Endpoint // Authentication
News & Commentary
7 Ways To Lock Down Your Privileged Accounts
Steve Zurier, Freelance Writer
Admin passwords contained within privileged accounts can open up the keys to the kingdom to determined attackers. Here's how to stop them.
By Steve Zurier Freelance Writer, 7/22/2016
Comment0 comments  |  Read  |  Post a Comment
Security Gets Political With Hacks, Darknet Sales
Terry Sweeney, News
As presidential campaigns get into full swing, neither party is immune to online chicanery -- and neither are voters
By Terry Sweeney , 7/21/2016
Comment0 comments  |  Read  |  Post a Comment
Ex-Cardinal Exec Jailed For Hacking Astros
Dark Reading Staff, Quick Hits
Christopher Correa gets 46 months for unlawful access of rivals database and downloading confidential details.
By Dark Reading Staff , 7/20/2016
Comment0 comments  |  Read  |  Post a Comment
Locking Down Windows 10: 6 New Features
Rutrell Yasin, Business Technology Writer, Tech Writers Bureau
The latest version of Windows includes expanded identity and access controls, advanced Bitlocker encryption, and new malware protections.
By Rutrell Yasin Business Technology Writer, Tech Writers Bureau, 7/18/2016
Comment0 comments  |  Read  |  Post a Comment
Staying Cyber Safe At The Olympics
Ericka Chickowski, Contributing Writer, Dark Reading
Travel tips and more in hostile environments abroad.
By Ericka Chickowski Contributing Writer, Dark Reading, 7/16/2016
Comment1 Comment  |  Read  |  Post a Comment
What SMBs Need To Know About Security But Are Afraid To Ask
Sean Martin, CISSP | President, imsmartin
A comprehensive set of new payment protection resources from the PCI Security Standards Council aims to help small- and medium-sized businesses make security a priority.
By Sean Martin CISSP | President, imsmartin, 7/14/2016
Comment1 Comment  |  Read  |  Post a Comment
Facebook Will Offer 'Secret Conversations' On Messenger
Dark Reading Staff, Quick Hits
New feature with end-to-end encryption on some opt-in messages likely to be available soon.
By Dark Reading Staff , 7/11/2016
Comment0 comments  |  Read  |  Post a Comment
Passwords To Be Phased Out By 2025, Say InfoSec Pros
Dark Reading Staff, Quick Hits
Behavioral biometrics technology and two-factor authentication are on the rise as safer alternatives, according to a study.
By Dark Reading Staff , 6/30/2016
Comment6 comments  |  Read  |  Post a Comment
The Blind Spot Between The Cloud & The Data Center
Saryu Nayyar, CEO, GuruculCommentary
Ask most enterprise security analysts responsible for detection and response about their visibility into identity access risks and youre likely to get some confused looks. Heres why.
By Saryu Nayyar CEO, Gurucul, 6/27/2016
Comment2 comments  |  Read  |  Post a Comment
Internet Of Things & The Platform Of Parenthood
Don Bailey, Founder & CEO, Lab Mouse SecurityCommentary
A new fathers musings on the problems with securing embedded systems, and why there are so few incentives for architecting trustworthy IoT technology from the ground up.
By Don Bailey Founder & CEO, Lab Mouse Security, 6/23/2016
Comment21 comments  |  Read  |  Post a Comment
Phishing, Whaling & The Surprising Importance Of Privileged Users
Joseph Opacki, VP, Threat Research, PhishLabsCommentary
By bagging a privileged user early on, attackers can move from entry point to mission accomplished in no time at all.
By Joseph Opacki VP, Threat Research, PhishLabs, 6/21/2016
Comment2 comments  |  Read  |  Post a Comment
5 Tips For Staying Cyber-Secure On Your Summer Vacation
Emily Johnson, Associate Editor, UBM AmericasNews
Stick with mobile payment apps and carrier networks when traveling. And don't broadcast your plans or locations via social media.
By Emily Johnson Associate Editor, UBM Americas, 6/20/2016
Comment3 comments  |  Read  |  Post a Comment
Pretty Good Passwords: Cartoon Caption Contest Winners
Marilyn Cohodas, Community Editor, Dark ReadingCommentary
Sticky notes, multi-factor authentication, password reuse and Donald Trump. And the winner is...
