Endpoint
News & Commentary
Blockchains New Role In The Internet of Things
Mance Harmon, Co-founder & CEO, SwirldsCommentary
With next gen distributed consensus algorithms that combine both security and performance, organizations can defend against DDoS attacks, even those that leverage IoT devices
By Mance Harmon Co-founder & CEO, Swirlds, 2/23/2017
Comment1 Comment  |  Read  |  Post a Comment
Netflix Debuts 'Stethoscope' Open-Source Security Tool
Dark Reading Staff, Quick Hits
Entertainment giant offers open-source app for security.
By Dark Reading Staff , 2/23/2017
Comment0 comments  |  Read  |  Post a Comment
Tunneling Through The "Walls" Of IoT In The Enterprise
Jose Nazario, Director of Security Research at FastlyCommentary
The movie "Die Hard" has a thing or two to teach us about the pitfalls of the Internet of Things.
By Jose Nazario Director of Security Research at Fastly, 2/22/2017
Comment1 Comment  |  Read  |  Post a Comment
6 Tips for Preventing Laptop Data Theft
Steve Zurier, Freelance WriterNews
Experts point to stronger passwords, full-disk encryption, and multi-factor authentication as ways to stop data theft in the event a laptop is lost or stolen.
By Steve Zurier Freelance Writer, 2/22/2017
Comment0 comments  |  Read  |  Post a Comment
Speak Up: Ransomware Attack Uses Voice Recognition
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
New variant of Android ransomware comes with a bizarre twist.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 2/22/2017
Comment0 comments  |  Read  |  Post a Comment
Social Media Impersonators Drive Security Risk
Kelly Sheridan, Associate Editor, InformationWeekNews
A new pool of research digs into the fraudulent social media accounts, a growing threat to individuals and businesses.
By Kelly Sheridan Associate Editor, InformationWeek, 2/21/2017
Comment0 comments  |  Read  |  Post a Comment
Preparing Security For Windows 7 End-Of-Life Support
Udi Yavo, Co-founder and CTO of enSiloCommentary
Moving to Microsoft's latest OS may give you flashbacks to when XP support ended.
By Udi Yavo Co-founder and CTO of enSilo, 2/21/2017
Comment0 comments  |  Read  |  Post a Comment
Voice Biometrics Prone To Error, Study Shows
Steve Zurier, Freelance WriterNews
New research shows the need for a holistic solution to authentication, not just voice biometrics alone.
By Steve Zurier Freelance Writer, 2/20/2017
Comment0 comments  |  Read  |  Post a Comment
MEDJACK.3 Poses Advanced Threat To Hospital Devices
Kelly Sheridan, Associate Editor, InformationWeekNews
A newly discovered version of the "medical device hijack" attack targets older operating systems to bypass security measures and steal patient data.
By Kelly Sheridan Associate Editor, InformationWeek, 2/16/2017
Comment0 comments  |  Read  |  Post a Comment
IoT Security: A Ways To Go, But Some Interim Steps For Safety
Terry Sweeney, Contributing EditorNews
The Internet of Things remains vulnerable to botnets and malware, but Cisco's Anthony Grieco offers some tips to keep networks and users more secure
By Terry Sweeney Contributing Editor, 2/15/2017
Comment0 comments  |  Read  |  Post a Comment
CrowdStrike Fails In Bid To Stop NSS Labs From Publishing Test Results At RSA
Jai Vijayan, Freelance writerNews
NSS results are based on incomplete and materially incorrect data, CrowdStrike CEO George Kurtz says.
By Jai Vijayan Freelance writer, 2/14/2017
Comment1 Comment  |  Read  |  Post a Comment
Why Identity Has Become A Top Concern For CSOs
Saryu Nayyar, CEO, GuruculCommentary
Seven of the world's top security leaders share their fears and challenges around the critical new role of identity in the fight against cyber adversaries.
By Saryu Nayyar CEO, Gurucul, 2/14/2017
Comment1 Comment  |  Read  |  Post a Comment
National Security, Regulation, Identity Top Themes At Cloud Security Summit
Sara Peters, Senior Editor at Dark ReadingNews
Gen. Keith Alexander gives Trump a thumbs-up and Cloud Security Alliance releases a new application.
By Sara Peters Senior Editor at Dark Reading, 2/13/2017
Comment0 comments  |  Read  |  Post a Comment
Verizon Data Breach Digest Triangulates Humanity Inside Security
Terry Sweeney, Contributing EditorNews
The 99-page report breaks out 16 different attack scenarios and specifies the target, sophistication level, attributes, and attack patterns, along with their times to discovery and containment.
By Terry Sweeney Contributing Editor, 2/13/2017
Comment4 comments  |  Read  |  Post a Comment
Keep Employees Secure, Wherever They Are
Matthew Gyde, Group Executive, Security, for Dimension DataCommentary
As workers grow more dispersed, organizations need to focus on three areas to maintain security.
By Matthew Gyde Group Executive, Security, for Dimension Data, 2/10/2017
Comment0 comments  |  Read  |  Post a Comment
4 Signs You, Your Users, Tech Peers & C-Suite All Have 'Security Fatigue'
Tom Pendergast, Chief Strategist, Security, Privacy, & Compliance, MediaProCommentary
If security fatigue is the disease we've all got, the question is how do we get over it?
By Tom Pendergast Chief Strategist, Security, Privacy, & Compliance, MediaPro, 2/9/2017
Comment5 comments  |  Read  |  Post a Comment
Harvest Season: Why Cyberthieves Want Your Compute Power
Dave Klein, Regional Director of Sales Engineering & Architecture, GuardiCoreCommentary
Attackers are hijacking compute power in order to pull off their other crimes.
By Dave Klein Regional Director of Sales Engineering & Architecture, GuardiCore, 2/9/2017
Comment0 comments  |  Read  |  Post a Comment
AT&T, IBM, Palo Alto Networks, Symantec, Team Up In IoT Security
Dark Reading Staff, Quick Hits
IoT Cybersecurity Alliance is made up of AT&T, IBM, Nokia, Palo Alto Networks, Symantec, and Trustonic.
By Dark Reading Staff , 2/9/2017
Comment0 comments  |  Read  |  Post a Comment
Sophos Acquisition Targets Next-Gen Endpoint Security
Dark Reading Staff, Quick Hits
Sophos buys Invincea to bring next-gen malware protection and machine learning into its product portfolio.
By Dark Reading Staff , 2/8/2017
Comment1 Comment  |  Read  |  Post a Comment
What to Watch (& Avoid) At RSAC
Mike D. Kail, Chief Innovation Officer, CybricCommentary
A renowned security veteran shares his RSA dance card, offering views on technologies destined for the dustbin of history and those that will move the industry forward.
By Mike D. Kail Chief Innovation Officer, Cybric, 2/8/2017
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
5 Security Technologies to Watch in 2017
Emerging tools and services promise to make a difference this year. Are they on your company's list?
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.