Attacks/Breaches
News & Commentary
As Malware Surges, U.S. Remains Biggest Source of Attacks
Jai Vijayan, Freelance writerNews
The country leads others in malicious IP, URLs and phishing sites.
By Jai Vijayan Freelance writer, 4/24/2015
Comment1 Comment  |  Read  |  Post a Comment
Defense Secretary Outlines New Cybersecurity Strategy
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Russian hackers were caught infiltrating unclassified military networks earlier this year, he said.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 4/24/2015
Comment1 Comment  |  Read  |  Post a Comment
Cybersecurity: Don’t Bank On It With 3rd Parties
Greg Dickinson, CEO, HiperosCommentary
Not knowing that a contractor’s employee had access to system passwords is not a valid excuse when your client’s records are stolen.
By Greg Dickinson CEO, Hiperos, 4/24/2015
Comment1 Comment  |  Read  |  Post a Comment
From The RSA Keynote Stage, Day Two
Sara Peters, Senior Editor at Dark ReadingNews
A 9-year-old CEO hacker, a record-breaking swimmer, and a variety of ideas about data-driven security hit the RSA stage.
By Sara Peters Senior Editor at Dark Reading, 4/22/2015
Comment0 comments  |  Read  |  Post a Comment
‘Golden Hour’ Incident Response Agility
Torry Campbell, Chief Technical Officer of Endpoint and Management at Intel Security
Security leaders must encourage and integrate data, processes, and controls to facilitate comprehension and investment of precious human capital in higher-level tasks.
By Torry Campbell Chief Technical Officer of Endpoint and Management at Intel Security, 4/22/2015
Comment0 comments  |  Read  |  Post a Comment
The Bad News For Infosec In The Target Settlement
Giora Engel, VP Product & Strategy, LightCyberCommentary
The legal argument behind the $10 million Class Action lawsuit and subsequent settlement is a gross misrepresentation of how attackers operate.
By Giora Engel VP Product & Strategy, LightCyber, 4/22/2015
Comment5 comments  |  Read  |  Post a Comment
Bank Botnets Continue to Thrive One Year After Gameover Zeus Takedown
Jai Vijayan, Freelance writerNews
Features on new botnets suggest attackers have learned from the lessons of takedown.
By Jai Vijayan Freelance writer, 4/22/2015
Comment0 comments  |  Read  |  Post a Comment
Zero-Day Malvertising Attack Went Undetected For Two Months
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Researchers at Malwarebytes tracked stealthy attack campaign that infected some major websites with malicious ads harboring ransomware.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 4/21/2015
Comment3 comments  |  Read  |  Post a Comment
Virginia Forms First State-Level Cyberthreat Intel-Sharing Organization
Dark Reading Staff, Quick Hits
Governor Terry McAuliffe today announced Virginia's new Information Sharing and Analysis Organization (ISAO).
By Dark Reading Staff , 4/21/2015
Comment0 comments  |  Read  |  Post a Comment
Health Insurers’ Digital Footprint Widening Attack Surface
Peter Zavlaris, Analyst, RiskIQCommentary
Insurers are ripe targets for attackers since they’re efficient concentrators of every kind of data needed for identity theft, credit card and insurance fraud. Here’s proof.
By Peter Zavlaris Analyst, RiskIQ, 4/21/2015
Comment1 Comment  |  Read  |  Post a Comment
DHS: Most Organizations Need Improvement In Managing Security Risk
Rutrell Yasin, Business Technology Writer, Tech Writers BureauCommentary
At a Department of Homeland Security Summit, government and corporate security teams are taken to task for failing to address critical issues of software assurance, testing and lifecycle support.
By Rutrell Yasin Business Technology Writer, Tech Writers Bureau, 4/20/2015
Comment0 comments  |  Read  |  Post a Comment
Inside the 4 Most Common Threat Actor Tools
 Dr. Chase Cunningham, Head of Threat Intelligence, FireHostCommentary
How do you prevent your environment from becoming the next target? Turn the tables on your attackers.
By Dr. Chase Cunningham Head of Threat Intelligence, FireHost, 4/17/2015
Comment0 comments  |  Read  |  Post a Comment
7 Deadly Sins That Get Users Hacked
Ericka Chickowski, Contributing Writer, Dark Reading
How users and their endpoints are leveraged by the bad guys to eventually find their way to critical data
By Ericka Chickowski Contributing Writer, Dark Reading, 4/16/2015
Comment11 comments  |  Read  |  Post a Comment
Breach Defense Playbook
Ryan Vela  , Regional Director for General Dynamics Fidelis Cybersecurity Solutions (GDFidelis)
How to be smart about defending against your next attack.
By Ryan Vela Regional Director for General Dynamics Fidelis Cybersecurity Solutions (GDFidelis), 4/16/2015
Comment0 comments  |  Read  |  Post a Comment
Harnessing The Power Of Cyber Threat Intelligence
Stu Solomon,  VP, General Counsel & Chief Risk Officer, iSIGHT PartnersCommentary
Here are six real-world examples of how changing your modus operandi from reactive to proactive can drive rapid response to the threats that matter.
By Stu Solomon VP, General Counsel & Chief Risk Officer, iSIGHT Partners, 4/16/2015
Comment2 comments  |  Read  |  Post a Comment
Why Standardized Threat Data Will Help Stop the Next Big Breach
Bill Nelson, President & CEO, Financial Services Information Sharing and Analysis Center (FS-ISAC) and CEO, SoltraCommentary
Adopting industry standards for threat intelligence will reduce a lot of the heavy lifting and free cyber security first responders to focus on what they do best.
By Bill Nelson President & CEO, Financial Services Information Sharing and Analysis Center (FS-ISAC) and CEO, Soltra, 4/15/2015
Comment0 comments  |  Read  |  Post a Comment
'APT-On-APT' Action
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
New spin on the cyber espionage attack: spies hacking other spies for information.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 4/14/2015
Comment0 comments  |  Read  |  Post a Comment
Police Pay Off Ransomware Operators, Again
Sara Peters, Senior Editor at Dark ReadingNews
Law enforcement agencies are proving to be easy marks -- but are they any worse than the rest of us?
By Sara Peters Senior Editor at Dark Reading, 4/14/2015
Comment1 Comment  |  Read  |  Post a Comment
Verizon DBIR: Mobile Devices Not A Factor In Real-World Attacks
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
New annual Verizon Data Breach Investigations Report shows most attacks affect a secondary victim, the average cost of a data breach is just 58 cents per stolen record -- and attackers are not going after mobile en masse.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 4/14/2015
Comment2 comments  |  Read  |  Post a Comment
Chinese Nation-State Hackers Give Up Attack Campaign
Sara Peters, Senior Editor at Dark ReadingNews
It worked on Hurricane Panda. Can APT30 and other organized cyberespionage groups also be convinced that an attack campaign isn't worth the trouble?
By Sara Peters Senior Editor at Dark Reading, 4/13/2015
Comment2 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-4403
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in Zen Cart 1.3.9h allow remote attackers to hijack the authentication of administrators for requests that (1) delete a product via a delete_product_confirm action to product.php or (2) disable a product via a setflag action to categories.ph...

