Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

News & Commentary
Required MFA Is Not Sufficient for Strong Security: Report
Robert Lemos, Contributing WriterNews
Attackers and red teams find multiple ways to bypass poorly deployed MFA in enterprise environments, underscoring how redundancy and good design are still required.
By Robert Lemos Contributing Writer, 6/9/2021
Comment0 comments  |  Read  |  Post a Comment
New Security Event @Hack to Take Place in Saudi Arabia
Dark Reading Staff, Quick Hits
The Saudi Federation of Cybersecurity, Programming, and Drones (SAFCSP) and Informa Tech will launch a multi-day event in Riyadh this November.
By Dark Reading Staff , 6/9/2021
Comment0 comments  |  Read  |  Post a Comment
With Cloud, CDO and CISO Concerns Are Equally Important
Ameesh Divatia, Co-Founder & CEO of BaffleCommentary
Navigated properly, a melding of these complementary perspectives can help keep an organization more secure.
By Ameesh Divatia Co-Founder & CEO of Baffle, 6/9/2021
Comment0 comments  |  Read  |  Post a Comment
Colonial Pipeline CEO: Ransomware Attack Started via Pilfered 'Legacy' VPN Account
Dark Reading Staff, Quick Hits
No multifactor authentication was attached to the stolen VPN password used by the attackers, Colonial Pipeline president & CEO Joseph Blount told a Senate committee today.
By Dark Reading Staff , 6/8/2021
Comment0 comments  |  Read  |  Post a Comment
First Known Malware Surfaces Targeting Windows Containers
Jai Vijayan, Contributing WriterNews
Siloscape is designed to create a backdoor in Kubernetes clusters to run malicious containers.
By Jai Vijayan Contributing Writer, 6/7/2021
Comment0 comments  |  Read  |  Post a Comment
CISA Warns Criminals Seek to Exploit Critical VMware Bug
Dark Reading Staff, Quick Hits
Organizations running vCenter Server and VMware Cloud Foundation are urged to apply fixes deployed on May 25.
By Dark Reading Staff , 6/7/2021
Comment0 comments  |  Read  |  Post a Comment
Cartoon Caption Winner: Road Trip
John Klossner, CartoonistCommentary
And the winner of Dark Reading's cartoon caption contest is ...
By John Klossner Cartoonist, 6/7/2021
Comment0 comments  |  Read  |  Post a Comment
Organizations Shift Further Left in App Development
Dark Reading Staff, Quick Hits
Most IT and security professionals surveyed think security is a critical enough reason to pause app development.
By Dark Reading Staff , 6/4/2021
Comment0 comments  |  Read  |  Post a Comment
What the FedEx Logo Taught Me About Cybersecurity
Matt Shea, Head of Federal @ MixModeCommentary
Cyber threats are staring you in the face, but you can't see them.
By Matt Shea Head of Federal @ MixMode, 6/4/2021
Comment1 Comment  |  Read  |  Post a Comment
FireEye Sells Products Business to Symphony Group for $1.2B
Dark Reading Staff, Quick Hits
The transaction will include the FireEye brand name; the business that remains will be called Mandiant Solutions.
By Dark Reading Staff , 6/2/2021
Comment0 comments  |  Read  |  Post a Comment
Return to Basics: Email Security in the Post-COVID Workplace
Eyal Benishti, CEO & Founder of IRONSCALESCommentary
As we reimagine the post-pandemic workplace, we must also reevaluate post-pandemic email security practices.
By Eyal Benishti CEO & Founder of IRONSCALES, 6/1/2021
Comment0 comments  |  Read  |  Post a Comment
3 SASE Misconceptions to Consider
Jay Barbour, Masergy Director of Security Product ManagementCommentary
SASE is all the rage, promising things IT leaders have long dreamed about, but a purist approach may create consequences.
By Jay Barbour Masergy Director of Security Product Management, 5/31/2021
Comment0 comments  |  Read  |  Post a Comment
Acronis: Pandemic Hastened Cloud Migration, Prompting New Security Issues
Terry Sweeney, Contributing EditorCommentary
SPONSORED: WATCH NOW -- The COVID-19 pandemic has accelerated an ongoing shift in data away from business data centers to home offices and the cloud, explains Candid Wust, VP of cyber protection research for Acronis.
By Terry Sweeney Contributing Editor, 5/27/2021
Comment0 comments  |  Read  |  Post a Comment
How Menlo Uses Isolation to Secure Mobile Devices in the Cloud
Terry Sweeney, Contributing EditorCommentary
SPONSORED: WATCH NOW -- Mobile devices like smartphones and tablets have emerged as popular targets for bad actors looking to break into to cloud-based networks, according to Poornima DeBolle, chief product officer for Menlo Security.
By Terry Sweeney Contributing Editor, 5/27/2021
Comment0 comments  |  Read  |  Post a Comment
Zscaler Buys Deception Technology Startup
Dark Reading Staff, Quick Hits
ZScaler's CEO says Smokescreen Technologies' capabilities will be integrated with Zscalers ZIA and ZPA products.
By Dark Reading Staff , 5/26/2021
Comment0 comments  |  Read  |  Post a Comment
Cloud Compromise Costs Organizations $6.2M Per Year
Kelly Sheridan, Staff Editor, Dark ReadingNews
Organizations reported an average of 19 cloud-based compromises in the past year, but most don't evaluate the security of SaaS apps before deployment.
By Kelly Sheridan Staff Editor, Dark Reading, 5/25/2021
Comment0 comments  |  Read  |  Post a Comment
Businesses Boost Security Budgets. Where Will the Money Go?
Kelly Sheridan, Staff Editor, Dark ReadingNews
Most organizations plan to spend more on security, leaders say in a report that explores their toughest challenges, post-breach costs, and spending priorities.
By Kelly Sheridan Staff Editor, Dark Reading, 5/25/2021
Comment0 comments  |  Read  |  Post a Comment
As Threat Hunting Matures, Malware Labs Emerge
Tomislav Pericin, Chief Software Architect & Co-Founder, ReversingLabsCommentary
By leveraging their analysis outputs, security pros can update detection rules engines and establish a stronger security posture in the process.
By Tomislav Pericin Chief Software Architect & Co-Founder, ReversingLabs, 5/24/2021
Comment0 comments  |  Read  |  Post a Comment
Maricopa County CISO: Online Misinformation/Disinformation in 2020 Election a 'Gamechanger'
Kelly Jackson Higgins, Executive Editor at Dark ReadingQuick Hits
Custom playbooks played a key role in the Arizona election jurisdiction's security strategy.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 5/20/2021
Comment0 comments  |  Read  |  Post a Comment
100M Users' Data Exposed via Third-Party Cloud Misconfigurations
Dark Reading Staff, Quick Hits
Researchers who examined 23 Android apps report developers potentially exposed the data of more than 100 million people.
By Dark Reading Staff , 5/20/2021
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
Posted by vderrill
Current Conversations Zoom Zoom!
In reply to: sorry about this
Post Your Own Reply
More Conversations
PR Newswire
Commentary
What the FedEx Logo Taught Me About Cybersecurity
Matt Shea, Head of Federal @ MixMode,  6/4/2021
Edge-DRsplash-10-edge-articles
A View From Inside a Deception
Sara Peters, Senior Editor at Dark Reading,  6/2/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23394
PUBLISHED: 2021-06-13
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
CVE-2021-34682
PUBLISHED: 2021-06-12
Receita Federal IRPF 2021 1.7 allows a man-in-the-middle attack against the update feature.
CVE-2021-31811
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-31812
PUBLISHED: 2021-06-12
In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
CVE-2021-32552
PUBLISHED: 2021-06-12
It was discovered that read_file() in apport/hookutils.py would follow symbolic links or open FIFOs. When this function is used by the openjdk-16 package apport hooks, it could expose private data to other local users.