Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Opinion

posted in April 2017
10 Cybercrime Myths that Could Cost You Millions
Commentary  |  4/29/2017  | 
Dont let a cybersecurity fantasy stop you from building the effective countermeasures you need to protect your organization from attack.
A Day in the Life of a Security Avenger
Commentary  |  4/28/2017  | 
Behind the scenes with a security researcher as we follow her through a typical day defending the world against seemingly boundless cyberthreats and attacks
OWASP Top 10 Update: Is It Helping to Create More Secure Applications?
Commentary  |  4/27/2017  | 
What has not been updated in the new Top 10 list is almost more significant than what has.
New OWASP Top 10 Reveals Critical Weakness in Application Defenses
Commentary  |  4/27/2017  | 
It's time to move from a dependence on the flawed process of vulnerability identification and remediation to a two-pronged approach that also protects organizations from attacks.
Threat Intelligence Is (Still) Broken: A Cautionary Tale from the Past
Commentary  |  4/26/2017  | 
There is much to be learned from the striking parallels between counter-terrorism threat analysis before 9-11 and how we handle cyber threat intelligence today.
What Role Should ISPs Play in Cybersecurity?
Commentary  |  4/26/2017  | 
There are many actions ISPs could do to make browsing the Web safer, but one thing stands out.
Locky Returns with a New (Borrowed) Distribution Method
Partner Perspectives  |  4/26/2017  | 
A layered defense is a strong security posture for dealing with a threat like Locky, that can come in different disguises.
Why (& How) CISOs Should Talk to Company Boards
Commentary  |  4/25/2017  | 
The C-Suite needs to minimize cybersecurity risk in order to maximize its principal goal of attaining high-level, sustainable growth.
IT-OT Convergence: Coming to an Industrial Plant Near You
Commentary  |  4/25/2017  | 
There's been a big divide between IT and OT, but that must end. Here's how to make them come together.
The Road Less Traveled: Building a Career in Cyberthreat Intelligence
Commentary  |  4/24/2017  | 
It's hard to become a threat intelligence pro, but there are three primary ways of going about it.
Best Practices for Securing Open Source Code
Commentary  |  4/21/2017  | 
Attackers see open source components as an obvious target because there's so much information on how to exploit them. These best practices will help keep you safer.
IHG Hack Hit Hospitality Guests in the Wallet
Curt Franklin  |  4/20/2017  | 
Malware on IHG servers sent credit card info to stay with thieves.
Kill Chain & the Internet of Things
Commentary  |  4/20/2017  | 
IoT things such as security cameras, smart thermostats and wearables are particularly easy targets for kill chain intruders, but a layered approach to security can help thwart an attack.
Cutting through the Noise: Is It AI or Pattern Matching?
Commentary  |  4/20/2017  | 
Many vendors are fudging terms when trying to sell their artificial intelligence security systems. Here's what you need to know when you buy.
Google Won't Trust Symantec and Neither Should You
Commentary  |  4/19/2017  | 
As bad as this controversy is for Symantec, the real damage will befall the company and individual web sites deemed untrustworthy by a Chrome browser on the basis of a rejected Symantec certificate.
Snowden Says Mass Surveillance Programs 'Are About Power'
Commentary  |  4/19/2017  | 
Edward Snowden shared his views of the implications of mass surveillance programs and the government's objective in implementing them.
Join Dark Reading for a 4/20 Twitter Chat on AppSec
Commentary  |  4/19/2017  | 
The @DarkReading team will host a conversation about application security on 4/20 at 2 p.m. ET.
The Architecture of the Web Is Unsafe for Today's World
Commentary  |  4/19/2017  | 
The Internet is based on protocols that assume content is secure. A new, more realistic model is needed.
Intrusion Suppression:' Transforming Castles into Prisons
Commentary  |  4/18/2017  | 
How building cybersecurity structures that decrease adversaries dwell time can reduce the damage from a cyberattack.
How Top Security Execs are Doing More with Less
Commentary  |  4/18/2017  | 
Even the largest corporations aren't immune to the cybersecurity skills gap an inside look at how they are coping and adjusting.
Cybercrime Tactics & Techniques: Q1 2017
Partner Perspectives  |  4/18/2017  | 
A deep dive into the threats that got our attention during the first three months of the year and what to expect going forward.
The Implications Behind Proposed Internet Privacy Rules
Commentary  |  4/18/2017  | 
The FCC's overreach needed to be undone to protect the FTC's authority over privacy.
FDA Warns Abbott on IoT Vulnerability & More
Curt Franklin  |  4/17/2017  | 
The FDA delivered a strongly worded warning to Abbott Labs about continuing vulnerabilities and defects in implantable devices.
The Second Coming of Managed File Transfer Has Arrived
Commentary  |  4/17/2017  | 
Sometimes, a mature, embedded technology still makes the most sense, especially when it comes to data security.
10 Questions To Get Practical Answers At Interop ITX
Commentary  |  4/14/2017  | 
May 15-19 in Las Vegas: How to get solutions and advice from top speakers for the things that you really want to know.