CVE-2012-2930
Published: 2015-04-24
Multiple cross-site request forgery (CSRF) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to hijack the authentication of administrators for requests that (1) add a user via an adduser action to admin/index.php or (2) conduct static PHP code injection attacks in .htusers...

CVE-2012-2932
Published: 2015-04-24
Multiple cross-site scripting (XSS) vulnerabilities in TinyWebGallery (TWG) before 1.8.8 allow remote attackers to inject arbitrary web script or HTML via the (1) selitems[] parameter in a copy, (2) chmod, or (3) arch action to admin/index.php or (4) searchitem parameter in a search action to admin/...

CVE-2012-5451
Published: 2015-04-24
Multiple stack-based buffer overflows in HttpUtils.dll in TVMOBiLi before 2.1.0.3974 allow remote attackers to cause a denial of service (tvMobiliService service crash) via a long string in a (1) GET or (2) HEAD request to TCP port 30888.

CVE-2015-0297
Published: 2015-04-24
Red Hat JBoss Operations Network 3.3.1 does not properly restrict access to certain APIs, which allows remote attackers to execute arbitrary Java methos via the (1) ServerInvokerServlet or (2) SchedulerService or (3) cause a denial of service (disk consumption) via the ContentManager.

Dark Reading Radio
Archived Dark Reading Radio
Join security and risk expert John Pironti and Dark Reading Editor-in-Chief Tim Wilson for a live online discussion of the sea-changing shift in security strategy and the many ways it is affecting IT and business.