Commentary
Content posted in October 2013
Simple Security Is A Better Bet
Commentary  |  10/31/2013  | 
Complex security programs are little better than no security
Q&A: FedRAMP Director Discusses Cloud Security Innovation
Commentary  |  10/31/2013  | 
Maria Roat, FedRAMP director, speaks with former Transportation Department CIO Nitin Pradhan on the federal government's approach to security assessment, authorization, and continuous monitoring for cloud products and services.
Looking For A Security Job? You Don't Need To Be Bo Derek
Commentary  |  10/30/2013  | 
7 tips to convince a hiring manager that you're a perfect fit.
Vanishing IT Security Boundaries Reappearing Disguised As Identity
Commentary  |  10/30/2013  | 
It's that time of year, when nothing is as it seems. If cloud and mobile are haunting your dreams, consider some open protocol treats.
Think Hackers Are IT's Biggest Threat? Guess Again
Commentary  |  10/29/2013  | 
More than one third of all data security breaches at government agencies are caused accidentally by internal employees.
Quick Guide To Flash Storage Latency Wars
Commentary  |  10/29/2013  | 
Because latency is the key performance differentiator in server-side flash, SSD, PCIe and memory bus flash storage vendors are competing on speed.
Failure To Deploy: Aided And Abetted By Shelfware
Commentary  |  10/28/2013  | 
It takes more than technology acquisition to protect against the insider threat -- just ask the NSA
Experian Breach Fallout: ID Theft Nightmares Continue
Commentary  |  10/24/2013  | 
Data brokers amassing gigantic data stores of people's valuable personal information are too big to not fail. Why are consumers getting stuck with the mess?
Is Your DNS Server A Weapon?
Commentary  |  10/21/2013  | 
As we improve our defenses against distributed-denial-of-service (DDoS) attacks, the bad guys adapt and step up their game, too. Here's how to use your domain name servers to ward off hackers.
The Reality Of Freshly Minted Software Engineers
Commentary  |  10/15/2013  | 
Why do recent computer science graduates need to be retrained when they hit the commercial world?
We're All The APT
Commentary  |  10/12/2013  | 
XKeyscore, FoxAcid: APT lines are blurring
Don't Let 'Spooks' Get Your Cloud Data
Commentary  |  10/10/2013  | 
Lesson from National Cyber Security Awareness Month: Keys are the key, and keep it simple.
Evasion Techniques And Sneaky DBAs
Commentary  |  10/7/2013  | 
Why should DBAs introduce security measures that make their jobs harder for the nebulous benefit of better security?
Distributing Malware Through Future App Stores
Commentary  |  10/7/2013  | 
Difficult times ahead for app markets as professional malware developers ramp their evasion techniques
Next-Gen Spam: Quality Over Quantity
Commentary  |  10/3/2013  | 
The industry has been remarkably innovative in developing business models to extract money from the unwary.
Stratfor Hacker: FBI Entrapment Shaped My Case
Commentary  |  10/3/2013  | 
Hacker Jeremy Hammond asks for leniency before sentencing, citing the role of FBI informant Sabu in his case. How far can the FBI go with suspected computer criminals?
WordPress Attacks: Time To Wake Up
Commentary  |  10/1/2013  | 
The latest WordPress hacks highlight our continued laziness when implementing online security, a problem made worse by free, easy-to-use sites.
Security Skills For 2023
Commentary  |  10/1/2013  | 
Align your career with these top security trends
Make The Most Of National Cyber Security Awareness Month
Commentary  |  10/1/2013  | 
NCSAM is a catalyst to get extra attention for your security programs
Penetration Testing With Honest-To-Goodness Malware
Commentary  |  10/1/2013  | 
When did penetration-testing methodologies stop replicating the vectors attackers make?


Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Security Technologies to Watch in 2017
Emerging tools and services promise to make a difference this year. Are they on your company's list?
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.