Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Opinion

Content posted in January 2020
Embracing a Prevention Mindset to Protect Critical Infrastructure
Commentary  |  1/31/2020  | 
A zero-trust, prevention-first approach is necessary to keep us safe, now and going forward.
Cisco: Privacy Efforts Pay Off Directly
Larry Loeb  |  1/31/2020  | 
Cisco's research has proven that beyond meeting compliance requirements, good privacy is good for business and individuals.
How to Secure Your IoT Ecosystem in the Age of 5G
Commentary  |  1/30/2020  | 
For businesses planning to adopt 5G, the sheer number of IoT devices creates a much larger attack surface.
Election Security 2020: How We Should Allocate $425M in Funding
Commentary  |  1/30/2020  | 
Too many states and municipalities still rely on aging systems; it's time they upped their game and treated election technology like they would any other security project.
All Your Intel L1 Cache Belongs to CacheOut
Larry Loeb  |  1/30/2020  | 
Once again, a novel 'speculative execution side-channel' attack has been discovered by researchers.
Securing Containers with Zero Trust
Commentary  |  1/29/2020  | 
A software identity-based approach should become a standard security measure for protecting workloads in all enterprise networks.
Threat Hunting Is Not for Everyone
Commentary  |  1/29/2020  | 
Threat hunting is a sophisticated, advanced technique that should be reserved for specific instances and be conducted only by trained professionals.
Why Companies Should Care about Data Privacy Day
Commentary  |  1/29/2020  | 
Marking yesterday's 14th anniversary of Europe's first data protection day reminds us how far we still have to go.
CCPA: Cut From the Same Cloth as PCI DSS
Commentary  |  1/28/2020  | 
Finally, some good news about CCPA: If you've built your security infrastructure to PCI DSS standards, you may be already covered by California's new data protection rules
RDG Gets Fooled by UDP
Larry Loeb  |  1/28/2020  | 
Security researchers have found that the implementation in Remote Desktop Gateway of string segmentation lays it open to memory corruption vulnerabilities.
How to Get the Most Out of Your Security Metrics
Commentary  |  1/27/2020  | 
There's an art to reporting security metrics so that they speak the language of leadership and connect the data from tools to business objectives.
Ransomware Costs More in Q4
Larry Loeb  |  1/27/2020  | 
In Q4 of 2019, the average ransom payment increased by 104% to $84,116, finds Coveware report.
GE Medical Instrumentation on the Critical List
Larry Loeb  |  1/24/2020  | 
DHS-CISA has issued a security advisory about GE Carescape medical instrumentation that enumerates many vulnerabilities present in them.
5 Resume Basics for a Budding Cybersecurity Career
Commentary  |  1/24/2020  | 
You'll need to add resume tactician to your skill set in order to climb up the next rung on the security job ladder. Here's how.
Deconstructing Web Cache Deception Attacks: They're Bad; Now What?
Commentary  |  1/23/2020  | 
Expect cache attacks to get worse before they get better. The problem is that we don't yet have a good solution.
Weathering the Privacy Storm from GDPR to CCPA & PDPA
Commentary  |  1/23/2020  | 
A general approach to privacy, no matter the regulation, is the only way companies can avoid a data protection disaster in 2020 and beyond.
EFS Ransomware Slips by AV Products
Larry Loeb  |  1/23/2020  | 
Inside of Windows is a methodology called Encrypting File System. It works on individual files or folders, rather than at the whole disk level like BitLocker does.
Why DPOs and CISOs Must Work Closely Together
Commentary  |  1/22/2020  | 
Recent data protection laws mean that the data protection officer and CISO must work in tandem to make sure users' data is protected.
Cybersecurity Lessons Learned from 'The Rise of Skywalker'
Commentary  |  1/22/2020  | 
They're especially relevant regarding several issues we face now, including biometrics, secure data management, and human error with passwords.
Avoid That Billion-Dollar Fine: Blurring the Lines Between Security and Privacy
Commentary  |  1/21/2020  | 
While doing good for the user is the theoretical ideal, the threat of fiscal repercussions should drive organizations to take privacy seriously. That means security and data privacy teams must work more closely.
