Author

 Curtis Dalton
Twitter
LinkedIn
RSS
E-Mail

Profile of Curtis Dalton

SVP & Global Head of Security Services for Pactera US (a Blackstone portfolio company)
Member Since: 3/2/2016
Author
News & Commentary Posts: 1
Comments: 0

Curtis Dalton is an information security and technology executive with 24 years' experience and a proven track record in management, technology and security. Prior to joining Pactera, Dalton was Chief Information Security Officer for Sapient - a global IT services and digital services provider. For Sapient, Dalton developed an acclaimed security program rooted in ISO 27001 globally to support a burgeoning business which doubled over his tenure.
Dalton's experience dates back to the beginning of the security profession when he helped develop one of the first firewalls, implemented one of the first global VPN solutions, and developed an early Data Loss Prevention solution in the mid '90's. Dalton is a published author & speaker with fifteen articles and cover stories appearing within leading publications, and a popular security architecture book published by Osborne McGraw-Hill. Dalton is certified as CISSP, CISM, ISMS Lead Auditor/Lead Implementer and is an active member within the information security community including ISC2, ISACA, ISSA, InfraGard and IAPP.

Articles by Curtis Dalton
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Worst Password Blunders of 2018 Hit Organizations East and West
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
2019 Attacker Playbook
Ericka Chickowski, Contributing Writer, Dark Reading,  12/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-20173
PUBLISHED: 2018-12-17
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.
CVE-2017-18352
PUBLISHED: 2018-12-17
Error reporting within Rendertron 1.0.0 allows reflected Cross Site Scripting (XSS) from invalid URLs.
CVE-2017-18353
PUBLISHED: 2018-12-17
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.
CVE-2017-18354
PUBLISHED: 2018-12-17
Rendertron 1.0.0 allows for alternative protocols such as 'file://' introducing a Local File Inclusion (LFI) bug where arbitrary files can be read by a remote attacker.
CVE-2017-18355
PUBLISHED: 2018-12-17
Installed packages are exposed by node_modules in Rendertron 1.0.0, allowing remote attackers to read absolute paths on the server by examining the "_where" attribute of package.json files.