Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Planning Our Passwordless Future
Colonial Pipeline Cyberattack: What Security Pros Need to Know
Troy Hunt: Organizations Make Security Choices Tough for Users
7 Modern-Day Cybersecurity Realities
News & Commentary
Rapid7 Source Code Accessed in Supply Chain Attack
Dark Reading Staff, Quick Hits
An investigation of the Codecov attack revealed intruders accessed Rapid7 source code repositories containing internal credentials and alert-related data.
By Dark Reading Staff , 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
How Faster COVID-19 Research Is Being Made Possible by Secure Silicon
Sara Peters, Senior Editor at Dark Reading
When Intel and Leidos set up a "trusted execution environment" to enable a widespread group of researchers to securely share and confidentially compute real-world data, it was no small achievement.
By Sara Peters Senior Editor at Dark Reading, 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
Cisco Confirms Plans to Acquire Kenna Security
Dark Reading Staff, Quick Hits
Cisco plans to integrate Kenna's vulnerability management technology into its SecureX platform.
By Dark Reading Staff , 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
SOC Teams Burdened by Alert Fatigue Explore XDR
Joan Goodchild, Staff EditorQuick Hits
ESG research finds a complex attack surface and threat landscape make alerts too overwhelming to monitor accurately
By Joan Goodchild Staff Editor, 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
Wi-Fi Design, Implementation Flaws Allow a Range of Frag Attacks
Robert Lemos, Contributing WriterNews
Every Wi-Fi product is affected by at least one fragmentation and aggregation vulnerability, which could lead to a machine-in-the-middle attack, researcher says.
By Robert Lemos Contributing Writer, 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
Security Trends to Follow at RSA Conference 2021
Yonit Wiseman, Associate at YL VenturesCommentary
Here are three key categories of sessions that provide an inside look at some of today's most interesting cybersecurity trends.
By Yonit Wiseman Associate at YL Ventures, 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
Software, Incident Response Among Big Focus Areas in Biden's Cybersecurity Executive Order
Jai Vijayan, Contributing WriterNews
Overall objectives are good, but EO may be too prescriptive in parts, industry experts say.
By Jai Vijayan Contributing Writer, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
85% of Data Breaches Involve Human Interaction: Verizon DBIR
Kelly Sheridan, Staff Editor, Dark ReadingNews
Ransomware, phishing, and Web application attacks all increased during a year in which the majority of attacks involved a human element.
By Kelly Sheridan Staff Editor, Dark Reading, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
Firms Struggle to Secure Multicloud Misconfigurations
Robert Lemos, Contributing WriterNews
Half of companies had at least one case of having all ports open to the public, while more than a third had an exposed database.
By Robert Lemos Contributing Writer, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
Dragos & IronNet Partner on Critical Infrastructure Security
Dark Reading Staff, Quick Hits
The IT and OT security providers will integrate solutions aimed at improving critical infrastructure security
By Dark Reading Staff , 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
When AI Becomes the Hacker
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Bruce Schneier explores the potential dangers of artificial intelligence (AI) systems gone rogue in society.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
Microsoft Adds GPS Location to Identity & Access Control in Azure AD
Dark Reading Staff, Quick Hits
New capabilities let admins restrict access to resources from privileged access workstations or regions based on GPS location.
By Dark Reading Staff , 5/13/2021
Comment1 Comment  |  Read  |  Post a Comment
Adapting to the Security Threat of Climate Change
Lewis Huynh, Chief Security Officer, NinjaRMCommentary
Business continuity plans that address natural and manmade disasters can help turn a cataclysmic business event into a minor slowdown.
By Lewis Huynh Chief Security Officer, NinjaRM, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
Defending the Castle: How World History Can Teach Cybersecurity a Lesson
Rob Gurzeev, CEO and Co-Founder of CyCognitoCommentary
Cybersecurity attackers follow the same principles practiced in warfare for millennia. They show up in unexpected places, seeking out portions of an organization's attack surface that are largely unmonitored and undefended.
By Rob Gurzeev CEO and Co-Founder of CyCognito, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
Verizon DBIR 2021: "Winners" No Surprise, But All-round Vigilance Essential
Maxine Holt, Senior Research Director, Cybersecurity, OmdiaCommentary
Verizon's Data Breach Investigations Report (DBIR) covers 2020 -- a year like no other. Phishing, ransomware, and innovation caused big problems.
By Maxine Holt Senior Research Director, Cybersecurity, Omdia, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
Despite Heightened Breach Fears, Incident Response Capabilities Lag
Jai Vijayan, Contributing WriterNews
Many organizations remain unprepared to detect, respond, and contain a breach, a new survey shows.
By Jai Vijayan Contributing Writer, 5/12/2021
Comment0 comments  |  Read  |  Post a Comment
Researchers Unearth 167 Fake iOS & Android Trading Apps
Dark Reading Staff, Quick Hits
The apps are disguised as financial trading, banking, and cryptocurrency apps from well-known and trusted organizations.
By Dark Reading Staff , 5/12/2021
Comment0 comments  |  Read  |  Post a Comment
Putting the Spotlight on DarkSide
Kelly Sheridan, Staff Editor, Dark ReadingNews
Incident responders share insight on the DarkSide ransomware group connected to the recent Colonial Pipeline ransomware attack.
By Kelly Sheridan Staff Editor, Dark Reading, 5/12/2021
Comment0 comments  |  Read  |  Post a Comment
66% of CISOs Feel Unprepared for Cyberattacks
Dark Reading Staff, Quick Hits
More than half of CISOs surveyed are more concerned about a cyberattack in 2021 than in 2020, researchers report.
By Dark Reading Staff , 5/12/2021
Comment0 comments  |  Read  |  Post a Comment
Vulnerable Protocols Leave Firms Open to Further Compromises
Robert Lemos, Contributing WriterNews
Companies may no longer have Internet-facing file servers or weakly secured Web servers, but attackers that get by the perimeter have a wide-open landscape of vulnerability.
By Robert Lemos Contributing Writer, 5/12/2021
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
Dark Reading Is Getting an Upgrade!

Find out more about our plans to improve the look, functionality, and performance of the Dark Reading site in the coming months.

When Intel and Leidos set up a "trusted execution environment" to enable a widespread group of researchers to securely share and confidentially compute real-world data, it was no small achievement.
Majority of global IT decision makers say cybersecurity is extremely or more important now than it was pre-pandemic, according to Cisco.
In an effort to protect their organizations, security professionals can overdo it. The result often works against them.
Register for Dark Reading Newsletters
Cartoon
White Papers
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-29040
PUBLISHED: 2021-05-16
The JSON web services in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 97, 7.1 before fix pack 20 and 7.2 before fix pack 10 may provide overly verbose error messages, which allows remote attackers to use the contents of error messages to help launch another, more focused att...
CVE-2021-29041
PUBLISHED: 2021-05-16
Denial-of-service (DoS) vulnerability in the Multi-Factor Authentication module in Liferay DXP 7.3 before fix pack 1 allows remote authenticated attackers to prevent any user from authenticating by (1) enabling Time-based One-time password (TOTP) on behalf of the other user or (2) modifying the othe...
CVE-2021-29047
PUBLISHED: 2021-05-16
The SimpleCaptcha implementation in Liferay Portal 7.3.4, 7.3.5 and Liferay DXP 7.3 before fix pack 1 does not invalidate CAPTCHA answers after it is used, which allows remote attackers to repeatedly perform actions protected by a CAPTCHA challenge by reusing the same CAPTCHA answer.
CVE-2021-22668
PUBLISHED: 2021-05-16
Delta Industrial Automation CNCSoft ScreenEditor Versions 1.01.28 (with ScreenEditor Version 1.01.2) and prior are vulnerable to an out-of-bounds read while processing project files, which may allow an attacker to execute arbitrary code.
CVE-2021-29039
PUBLISHED: 2021-05-16
Cross-site scripting (XSS) vulnerability in the Asset module's categories administration page in Liferay Portal 7.3.4 allows remote attackers to inject arbitrary web script or HTML via the site name.
Flash Poll
Video
Slideshows
Twitter Feed