Author

 Samuel Visner & Beth Musumeci
Twitter
LinkedIn
RSS
E-Mail

Profile of Samuel Visner & Beth Musumeci

Senior VP, General Manager & Senior VP, ICF Commercial Cybersecurity Practice
News & Commentary Posts: 1

Samuel Visner joined ICF in 2014 and has more than 35 years of experience in the national security and cybersecurity domains for the private sector and for the US federal government. Previously, Sam was vice president and general manager of CSC Global Cybersecurity and was senior vice president at SAIC. Sam also served as chief, signals intelligence programs, at the National Security Agency.  Sam is actively involved in and provides leadership to industry organizations, including the National Intelligence Council, the Cyber R&D Task Force of the Intelligence, National Security Alliance and Cyber Committee of the Armed Forces Communications, and Electronics Association.

Sam presents and writes on cybersecurity issues and is an adjunct professor at Georgetown University where he teaches cybersecurity policy and operations. He has a master's degree in telecommunications from George Washington University and a bachelor's degree in international politics from Georgetown University

Beth Musumeci is the senior vice president of ICF's commercial cybersecurity practice.  She joined ICF International in 2015 and has more than 20 years of experience in cybersecurity work for the private sector and for the US federal government. Prior to ICF, Beth led strategy and transformation, and was the general manager for CSC's global commercial cyber security practice.  She was an early pioneer in establishing security operations centers, and led the establishment of their global logical security operations center spanning five continents and serving hundreds of customers. 

Early in her career, Beth was a practitioner in the chemical, energy and natural resources industry as a lead information risk manager.  She began her career at the DuPont Company. Beth is based in Delaware and travels globally to foster partnerships and serve as a trusted advisor to clients worldwide.

 

Articles by Samuel Visner & Beth Musumeci
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11763
PUBLISHED: 2018-09-25
In Apache HTTP Server 2.4.17 to 2.4.34, by sending continuous, large SETTINGS frames a client can occupy a connection, server thread and CPU time without any connection timeout coming to effect. This affects only HTTP/2 connections. A possible mitigation is to not enable the h2 protocol.
CVE-2018-14634
PUBLISHED: 2018-09-25
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerabl...
CVE-2018-1664
PUBLISHED: 2018-09-25
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. ...
CVE-2018-1669
PUBLISHED: 2018-09-25
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote atta...
CVE-2018-1539
PUBLISHED: 2018-09-25
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.