Commentary

Content posted in October 2013
Simple Security Is A Better Bet
Commentary  |  10/31/2013  | 
Complex security programs are little better than no security
Q&A: FedRAMP Director Discusses Cloud Security Innovation
Commentary  |  10/31/2013  | 
Maria Roat, FedRAMP director, speaks with former Transportation Department CIO Nitin Pradhan on the federal government's approach to security assessment, authorization, and continuous monitoring for cloud products and services.
Looking For A Security Job? You Don't Need To Be Bo Derek
Commentary  |  10/30/2013  | 
7 tips to convince a hiring manager that you're a perfect fit.
Vanishing IT Security Boundaries Reappearing Disguised As Identity
Commentary  |  10/30/2013  | 
It's that time of year, when nothing is as it seems. If cloud and mobile are haunting your dreams, consider some open protocol treats.
Think Hackers Are IT's Biggest Threat? Guess Again
Commentary  |  10/29/2013  | 
More than one third of all data security breaches at government agencies are caused accidentally by internal employees.
Quick Guide To Flash Storage Latency Wars
Commentary  |  10/29/2013  | 
Because latency is the key performance differentiator in server-side flash, SSD, PCIe and memory bus flash storage vendors are competing on speed.
Failure To Deploy: Aided And Abetted By Shelfware
Commentary  |  10/28/2013  | 
It takes more than technology acquisition to protect against the insider threat -- just ask the NSA
Experian Breach Fallout: ID Theft Nightmares Continue
Commentary  |  10/24/2013  | 
Data brokers amassing gigantic data stores of people's valuable personal information are too big to not fail. Why are consumers getting stuck with the mess?
Is Your DNS Server A Weapon?
Commentary  |  10/21/2013  | 
As we improve our defenses against distributed-denial-of-service (DDoS) attacks, the bad guys adapt and step up their game, too. Here's how to use your domain name servers to ward off hackers.
The Reality Of Freshly Minted Software Engineers
Commentary  |  10/15/2013  | 
Why do recent computer science graduates need to be retrained when they hit the commercial world?
We're All The APT
Commentary  |  10/12/2013  | 
XKeyscore, FoxAcid: APT lines are blurring
Don't Let 'Spooks' Get Your Cloud Data
Commentary  |  10/10/2013  | 
Lesson from National Cyber Security Awareness Month: Keys are the key, and keep it simple.
Evasion Techniques And Sneaky DBAs
Commentary  |  10/7/2013  | 
Why should DBAs introduce security measures that make their jobs harder for the nebulous benefit of better security?
Distributing Malware Through Future App Stores
Commentary  |  10/7/2013  | 
Difficult times ahead for app markets as professional malware developers ramp their evasion techniques
Next-Gen Spam: Quality Over Quantity
Commentary  |  10/3/2013  | 
The industry has been remarkably innovative in developing business models to extract money from the unwary.
Stratfor Hacker: FBI Entrapment Shaped My Case
Commentary  |  10/3/2013  | 
Hacker Jeremy Hammond asks for leniency before sentencing, citing the role of FBI informant Sabu in his case. How far can the FBI go with suspected computer criminals?
WordPress Attacks: Time To Wake Up
Commentary  |  10/1/2013  | 
The latest WordPress hacks highlight our continued laziness when implementing online security, a problem made worse by free, easy-to-use sites.
Security Skills For 2023
Commentary  |  10/1/2013  | 
Align your career with these top security trends
Make The Most Of National Cyber Security Awareness Month
Commentary  |  10/1/2013  | 
NCSAM is a catalyst to get extra attention for your security programs
Penetration Testing With Honest-To-Goodness Malware
Commentary  |  10/1/2013  | 
When did penetration-testing methodologies stop replicating the vectors attackers make?


12 Free, Ready-to-Use Security Tools
Steve Zurier, Freelance Writer,  10/12/2018
Most IT Security Pros Want to Change Jobs
Dark Reading Staff 10/12/2018
6 Security Trends for 2018/2019
Curtis Franklin Jr., Senior Editor at Dark Reading,  10/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-10839
PUBLISHED: 2018-10-16
Qemu emulator <= 3.0.0 built with the NE2000 NIC emulation support is vulnerable to an integer overflow, which could lead to buffer overflow issue. It could occur when receiving packets over the network. A user inside guest could use this flaw to crash the Qemu process resulting in DoS.
CVE-2018-13399
PUBLISHED: 2018-10-16
The Microsoft Windows Installer for Atlassian Fisheye and Crucible before version 4.6.1 allows local attackers to escalate privileges because of weak permissions on the installation directory.
CVE-2018-18381
PUBLISHED: 2018-10-16
Z-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the uploading of image attachments.
CVE-2018-18382
PUBLISHED: 2018-10-16
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action.
CVE-2018-18374
PUBLISHED: 2018-10-16
XSS exists in the MetInfo 6.1.2 admin/index.php page via the anyid parameter.