Endpoint

News & Commentary
Biometrics Are Coming & So Are Security Concerns
Michael Fauscette, Chief Research Officier at G2 CrowdCommentary
Could these advanced technologies be putting user data at risk?
By Michael Fauscette Chief Research Officier at G2 Crowd, 4/20/2018
Comment0 comments  |  Read  |  Post a Comment
Microsoft CISO Talks Threat Intel, 'Data Inclusion'
Kelly Sheridan, Staff Editor, Dark ReadingNews
Dark Reading caught up with Microsoft's Bret Arsenault to discuss intelligence, identity, and the need to leverage more diverse datasets.
By Kelly Sheridan Staff Editor, Dark Reading, 4/19/2018
Comment2 comments  |  Read  |  Post a Comment
Securing Social Media: National Safety, Privacy Concerns
Kelly Sheridan, Staff Editor, Dark ReadingNews
It's a critical time for social media platforms and the government agencies and private businesses and individuals using them.
By Kelly Sheridan Staff Editor, Dark Reading, 4/19/2018
Comment2 comments  |  Read  |  Post a Comment
First Public Demo of Data Breach via IoT Hack Comes to RSAC
Sara Peters, Senior Editor at Dark ReadingNews
At RSA Conference, senior researchers will show how relatively unskilled attackers can steal personally identifiable information without coming into contact with endpoint security tools.
By Sara Peters Senior Editor at Dark Reading, 4/19/2018
Comment0 comments  |  Read  |  Post a Comment
DHS Helps Shop Android IPS Prototype
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
A MITRE-developed intrusion prevention system for mobile technology is showcased here this week at the RSA Conference.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 4/18/2018
Comment0 comments  |  Read  |  Post a Comment
8 Ways Hackers Monetize Stolen Data
Steve Zurier, Freelance Writer
Hackers are craftier than ever, pilfering PII piecemeal so bad actors can combine data to set up schemes to defraud medical practices, steal military secrets and hijack R&D product information.
By Steve Zurier Freelance Writer, 4/17/2018
Comment2 comments  |  Read  |  Post a Comment
Why We Need Privacy Solutions That Scale Across Borders
Chris Babel, CEO, TrustArcCommentary
New privacy solutions are becoming scalable, smarter, and easier to address compliance across industries and geographies.
By Chris Babel CEO, TrustArc, 4/17/2018
Comment0 comments  |  Read  |  Post a Comment
Microsoft to Roll Out Azure Sphere for IoT Security
Kelly Sheridan, Staff Editor, Dark ReadingNews
Azure Sphere, now in preview, is a three-part program designed to secure the future of connected devices and powered by its own custom version of Linux.
By Kelly Sheridan Staff Editor, Dark Reading, 4/16/2018
Comment0 comments  |  Read  |  Post a Comment
Companies Still Suffering From Poor Credential Hygiene: New Report
Dark Reading Staff, Quick Hits
Credentials are being mis-handled and it's hurting most companies, according to a new report out today.
By Dark Reading Staff , 4/16/2018
Comment0 comments  |  Read  |  Post a Comment
INsecurity Conference Seeks Security Pros to Speak on Best Practices
Tim Wilson, Editor in Chief, Dark Reading, News
Dark Reading's second annual data defense conference will be held Oct. 23-25 in Chicago; call for speakers is issued.
By Tim Wilson, Editor in Chief, Dark Reading , 4/16/2018
Comment0 comments  |  Read  |  Post a Comment
How GDPR Forces Marketers to Rethink Data & Security
Roger Kjensrud, CTO, ImpactCommentary
The European regulation is making marketing technology companies re-examine their security, and that's a good thing.
By Roger Kjensrud CTO, Impact, 4/16/2018
Comment0 comments  |  Read  |  Post a Comment
7 Non-Financial Data Types to Secure
Curtis Franklin Jr., Senior Editor at Dark Reading
Credit card and social security numbers aren't the only sensitive information that requires protection.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 4/14/2018
Comment1 Comment  |  Read  |  Post a Comment
Power Line Vulnerability Closes Air Gap
Dark Reading Staff, Quick Hits
A new demonstration of malware shows that air-gapped computers may still be at risk.
By Dark Reading Staff , 4/13/2018
Comment0 comments  |  Read  |  Post a Comment
Cisco, ISARA to Test Hybrid Classic, Quantum-Safe Digital Certificates
Jai Vijayan, Freelance writerNews
Goal is to make it easier for organizations to handle the migration to quantum computing when it becomes available.
By Jai Vijayan Freelance writer, 4/13/2018
Comment0 comments  |  Read  |  Post a Comment
Businesses Calculate Cost of GDPR as Deadline Looms
Kelly Sheridan, Staff Editor, Dark ReadingNews
Surveys highlight the financial burden of GDPR as companies scramble to meet the May 25 deadline.
By Kelly Sheridan Staff Editor, Dark Reading, 4/12/2018
Comment0 comments  |  Read  |  Post a Comment
Facebook Rolls Out 'Data Abuse Bounty' Program
Kelly Sheridan, Staff Editor, Dark ReadingNews
The social media giant also got hit with a lawsuit the day before unveiling its new reward program.
By Kelly Sheridan Staff Editor, Dark Reading, 4/11/2018
Comment0 comments  |  Read  |  Post a Comment
Palo Alto Networks Buys Secdo for Endpoint Detection
Dark Reading Staff, Quick Hits
The acquisition is intended to ramp up Palo Alto's endpoint detection capabilities with new tech and talent.
By Dark Reading Staff , 4/11/2018
Comment0 comments  |  Read  |  Post a Comment
Carbon Black Files IPO, Plans to Raise $100M
Dark Reading Staff, Quick Hits
The endpoint security firm filed a registration statement with the Securities and Exchange Commission on April 9.
By Dark Reading Staff , 4/11/2018
Comment0 comments  |  Read  |  Post a Comment
Pairing Policy & Technology: BYOD That Works for Your Enterprise
Peter Merkulov and Alison Turner, Chief Technology Officer at Globalscape & Director of Product Marketing at GlobalscapeCommentary
An intelligent security policy coupled with the right technology can set you up for success with BYOD.
By Peter Merkulov and Alison Turner Chief Technology Officer at Globalscape & Director of Product Marketing at Globalscape, 4/10/2018
Comment0 comments  |  Read  |  Post a Comment
HTTP Injector Steals Mobile Internet Access
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
Users aren't shy about sharing the technique and payload in a new attack.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 4/10/2018
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
8 Ways Hackers Monetize Stolen Data
Steve Zurier, Freelance Writer,  4/17/2018
Securing Social Media: National Safety, Privacy Concerns
Kelly Sheridan, Staff Editor, Dark Reading,  4/19/2018
Firms More Likely to Tempt Security Pros With Big Salaries than Invest in Training
Sara Peters, Senior Editor at Dark Reading,  4/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.