Health Savings Account Fraud: The Rapidly Growing Threat
Commentary  |  4/14/2017  | 
As income tax season comes to a close, financially-motivated cybercriminals are honing new tactics for monetizing medical PII.
Wikileaks Vault 7 Hacks Hit Dozens
Curt Franklin  |  4/13/2017  | 
The attacks detailed in Wikipedia's Vault 7 release of CIA information have hit at least 40 targets since the information release.
Got an Industrial Network? Reduce your Risk of a Cyberattack with Defense in Depth
Commentary  |  4/13/2017  | 
If an aggressive, all-out cyberdefense strategy isnt already on your operational technology plan for 2017, its time to get busy.
So You Want to Be a Security Rock Star?
Commentary  |  4/13/2017  | 
While the thrill of crafting attention-grabbing stunt hacks may seem like the coolest job on earth, what our industry needs more of are strong defenders who can fix things as well as break them.
Cybersecurity & Fitness: Weekend Warriors Need Not Apply
Commentary  |  4/12/2017  | 
It takes consistency and a repeatable but flexible approach to achieve sustainable, measurable gains in both disciplines.
Securing your Privacy on Android
Partner Perspectives  |  4/12/2017  | 
If you work at a company that allows you to use your mobile device to login to email, access company data, or connect to company Wi-Fi, youre more of a security risk than you think.
How Innovative Companies Lock Down Data
Commentary  |  4/12/2017  | 
A mix of back-to-basics security and a set of new, data-centric best practices is key to defending against a future of growing and sophisticated cyberattacks.
Tax Season Surprise: W-2 Fraud
Commentary  |  4/11/2017  | 
W-2 fraud used to target businesses exclusively but has now set its sights on many other sectors. Here's what you can do to prevent it from happening to you.
When Hacks Are about Image instead of Money
Commentary  |  4/11/2017  | 
If you think fake news is a problem, how about the possibility of fake medical or financial information making the rounds with no way to verify its legitimacy?
Infoblox Serves SDN DNS to Carriers With Trinzic Flex
Curt Franklin  |  4/10/2017  | 
Infoblox's latest appliance, Trinzic Flex, brings its traditional DNS, DHCP and more to SDN and NFV at carrier scale.
Setting Up Security as a Business: 3 Best Practices for Security Execs
Commentary  |  4/10/2017  | 
Security leaders need to show they provide more than stop-the-bad guys services. Here's how.
The New Shadow IT: Custom Data Center Applications
Commentary  |  4/7/2017  | 
If you think youve finally gotten control of unsanctioned user apps, think again. The next wave of rogue apps is on its way from your data center to the cloud.
OSX.Dok: New & Sophisticated Mac Malware Strikes
Partner Perspectives  |  4/7/2017  | 
Phishing-deployed malware can capture account credentials for any website users log into.
How to Crack Cybersecuritys Glass Ceiling
Commentary  |  4/6/2017  | 
Sage career advice to young women from the female CTO of a security startup: Get a pair of earplugs, and put them in when you hear words like 'can't' or 'don't.'
Commodity Ransomware Is Here
Commentary  |  4/6/2017  | 
When deploying ransomware is as easy as ordering a pizza, the best defense is through better threat intelligence sharing.
McAfee's Independence Day
Curt Franklin  |  4/5/2017  | 
Six years after a purchase by Intel, McAfee is once again a private company with a new focus and an old name.
Banks Must Focus More on Cyber-Risk
Commentary  |  4/5/2017  | 
Recent guidelines from the Federal Reserve are aimed at stemming the tide of successful exploits.
GDPR Doesnt Need to be GDP-Argh!
Commentary  |  4/5/2017  | 
These 10 steps will ease the pain of compliance with the General Data Protection Regulation, the EU's new privacy law that goes into effect in a little over a year.
The Power of the Crowd: 3 Approaches to Sharing Threat Intel
Commentary  |  4/4/2017  | 
Crowdsourced intelligence can help you build a stronger, more informed cyberdefense. Heres how.
Top 5 Dumbest Cyber Threats That Still Pay Off
Partner Perspectives  |  4/4/2017  | 
Some hackers are fairly predictable in their successful use of really dumb attacks.
To Attract and Retain Better Employees, Respect Their Data
Commentary  |  4/3/2017  | 
A lack of privacy erodes trust that employees should have in management.


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11583
PUBLISHED: 2020-08-03
A GET-based XSS reflected vulnerability in Plesk Obsidian 18.0.17 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
CVE-2020-11584
PUBLISHED: 2020-08-03
A GET-based XSS reflected vulnerability in Plesk Onyx 17.8.11 allows remote unauthenticated users to inject arbitrary JavaScript, HTML, or CSS via a GET parameter.
CVE-2020-5770
PUBLISHED: 2020-08-03
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.01 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
CVE-2020-5771
PUBLISHED: 2020-08-03
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious backup archive.
CVE-2020-5772
PUBLISHED: 2020-08-03
Improper Input Validation in Teltonika firmware TRB2_R_00.02.04.01 allows a remote, authenticated attacker to gain root privileges by uploading a malicious package file.