Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Opinion

Content posted in April 2016
Stop Building Silos. Security Is Everyones Problem
Commentary  |  4/29/2016  | 
Yes, its true that the speed of DevOps has made security more difficult. But that doesnt mean accelerated release cycles and secure applications have to be mutually exclusive.
The Morning After: What Happens to Data Post Breach?
Partner Perspectives  |  4/28/2016  | 
We need consumers and businesses to not simply shrug off data breaches but to take active measures to protect their data. We are hopeful that new insights will provide a compelling answer to the question So what?
6 Reasons ISPs Must Step Up Defenses Against DDoS Attacks
Commentary  |  4/28/2016  | 
Conducting a DDoS attack used to require a significant amount of talent. But today, a high school student with basic hacking skills can access tools that will challenge even the most experienced ISP security teams.
8 Signs Your Security Culture Lacks Consistency
Commentary  |  4/27/2016  | 
Organizations that practice what they preach and match their actions to their words do far better achieving their goals than those that do not. Here's why that matters.
10 Questions To Ask Yourself About Securing Big Data
Partner Perspectives  |  4/27/2016  | 
Big data introduces new wrinkles for managing data volume, workloads, and tools. Securing increasingly large amounts of data begins with a good governance model across the information life cycle. From there, you may need specific controls to address various vulnerabilities. Here are a set of questions to help ensure that you have everything covered.
Crowdsourcing The Dark Web: A One-Stop Ran$om Shop
Commentary  |  4/26/2016  | 
Say hello to Ran$umBin, a new kind of ransom market dedicated to criminals and victims alike.
Surviving InfoSec: Digital Crime And Emotional Grime
Commentary  |  4/25/2016  | 
The never ending stream of threats, vulnerabilities, and potential attacks can take its toll on the typical security professional. Heres how to fight back against the pressure.
Dark Reading Marks 10th Anniversary With Month Of Special Coverage
Commentary  |  4/25/2016  | 
Looking back at the decade in security.
Be Prepared: How Proactivity Improves Cybersecurity Defense
Commentary  |  4/23/2016  | 
These five strategies will help you achieve a state of readiness in a landscape of unpredictable risk.
The Problem With Patching: 7 Top Complaints
Commentary  |  4/22/2016  | 
Is your security team suffering from patching fatigue? Check out these tips and eliminate critical vulnerabilities in your IT environment.
Mea Culpa: Time To Build Security Into Connectivity
Commentary  |  4/21/2016  | 
How those of us who spent decades developing faster, easier, and more scalable networking technology have made the lives of our security counterparts a living hell.
Security Lessons from C-3PO, Former CSO of the Millennium Falcon
Commentary  |  4/21/2016  | 
The business will take risks. When and how to speak up.
The Perils Of Dynamically Pulling Dependencies
Partner Perspectives  |  4/21/2016  | 
The wide range of functions and broad availability of external packages is a tremendous boon to software development, but keep an eye on the security implications to manage your risk.
Internal Pen-Testing: Not Just For Compliance Audits Anymore
Commentary  |  4/20/2016  | 
How turning your internal penetration team into a 'Friendly Network Force' can identify and shut down the cracks in your security program.
Device Advice: Keeping Fraudsters From Consumer Info
Commentary  |  4/19/2016  | 
Data breaches are the first stop for criminals with intentions to steal personally identifiable information. These tips show how to fight fraud while optimizing the customer experience.
Privacy Debate: Apple & Google Today; AWS or Azure Tomorrow?
Commentary  |  4/18/2016  | 
Why the recent fight over mobile phone security and encryption is moving to the cloud.
Which Critical Infrastructure Attack Will Be Our Bangladesh Factory Collapse?
Partner Perspectives  |  4/18/2016  | 
Critical infrastructure security is finally getting the attention it deserves; lets hope that it is enough to prevent a major disaster.
Rethinking Application Security With Microservices Architectures
Commentary  |  4/15/2016  | 
The advantages offered by the container model go against many of the assumptions of traditional security mechanisms. Here are 5 new concepts & 4 best practices youll need to understand.
5 Steps to Improve Your Software Supply Chain Security
Commentary  |  4/14/2016  | 
Organizations that take control of their software supply chains will see tremendous gains in developer productivity, improved quality, and lower risk.
Java Deserialization: Running Faster Than a Bear
Commentary  |  4/14/2016  | 
Software components that were once good can sour instantly when new vulnerabilities are discovered within them. When that happens, the bears are coming, and you have to respond quickly.
Is Cloud Security An Exaggerated Concern?
Partner Perspectives  |  4/14/2016  | 
Research indicates the challenge has never been about security, but about transparency.
Securing the Weakest Link: Insiders
Commentary  |  4/13/2016  | 
No longer is a hoodie-wearing malicious hacker the most obvious perpetrator of an inside cyber attack.
Managing The Message Before The Breach
Commentary  |  4/12/2016  | 
No leader wants to see their company exploited by creative cyber villains. Heres how CISOs can stay ahead of the game with a strategic plan.
Dark Reading Radio: Advancing Your Security Career
Commentary  |  4/12/2016  | 
INCYMI! Join us for a fascinating discussion on key trends and opportunities in the rapidly evolving world of cybersecurity.
7 Profiles Of Highly Risky Insiders
Commentary  |  4/8/2016  | 
To understand who these insiders are and why they pose a risk, start by looking at the root of the problem.
Healthcare Organizations Must Consider The Financial Impact Of Ransomware Attacks
Partner Perspectives  |  4/7/2016  | 
Sometimes the impact of an attack can extend well beyond the attack itself.
Context & Awareness: Its All About The Apps
Commentary  |  4/7/2016  | 
Why data context, application awareness and training are keys to mitigating security risks,
Understanding The Cloud Threat Surface
Commentary  |  4/6/2016  | 
How todays borderless environment creates new threat vectors from third-party apps, brute force password attacks, and login attempts with stolen credentials.
How to Hack Your Own Car
Commentary  |  4/5/2016  | 
As vehicles become more software-driven, car manufacturers are keeping the inner workings of electronics systems more secretive. Here's one way to maintain security updates and still preserve your 'freedom to tinker.'
CAs Need To Force Rules Around Trust
Commentary  |  4/4/2016  | 
Google Symantec flap reveals worrisome weakness in the CA system.
Knowledge Gap Series: 3 Steps To Deal With The High Turnover In Your Security Department
Partner Perspectives  |  4/4/2016  | 
Follow these suggestions to significantly decrease the probability that your organization is a future security headline.
Avoiding Legal Landmines in Data Breach Response
Commentary  |  4/4/2016  | 
Building a legally defensible cybersecurity program means seeking out guidance from legal advisors before a serious incident forces you together.
Raising The Stakes For Application Security
Commentary  |  4/1/2016  | 
Why, if we already know most everything we need to know about exploited vulnerabilities in software, do hacks keep happening?


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-21742
PUBLISHED: 2021-09-25
There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages.
CVE-2020-20508
PUBLISHED: 2021-09-24
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.
CVE-2020-20514
PUBLISHED: 2021-09-24
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.
CVE-2016-6555
PUBLISHED: 2021-09-24
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in ver...
CVE-2016-6556
PUBLISHED: 2021-09-24
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP agent supplied data. By creating a malicious SNMP 'sysName' or 'sysContact' response, an attacker can store an XSS payload which will trigger when a user of the web UI views the data. This iss...