Attacks/Breaches

News & Commentary
US Intel Officials Share Their National Cybersecurity Concerns
Kelly Sheridan, Staff Editor, Dark ReadingNews
Leaders in the security sector discuss the most pressing cyberthreats threatening the United States and what can be done to mitigate them.
By Kelly Sheridan Staff Editor, Dark Reading, 7/20/2018
Comment0 comments  |  Read  |  Post a Comment
Singapore Health Services Data Breach Exposes Info on 1.5 Million People
Jai Vijayan, Freelance writerNews
Attackers, repeatedly and specifically, targeted Singapore Prime Minister Lee Hsien Loong's medication data.
By Jai Vijayan Freelance writer, 7/20/2018
Comment1 Comment  |  Read  |  Post a Comment
Microsoft: Three Hacking Attempts Made on Midterm Elections
Dark Reading Staff, Quick Hits
Microsoft detected data indicating three congressional candidates were being hit with cyberattacks - the first to target midterm elections.
By Dark Reading Staff , 7/20/2018
Comment0 comments  |  Read  |  Post a Comment
HR Services Firm ComplyRight Suffers Major Data Breach
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
More than 7,500 customer companies were affected, and the number of individuals whose information was leaked is unknown.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 7/20/2018
Comment0 comments  |  Read  |  Post a Comment
Why Artificial Intelligence Is Not a Silver Bullet for Cybersecurity
Tomas Honzak,  Director, Security and Compliance, GoodDataCommentary
Like any technology, AI and machine learning have limitations. Three are detection, power, and people.
By Tomas Honzak Director, Security and Compliance, GoodData, 7/20/2018
Comment0 comments  |  Read  |  Post a Comment
Cyberattacks in Finland Surge During Trump-Putin Summit
Jai Vijayan, Freelance writerNews
Attackers targeted IoT devices like they did during Trump's June meeting with North Korea's Kim Jong-un, but this time China was the top-attacking nation.
By Jai Vijayan Freelance writer, 7/19/2018
Comment0 comments  |  Read  |  Post a Comment
Robotic Vacuums May Hoover Your Data
Dark Reading Staff, Quick Hits
Researchers have discovered a pair of vulnerabilities that allow unauthorized code execution in a robotic vacuum.
By Dark Reading Staff , 7/19/2018
Comment0 comments  |  Read  |  Post a Comment
The Fundamental Flaw in Security Awareness Programs
Ira Winkler, CISSP, President, Secure MentemCommentary
It's a ridiculous business decision to rely on the discretion of a minimally trained user to thwart a highly skilled sociopath, financially motivated criminal, or nation-state.
By Ira Winkler CISSP, President, Secure Mentem, 7/19/2018
Comment3 comments  |  Read  |  Post a Comment
Beyond Passwords: Why Your Company Should Rethink Authentication
Rajiv Dholakia, VP Products, Nok Nok LabsCommentary
Scaling security infrastructure requires scaling trust of users, devices, and methods of authentication. Here's how to get started.
By Rajiv Dholakia VP Products, Nok Nok Labs, 7/19/2018
Comment0 comments  |  Read  |  Post a Comment
Number of Retailers Impacted by Breaches Doubles
Ericka Chickowski, Contributing Writer, Dark ReadingNews
The retail race for digital transformation is being run without the safety of security measures.
By Ericka Chickowski Contributing Writer, Dark Reading, 7/19/2018
Comment0 comments  |  Read  |  Post a Comment
Make Security Boring Again
Joel Fulton, Chief Information Security Officer for SplunkCommentary
In the public sector and feeling overwhelmed? Focus on the basics, as mind numbing as that may sound.
By Joel Fulton Chief Information Security Officer for Splunk, 7/18/2018
Comment0 comments  |  Read  |  Post a Comment
New Subscription Service Takes on Ransomware Protection
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
Training and response is the basis of a new offering that addresses ransomware and extortion attacks.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 7/18/2018
Comment0 comments  |  Read  |  Post a Comment
Microsoft Moves Up As Phishers' Favorite Target for Brand Spoofing
Dark Reading Staff, Quick Hits
Researchers compiled a list of the most common brands to impersonate by detecting and analyzing new phishing URLs.
By Dark Reading Staff , 7/18/2018
Comment0 comments  |  Read  |  Post a Comment
From Bullets to Clicks: The Evolution of the Cyber Arms Race
Nir Gaist, CTO and Founder of NyotronCommentary
Cyber strategies have become as important as physical weapons in the battle for political advantage. Here's a quick look at four broad categories.
By Nir Gaist CTO and Founder of Nyotron, 7/18/2018
Comment0 comments  |  Read  |  Post a Comment
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Trump administration's initial lack of a unified front in the wake of Russian election-hacking indictments worries cybersecurity experts.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 7/17/2018
Comment6 comments  |  Read  |  Post a Comment
Cloud Security: Lessons Learned from Intrusion Prevention Systems
Gunter Ollmann, CTO, Security, Microsoft Cloud and AI Division   Commentary
The advancement of AI-driven public cloud technology is changing the game of "protection by default" in the enterprise.
By Gunter Ollmann CTO, Security, Microsoft Cloud and AI Division , 7/17/2018
Comment0 comments  |  Read  |  Post a Comment
SCADA/ICS Dangers & Cybersecurity Strategies
Peter Newton, Senior Director of Product Marketing at FortinetCommentary
Nearly 60% of surveyed organizations using SCADA or ICS reported they experienced a breach in those systems in the last year. Here are four tips for making these systems safer.
By Peter Newton Senior Director of Product Marketing at Fortinet, 7/17/2018
Comment0 comments  |  Read  |  Post a Comment
7 Nigerians Indicted for Fraud Operation on Dating Sites
Dark Reading Staff, Quick Hits
Con artists have been charged with operating a scheme that cost users of American dating websites more than $1.5 million.
By Dark Reading Staff , 7/17/2018
Comment0 comments  |  Read  |  Post a Comment
Russian National Vulnerability Database Operation Raises Suspicions
Jai Vijayan, Freelance writerNews
Recorded Future says Russia's Federal Service for Technical and Export Control has ability to find, weaponize vulnerabilities under cover of doing technology inspections.
By Jai Vijayan Freelance writer, 7/16/2018
Comment0 comments  |  Read  |  Post a Comment
Less Than Half of Cyberattacks Detected via Antivirus: SANS
Kelly Sheridan, Staff Editor, Dark ReadingNews
Companies are buying next-gen antivirus and fileless attack detection tools but few have the resources to use them, researchers report.
By Kelly Sheridan Staff Editor, Dark Reading, 7/16/2018
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
Posted by Kolina
Current Conversations I have the same fillings about Google's work on this.. Great written
In reply to: ... HA!">Re: Google teaming with ... HA!
Post Your Own Reply
More Conversations
PR Newswire
White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
The Fundamental Flaw in Security Awareness Programs
Ira Winkler, CISSP, President, Secure Mentem,  7/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14492
PUBLISHED: 2018-07-21
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
CVE-2018-3770
PUBLISHED: 2018-07-20
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files.
CVE-2018-3771
PUBLISHED: 2018-07-20
An XSS in statics-server <= 0.0.9 can be used via injected iframe in the filename when statics-server displays directory index in the browser.
CVE-2018-5065
PUBLISHED: 2018-07-20
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Use-after-free vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
CVE-2018-5066
PUBLISHED: 2018-07-20
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.