Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

News & Commentary
How Capture the Flag Competitions Strengthen the Cybersecurity Workforce
Dr. Giovanni Vigna, Chief Technology Officer at LastlineCommentary
These competitions challenge participants with problems involving digital forensics, cryptography, binary analysis, web security, and many other fields.
By Dr. Giovanni Vigna Chief Technology Officer at Lastline, 7/18/2019
Comment1 Comment  |  Read  |  Post a Comment
Is 2019 the Year of the CISO?
Terry Ray, Chief Technology Officer, ImpervaCommentary
The case for bringing the CISO to the C-suite's risk and business-strategy table.
By Terry Ray Chief Technology Officer, Imperva, 7/16/2019
Comment0 comments  |  Read  |  Post a Comment
Most Organizations Lack Cyber Resilience
Marc Wilczek, Digital Strategist & CIO AdvisorCommentary
Despite increasing threats, many organizations continue to run with only token cybersecurity and resilience.
By Marc Wilczek Digital Strategist & CIO Advisor, 7/11/2019
Comment0 comments  |  Read  |  Post a Comment
Summer: A Time for Vacations & Cyberattacks?
Robert Lemos, Contributing WriterNews
About a third of cybersecurity professionals believe that their companies see more cyberattacks during the summer, but the survey data does not convince on the reasons for the perception of a summer bump.
By Robert Lemos Contributing Writer, 7/11/2019
Comment1 Comment  |  Read  |  Post a Comment
4 Reasons Why SOC Superstars Quit
Edy Almer, VP Product, CyberbitCommentary
Security analysts know they are a hot commodity in the enviable position of writing their own ticket. Here's how to keep them engaged, challenged, and happy.
By Edy Almer VP Product, Cyberbit, 7/10/2019
Comment3 comments  |  Read  |  Post a Comment
DevOps' Inevitable Disruption of Security Strategy
Ericka Chickowski, Contributing WriterNews
Black Hat USA programming will dive into the ways DevOps-driven shifts in practices and tools are introducing both new vulnerabilities and new ways of securing enterprises.
By Ericka Chickowski Contributing Writer, 7/9/2019
Comment0 comments  |  Read  |  Post a Comment
Disarming Employee Weaponization
Ilan Abadi, VP and Global CISO, Teva Pharmaceutical IndustriesCommentary
Human vulnerability presents a real threat for organizations. But it's also a remarkable opportunity to turn employees into our strongest cyber warriors.
By Ilan Abadi VP and Global CISO, Teva Pharmaceutical Industries, 7/3/2019
Comment1 Comment  |  Read  |  Post a Comment
Building the Future Through Security Internships
Kathryn Kun, Director of Adversarial ResilienceCommentary
Akamai University, a 12-week internship program, was built from the ground up with the goal of promoting the student not the company.
By Kathryn Kun Director of Adversarial Resilience, 7/1/2019
Comment1 Comment  |  Read  |  Post a Comment
More Supply, More Demand: Cybersecurity Skills Gap Remains
Robert Lemos, Contributing WriterNews
Although the number of programs for training workers in cybersecurity skills has increased, as well as the number of graduates, the gap in supply and demand for cybersecurity-skilled workers is essentially unchanged, leaving companies to struggle.
By Robert Lemos Contributing Writer, 6/27/2019
Comment1 Comment  |  Read  |  Post a Comment
Could Foster Kids Help Solve the Security Skills Shortage?
Neal O'Farrell, Founder, Foster WarriorsCommentary
Foster Warriors is a new nonprofit initiative focused on helping foster kids find a place in the world, and especially in the world of security. Join us!
By Neal O'Farrell Founder, Foster Warriors, 6/26/2019
Comment1 Comment  |  Read  |  Post a Comment
Florida Town Pays $600K to Ransomware Operators
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
Riviera Beach's decision to pay ransom to criminals might get files back, but it almost guarantees greater attacks against other governments.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 6/20/2019
Comment5 comments  |  Read  |  Post a Comment
'Democratizing' Machine Learning for Fraud Prevention & Payments Intelligence
Cleber Martins, Head of Payments Intelligence, ACI WorldwideCommentary
How fraud experts can fight cybercrime by 'downloading' their knowledge and experience into computer models.
