 
To successfully fight threats across industries, we must all use the same terminology.
Cyber Insurance Uptake Hampered By Skewed Data, Poor Communication
News  |  2/25/2017  | 
Only 29% of US businesses have cyber insurance; Deloitte outlines steps for insurance companies to improve risk models, communication, and policy sales.
Cloudflare Leaked Web Customer Data For Months
News  |  2/24/2017  | 
Potential scope of issue evokes comparisons to Heartbleed.
20 Cybersecurity Startups To Watch In 2017
Slideshows  |  2/24/2017  | 
VC money flowed plentifully into the security market last year, fueling a new crop of innovative companies.
IaaS: The Next Chapter In Cloud Security
Commentary  |  2/24/2017  | 
Organizations adopting IaaS must update their approach to security by using the shared responsibility model.
Suspect Arrested In Connection With Mirai Botnet
Quick Hits  |  2/24/2017  | 
One million Deutsche Telekom customers were knocked offline in a November 2016 cyberattack.
Florida Man Pleads Guilty To Clinton Foundation Hack Attempts
Quick Hits  |  2/24/2017  | 
Timothy Sedlak also convicted in child pornography case and sentenced to 42 years in jail, Reuters reports.
Russia Top Source Of Nefarious Internet Traffic
News  |  2/23/2017  | 
Honeypot research from F-Secure shows majority of illicit online activity coming from IP addresses in Russia - also where ransomware is a hot commodity.
Survey: Most Attackers Need Less Than 12 Hours To Break In
News  |  2/23/2017  | 
A Nuix study of DEFCON pen testers shows that the usual security controls are of little use against a determined intruder
Blockchains New Role In The Internet of Things
Commentary  |  2/23/2017  | 
With next gen distributed consensus algorithms that combine both security and performance, organizations can defend against DDoS attacks, even those that leverage IoT devices
Google Researchers 'Shatter' SHA-1 Hash
Quick Hits  |  2/23/2017  | 
'Collision' attack by researchers at CWI Institute and Google underscores need to retire SHA-1.
Netflix Debuts 'Stethoscope' Open-Source Security Tool
Quick Hits  |  2/23/2017  | 
Entertainment giant offers open-source app for security.
Road Map To A $200,000 Cybersecurity Job
Commentary  |  2/23/2017  | 
Looking to get ahead in cybersecurity? Here are four areas to keep in mind as you make a five-year career plan.
Microsoft Releases Security Updates For Some, Not All, Flaws
Quick Hits  |  2/23/2017  | 
February 21 release addresses Adobe Flash Player bugs for Internet Explorer on Windows 8.1 and Edge for Windows 10.
Exploit Kit-Based Attacks Decline Dramatically
News  |  2/23/2017  | 
But it's too soon to call this downward trend a permanent shift, experts say.
How to Secure Hyperconverged Infrastructures & Why It Is Different
Partner Perspectives  |  2/23/2017  | 
The next-generation datacenter requires new security practices, but that doesnt mean everything we learned about datacenter security becomes obsolete.
End-Of-Life Software Alive And Well On US PCs
News  |  2/23/2017  | 
7.5% of users ran unpatched Windows operating systems in Q4 of 2016, up from 6.1 percent in Q3 of 2016, new study shows.
Fewer Than One-Fourth Of Cybersecurity Job Candidates Are Qualified
News  |  2/22/2017  | 
ISACA report finds that 55% of security jobs take three- to six months to fill, and under 25% of candidates are qualified for the jobs they apply for.
Tunneling Through The "Walls" Of IoT In The Enterprise
Commentary  |  2/22/2017  | 
The movie "Die Hard" has a thing or two to teach us about the pitfalls of the Internet of Things.
Why We Need To Reinvent How We Catalogue Malware
Commentary  |  2/22/2017  | 
One obvious trend: crimeware technologies that come with simple user consoles and functionality to create unique binaries at the click of a button.
6 Tips for Preventing Laptop Data Theft
News  |  2/22/2017  | 
Experts point to stronger passwords, full-disk encryption, and multi-factor authentication as ways to stop data theft in the event a laptop is lost or stolen.
80% Of Web Applications Contain At Least One Security Bug
Quick Hits  |  2/22/2017  | 
Study by Contrast Security finds an average of 45 vulnerabilities per Web application.
Yahoo Trims Its Price Tag To Verizon By $350 Million
Quick Hits  |  2/22/2017  | 
Announcement of new deal price from the previous $4.8 billion allays fears of deal cancellation or even bigger price cut.
Speak Up: Ransomware Attack Uses Voice Recognition
News  |  2/22/2017  | 
New variant of Android ransomware comes with a bizarre twist.
Survey: 14% Of IT Execs Would Pay $500K To Avoid Shaming After A Breach
Partner Perspectives  |  2/22/2017  | 
Bitdefender report shows how negative media headlines following an attack can cause financial damage, ruin business forecasts and severely damage reputations.
Stolen Health Record Databases Sell For $500,000 In The Deep Web
News  |  2/21/2017  | 
Electronic health record databases proving to be some of the most lucrative stolen data sets in cybercrime underground.
Google Shines Light On Corporate Gmail Threats
Quick Hits  |  2/21/2017  | 
New data highlights the diversity of security threats putting corporate Gmail inboxes at risk.
Social Media Impersonators Drive Security Risk
News  |  2/21/2017  | 
A new pool of research digs into the fraudulent social media accounts, a growing threat to individuals and businesses.
Law Enforcement At RSAC: Collaboration Is Key To Online Crime Fighting
News  |  2/21/2017  | 
Agencies and investigators are reaching out across jurisdictions and international borders to vanquish spammers, botnet operators, and worse.
8 Valuable Security Certifications For 2017
Slideshows  |  2/21/2017  | 
A security credential could be the step towards your next job title. But which one to get?
Page 1 / 2   >   >>


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
5 Security Technologies to Watch in 2017
Emerging tools and services promise to make a difference this year. Are they on your company's list?
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.