Vulnerabilities / Threats
5/1/2013
01:05 PM
Tim Wilson
Tim Wilson
Commentary
50%
50%

Dark Reading's Seven-Year Itch

After seven years of covering the security industry, Dark Reading is just getting started

Seven years ago today, Dark Reading made its first appearance on the Web. The publication, like the security industry itself, has changed a great deal since May 1, 2006 -- and yet, as with the industry, many core themes remain constant.

When we launched Dark Reading, our goal was to build a single website where security professionals could go to find all of the information they needed about new threats and methods for stopping them.

In those days, nobody was talking about the cloud or advanced persistent threats or bring your own device. One of the biggest breaches that year was at the Department of Veterans Affairs, where an employee brought work home on a laptop that was subsequently stolen. One of our most popular stories was a penetration test by blogger Steve Stasiukonis, who put a benign infection on a bunch of thumb drives and placed them all over a company headquarters site (almost all of them were plugged into company computers).

Over the years, businesses have been inundated with new attacks ranging from Stuxnet to Storm, from Anonymous to Zeus. And yet, those lost laptops and infected thumb drives continue to be a problem for most enterprises.

In 2006, we were writing about the features of antivirus and IPS products, noting their particular flaws and inability to prevent attacks from penetrating. The integrity of the security perimeter was at risk.

Since then, we've seen the launch of a wide range of technologies and strategies, from next-generation firewalls to data leak prevention to threat intelligence services. And yet, experts are still complaining about the failure of AV technology, and most have all but given up the idea of maintaining a secure perimeter.

Perhaps the lesson we're taught from the past seven years is that while attacks and technology change, the nature of security itself doesn't. We may be dealing with an unprecedented volume and sophistication of malware, but that doesn't change the fact that humans are at the heart of most of our defenses -- and most of our compromises. And security, like everything else that's human, is a work in progress.

For Dark Reading's part, our pledge is to continue to strive to be that single source of news and information that you need in your efforts as a security professional. We've taken some steps recently to improve our content, such as the redesign launched in April, and we have more plans in store for improving the usefulness and interactivity of the site. We have an itch to take this site to a new level, and we look forward to the days ahead.

And for those of you who have been reading us over these past seven years, thank you. We hope we'll continue to be one of your primary sites for security news and information for another seven years -- and beyond.

--Tim Wilson, Kelly Jackson Higgins, and the staff and contributors of Dark Reading Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
jc
50%
50%
jc,
User Rank: Apprentice
5/2/2013 | 3:14:37 PM
re: Dark Reading's Seven-Year Itch
Happy Birthday Dark Reading!
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-1637
Published: 2015-03-06
Schannel (aka Secure Channel) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly restrict TLS state transitions, which makes it easier for r...

CVE-2014-2130
Published: 2015-03-05
Cisco Secure Access Control Server (ACS) provides an unintentional administration web interface based on Apache Tomcat, which allows remote authenticated users to modify application files and configuration files, and consequently execute arbitrary code, by leveraging administrative privileges, aka B...

CVE-2014-9688
Published: 2015-03-05
Unspecified vulnerability in the Ninja Forms plugin before 2.8.10 for WordPress has unknown impact and remote attack vectors related to admin users.

CVE-2015-0598
Published: 2015-03-05
The RADIUS implementation in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted IPv6 Attributes in Access-Accept packets, aka Bug IDs CSCur84322 and CSCur27693.

CVE-2015-0607
Published: 2015-03-05
The Authentication Proxy feature in Cisco IOS does not properly handle invalid AAA return codes from RADIUS and TACACS+ servers, which allows remote attackers to bypass authentication in opportunistic circumstances via a connection attempt that triggers an invalid code, as demonstrated by a connecti...

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.