By Cleber Martins Head of Payments Intelligence, ACI Worldwide, 6/20/2019
Comment0 comments  |  Read  |  Post a Comment
Cybersecurity Accountability Spread Thin in the C-Suite
Ericka Chickowski, Contributing WriterNews
While cybersecurity discussions have permeated board meetings, the democratization of accountability has a long way to go.
By Ericka Chickowski Contributing Writer, 6/20/2019
Comment0 comments  |  Read  |  Post a Comment
How Hackers Emptied Church Coffers with a Simple Phishing Scam
Sam Bocetta, Security AnalystCommentary
Cyber thieves aren't bound by a code of ethics. They look for weak targets and high rewards, which is exactly what Saint Ambrose Catholic offered.
By Sam Bocetta Security Analyst, 6/19/2019
Comment0 comments  |  Read  |  Post a Comment
The Evolution of Identity
Kathleen Peters, SVP & Head of Fraud & Identity, ExperianCommentary
How data and technology can help businesses make the right fraud decisions, protect people's identities, and create an improved customer experience.
By Kathleen Peters SVP & Head of Fraud & Identity, Experian, 6/18/2019
Comment0 comments  |  Read  |  Post a Comment
Sensory Overload: Filtering Out Cybersecurity's Noise
Joshua Goldfarb, Independent ConsultantCommentary
No organization can prioritize and mitigate hundreds of risks effectively. The secret lies in carefully filtering out the risks, policies, and processes that waste precious time and resources.
By Joshua Goldfarb Independent Consultant, 6/14/2019
Comment1 Comment  |  Read  |  Post a Comment
New Funding Values KnowBe4 at $1 Billion
Dark Reading Staff, Quick Hits
The $300 million investment is being led by KKR.
By Dark Reading Staff , 6/12/2019
Comment0 comments  |  Read  |  Post a Comment
Tomorrow's Cybersecurity Analyst Is Not Who You Think
Chris Schueler, Senior VP, Managed Security Services, TrustwaveCommentary
Organizations can't just rely on diverse and cutting-edge technologies to fight adversaries. They will also need people with diverse expertise and backgrounds.
By Chris Schueler Senior VP, Managed Security Services, Trustwave, 6/12/2019
Comment1 Comment  |  Read  |  Post a Comment
What 3 Powerful GoT Women Teach Us about Cybersecurity
Orion Cassetto, Senior Product Maester, ExabeamCommentary
Imagine Game of Thrones' Daenerys Targaryen, Arya Stark, and Cersei Lannister on the front lines in the real-world battleground of enterprise security.
By Orion Cassetto Senior Product Maester, Exabeam, 6/11/2019
Comment0 comments  |  Read  |  Post a Comment
Unmixed Messages: Bringing Security & Privacy Awareness Together
Tom Pendergast & Jeff Morgenroth, Chief Learning Officer at MediaPRO/Instructional Designer at MediaPROCommentary
Security and privacy share the same basic goals, so it just makes sense to combine efforts in those two areas. But that can be easier said than done.
By Tom Pendergast & Jeff Morgenroth Chief Learning Officer at MediaPRO/Instructional Designer at MediaPRO, 6/10/2019
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
US Mayors Commit to Just Saying No to Ransomware
Robert Lemos, Contributing Writer,  7/16/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-17210
PUBLISHED: 2019-07-20
An issue was discovered in PrinterOn Central Print Services (CPS) through 4.1.4. The core components that create and launch a print job do not perform complete verification of the session cookie that is supplied to them. As a result, an attacker with guest/pseudo-guest level permissions can bypass t...
CVE-2019-12934
PUBLISHED: 2019-07-20
An issue was discovered in the wp-code-highlightjs plugin through 0.6.2 for WordPress. wp-admin/options-general.php?page=wp-code-highlight-js allows CSRF, as demonstrated by an XSS payload in the hljs_additional_css parameter.
CVE-2019-9229
PUBLISHED: 2019-07-20
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can...
CVE-2019-12815
PUBLISHED: 2019-07-19
An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and information disclosure without authentication, a related issue to CVE-2015-3306.
CVE-2019-13569
PUBLISHED: 2019-07-19
A SQL injection vulnerability exists in the Icegram Email Subscribers & Newsletters plugin through 4.1.7 for WordPress. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.