Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Opinion

Content posted in January 2013
Big Data Security Discussion
Commentary  |  1/31/2013  | 
Answers to common big-data security questions
Going Green With Your Ones And Zeros
Commentary  |  1/30/2013  | 
For better security, use less data
Combatting Advanced Threats In 2013 Through Basics
Commentary  |  1/28/2013  | 
Focus on fixing the problems of a past generation before focusing on the next
Security No-Man's Land
Commentary  |  1/28/2013  | 
As the industry descends on the RSA Conference to discuss the latest and greatest in security, the underserved midmarket continues to struggle with basic blocking and tackling. The industry machinery is not built to solve that problem
The Three Worst Words In The English Language: Can't We Just?
Commentary  |  1/25/2013  | 
The road to poor identity and access management architecture is paved with "can't we justs." It's 2013: Find a way
Is Mobile Device Management The Answer?
Commentary  |  1/23/2013  | 
MDM software is being considered by healthcare IT execs concerned about security.
Acing An Audit In 30 Minutes
Commentary  |  1/18/2013  | 
Compliance audits don't have to be chaotic events
Java Security Warnings: Cut Through The Confusion
Commentary  |  1/18/2013  | 
Recent warnings to deactivate Java are raising additional questions: What about JavaScript, EJB, JavaFX, Android and any other use of the programming language?
Uncertain State Of Cyber War
Commentary  |  1/17/2013  | 
Just what does "cyber warfare" mean? We're still figuring out tactics and capabilities.
Cartoon: Forgot Password? Click Here
Commentary  |  1/14/2013  | 
All Your Base Are In An Indeterminate State
Commentary  |  1/14/2013  | 
Or the importance of timeliness in monitoring
How Well Do You Know Your Data?
Commentary  |  1/9/2013  | 
The more you know about your data, the more effectively you can protect it
McAfee Takes Belize: Social Engineering Lesson
Commentary  |  1/9/2013  | 
Eccentric antivirus firm founder John McAfee says he tricked people with spyware -- using free laptops. Social engineering attacks remain cheap, easy and effective.
When Cloud Computing Is The Wrong Fit
Commentary  |  1/9/2013  | 
ROI is the first question to answer when deciding if cloud computing is a good platform for your enterprise. Three others involve compliance, infrastructure, and a strong business case.
What Is It You Would Say That You Do Here?
Commentary  |  1/8/2013  | 
Here is a dangerous question to start the new year: Does your company actually need a security department? If you are doing CYA instead of CIA, the answer is probably no
You Keep Using That Word ...
Commentary  |  1/4/2013  | 
When monitoring doesn't mean what you think it does


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-31378
PUBLISHED: 2021-10-19
In broadband environments, including but not limited to Enhanced Subscriber Management, (CHAP, PPP, DHCP, etc.), on Juniper Networks Junos OS devices where RADIUS servers are configured for managing subscriber access and a subscriber is logged in and then requests to logout, the subscriber may be fo...
CVE-2021-31379
PUBLISHED: 2021-10-19
An Incorrect Behavior Order vulnerability in the MAP-E automatic tunneling mechanism of Juniper Networks Junos OS allows an attacker to send certain malformed IPv4 or IPv6 packets to cause a Denial of Service (DoS) to the PFE on the device which is disabled as a result of the processing of these pac...
CVE-2021-31380
PUBLISHED: 2021-10-19
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to disclose sensitive information in the HTTP response which allows the attacker to obtain sensitive informati...
CVE-2021-31381
PUBLISHED: 2021-10-19
A configuration weakness in the JBoss Application Server (AppSvr) component of Juniper Networks SRC Series allows a remote attacker to send a specially crafted query to cause the web server to delete files which may allow the attacker to disrupt the integrity and availability of the system.
CVE-2021-31382
PUBLISHED: 2021-10-19
On PTX1000 System, PTX10002-60C System, after upgrading to an affected release, a Race Condition vulnerability between the chassis daemon (chassisd) and firewall process (dfwd) of Juniper Networks Junos OS, may update the device's interfaces with incorrect firewall filters. This issue only occurs wh...