Reusing Code? Inspect It First
Larry Loeb  |  1/21/2020  | 
Microsoft is doing something concrete about container security with the release of the Microsoft Application Inspector, a cross-platform tool whose primary objective is to identify source code features in a systematic and scalable way.
Data Awareness Is Key to Data Security
Commentary  |  1/21/2020  | 
Traditional data-leak prevention is not enough for businesses facing today's dynamic threat landscape.
Are We Secure Yet? How to Build a 'Post-Breach' Culture
Commentary  |  1/20/2020  | 
There are many ways to improve your organization's cybersecurity practices, but the most important principle is to start from the top.
FireEye Finds Mitigation of CVE-2019-19781 Comes With a Price
Larry Loeb  |  1/20/2020  | 
One threat actor is taking advantage of the current problems with Citrix ADC/Netscaler for their own advantage.
Phishing Today, Deepfakes Tomorrow: Training Employees to Spot This Emerging Threat
Commentary  |  1/16/2020  | 
Cybercriminals are evolving their tactics, and the security community anticipates voice and video fraud to play a role in one of the next big data breaches -- so start protecting your business now.
German Companies Want Even More Local Clouds
Oliver Schonschek  |  1/16/2020  | 
The European data infrastructure GAIA-X can help connect thedisparate needs of German firms and create market access for providers from the EU and beyond.
NSA Schools Microsoft About Crypto
Larry Loeb  |  1/16/2020  | 
In an unprecedented move, the National Security Agency advised Microsoft about a bug in one of the CryptoAPI libraries used since NT 4.0 days.
Active Directory Needs an Update: Here's Why
Commentary  |  1/16/2020  | 
AD is still the single point of authentication for most companies that use Windows. But it has some shortcomings that should be addressed.
Why Firewalls Aren't Going Anywhere
Commentary  |  1/15/2020  | 
Written off multiple times as obsolete, firewalls continue to elude demise by adding features and ensuring that VPNs keep humming.
How SD-WAN Helps Achieve Data Security and Threat Protection
Commentary  |  1/15/2020  | 
Enterprises currently consider the technology a best practice because of its flexibility, scalability, performance, and agility.
Donors to Australia Fire Site Treated as Suckers by Magecart
Larry Loeb  |  1/15/2020  | 
E-commerce fraud has no morals.
Global Predictions for Energy Cyber Resilience in 2020
Commentary  |  1/14/2020  | 
How prepared is the energy sector for an escalating attack surface in the operating technology environment? Here are five trends to watch.
Processor Vulnerabilities Put Virtual Workloads at Risk
Commentary  |  1/14/2020  | 
Meltdown, Spectre exploits will likely lead to customers making tradeoffs between performance and security of applications, especially virtual and cloud-based apps
Things Get Intense for Citrix ADC/Gateway
Larry Loeb  |  1/14/2020  | 
Scans have found that there are almost 10,000 vulnerable Internet-facing hosts in the US, with 2500 in Germany and 2000 in the UK.
Will This Be the Year of the Branded Cybercriminal?
Commentary  |  1/13/2020  | 
Threat actors will continue to grow enterprise-style businesses that evolve just like their legitimate counterparts.
Despite Google's Efforts, Bread Isn't Toast
Larry Loeb  |  1/13/2020  | 
The authors of the Bread malware have proven themselves to be unrelenting in their efforts to avoid being first discovered by and then dumped from Google's Play Store.
5 Tips on How to Build a Strong Security Metrics Framework
Commentary  |  1/10/2020  | 
The carpentry maxim "measure twice, cut once" underscores the importance of timely, accurate, and regular metrics to inform security leaders' risk decisions.
Cheap Phone Has Cheap Security
Larry Loeb  |  1/9/2020  | 
Phone looks a steal a $35 but it comes with free, pre-installed malware!
