Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Careers & People posted in March 2016
Cybercrime: A Black Market Price List From The Dark Web
Slideshows  |  3/30/2016  | 
What does it cost for malware, stolen identities and other tools of the cybercriminal trade? Probably less than you think.
Think Risk When You Talk About Application Security Today
Commentary  |  3/23/2016  | 
Security from a risk-based perspective puts the focus on component failures and provides robust security for the ultimate target of most attacks -- company, customer and personal data.
Tell DR: What Are Your Biggest Unanswered Security Questions?
Commentary  |  3/19/2016  | 
Fill us in, Dark Reading community. What challenges and mysteries leave you scratching your heads and throwing up your hands?
No Place For Tor In The Secured Workplace
Commentary  |  3/18/2016  | 
When it comes to corporate security, anonymity does not necessarily ensure protection of ones private information nor that of your employer.
Beyond Back Doors: Recalibrating The Encryption Policy Debate
Commentary  |  3/17/2016  | 
Three compelling reasons why access to back doors should not be the intelligence and law enforcement communitys main policy thrust in the fight against terrorism.
Home Depot To Pay $19.5 Million In Data Breach Settlement
Quick Hits  |  3/17/2016  | 
Home improvement chain agrees to pay for out-of-pocket losses incurred by US shoppers from 2014 data breach, and promises to improve its payment systems' data security.
Anonymous To Launch Cyberattacks Against Trump Campaign Starting April 1
News  |  3/15/2016  | 
Planned attacks a response to candidates controversial campaign rhetoric, hacking collective says.
CISO Playbook: Suit-up & Play Offense
Commentary  |  3/15/2016  | 
In the game of IT security there are thousands of tools available, but the very best strategy to prepare for an opponent is to know your own weaknesses.
5 Hot Security Job Skills
News  |  3/14/2016  | 
Cybersecurity job openings are looking for people with a blend of technical, security, and industry-specific talents -- and it helps to know Python, Hadoop, MongoDB, and other big-data analysis tools, too.
FBI's Most Wanted Cybercriminals
Slideshows  |  3/14/2016  | 
The Federal Bureau of Investigation has got millions of dollars worth of rewards waiting for those who can help them nab these accused cyber thieves, spies and fraudsters.
Must Haves & Must Dos For The First Federal CISO
Commentary  |  3/11/2016  | 
Offensive and defensive experience, public/private sector know-how, mini-NSA mindset and vision are top traits we need in a chief information security officer.
Presidential Candidates Get Graded On Their Cybersecurity Stances
News  |  3/10/2016  | 
Trump, Clinton, Sanders, Cruz, Rubio, Kasich, are all unified when it comes to blaming China -- but no one gets higher than a "C" average grade in any category.
Security Lessons From The Gluten Lie
Commentary  |  3/10/2016  | 
How faith healers and security vendors have learned what lies work.
Why Security & DevOps Cant Be Friends
Commentary  |  3/9/2016  | 
Legacy applications are a brush fire waiting to happen. But retrofitting custom code built in the early 2000s is just a small part of the application security problem.
The New BEC Phishing Attack: Stealing Data Instead Of Cash
Quick Hits  |  3/8/2016  | 
Duped by phishers posing as company executives, Seagate and Snapchat expose employee tax, payroll data.
Forgot My Password: Caption Contest Winners Announced
Commentary  |  3/8/2016  | 
Sticky notes, clouds and authentication jokes. And the winning caption is...
A Warning for Wearables: Think Before You Emote
Commentary  |  3/8/2016  | 
An examination of how wearable devices could become the modern equivalent of blogs broadcasting proprietary workplace information directly to the Internet of Things -- and beyond.
Hottest Topics To Come Out Of RSA Conference
News  |  3/8/2016  | 
Encryption, bug bounties, and threat intel dominated the mindshare of the cybersecurity hive mind at RSAC last week.
Cloud Survival Guide: 3 Tips For CISOs
Commentary  |  3/7/2016  | 
To thrive in the cloud era, CISOs must refashion their roles as business enablers, adopt automation wherever possible, and go back to the basics on security hygiene.
Encryption, Privacy & Skills Shortage Hot Topics On RSA Keynote Stage
News  |  3/1/2016  | 
From the president of RSA to the director of the NSA, all RSA conference keynotes mentioned needs for protecting liberties and increasing the infosec workforce.
To Improve Workforce Diversity, Widen The Search, Feed Infosec Talent Pipeline
News  |  3/1/2016  | 
RSA Conference 2016: Session panelists offered practical tips on how to attract more women and minorities, and challenged attendees to do some soul-searching.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-40690
PUBLISHED: 2021-09-19
All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secureValidation" property is not passed correctly when creating a KeyInfo from a KeyInfoReference element. This allows an attacker to abuse an XPath Transform to extract...
CVE-2021-41073
PUBLISHED: 2021-09-19
loop_rw_iter in fs/io_uring.c in the Linux kernel through 5.14.6 allows local users to gain privileges by using IORING_OP_PROVIDE_BUFFERS to trigger a free of a kernel buffer, as demonstrated by using /proc/<pid>/maps for exploitation.
CVE-2021-23441
PUBLISHED: 2021-09-19
All versions of package com.jsoniter:jsoniter are vulnerable to Deserialization of Untrusted Data via malicious JSON strings. This may lead to a Denial of Service, and in certain cases, code execution.
CVE-2021-41393
PUBLISHED: 2021-09-18
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows forgery of SSH host certificates in some situations.
CVE-2021-41394
PUBLISHED: 2021-09-18
Teleport before 4.4.11, 5.x before 5.2.4, 6.x before 6.2.12, and 7.x before 7.1.1 allows alteration of build artifacts in some situations.