Content tagged with Advanced Threats
Latest
NIST Removes Cryptography Algorithm from Random Number Generator Recommendations
Products and Releases  |  4/22/2014  | 
September 2013, news reports prompted public concern about the trustworthiness of Dual_EC_DRBG. As a result, NIST immediately recommended against the use of the algorithm and reissued SP 800-90A for public comment.
Belden Rolls Out Advanced Cyber Security Toolkit
Products and Releases  |  4/22/2014  | 
New Tofino Enforcer Software Development Kit Brings Next Generation Security to SCADA Networks
Cartoon: E2c$y5tion
Cartoon Contest  |  4/18/2014  | 
11 Heartbleed Facts: Vulnerability Discovery, Mitigation Continue
News  |  4/17/2014  | 
Millions of websites, applications from Cisco and VMware, Google Play apps, as well as millions of Android devices are vulnerable -- and the list keeps growing.
Heartbleed Will Go On Even After The Updates
News  |  4/10/2014  | 
What's next now that the mindset is 'assume the worst has already occurred?'
More Than A Half-Million Servers Exposed To Heartbleed Flaw
News  |  4/9/2014  | 
What the newly exposed SSL/TLS threat really means for enterprises and end-users.
One Year Later: The APT1 Report
Commentary  |  4/8/2014  | 
One of the most positive impacts of APT1 is the undeniable rise in the stature of the threat intelligence industry. "Threat Intelligence" is the SIEM, the NAC of 2014.
Advanced Attacks Are The New Norm, Study Says
Quick Hits  |  4/4/2014  | 
According to the Websense 2014 Threat Report, most malicious exploits now are advanced and targeted.
Advanced Persistent Threats: What Are They, Really?
Advanced Persistent Threats: What Are They, Really?
Dark Reading Videos  |  4/4/2014  | 
There seem to be as many definitions of APT as there are actual APTs. So what is an advanced persistent threat, really?
Windows XP
Flash Poll  |  4/2/2014  | 
Cyber Criminals Operate On A Budget, Too
Quick Hits  |  4/1/2014  | 
New report shines light on how attacks have gotten more advanced but still basically use some of the same old, same old, tools
Attacks Rise On Network 'Blind' Spot
News  |  3/27/2014  | 
Interop speaker says DDoS attacks are not the only forms of abuse on the Domain Name Server.
FireEye Releases Comprehensive Analysis of 2013 Zero-day Attacks; Impact on Security Models
Products and Releases  |  3/27/2014  | 
New Research Paper Offers Insight into Industry’s Leading Zero-day and Advanced Threat Detection Models
A Cyber History Of The Ukraine Conflict
Commentary  |  3/27/2014  | 
The CTO for the US Cyber Consequences Unit offers a brief lesson in Russian geopolitics and related cyber flare-ups, and explains why we should be concerned.
Facebook Builds Its Own Threat Modeling System
Quick Hits  |  3/26/2014  | 
The tool helps the social network gather, store, analyze, and react to the latest threats against it.


Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Containing Corporate Data on Mobile Devices
Containing Corporate Data on Mobile Devices
If you’re still focused on securing endpoints, you’ve got your work cut out for you. WiFi network provider iPass surveyed 1,600 mobile workers and found that the average US employee carries three devices -- a smartphone, a computer, and a tablet or e-reader -- with more than 80% of them doing work on personal devices.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-1421
Published: 2014-04-22
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php.

CVE-2013-2105
Published: 2014-04-22
The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html.

CVE-2013-2187
Published: 2014-04-22
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to the home page.

CVE-2013-4116
Published: 2014-04-22
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

CVE-2013-4472
Published: 2014-04-22
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

Best of the Web