Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Vulnerabilities / Threats posted in November 2014
Why We Need Better Cyber Security: A Graphical Snapshot
Slideshows  |  11/28/2014  | 
By 2022, demand for security industry professionals will grow 37%.
Dangers Of Shopping Are Evolving
Quick Hits  |  11/26/2014  | 
Point-of-sale malware is making brick-and-mortar shopping more dangerous. Online, attackers are beginning to value user accounts with payment information attached more than credit card details themselves.
6 Million+ Email Accounts Worldwide Exposed In Past 3 Months
Quick Hits  |  11/25/2014  | 
Spike in number of stolen accounts likely due to uptick in major data breaches, researchers say.
Underground Carders Abusing Charities To Verify Stolen Payment Data
News  |  11/25/2014  | 
Charities' weak fraud controls make things easier on donors and criminals alike.
Don't Discount XSS Vulnerabilities
News  |  11/24/2014  | 
XSS flaws are more serious than you'd think.
Cyber Security Needs Its Ralph Nader
Commentary  |  11/24/2014  | 
It took thousands of unnecessary traffic fatalities to create an environment for radical transformation of the auto industry. What will it take for a similar change to occur in data security?
Cloud Security By The Numbers
Slideshows  |  11/21/2014  | 
Quantifying the perceptions around cloud security practices.
The Week When Attackers Started Winning The War On Trust
Commentary  |  11/21/2014  | 
The misuse of keys and certificates is not exotic or hypothetical. Its a real threat that could undermine most, if not all, critical security controls, as recent headlines strongly show.
Russian Cyber Espionage Under The Microscope
News  |  11/20/2014  | 
New report shows level of coordination and strategy by three main groups of cyberspies out of Russia.
New Citadel Attack Targets Password Managers
News  |  11/20/2014  | 
IBM researchers have found signs that the prolific data steal Trojan is now being used to attack widely used password managers.
Surveillance Cameras Next On The Insecure IoT List
News  |  11/20/2014  | 
Three buffer overflow vulnerabilities leave HikVision video recorders open to remote code execution.
Internet Architecture Board Calls For Net Encryption By Default
News  |  11/19/2014  | 
The Internet Architecture Board (IAB) urges encryption across the protocol stack to usher in an era where encrypted traffic is the norm. But there are possible security tradeoffs.
Machine Learning: A Solution to Today's Security Threats & One Step Closer to AI
Partner Perspectives  |  11/19/2014  | 
Algorithms can identify threats that have been missed by traditional security mechanisms.11/19/2014 11:44:00 AM
The Rise Of The Resilient Mobile Botnet
News  |  11/19/2014  | 
New report on what researchers call one of the 'most sophisticated mobile botnets online' shows how profitable mobile malware has become.
Microsoft Issues Emergency Patch Amid Targeted Attacks
News  |  11/18/2014  | 
Windows Kerberos authentication bug "critical."
Is Security Awareness Training Really Worth It?
News  |  11/18/2014  | 
Experts weigh in on the value of end-user security training, and how to make education more effective.
Deconstructing The Cyber Kill Chain
Commentary  |  11/18/2014  | 
As sexy as it is, the Cyber Kill Chain model can actually be detrimental to network security because it reinforces old-school, perimeter-focused, malware-prevention thinking.
Why Cyber Security Starts At Home
Commentary  |  11/17/2014  | 
Even the grandmas on Facebook need to know and practice basic security hygiene, because what happens anywhere on the Internet can eventually affect us all.
Microsoft Fixes Critical SChannel & OLE Bugs, But No Patches For XP
News  |  11/14/2014  | 
No patches released for the now-unsupported XP even though the 19-year-old OLE bug is critical and "Winshock" bug in Windows' SSL/TLS installation could be worse than Heartbleed.
Rethinking Security With A System Of 'Checks & Balances'
Commentary  |  11/14/2014  | 
For too long, enterprises have given power to one branch of security governance -- prevention -- at the expense of the other two: detection and response.
Time To Turn The Tables On Attackers
Commentary  |  11/13/2014  | 
As a security industry, we need to arm business with innovative technologies that provide visibility, analysis, and action to prevent inevitable breaches from causing irreparable damage.