Operationalizing Threat Intelligence at Scale in the SOC
Commentary  |  1/9/2020  | 
Open source platforms such as the Malware Information Sharing Platform are well positioned to drive a community-based approach to intelligence sharing.
Cloud Monitoring: The New 'Alert Overload' Problem & How to Fix It
Joe Vadakkan  |  1/8/2020  | 
While cloud computing offers a variety of proven business benefits, from a security perspective, IT teams are often still wavering in uncharted territory and cloud monitoring is one such area.
The "Art of Cloud War" for Business-Critical Data
Commentary  |  1/8/2020  | 
How business executives' best intentions may be negatively affecting security and risk mitigation strategies -- and exposing weaknesses in organizational defenses.
Researcher Proven Right, but It Took 10 Years
Larry Loeb  |  1/7/2020  | 
After a decade of trying, security researcher Thierry Zoller has finally seen the generalized vulnerability he found in some AV products patched.
New Standards Set to Reshape Future of Email Security
Commentary  |  1/7/2020  | 
Emerging specs and protocols expected to make the simple act of opening an email a less risky proposition
Why Cisco's DCNM Is in a World of Trouble
Larry Loeb  |  1/6/2020  | 
Vendor's Data Center Network Manager (DCNM) has racked up three critical authentication bypass vulnerabilities at the top of the list of 12 separate problems that were announced on January 2.
Client-Side JavaScript Risks & the CCPA
Commentary  |  1/6/2020  | 
How California's new privacy law increases the liability for securing Web-facing user data, and what enterprises can do to mitigate their risk.
FPGAs Do It Faster Than CPUs
Larry Loeb  |  1/3/2020  | 
Researchers' use of a 'Jackhammer' exploit has shown again how one problem can be exploited in many ways, with each iteration of an attack becoming faster and more efficient.
Organizations May 'Uncloud' Over Security, Budgetary Concerns
Commentary  |  1/3/2020  | 
While most cloud vendors forecast continued adoption and growth, some customers are taking a harder look at the cloud services they're using
Mechanics of a Crypto Heist: How SIM Swappers Can Steal Cryptocurrency
Commentary  |  1/2/2020  | 
The true vulnerability at the heart of SIM-swap attacks on crypto accounts lies in crypto exchanges' and email providers' variable implementation of 2FA.
Fortinet Finds Loader Uses Updated Version of Backdoor
Larry Loeb  |  1/2/2020  | 
Security firm Fortinet has found traces of how the financially motivated FIN7 group manages to keep on delivering the Carbanak backdoor malware.


COVID-19: Latest Security News & Commentary
Dark Reading Staff 10/23/2020
7 Tips for Choosing Security Metrics That Matter
Ericka Chickowski, Contributing Writer,  10/19/2020
Russian Military Officers Unmasked, Indicted for High-Profile Cyberattack Campaigns
Kelly Jackson Higgins, Executive Editor at Dark Reading,  10/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-24847
PUBLISHED: 2020-10-23
A Cross-Site Request Forgery (CSRF) vulnerability is identified in FruityWifi through 2.4. Due to a lack of CSRF protection in page_config_adv.php, an unauthenticated attacker can lure the victim to visit his website by social engineering or another attack vector. Due to this issue, an unauthenticat...
CVE-2020-24848
PUBLISHED: 2020-10-23
FruityWifi through 2.4 has an unsafe Sudo configuration [(ALL : ALL) NOPASSWD: ALL]. This allows an attacker to perform a system-level (root) local privilege escalation, allowing an attacker to gain complete persistent access to the local system.
CVE-2020-5990
PUBLISHED: 2020-10-23
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in the ShadowPlay component which may lead to local privilege escalation, code execution, denial of service or information disclosure.
CVE-2020-25483
PUBLISHED: 2020-10-23
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
CVE-2020-5977
PUBLISHED: 2020-10-23
NVIDIA GeForce Experience, all versions prior to 3.20.5.70, contains a vulnerability in NVIDIA Web Helper NodeJS Web Server in which an uncontrolled search path is used to load a node module, which may lead to code execution, denial of service, escalation of privileges, and information disclosure.