Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Author

 Stephen Cox
LinkedIn
RSS
E-Mail

Profile of Stephen Cox

VP & CSA, SecureAuth
Member Since: 4/1/2019
Author
News & Commentary Posts: 2
Comments: 1

Stephen Cox is a technology veteran with nearly 20 years in the IT industry, including 10 years of experience leading software development teams in the security industry. A key player in some of the most influential IT security firms in the world, he is recognized as an expert in identity, network and endpoint threat detection, as well as an accomplished software architect. As vice president and chief security architect at SecureAuth, Stephen is helping to establish identity as the third pillar of security and the mission to eliminate identity-related breaches. Previously, Stephen served as technical lead of the endpoint and FireEye-as-a-Service development teams at FireEye/Mandiant. These teams specialized in forensics and endpoint event monitoring as part of the FireEye HX platform. Before Mandiant, Stephen was at RSA NetWitness, working as principal developer of NetWitness Spectrum. He served a number of years at VeriSign in support of the DNS Resolution Operations team, and also in various software development roles at Northrop Grumman and America Online.
 
Stephen holds a Master of Science in Software Engineering and a Bachelor of Science in Integrative Studies, both from George Mason University.

Articles by Stephen Cox
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Look Beyond the 'Big 5' in Cyberattacks
Robert Lemos, Contributing Writer,  11/25/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: I think the boss is bing watching '70s TV shows again!
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-16958
PUBLISHED: 2020-12-01
Cross-site Scripting (XSS) vulnerability in SolarWinds Web Help Desk 12.7.0 allows attacker to inject arbitrary web script or HTML via Location Name.
CVE-2020-8539
PUBLISHED: 2020-12-01
Kia Motors Head Unit with Software version: SOP.003.30.18.0703, SOP.005.7.181019, and SOP.007.1.191209 may allow an attacker to inject unauthorized commands, by executing the micomd executable deamon, to trigger unintended functionalities. In addition, this executable may be used by an attacker to i...
CVE-2020-11990
PUBLISHED: 2020-12-01
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with the app externally.
CVE-2020-29315
PUBLISHED: 2020-12-01
ThinkAdmin version v1 v6 has a stored XSS vulnerability which allows remote attackers to inject an arbitrary web script or HTML.
CVE-2020-28971
PUBLISHED: 2020-12-01
An issue was discovered on Western Digital My Cloud OS 5 devices before 5.06.115. A NAS Admin authentication bypass vulnerability could allow an unauthenticated user to execute privileged commands on the device via a cookie, because of insufficient validation of URI paths.