Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Commentary

Content posted in December 2020
How to Build Cyber Resilience in a Dangerous Atmosphere
Commentary  |  12/31/2020  | 
Our polarized climate and COVID-19 are putting the nation's cybersecurity in imminent danger, and it's past time to act.
Mobile Endpoint Security: Still the Crack in the Enterprise's Cyber Armor
Commentary  |  12/30/2020  | 
A combination of best practices and best-in-class technology will help keep your enterprise from falling victim to ever-growing threats.
Reducing the Risk of Third-Party SaaS Apps to Your Organization
Commentary  |  12/29/2020  | 
Such apps may try to leak your data, or can contain malicious code. And even legitimate apps may be poorly written, creating security risks.
India: A Growing Cybersecurity Threat
Commentary  |  12/29/2020  | 
Geopolitical tensions and a dramatic rise in offensive and defensive cyber capabilities lead India to join Iran, Russia, China, and North Korea as a top nation-state adversary.
Defending the COVID-19 Vaccine Supply Chain
Commentary  |  12/28/2020  | 
We must treat this supply chain like a piece of our nation's critical infrastructure, just like the electrical grid or air traffic control system.
10 Benefits of Running Cybersecurity Exercises
Commentary  |  12/28/2020  | 
There may be no better way to ascertain your organization's strengths and weaknesses than by running regular security drills.
Quarterbacking Vulnerability Remediation
Commentary  |  12/24/2020  | 
It's time that security got out of the armchair and out on the field.
Enterprise IoT Security Is a Supply Chain Problem
Commentary  |  12/23/2020  | 
Organizations that wish to take advantage of the potential benefits of IoT systems in enterprise environments should start evaluating third-party risk during the acquisition process.
Prepare to Fight Upcoming Cyber-Threat Innovations
Commentary  |  12/22/2020  | 
Cybercriminals are preparing to use computing performance innovations to launch new types of attacks.
Security as Code: How Repeatable Policy-Driven Deployment Improves Security
Commentary  |  12/22/2020  | 
The SaC approach lets users codify and enforce a secure state of application configuration deployment that limits risk.
We Have a National Cybersecurity Emergency -- Here's How We Can Respond
Commentary  |  12/21/2020  | 
Let's prioritize bipartisan strategic actions that can ensure our national security and strengthen the economy. Here are five ideas for how to do that.
2021 Cybersecurity Predictions: The Intergalactic Battle Begins
Commentary  |  12/18/2020  | 
There's much in store for the future of cybersecurity, and the most interesting things aren't happening on Earth.
VPNs, MFA & the Realities of Remote Work
Commentary  |  12/17/2020  | 
The work-from-home-era is accelerating cloud-native service adoption.
Corporate Credentials for Sale on the Dark Web: How to Protect Employees and Data
Commentary  |  12/16/2020  | 
It's past time to retire passwords in favor of other methods for authenticating users and securing systems.
Why the Weakest Links Matter
Commentary  |  12/16/2020  | 
The recent FireEye and SolarWinds compromises reinforce the fact that risks should be understood, controls should be in place, and care should be taken at every opportunity.
SSO and MFA Are Only Half Your Identity Governance Strategy
Commentary  |  12/16/2020  | 
We need better ways to manage user identities for accessing applications, especially given the strain it places on overworked IT and security teams.
Nowhere to Hide: Don't Let Your Guard Down This Holiday Season
Commentary  |  12/15/2020  | 
Harden your defenses to ensure that your holiday downtime doesn't become an open door for cyber threats.
The Private Sector Needs a Cybersecurity Transformation
Commentary  |  12/15/2020  | 
Cybersecurity must get to the point where it's equated with actually stopping an attack by identifying the methods the bad guys use and taking those methods away.
Startups Should Do Things That Don't Scale, but Security Isn't One of Them
Commentary  |  12/14/2020  | 
Emerging businesses that don't embrace scalable security do so at their own peril.
Penetration Testing: A Road Map for Improving Outcomes
Commentary  |  12/11/2020  | 
As cybersecurity incidents gain sophistication, to ensure we are assessing security postures effectively, it is critical to copy real-world adversaries' tools, tactics, and procedures during testing activities.
