Commentary

Content posted in March 2016
Machine Learning In Security: Seeing the Nth Dimension in Signatures
Commentary  |  3/31/2016  | 
How adding supervised machine learning to the development of n-dimensional signature engines is moving the detection odds back to the defender.
'FBiOS' Case Heading For A New Firestorm
Commentary  |  3/30/2016  | 
The surprise developments in the FBI v Apple case offer little reason to celebrate for encryption and privacy advocates.
Machine Learning In Security: Good & Bad News About Signatures
Commentary  |  3/30/2016  | 
Why security teams that rely solely on signature-based detection are overwhelmed by a high number of alerts.
From NY To Bangladesh: Inside An Inexcusable Cyber Heist
Commentary  |  3/29/2016  | 
A spelling error was the tipoff to last months multimillion-dollar digital bank heist. But could multifactor authentication have prevented it in the first place?
How 4 Startups Are Harnessing AI In The Invisible Cyberwar
Commentary  |  3/25/2016  | 
Cybersecurity startups are setting their scopes on a potential goldmine of automated systems they hope will be more effective than hiring human enterprise security teams.
Mobile Security: Why App Stores Dont Keep Users Safe
Commentary  |  3/24/2016  | 
In a preview of his Black Hat Asia Briefing next week, a security researcher offers more proof of trouble in the walled gardens of the Apple and Google App stores.
Think Risk When You Talk About Application Security Today
Commentary  |  3/23/2016  | 
Security from a risk-based perspective puts the focus on component failures and provides robust security for the ultimate target of most attacks -- company, customer and personal data.
Vuln Disclosure: Why Security Vendors & Researchers Dont Trust Each Other
Commentary  |  3/22/2016  | 
The security industry doesnt need a one-size-fits all vulnerability disclosure policy. It needs a culture change. Getting everyone to the table is the first step.
Cloud Security: Understanding New Risks, Rising To New Challenges
Commentary  |  3/21/2016  | 
In a business world dominated by the cloud, security ops has to change the way we play the game in order to accomplish our strategic goals.
Tell DR: What Are Your Biggest Unanswered Security Questions?
Commentary  |  3/19/2016  | 
Fill us in, Dark Reading community. What challenges and mysteries leave you scratching your heads and throwing up your hands?
No Place For Tor In The Secured Workplace
Commentary  |  3/18/2016  | 
When it comes to corporate security, anonymity does not necessarily ensure protection of ones private information nor that of your employer.
Security Lessons From My Stock Broker
Commentary  |  3/17/2016  | 
Or, how to lie with metrics.
Beyond Back Doors: Recalibrating The Encryption Policy Debate
Commentary  |  3/17/2016  | 
Three compelling reasons why access to back doors should not be the intelligence and law enforcement communitys main policy thrust in the fight against terrorism.
EU-US Privacy Shield: What Now, What Next?
Commentary  |  3/16/2016  | 
The good news: We finally have a clear direction for continuing trans-Atlantic data transfer after several months in limbo. The bad news is in the remaining uncertainties.
CISO Playbook: Suit-up & Play Offense
Commentary  |  3/15/2016  | 
In the game of IT security there are thousands of tools available, but the very best strategy to prepare for an opponent is to know your own weaknesses.
Dark Reading Radio: When Will Passwords Finally Die?
Commentary  |  3/14/2016  | 
Join us this Wednesday, March 16, at 1pm EDT/10am PDT, for the next episode of Dark Reading Radio.
Understanding The 2 Sides Of Application Security Testing
Commentary  |  3/14/2016  | 
Everybody likes to focus on the top 10 vulnerabilities, but I've never found a company with a top 10 vulnerabilities problem. Every company has a different top 10.
Must Haves & Must Dos For The First Federal CISO
Commentary  |  3/11/2016  | 
Offensive and defensive experience, public/private sector know-how, mini-NSA mindset and vision are top traits we need in a chief information security officer.
Security Lessons From The Gluten Lie
Commentary  |  3/10/2016  | 
How faith healers and security vendors have learned what lies work.
Why Security & DevOps Cant Be Friends
Commentary  |  3/9/2016  | 
Legacy applications are a brush fire waiting to happen. But retrofitting custom code built in the early 2000s is just a small part of the application security problem.
Forgot My Password: Caption Contest Winners Announced
Commentary  |  3/8/2016  | 
Sticky notes, clouds and authentication jokes. And the winning caption is...
A Warning for Wearables: Think Before You Emote
Commentary  |  3/8/2016  | 
An examination of how wearable devices could become the modern equivalent of blogs broadcasting proprietary workplace information directly to the Internet of Things -- and beyond.
Cloud Survival Guide: 3 Tips For CISOs
Commentary  |  3/7/2016  | 
To thrive in the cloud era, CISOs must refashion their roles as business enablers, adopt automation wherever possible, and go back to the basics on security hygiene.
Why Marrying Infosec & Info Governance Boosts Security Capabilities
Commentary  |  3/4/2016  | 
In todays data centric world, security pros need to know where sensitive data is supposed to be, not just where it actually is now.
IoT Security Checklist: Get Ahead Of The Curve
Commentary  |  3/3/2016  | 
The security industry needs to take a Consumer Reports approach to Internet of Things product safety, including rigorous development practices and both physical and digital testing.
Why Your Security Tools Are Exposing You to Added Risks
Commentary  |  3/2/2016  | 
The big lesson from 12 months of security product vulnerabilities: theres no foundation of trust in any piece of software. They all represent a potential new attack vector.
Better Locks Than Back Doors: Why Apple Is Right About Encryption
Commentary  |  3/1/2016  | 
What the landmark privacy case and a new documentary about Stuxnet both have to say about the encryption versus government oversight debate.


High Stress Levels Impacting CISOs Physically, Mentally
Jai Vijayan, Freelance writer,  2/14/2019
Valentine's Emails Laced with Gandcrab Ransomware
Kelly Sheridan, Staff Editor, Dark Reading,  2/14/2019
Making the Case for a Cybersecurity Moon Shot
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  2/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-8980
PUBLISHED: 2019-02-21
A memory leak in the kernel_read_file function in fs/exec.c in the Linux kernel through 4.20.11 allows attackers to cause a denial of service (memory consumption) by triggering vfs_read failures.
CVE-2019-8979
PUBLISHED: 2019-02-21
Koseven through 3.3.9, and Kohana through 3.3.6, has SQL Injection when the order_by() parameter can be controlled.
CVE-2013-7469
PUBLISHED: 2019-02-21
Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.
CVE-2018-20146
PUBLISHED: 2019-02-21
An issue was discovered in Liquidware ProfileUnity before 6.8.0 with Liquidware FlexApp before 6.8.0. A local user could obtain administrator rights, as demonstrated by use of PowerShell.
CVE-2019-5727
PUBLISHED: 2019-02-21
Splunk Web in Splunk Enterprise 6.5.x before 6.5.5, 6.4.x before 6.4.9, 6.3.x before 6.3.12, 6.2.x before 6.2.14, 6.1.x before 6.1.14, and 6.0.x before 6.0.15 and Splunk Light before 6.6.0 has Persistent XSS, aka SPL-138827.