About Us

Dark Reading: Connecting The Information Security Community

Long one of the most widely-read cyber security news sites on the Web, Dark Reading is now the most trusted online community for security professionals like you. Our community members include thought-leading security researchers, CISOs, and technology specialists, along with thousands of other security professionals. We want you to join us.

This is where enterprise security staffers and decision-makers come to learn about new cyber threats, vulnerabilities, and technology trends. It's where they discuss potential defenses against the latest attacks, and key technologies and practices that may help protect their most sensitive data in the future. It's where they come to engage with one another and with Dark Reading editors to embrace new (and big) ideas, find answers to their IT security questions and solve their most pressing problems.

Dark Reading.com encompasses ten communities, each of which drills deeper into the enterprise security challenge: Attacks & Breaches, Application Security, Cloud Security, Data Leaks & Insider Threats, Endpoint Security & Privacy, Mobile Security, Network & Perimeter Security, Risk Management & Compliance, Security Management & Analytics, and Vulnerabilities and Threats. Each community is led by editors and subject matter experts who collaborate with security researchers, technology specialists, industry analysts and other Dark Reading members to provide timely, accurate and informative articles that lead to spirited discussions.

Our goal is to challenge community members to think about security by providing strong, even unconventional points of view, backed by hard-nosed reporting, hands-on experience and the professional knowledge that comes only with years of work in the information security industry.

We want you to be part of this community. Please join us on live chats, story discussions, polls, radio shows, reader-generated discussion boards, newsletters and other interactive features -- all for free. We'll also invite you to live events where we can continue these conversations face-to-face.

Simply register here – it's free – to join the conversation and fully benefit from all the features on this site. If you're interested in participating further, contact our editors – we're always on the lookout for industry thought leaders who'd like to offer their perspectives on IT security and its role in business.

Contact Us

Welcome to DarkReading.com.

View staff bios.

If you wish to no longer receive any promotional emails from UBM Tech please click here, unsub@ubm.com.

Title Name/Email Phone
Editor In Chief Tim Wilson 703-262-0680 Timothy.wilson@ubm.com
Senior Editor Kelly Jackson Higgins 434-960-9899 Kelly.jackson.higgins@ubm.com
Community Editor Marilyn Cohodas 978-590-5248 Marilyn.cohodas@ubm.com
Associate Editor Mathew J. Schwartz mat@penandcamera.com
     
Contributing Writers    
Contributing Writer Ericka Chickowski ericka@chickowski.com
Contributing Writer Robert Lemos mail@robertlemos.com
Contributing Writer Brian Prince securityradar@gmail.com
Contributing Writer John Sawyer johnsawyer@gmail.com
 
Editors
InformationWeek.com
VP and Editor In Chief Rob Preston 516-562-5692
Editor Chris Murphy 414-906-5331
Editor In Chief, InformationWeek.com Laurianne McLaughlin 516-562-7009
Managing Editor Paul Travis 516-562-5217
Managing Editor Jim Donahue 516-562-7980
Managing Editor Shane O'Neill 617-202-3710
InformationWeek
Government
Wyatt Kash Editor
917-930-8531
InformationWeek
Healthcare
David F. Carr Editor
     
InformationWeek Reports
Content Director, Reports Lorna Garey 978-694-1681
Managing Editor, Research Heather Vallis 516-562-7501
InformationWeek Business Technology Network
     
NetworkComputing.com
Networking, Communications, and Storage
Susan Fogarty Site Editor
Dr. Dobb's
The World of Software Development
Andrew Binstock Editor In Chief
 
UBM Tech
Paul Miller CEO
Marco Pardi President, Events
David Michael CIO
Kelley Damore Chief Community Officer
Simon Carless Exec. VP, Game & App Development and Black Hat
Rakhi Williams, Chief of Staff
Angela Scalpello Sr. VP, People & Culture

Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Containing Corporate Data on Mobile Devices
Containing Corporate Data on Mobile Devices
If you’re still focused on securing endpoints, you’ve got your work cut out for you. WiFi network provider iPass surveyed 1,600 mobile workers and found that the average US employee carries three devices -- a smartphone, a computer, and a tablet or e-reader -- with more than 80% of them doing work on personal devices.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-1421
Published: 2014-04-22
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Category Name field to category.php.

CVE-2013-2105
Published: 2014-04-22
The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html.

CVE-2013-2187
Published: 2014-04-22
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to the home page.

CVE-2013-4116
Published: 2014-04-22
lib/npm.js in Node Packaged Modules (npm) before 1.3.3 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names that are created when unpacking archives.

CVE-2013-4472
Published: 2014-04-22
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names.

Best of the Web