Risk
News & Commentary
Microsoft Rolls Out AI-based Security Risk Detection Tool
Kelly Sheridan, Associate Editor, Dark ReadingNews
Microsoft Security Risk Detection leverages artificial intelligence to root out bugs in software before it's released.
By Kelly Sheridan Associate Editor, Dark Reading, 7/21/2017
Comment2 comments  |  Read  |  Post a Comment
Dark Reading News Desk Live at Black Hat USA 2017
Dark Reading Staff, Commentary
Over 40 interviews streaming live right from Black Hat USA, July 26-27, from 2 p.m. - 7 p.m. Eastern Time (11 - 4 P.T.).
By Dark Reading Staff , 7/21/2017
Comment2 comments  |  Read  |  Post a Comment
Healthcare Industry Lacks Awareness of IoT Threat, Survey Says
Dawn Kawamoto, Associate Editor, Dark ReadingNews
Three-quarters of IT decision makers report they are "confident" or "very confident" that portable and connected medical devices are secure on their networks.
By Dawn Kawamoto Associate Editor, Dark Reading, 7/20/2017
Comment0 comments  |  Read  |  Post a Comment
Major Online Criminal Marketplaces AlphaBay and Hansa Shut Down
Dawn Kawamoto, Associate Editor, Dark ReadingNews
International law enforcement operations result in AlphaBay, the largest online marketplace for selling illegal goods from malware to herion, and Hansa, going dark.
By Dawn Kawamoto Associate Editor, Dark Reading, 7/20/2017
Comment0 comments  |  Read  |  Post a Comment
BEC Attacks Far More Lucrative than Ransomware over Past 3 Years
Dawn Kawamoto, Associate Editor, Dark ReadingNews
BEC fraud netted cyberthieves five times more profit than ransomware over a three-year period, according to Cisco's midyear report released today.
By Dawn Kawamoto Associate Editor, Dark Reading, 7/20/2017
Comment0 comments  |  Read  |  Post a Comment
Online Courses Projected to Drive Credit Card Fraud to $24B by 2018
Kelly Sheridan, Associate Editor, Dark ReadingNews
An underground ecosystem provides cybercriminals with online tutorials, tools, and credit card data they need to commit fraud.
By Kelly Sheridan Associate Editor, Dark Reading, 7/19/2017
Comment0 comments  |  Read  |  Post a Comment
98% of Companies Favor Integrating Security with DevOps
Dawn Kawamoto, Associate Editor, Dark ReadingNews
A majority of companies are either planning or have launched an integrated DevOps and security team, a new report shows.
By Dawn Kawamoto Associate Editor, Dark Reading, 7/19/2017
Comment0 comments  |  Read  |  Post a Comment
New Cyber Readiness Institute Aims to Improve Risk Management
Dark Reading Staff, Quick Hits
The nonprofit will bring together senior leaders of global companies to discuss best practices for managing security employees, processes, and tech.
By Dark Reading Staff , 7/19/2017
Comment1 Comment  |  Read  |  Post a Comment
Most Office 365 Admins Rely on Recycle Bin for Data Backup
Kelly Sheridan, Associate Editor, Dark ReadingNews
Nearly 66% of Office 365 administrators use Recycle Bin to back up their data, a practice that could leave data lost and unrecoverable.
By Kelly Sheridan Associate Editor, Dark Reading, 7/19/2017
Comment5 comments  |  Read  |  Post a Comment
Catastrophic Cloud Attack Costs Would Rival that of Hurricane Damages
Dawn Kawamoto, Associate Editor, Dark ReadingNews
Lloyd's of London estimates multi-billion-dollar loss figures in worst-case scenarios of a major zero-day exploit or massive cloud outage.
By Dawn Kawamoto Associate Editor, Dark Reading, 7/19/2017
Comment0 comments  |  Read  |  Post a Comment
Zero-Day Exploit Surfaces that May Affect Millions of IoT Users
Dark Reading Staff, Quick Hits
A zero-day vulnerability dubbed Devil's Ivy is discovered in a widely used third-party toolkit called gSOAP.
By Dark Reading Staff , 7/18/2017
Comment0 comments  |  Read  |  Post a Comment
Apple iOS Malware Growth Outpaces that of Android
Dawn Kawamoto, Associate Editor, Dark ReadingNews
Number of iOS devices running malicious apps more than tripled in three consecutive quarters, while infected Android devices remained largely flat, report shows.
By Dawn Kawamoto Associate Editor, Dark Reading, 7/18/2017
Comment0 comments  |  Read  |  Post a Comment
FBI Issues Warning on IoT Toy Security
Dark Reading Staff, Quick Hits
IoT toys are more than fun and games and can potentially lead to a violation of children's privacy and safety, the Federal Bureau of Investigation warned Monday.
By Dark Reading Staff , 7/17/2017
Comment1 Comment  |  Read  |  Post a Comment
AsTech Offers a $5 Million Security Breach Warranty
Dark Reading Staff, Quick Hits
AsTech expands its warranty program with a guarantee it will find Internet application vulnerabilities or it will pay up to $5 million if there is a breach.
By Dark Reading Staff , 7/14/2017
Comment0 comments  |  Read  |  Post a Comment
US Voters Consider Russia the Largest Security Risk to Elections
Dark Reading Staff, Quick Hits
Nearly half of US voters believe Russia is the largest security risk for elections in the nation, according to a survey.
By Dark Reading Staff , 7/13/2017
Comment5 comments  |  Read  |  Post a Comment
Verizon Suffers Cloud Data Leak Exposing Data on Millions of Customers
Dawn Kawamoto, Associate Editor, Dark ReadingNews
Six million of Verizon's US customers had their personal and account information exposed, including PIN numbers.
By Dawn Kawamoto Associate Editor, Dark Reading, 7/12/2017
Comment6 comments  |  Read  |  Post a Comment
How Active Intrusion Detection Can Seek and Block Attacks
Kelly Sheridan, Associate Editor, Dark ReadingNews
Researchers at Black Hat USA will demonstrate how active intrusion detection strategies can help administrators detect hackers who are overly reliant on popular attack tools and techniques.
By Kelly Sheridan Associate Editor, Dark Reading, 7/12/2017
Comment0 comments  |  Read  |  Post a Comment
Dealing with Due Diligence
Eldon Sprickerhoff, Founder and Chief Security Strategist,  eSentireCommentary
Companies will find themselves evaluating third-party cybersecurity more than ever -- and being subject to scrutiny themselves. Here's how to handle it.
By Eldon Sprickerhoff Founder and Chief Security Strategist, eSentire, 7/12/2017
Comment2 comments  |  Read  |  Post a Comment
US Government Limits Purchase of Kaspersky Lab Software
Dark Reading Staff, Quick Hits
Kaspersky Lab has been deleted from lists of approved vendors that government agencies use to buy tech products, the result of growing cybersecurity concerns.
By Dark Reading Staff , 7/12/2017
Comment0 comments  |  Read  |  Post a Comment
HyTrust Raises $36M, Buys DataGravity for Policy Enforcement
Dark Reading Staff, Quick Hits
Cloud security firm HyTrust closed $36 million in Series E funding and purchased DataGravity to automate policy enforcement for workload data.
By Dark Reading Staff , 7/11/2017
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] Assessing Cybersecurity Risk
[Strategic Security Report] Assessing Cybersecurity Risk
As cyber attackers become more sophisticated and enterprise defenses become more complex, many enterprises are faced with a complicated question: what is the risk of an IT security breach? This report delivers insight on how today's enterprises evaluate the risks they face. This report also offers a look at security professionals' concerns about a wide variety of threats, including cloud security, mobile security, and the Internet of Things.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.