By Marilyn Cohodas Community Editor, Dark Reading, 6/16/2016
Comment1 Comment  |  Read  |  Post a Comment
Self-Service Password Reset & Social Engineering: A Match Made In Hell
Jackson Shaw, Senior Director, Product Management, Dell SecurityCommentary
A sad tale of how hackers compromised a CEOs corporate account by trolling Facebook and LInkedin for answers to six common authentication questions. (And how to avoid that happening to you)
By Jackson Shaw Senior Director, Product Management, Dell Security, 6/13/2016
Comment9 comments  |  Read  |  Post a Comment
Twitter Says Its Servers Were Not Breached
Dark Reading Staff, Quick Hits
Account details leaked are from other hacked websites, claims the social media tool.
By Dark Reading Staff , 6/13/2016
Comment0 comments  |  Read  |  Post a Comment
Microsegmentation & The Need For An Intelligent Attack Surface
Doug Gourlay,  Corporate VP, Skyport SystemsCommentary
There is a fundamental difference in the security posture and technology for protecting the White House versus a Social Security office in California. So, too, for the critical apps and systems that are likely targets in your enterprise.
By Doug Gourlay Corporate VP, Skyport Systems, 6/7/2016
Comment0 comments  |  Read  |  Post a Comment
Poor Airport Security Practices Just Dont Fly
Joe Schorr, Director of Advanced Security Solutions, BomgarCommentary
Five lessons learned the hard way by the Tampa International Airport about bringing third parties into a security environment.
By Joe Schorr Director of Advanced Security Solutions, Bomgar, 5/24/2016
Comment0 comments  |  Read  |  Post a Comment
Google To Eliminate Passwords For Android Apps
Dark Reading Staff, Quick Hits
Project Abacus, in last stage of trial, will employ secure biometrics to unlock devices.
By Dark Reading Staff , 5/24/2016
Comment7 comments  |  Read  |  Post a Comment
Enterprises Must Consider Privacy Concern For Biometrics
Ericka Chickowski, Contributing Writer, Dark ReadingNews
On-server storage and processing of biometric authentication presents a host of regulatory and corporate responsibility issues.
By Ericka Chickowski Contributing Writer, Dark Reading, 5/12/2016
Comment3 comments  |  Read  |  Post a Comment
British Law Enforcement Agency Loses Bid To Get Passwords From Hacker Lauri Love
Dark Reading Staff, Quick Hits
Judge says National Crime Agency should use normal police powers -- not civil action -- to access information, allegedly hacked from US Army, NASA and US Federal Reserve networks.
By Dark Reading Staff , 5/11/2016
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
Posted by LegerMuller
Current Conversations Ah ok ^^
In reply to: Re: Wifi
Post Your Own Reply
More Conversations
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
DNS Threats: What Every Enterprise Should Know
Domain Name System exploits could put your data at risk. Here's some advice on how to avoid them.
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio

The cybersecurity profession struggles to retain women (figures range from 10 to 20 percent). It's particularly worrisome for an industry with a rapidly growing number of vacant positions.

So why does the shortage of women continue to be worse in security than in other IT sectors? How can men in infosec be better allies for women; and how can women be better allies for one another? What is the industry doing to fix the problem -- what's working, and what isn't?

Is this really a problem at all? Are the low numbers simply an indication that women do not want to be in cybersecurity, and is it possible that more women will never want to be in cybersecurity? How many women would we need to see in the industry to declare success?

Join Dark Reading senior editor Sara Peters and guests Angela Knox of Cloudmark, Barrett Sellers of Arbor Networks, Regina Wallace-Jones of Facebook, Steve Christey Coley of MITRE, and Chris Roosenraad of M3AAWG on Wednesday, July 13 at 1 p.m. Eastern Time to discuss all this and more.