Commentary
Content posted in April 2016
Stop Building Silos. Security Is Everyones Problem
Commentary  |  4/29/2016  | 
Yes, its true that the speed of DevOps has made security more difficult. But that doesnt mean accelerated release cycles and secure applications have to be mutually exclusive.
6 Reasons ISPs Must Step Up Defenses Against DDoS Attacks
Commentary  |  4/28/2016  | 
Conducting a DDoS attack used to require a significant amount of talent. But today, a high school student with basic hacking skills can access tools that will challenge even the most experienced ISP security teams.
8 Signs Your Security Culture Lacks Consistency
Commentary  |  4/27/2016  | 
Organizations that practice what they preach and match their actions to their words do far better achieving their goals than those that do not. Here's why that matters.
Crowdsourcing The Dark Web: A One-Stop Ran$om Shop
Commentary  |  4/26/2016  | 
Say hello to Ran$umBin, a new kind of ransom market dedicated to criminals and victims alike.
Surviving InfoSec: Digital Crime And Emotional Grime
Commentary  |  4/25/2016  | 
The never ending stream of threats, vulnerabilities, and potential attacks can take its toll on the typical security professional. Heres how to fight back against the pressure.
Dark Reading Marks 10th Anniversary With Month Of Special Coverage
Commentary  |  4/25/2016  | 
Looking back at the decade in security.
Be Prepared: How Proactivity Improves Cybersecurity Defense
Commentary  |  4/23/2016  | 
These five strategies will help you achieve a state of readiness in a landscape of unpredictable risk.
The Problem With Patching: 7 Top Complaints
Commentary  |  4/22/2016  | 
Is your security team suffering from patching fatigue? Check out these tips and eliminate critical vulnerabilities in your IT environment.
Mea Culpa: Time To Build Security Into Connectivity
Commentary  |  4/21/2016  | 
How those of us who spent decades developing faster, easier, and more scalable networking technology have made the lives of our security counterparts a living hell.
Security Lessons from C-3PO, Former CSO of the Millennium Falcon
Commentary  |  4/21/2016  | 
The business will take risks. When and how to speak up.
Internal Pen-Testing: Not Just For Compliance Audits Anymore
Commentary  |  4/20/2016  | 
How turning your internal penetration team into a 'Friendly Network Force' can identify and shut down the cracks in your security program.
Device Advice: Keeping Fraudsters From Consumer Info
Commentary  |  4/19/2016  | 
Data breaches are the first stop for criminals with intentions to steal personally identifiable information. These tips show how to fight fraud while optimizing the customer experience.
Privacy Debate: Apple & Google Today; AWS or Azure Tomorrow?
Commentary  |  4/18/2016  | 
Why the recent fight over mobile phone security and encryption is moving to the cloud.
Rethinking Application Security With Microservices Architectures
Commentary  |  4/15/2016  | 
The advantages offered by the container model go against many of the assumptions of traditional security mechanisms. Here are 5 new concepts & 4 best practices youll need to understand.
5 Steps to Improve Your Software Supply Chain Security
Commentary  |  4/14/2016  | 
Organizations that take control of their software supply chains will see tremendous gains in developer productivity, improved quality, and lower risk.
Java Deserialization: Running Faster Than a Bear
Commentary  |  4/14/2016  | 
Software components that were once good can sour instantly when new vulnerabilities are discovered within them. When that happens, the bears are coming, and you have to respond quickly.
Securing the Weakest Link: Insiders
Commentary  |  4/13/2016  | 
No longer is a hoodie-wearing malicious hacker the most obvious perpetrator of an inside cyber attack.
Managing The Message Before The Breach
Commentary  |  4/12/2016  | 
No leader wants to see their company exploited by creative cyber villains. Heres how CISOs can stay ahead of the game with a strategic plan.
Dark Reading Radio: Advancing Your Security Career
Commentary  |  4/12/2016  | 
INCYMI! Join us for a fascinating discussion on key trends and opportunities in the rapidly evolving world of cybersecurity.
7 Profiles Of Highly Risky Insiders
Commentary  |  4/8/2016  | 
To understand who these insiders are and why they pose a risk, start by looking at the root of the problem.
Context & Awareness: Its All About The Apps
Commentary  |  4/7/2016  | 
Why data context, application awareness and training are keys to mitigating security risks,
Understanding The Cloud Threat Surface
Commentary  |  4/6/2016  | 
How todays borderless environment creates new threat vectors from third-party apps, brute force password attacks, and login attempts with stolen credentials.
How to Hack Your Own Car
Commentary  |  4/5/2016  | 
As vehicles become more software-driven, car manufacturers are keeping the inner workings of electronics systems more secretive. Here's one way to maintain security updates and still preserve your 'freedom to tinker.'
CAs Need To Force Rules Around Trust
Commentary  |  4/4/2016  | 
Google Symantec flap reveals worrisome weakness in the CA system.
Avoiding Legal Landmines in Data Breach Response
Commentary  |  4/4/2016  | 
Building a legally defensible cybersecurity program means seeking out guidance from legal advisors before a serious incident forces you together.
Raising The Stakes For Application Security
Commentary  |  4/1/2016  | 
Why, if we already know most everything we need to know about exploited vulnerabilities in software, do hacks keep happening?


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
The Dark Reading Security Spending Survey
The Dark Reading Security Spending Survey
Enterprises are spending an unprecedented amount of money on IT security where does it all go? In this survey, Dark Reading polled senior IT management on security budgets and spending plans, and their priorities for the coming year. Download the report and find out what they had to say.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.