Security Spills: 9 Problems Causing the Most Stress
2019 Security Spending Outlook
6 Reasons to Be Wary of Encryption in Your Enterprise
Cartoon: Connected Car Security
7 Tips for Communicating with the Board
News & Commentary
Staffing Shortage Makes Vulnerabilities Worse
Dark Reading Staff, Quick Hits
Businesses don't have sufficient staff to find vulnerabilities or protect against their exploit, according to a new report by Ponemon Institute.
By Dark Reading Staff , 2/15/2019
Comment0 comments  |  Read  |  Post a Comment
Hackers Found Phishing for Facebook Credentials
Dark Reading Staff, Quick Hits
A "very realistic-looking" login prompt is designed to capture users' Facebook credentials, researchers report.
By Dark Reading Staff , 2/15/2019
Comment0 comments  |  Read  |  Post a Comment
ICS/SCADA Attackers Up Their Game
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
With attackers operating more aggressively and stealthily, some industrial network operators are working to get a jump on the threats.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 2/15/2019
Comment0 comments  |  Read  |  Post a Comment
Post-Quantum Crypto Standards Arent All About the Math
Ericka Chickowski, Contributing Writer, Dark ReadingNews
The industry needs to keep in mind the realities of hardware limits and transitional growing pains, according to Microsoft, Utimaco researchers.
By Ericka Chickowski Contributing Writer, Dark Reading, 2/15/2019
Comment0 comments  |  Read  |  Post a Comment
White-Hat Bug Bounty Programs Draw Inspiration from the Old West
Michelle Moore, Academic Director and Adjunct Professor, University of San DiegoCommentary
These programs are now an essential strategy in keeping the digital desperados at bay.
By Michelle Moore Academic Director and Adjunct Professor, University of San Diego, 2/15/2019
Comment0 comments  |  Read  |  Post a Comment
Mozilla, Internet Society and Others Pressure Retailers to Demand Secure IoT Products
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
New initiative offers five principles for greater IoT security.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 2/14/2019
Comment1 Comment  |  Read  |  Post a Comment
From 'O.MG' to NSA, What Hardware Implants Mean for Security
Robert Lemos, Technology Journalist/Data ResearcherNews
A wireless device resembling an Apple USB-Lightning cable that can exploit any system via keyboard interface highlights risks associated with hardware Trojans and insecure supply chains.
By Robert Lemos Technology Journalist/Data Researcher, 2/14/2019
Comment0 comments  |  Read  |  Post a Comment
High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writerNews
Some have even turned to alcohol and medication to cope with pressure.
By Jai Vijayan Freelance writer, 2/14/2019
Comment1 Comment  |  Read  |  Post a Comment
Toyota Prepping 'PASTA' for its GitHub Debut
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Carmaker's open source car-hacking tool platform soon will be available to the research community.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 2/14/2019
Comment0 comments  |  Read  |  Post a Comment
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark ReadingNews
In the weeks leading up to Valentine's Day 2019, researchers notice a new form of Gandcrab appearing in romance-themed emails.
By Kelly Sheridan Staff Editor, Dark Reading, 2/14/2019
Comment1 Comment  |  Read  |  Post a Comment
New Professional Development Institute Aims to Combat Cybersecurity Skills Shortage
Dark Reading Staff, Quick Hits
The (ISC)2 announces a new institute for working cybersecurity professionals to continue their education.
By Dark Reading Staff , 2/14/2019
Comment0 comments  |  Read  |  Post a Comment
Coffee Meets Bagel Confirms Hack on Valentine's Day
Dark Reading Staff, Quick Hits
The dating app says users' account data may have been obtained by an unauthorized party.
By Dark Reading Staff , 2/14/2019
Comment0 comments  |  Read  |  Post a Comment
Diversity Is Vital to Advance Security
Joan Pepin, CISO & VP of Operations, Auth0Commentary
Meet five female security experts who are helping to propel our industry forward.
By Joan Pepin CISO & VP of Operations, Auth0, 2/14/2019
Comment1 Comment  |  Read  |  Post a Comment
How to Create a Dream Team for the New Age of Cybersecurity
Gaurav Banga, Founder and CEO, BalbixCommentary
When each member of your security team is focused on one narrow slice of the pie, it's easy for adversaries to enter through the cracks. Here are five ways to stop them.
By Gaurav Banga Founder and CEO, Balbix, 2/14/2019
Comment0 comments  |  Read  |  Post a Comment
Security Spills: 9 Problems Causing the Most Stress
Kelly Sheridan, Staff Editor, Dark Reading
Security practitioners reveal what's causing them the most frustration in their roles.
By Kelly Sheridan Staff Editor, Dark Reading, 2/14/2019
Comment0 comments  |  Read  |  Post a Comment
2018 Was Second-Most Active Year for Data Breaches
Jai Vijayan, Freelance writerNews
Hacking by external actors caused most breaches, but Web intrusions and exposures compromised more records, according to Risk Based Security.
By Jai Vijayan Freelance writer, 2/13/2019
Comment1 Comment  |  Read  |  Post a Comment
Windows Executable Masks Mac Malware
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
A new strain of MacOS malware hides inside a Windows executable to avoid detection.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 2/13/2019
Comment0 comments  |  Read  |  Post a Comment
Ex-US Intel Officer Charged with Helping Iran Target Her Former Colleagues
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Monica Witt, former Air Force and counterintel agent, has been indicted for conspiracy activities with Iranian government, hackers.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 2/13/2019
Comment0 comments  |  Read  |  Post a Comment
Researchers Dig into Microsoft Office Functionality Flaws
Kelly Sheridan, Staff Editor, Dark ReadingNews
An ongoing study investigating security bugs in Microsoft Office has so far led to two security patches.
By Kelly Sheridan Staff Editor, Dark Reading, 2/13/2019
Comment0 comments  |  Read  |  Post a Comment
5 Expert Tips for Complying with the New PCI Software Security Framework
Rohit Sethi, COO of Security CompassCommentary
The Secure SLC Standard improves business efficiency for payment application vendors but could also stand as new security benchmark for other industries to follow.
By Rohit Sethi COO of Security Compass, 2/13/2019
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
Devastating Cyberattack on Email Provider Destroys 18 Years of Data
Jai Vijayan, Freelance writer,  2/12/2019
Up to 100,000 Reported Affected in Landmark White Data Breach
Kelly Sheridan, Staff Editor, Dark Reading,  2/12/2019
Register for Dark Reading Newsletters
Cartoon
White Papers
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-1695
PUBLISHED: 2019-02-15
IBM QRadar SIEM 7.2 and 7.3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 134177.
CVE-2018-1701
PUBLISHED: 2019-02-15
IBM InfoSphere Information Server 11.7 could allow an authenciated user under specialized conditions to inject commands into the installation process that would execute on the WebSphere Application Server. IBM X-Force ID: 145970.
CVE-2018-1727
PUBLISHED: 2019-02-15
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 147630.
CVE-2018-1895
PUBLISHED: 2019-02-15
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ...
CVE-2019-4059
PUBLISHED: 2019-02-15
IBM Rational ClearCase 1.0.0.0 GIT connector does not sufficiently protect the document database password. An attacker could obtain the password and gain unauthorized access to the document database. IBM X-Force ID: 156583.
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Flash Poll
Video
Slideshows
Twitter Feed