Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Author

 Sundeep Nehra & Dr. Mary Kay Vona
RSS
E-Mail

Profile of Sundeep Nehra & Dr. Mary Kay Vona

Financial Services Organization, Ernst & Young LLP
Member Since: 7/16/2019
Author
News & Commentary Posts: 1
Comments: 0

Sundeep Nehra, Principal, Cybersecurity leader,  Financial Services Office, Ernst & Young LLP

As a Principal in the Financial Services Office, Sundeep leads the Integrated Cyber and Resiliency Risk practice. He advises clients on issues related to cyber, technology and resiliency, as well as regulatory risk-related matters. Sundeep's professional skill sets involve enterprise risk management, core banking implementations, property and casualty insurance implementations, and large system design and development. Having more than 27 years of management consulting experience, Sundeep's primary focus is in financial services. His international experience includes leading global teams in US, India, Australia, Africa and Europe.

 

 

Mary Kay Vona, Principal,  People Advisory Services leader,  Financial Services Office,  Ernst & Young LLP

 

Dr. Mary Kay Vona is a nationally known financial services leader in EY's People Advisory Services. Her 35 years in consulting Fortune 500 companies makes her an asset to financial services firms in the areas of talent strategy, change management and business transformation.  Dr. Vona has held leadership roles in Human Capital Management at PwC and IBM, where she led the firm's communication sector.  At IBM, she also was Global Learning Partner, driving learning solutions, client relationships, staff development and thought leadership around the globe.

 

Articles by Sundeep Nehra & Dr. Mary Kay Vona
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-22521
PUBLISHED: 2021-07-30
A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges.
CVE-2021-34629
PUBLISHED: 2021-07-30
The SendGrid WordPress plugin is vulnerable to authorization bypass via the get_ajax_statistics function found in the ~/lib/class-sendgrid-statistics.php file which allows authenticated users to export statistic for a WordPress multi-site main site, in versions up to and including 1.11.8.
CVE-2021-34630
PUBLISHED: 2021-07-30
In the Pro and Enterprise versions of GTranslate < 2.8.65, the gtranslate_request_uri_var function runs at the top of all pages and echoes out the contents of $_SERVER['REQUEST_URI']. Although this uses addslashes, and most modern browsers automatically URLencode requests, this plugin is still vu...
CVE-2021-3636
PUBLISHED: 2021-07-30
It was found in OpenShift, before version 4.8, that the generated certificate for the in-cluster Service CA, incorrectly included additional certificates. The Service CA is automatically mounted into all pods, allowing them to safely connect to trusted in-cluster services that present certificates s...
CVE-2021-29297
PUBLISHED: 2021-07-30
Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".