Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Products and Releases

Content posted in August 2017
Hackers Cybersquat on Hundreds of Luxury Fashion Brand Domains
Products and Releases  |  8/31/2017  | 
DomainTools identifies over 500 websites tricking web users into thinking theyre clicking on to luxury fashion websites.
Nearly 25% of Companies Havent Hired a Data Protection Officer: Imperva
Products and Releases  |  8/29/2017  | 
Enterprises say they may look to AI or machine learning to ease the burden of GDPR compliance.
HyTrust Launches DataControl for VMware Cloud on AWS
Products and Releases  |  8/28/2017  | 
Aims to provide customers with an efficient, flexible way to secure critical business applications and data with encryption and key management
NIST, DHS Join Forces to Create Cybersecure Communities Around the Globe
Products and Releases  |  8/28/2017  | 
The groups jointly sponsor the 2018 Global City Teams Challenge (GCTC).
Rohde & Schwarz Cybersecurity Launches DNS Tunneling Detection
Products and Releases  |  8/28/2017  | 
Company launches enhanced traffic analysis capabilities to detect Domain Name Server (DNS) tunneling.
Respond Software Powers Self-Driving SOC
Products and Releases  |  8/25/2017  | 
Company receives $12 Million in Series A Funding from CRV and Foundation Capital.
Calyptix Releases Threat Intelligence Report
Products and Releases  |  8/25/2017  | 
The findings examine cybersecurity threats for small businesses in North America.
Druva Announces $80 Million in Growth Equity Funding
Products and Releases  |  8/23/2017  | 
Funding aims to redefine and accelerate Druva's position in the cloud data protection and management market.
Information Security Forum Updates Information Risk Assessment Methodology
Products and Releases  |  8/23/2017  | 
Methodology Helps Businesses Identify, Analyze and Treat Information Risk throughout the Organization.
Black Duck Streamlines DevSecOps with New Hub Detect Capability
Products and Releases  |  8/23/2017  | 
Multi-factor open source discovery solution provides universal package manager and CI tool support, in a move to improve detection accuracy.
One Identity Launches SaaS ID-Risk Solution
Products and Releases  |  8/23/2017  | 
One Identity Starling Identity Analytics & Risk Intelligence is designed to prevent data breaches from improper user entitlements.
Versive Raises $12.7 Million in Funding for AI-Powered Security Solutions
Products and Releases  |  8/23/2017  | 
Existing investors Goldman Sachs, Madrona Venture Group, Formation 8, and Vulcan Capital contributed to funding.
Bugcrowd Launches Bug Bounty Program for Wi-Fi Device Maker eero
Products and Releases  |  8/23/2017  | 
eeros bug bounty program will allow researchers to submit bugs in a visible, predictable and scalable system.
Nigerian Man Sentenced to Prison for Hacking and Fraud Scheme
Products and Releases  |  8/18/2017  | 
Operated Business Email Compromise Scam from Nigeria
Rackspace Deploys RiskIQ PassiveTotal
Products and Releases  |  8/17/2017  | 
Sqrrls Latest Software Release Adds Self-Service Analytics for Threat Hunters
Products and Releases  |  8/17/2017  | 
Version 2.8 of Sqrrls Threat Hunting Platform Streamlines Creation of Risk-Focused Threat Hunting Analytics
Wells Fargo Brings CEO Mobile Token to Business Customers
Products and Releases  |  8/17/2017  | 
New feature enhances banking user experience anytime, anywhere
ISACA Releases New CISM and CRISC Online Review Courses
Products and Releases  |  8/16/2017  | 
Exploit Leaks Led to Over Five Million Attacks in Q2 2017
Products and Releases  |  8/16/2017  | 
Exploit packages in-the-wild became the game changer of the cyber threat landscape in Q2 2017.
IBM Offers Women Scholarships to Hacker Halted Security Conference
Products and Releases  |  8/16/2017  | 
IBM will cover 100% of the entry fees for women to attend EC-Councils largest annual cyber security conference Hacker Halted.
Alert Logic Releases 2017 Cloud Security Report
Products and Releases  |  8/15/2017  | 
On-Premises Workloads Experience 51% Higher Rate of Security Incidents than Applications Running on Public Cloud Platforms
Darktrace Releases Version 3 of its AI Cyber Defense Solution
Products and Releases  |  8/9/2017  | 
Productivity boost for novice and expert analysts, and executives.
Hackers: Privileged Accounts Provide Fastest Access to Sensitive, Critical Data
Products and Releases  |  8/9/2017  | 
Nearly 75 percent state traditional perimeter security firewalls and antivirus are now irrelevant or obsolete.
Security Summit Alert: Tax Pros Warned of New Scam to Steal Their Passwords
Products and Releases  |  8/4/2017  | 
A new phishing email scam impersonates tax software providers, seeking to steal usernames and passwords.
Perimeterx Raises $23 million to Expand AI Behavioral Threat Platform
Products and Releases  |  8/4/2017  | 
The funding will be used to further improve its bot detection technology and expand into automated attack prevention.
Dash Employs Bugcrowd to Hack Its Blockchain
Products and Releases  |  8/4/2017  | 
Bugcrowds professional white-hat hackers and cyber security experts join forces to detect Dash vulnerabilities.
Nyotron Raises $21 Million Funding Round
Products and Releases  |  8/4/2017  | 
Appoints Former McAfee Executive Peter Stewart to Chief Executive Officer
Oracle, SafeLogic and OpenSSL Partner on Next Generation FIPS Module
Products and Releases  |  8/3/2017  | 
Oracle dedicates seed funding towards developing FIPS module for OpenSSL 1.1 and calls on corporate sponsors in the FOSS ecosystem to join the effort
GuardiCore Extends Series B Funding Round to $35 Million
Products and Releases  |  8/3/2017  | 
Funding to accelerate growth in large enterprise accounts and expand further into global markets San Francisco and Israel
HITRUST, Trend Micro Partner to Tackle Cyber Threat Management
Products and Releases  |  8/3/2017  | 
The partnership aims to drive cyber threat research and education to improve organizational cyber threat management.
CrowdStrike Launches Cybersecurity Search Engine
Products and Releases  |  8/3/2017  | 
New CrowdStrike Falcon Search Engine empowers next-gen Security Operation Centers to search in real-time on the worlds fastest and most comprehensive security platform.
Digital Guardian Launches Cloud-Based Data Loss Prevention Service
Products and Releases  |  8/3/2017  | 
Digital Guardian Analytics & Reporting Cloud is released, with aim to deliver data protection as a subscription-based cloud service
Accenture Security Report Identifies Top Cyber Threats of 2017
Products and Releases  |  8/3/2017  | 
Destructive ransomware, alternative crypto-currencies and increased use of deception tactics among threats driving even more lucrative criminal marketplace.


News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3493
PUBLISHED: 2021-04-17
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu kernel to allow unprivile...
CVE-2021-3492
PUBLISHED: 2021-04-17
Shiftfs, an out-of-tree stacking file system included in Ubuntu Linux kernels, did not properly handle faults occurring during copy_from_user() correctly. These could lead to either a double-free situation or memory not being freed at all. An attacker could use this to cause a denial of service (ker...
CVE-2020-2509
PUBLISHED: 2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later Q...
CVE-2020-36195
PUBLISHED: 2021-04-17
An SQL injection vulnerability has been reported to affect QNAP NAS running Multimedia Console or the Media Streaming add-on. If exploited, the vulnerability allows remote attackers to obtain application information. QNAP has already fixed this vulnerability in the following versions of Multimedia C...
CVE-2021-29445
PUBLISHED: 2021-04-16
jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDe...