Slideshows

Content posted in January 2017
6 Free Ransomware Decryption Tools
Slideshows  |  1/30/2017  | 
The No More Ransom group has been working to get free decryptor tools into the hands of security professionals and the general public.
7 Tips For Getting Your Security Budget Approved
Slideshows  |  1/27/2017  | 
How to have a productive conversation with business leaders and get your security budget approved.
SOC Maturity By The Numbers
Slideshows  |  1/25/2017  | 
Most large organizations today have security operations centers in play, but only 15% rate theirs as mature.
7 Common Reasons Companies Get Hacked
Slideshows  |  1/18/2017  | 
Many breaches stem from the same root causes. What are the most common security problems leaving companies vulnerable?
10 Cocktail Party Security Tips From The Experts
Slideshows  |  1/13/2017  | 
Security pros offer basic advice to help average users ward off the bad guys.
What To Watch For With Ransomware: 2017 Edition
Slideshows  |  1/7/2017  | 
Ransomware will continue to evolve in 2017, bringing new and diverse threats to businesses. What changes are in store?
7 Ways To Fine-Tune Your Threat Intelligence Model
Slideshows  |  1/5/2017  | 
The nature of security threats is too dynamic for set-and-forget. Here are some ways to shake off that complacency.


Election Websites, Back-End Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Intel Reveals New Spectre-Like Vulnerability
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/15/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-13435
PUBLISHED: 2018-08-16
** DISPUTED ** An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of interest w...
CVE-2018-13446
PUBLISHED: 2018-08-16
** DISPUTED ** An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. ...
CVE-2018-14567
PUBLISHED: 2018-08-16
libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.
CVE-2018-15122
PUBLISHED: 2018-08-16
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.
CVE-2018-11509
PUBLISHED: 2018-08-16
ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.