Vulnerabilities / Threats // Insider Threats
News & Commentary
7 Ways To Charm Users Out of Their Passwords
Terry Sweeney, Contributing Editor
While the incentives have changed over time, it still takes remarkably little to get users to give up their passwords.
By Terry Sweeney Contributing Editor, 7/27/2016
Comment8 comments  |  Read  |  Post a Comment
Dark Reading News Desk Coming Back To Black Hat, Live
Sara Peters, Senior Editor at Dark ReadingNews
Live from Las Vegas: 40 video interviews with Black Hat USA conference speakers and sponsors. Wednesday Aug. 3, Thursday Aug, 4, 2 p.m. - 6:10 p.m. ET.
By Sara Peters Senior Editor at Dark Reading, 7/27/2016
Comment0 comments  |  Read  |  Post a Comment
Majority Of Companies Say Trade Secrets Likely Compromised
Jai Vijayan, Freelance writerNews
About 60 percent of companies in a survey by Ponemon and Kilpatrick Townsend say at least some of their trade secrets are likely in the hands of rivals
By Jai Vijayan Freelance writer, 7/21/2016
Comment0 comments  |  Read  |  Post a Comment
Ex-Cardinal Exec Jailed For Hacking Astros
Dark Reading Staff, Quick Hits
Christopher Correa gets 46 months for unlawful access of rival’s database and downloading confidential details.
By Dark Reading Staff , 7/20/2016
Comment0 comments  |  Read  |  Post a Comment
What SMBs Need To Know About Security But Are Afraid To Ask
Sean Martin, CISSP | President, imsmartin
A comprehensive set of new payment protection resources from the PCI Security Standards Council aims to help small- and medium-sized businesses make security a priority.
By Sean Martin CISSP | President, imsmartin, 7/14/2016
Comment1 Comment  |  Read  |  Post a Comment
What I Expect to See At Black Hat 2016: 5 Themes
Chris Wysopal, CTO, CISO and co-founder, VeracodeCommentary
Over the years, Black Hat has morphed from a little show for security researchers to a big conference that attracts everyone from black-hat hackers to C-level security execs. Here’s what piques my interest this year.
By Chris Wysopal CTO, CISO and co-founder, Veracode, 7/13/2016
Comment1 Comment  |  Read  |  Post a Comment
A Holistic Approach to Cybersecurity Wellness: 3 Strategies
Dotan Bar Noy,  CEO & Co-Founder, ReSec TechnologiesCommentary
Security professionals need to rely on more than ‘vaccinations’ to protect the health and safety of company systems and data.
By Dotan Bar Noy CEO & Co-Founder, ReSec Technologies, 7/7/2016
Comment1 Comment  |  Read  |  Post a Comment
Big Business Ransomware: A Lucrative Market in the Underground Economy
Michael Sutton, Chief Information Security Office, ZscalerCommentary
Why lock and/or pilfer a person’s files worth hundreds of dollars when corporate data is infinitely more valuable?
By Michael Sutton Chief Information Security Office, Zscaler, 7/1/2016
Comment1 Comment  |  Read  |  Post a Comment
China’s Economic Cyber-Spying Drops Post Sept Talks: US Official
Dark Reading Staff, Quick Hits
U.S. Assistant Attorney General John Carlin's statement finds support in FireEye report of a 90% fall in China-based hacking.
By Dark Reading Staff , 7/1/2016
Comment0 comments  |  Read  |  Post a Comment
The Attribution Question: Does It Matter Who Attacked You?
Sara Peters, Senior Editor at Dark ReadingNews
Everyone will ask whodunnit, but how can an organization put that information to practical use during disaster recovery and planning for the future?
By Sara Peters Senior Editor at Dark Reading, 6/29/2016
Comment3 comments  |  Read  |  Post a Comment
Hackers Pilfer $10 Million From Ukraine Bank
Dark Reading Staff, Quick Hits
Reports allege criminals used SWIFT to transfer money, have compromised several Ukraine, Russia banks.
By Dark Reading Staff , 6/29/2016
Comment3 comments  |  Read  |  Post a Comment
Microsoft + LinkedIn: How To Spot Insider Trading Risk Early
Eleonore Fournier-Tombs, Field Data Scientist, RedOwlCommentary
With the explosion of mobile, cloud, and the blurring of work and personal data, companies considering M&A have a lot to worry about when it comes to insider threats.