Cloud Identity and Access Management: Understanding the Chain of Access
Commentary  |  12/10/2020  | 
Here's where enterprises encounter challenges with cloud IAM and the best practices they should follow to correct these mistakes.
The Line Between Physical Security & Cybersecurity Blurs as World Gets More Digital
Commentary  |  12/10/2020  | 
Security teams are being challenged by the connected nature of IP devices, and preventing them from being compromised by cybercriminals has become an essential part of keeping people and property safe.
The Holiday Shopping Season: A Prime Opportunity for Triangulation Fraud
Commentary  |  12/9/2020  | 
As e-commerce sales increase, so does the risk of hard-to-detect online fraud.
Navigating the Security Maze in a New Era of Cyberthreats
Commentary  |  12/9/2020  | 
Multiple, dynamic threats have reshaped the cyber-risk landscape; ignore them at your peril.
Why Compliance Is No Longer King for Financial Services Cybersecurity
Commentary  |  12/8/2020  | 
Financial services companies' experience in risk management serves them well when it comes to minimizing their cyber-risk.
Attackers Know Microsoft 365 Better Than You Do
Commentary  |  12/8/2020  | 
Users have taken to Microsoft Office 365's tools, but many are unaware of free features that come with their accounts -- features that would keep them safe.
Avoiding a 1984-Like Future
Commentary  |  12/7/2020  | 
We must not simply trust technology to be safe. Technology providers and users should agree on severe security practices, and these standards must be implemented wherever data goes.
Flash Dies but Warning Signs Persist: A Eulogy for Tech's Terrible Security Precedent
Commentary  |  12/4/2020  | 
Flash will be gone by the end of the year, but the ecosystem that allowed it to become a software security serial killer is ready to let it happen again.
Cloud Security Threats for 2021
Commentary  |  12/3/2020  | 
Most of these issues can be remediated, but many users and administrators don't find out about them until it's too late.
From FUD to Fix: Why the CISO-Vendor Partnership Needs to Change Now
Commentary  |  12/3/2020  | 
CISOs and their staffs are up against too many systems, screens, and alerts, with too few solutions to effectively address pain points.
Automated Pen Testing: Can It Replace Humans?
Commentary  |  12/2/2020  | 
These tools have come a long way, but are they far enough along to make human pen testers obsolete?
Why I'd Take Good IT Hygiene Over Security's Latest Silver Bullet
Commentary  |  12/2/2020  | 
Bells and whistles are great, but you can stay safer by focusing on correct configurations, posture management, visibility, and patching.
The Cybersecurity Skills Gap: It Doesn't Have to Be This Way
Commentary  |  12/1/2020  | 
Once it becomes clear that off-the-shelf experts aren't realistic at scale, cultivating entry-level talent emerges as the only long-term solution -- not just for a hiring organization but for the field as a whole.
Can't Afford a Full-time CISO? Try the Virtual Version
Commentary  |  12/1/2020  | 
A vCISO can align a company's information security program to business strategy and budgeting guidance to senior management.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Everything You Need to Know About DNS Attacks
It's important to understand DNS, potential attacks against it, and the tools and techniques required to defend DNS infrastructure. This report answers all the questions you were afraid to ask. Domain Name Service (DNS) is a critical part of any organization's digital infrastructure, but it's also one of the least understood. DNS is designed to be invisible to business professionals, IT stakeholders, and many security professionals, but DNS's threat surface is large and widely targeted. Attackers are causing a great deal of damage with an array of attacks such as denial of service, DNS cache poisoning, DNS hijackin, DNS tunneling, and DNS dangling. They are using DNS infrastructure to take control of inbound and outbound communications and preventing users from accessing the applications they are looking for. To stop attacks on DNS, security teams need to shore up the organization's security hygiene around DNS infrastructure, implement controls such as DNSSEC, and monitor DNS traffic
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-33196
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
CVE-2023-33185
PUBLISHED: 2023-05-26
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email bounces, subscriptions, etc. These requests ar...
CVE-2023-33187
PUBLISHED: 2023-05-26
Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to `type="text"` via a javascript "Show Password" button. This differs from the expected behavior which always obfuscates `ty...
CVE-2023-33194
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was...
CVE-2023-2879
PUBLISHED: 2023-05-26
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file