The Enemy Who Is Us: DoD Puts Contractors On Notice For Insider Threats
Commentary  |  11/13/2014  | 
New rule requires US government contractors to gather and report information on insider threat activity on classified networks.
Expired Antivirus Software No. 1 Cause Of Unprotected Windows 8 PCs
News  |  11/13/2014  | 
New data from Microsoft shows that nearly 10% of Windows 8 users are running expired AV software on their systems, making them four times more likely to get infected.
Better Together: Why Cyber Security Vendors Are Teaming Up
Commentary  |  11/12/2014  | 
Alliances, mergers, and acquisitions are ushering in an era of unprecedented co-opetition among former rivals for your point solution business.
POS Malware Continues To Evolve
News  |  11/11/2014  | 
New report out today details three prevalent families.
Small-to-Midsized Businesses Targeted In More Invasive Cyberattacks
News  |  11/11/2014  | 
How notorious remote access tools Predator Pain and Limitless have evolved into bargain-basement tools accessible to masses of cybercriminals.
How Enterprises Can Get The Most From Threat Intelligence
News  |  11/11/2014  | 
Understanding the threats faced by your organization can improve your defenses. Here are some tips for choosing tools and services -- and maximizing their impact.
Walk & Stalk: A New Twist In Cyberstalking
Commentary  |  11/11/2014  | 
How hackers can turn Wifi signals from smartphones and tablets into a homing beacon that captures users' online credentials and follows them, undetected, throughout the course of the day.
New Attack Method Can Hit 95% Of iOS Devices
News  |  11/10/2014  | 
Masque Attack replaces legit apps with malware using the same bundle identifier names.
The Staggering Complexity of Application Security
Commentary  |  11/10/2014  | 
During the past few decades of high-speed coding we have automated our businesses so fast that we are now incapable of securing what we have built.
Stop Trusting Signed Malware: 3 Steps
Commentary  |  11/7/2014  | 
Cybercriminals who manipulate valid signatures and certificates to get malware into an organization is a more common tactic than you think.
Privacy Versus The 'Tyranny Of The Algorithm'
News  |  11/5/2014  | 
Health, social media, buying trends, and other data and activity are routinely bartered for profit, but at what cost to the consumer or user?
iOS 8 Vs. Android: How Secure Is Your Data?
Commentary  |  11/5/2014  | 
With iOS 8, the lines between iOS and Android are blurring. No longer is iOS the heavily fortified environment and Android the wide-open one.
Breach Fatigue Sets In With Consumers
News  |  11/4/2014  | 
Report from Ponemon and RSA shows that consumers aren't really adjusting behavior due to mega breaches.
Preparing For A Data Breach: Think Stop, Drop & Roll
Commentary  |  11/3/2014  | 
Breaches are going to happen, which is why we need to treat incident response readiness like fire drills, practicing time and time again until the response is practically instinctive.


US Turning Up the Heat on North Korea's Cyber Threat Operations
Jai Vijayan, Contributing Writer,  9/16/2019
Preventing PTSD and Burnout for Cybersecurity Professionals
Craig Hinkley, CEO, WhiteHat Security,  9/16/2019
NetCAT Vulnerability Is Out of the Bag
Dark Reading Staff 9/12/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3738
PUBLISHED: 2019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Improper Verification of Cryptographic Signature vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
CVE-2019-3739
PUBLISHED: 2019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
CVE-2019-3740
PUBLISHED: 2019-09-18
RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
CVE-2019-3756
PUBLISHED: 2019-09-18
RSA Archer, versions prior to 6.6 P3 (6.6.0.3), contain an information disclosure vulnerability. Information relating to the backend database gets disclosed to low-privileged RSA Archer users' UI under certain error conditions.
CVE-2019-3758
PUBLISHED: 2019-09-18
RSA Archer, versions prior to 6.6 P2 (6.6.0.2), contain an improper authentication vulnerability. The vulnerability allows sysadmins to create user accounts with insufficient credentials. Unauthenticated attackers could gain unauthorized access to the system using those accounts.