By Eleonore Fournier-Tombs Field Data Scientist, RedOwl, 6/28/2016
Comment0 comments  |  Read  |  Post a Comment
Phishing, Whaling & The Surprising Importance Of Privileged Users
Joseph Opacki, VP, Threat Research, PhishLabsCommentary
By bagging a privileged user early on, attackers can move from entry point to mission accomplished in no time at all.
By Joseph Opacki VP, Threat Research, PhishLabs, 6/21/2016
Comment2 comments  |  Read  |  Post a Comment
5 Tips For Staying Cyber-Secure On Your Summer Vacation
Emily Johnson, Associate Editor, UBM AmericasNews
Stick with mobile payment apps and carrier networks when traveling. And don't broadcast your plans or locations via social media.
By Emily Johnson Associate Editor, UBM Americas, 6/20/2016
Comment3 comments  |  Read  |  Post a Comment
Self-Service Password Reset & Social Engineering: A Match Made In Hell
Jackson Shaw, Senior Director, Product Management, Dell SecurityCommentary
A sad tale of how hackers compromised a CEO’s corporate account by trolling Facebook and LInkedin for answers to six common authentication questions. (And how to avoid that happening to you)
By Jackson Shaw Senior Director, Product Management, Dell Security, 6/13/2016
Comment9 comments  |  Read  |  Post a Comment
FBI Report: Deconstructing The Wide Scope Of Internet Crime
Ericka Chickowski, Contributing Writer, Dark Reading
Hottest crimes reported to IC3 last year include ransomware and email scams via business email compromise and all account compromise attacks.
By Ericka Chickowski Contributing Writer, Dark Reading, 5/27/2016
Comment0 comments  |  Read  |  Post a Comment
Bangladesh Reopens 2013 Cold Case Of Bank Theft Via SWIFT
Dark Reading Staff, Quick Hits
Authorities cite similarities in Sonali Bank hack with February's $81 million central bank theft.
By Dark Reading Staff , 5/26/2016
Comment0 comments  |  Read  |  Post a Comment
APWG: Phishing Attacks Jump 250% From Oct Through March
Dark Reading Staff, Quick Hits
Quarterly and monthly totals are the highest since the Anti-Phishing Working Group began tracking phishing in 2004.
By Dark Reading Staff , 5/25/2016
Comment0 comments  |  Read  |  Post a Comment
Ukrainian Pleads Guilty To Stealing Press Releases For Insider Trading
Dark Reading Staff, Quick Hits
In largest known cyber securities fraud to date, hackers and traders made $30 million from unreleased press releases.
By Dark Reading Staff , 5/17/2016
Comment1 Comment  |  Read  |  Post a Comment
Bangladesh Bank Theft: New York Fed Stands By Transfer Procedures
Dark Reading Staff, Quick Hits
Bank replies to US lawmaker query whether transfer of funds should have been blocked.
By Dark Reading Staff , 5/16/2016
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Why else would HR ask me if I have a handicap?"
Current Issue
The Changing Face of Identity Management
Mobility and cloud services are altering the concept of user identity. Here are some ways to keep up.
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio

The cybersecurity profession struggles to retain women (figures range from 10 to 20 percent). It's particularly worrisome for an industry with a rapidly growing number of vacant positions.

So why does the shortage of women continue to be worse in security than in other IT sectors? How can men in infosec be better allies for women; and how can women be better allies for one another? What is the industry doing to fix the problem -- what's working, and what isn't?

Is this really a problem at all? Are the low numbers simply an indication that women do not want to be in cybersecurity, and is it possible that more women will never want to be in cybersecurity? How many women would we need to see in the industry to declare success?

Join Dark Reading senior editor Sara Peters and guests Angela Knox of Cloudmark, Barrett Sellers of Arbor Networks, Regina Wallace-Jones of Facebook, Steve Christey Coley of MITRE, and Chris Roosenraad of M3AAWG on Wednesday, July 13 at 1 p.m. Eastern Time to discuss all this and more.