Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

7 Signs of the Rising Threat of Magecart Attacks in 2019
Effective Pen Tests Follow These 7 Steps
Demystifying the Dark Web: What You Need to Know
How Enterprises Are Developing Secure Applications
Name That Toon: End User Lockdown
News & Commentary
Consumer IoT Devices Are Compromising Enterprise Networks
Ericka Chickowski, Contributing WriterNews
While IoT devices continue to multiply, the latest studies show a dangerous lack of visibility into those connected to enterprise networks.
By Ericka Chickowski Contributing Writer, 5/22/2019
Comment0 comments  |  Read  |  Post a Comment
What You Need to Know About Zero Trust Security
Curtis Franklin Jr., Senior Editor at Dark Reading
The zero trust model might be the answer to a world in which perimeters are made to be breached. Is it right for your organization?
By Curtis Franklin Jr. Senior Editor at Dark Reading, 5/22/2019
Comment0 comments  |  Read  |  Post a Comment
Satan Ransomware Adds More Evil Tricks
Robert Lemos, Contributing WriterNews
The latest changes to the Satan ransomware framework demonstrate attackers are changing their operations while targeting victims more carefully.
By Robert Lemos Contributing Writer, 5/21/2019
Comment1 Comment  |  Read  |  Post a Comment
49 Million Instagram Influencer Records Exposed in Open Database
Dark Reading Staff, Quick Hits
An AWS-hosted database was configured with no username or password required for access to personal data.
By Dark Reading Staff , 5/21/2019
Comment0 comments  |  Read  |  Post a Comment
To Narrow the Cyber Skills Gap with Attackers, Cut the Red Tape
James Hadley, CEO at Immersive LabsCommentary
Attackers are getting further ahead, and entrenched corporate rules shoulder much of the blame.
By James Hadley CEO at Immersive Labs, 5/21/2019
Comment2 comments  |  Read  |  Post a Comment
KnowBe4 Focuses on Security Culture with CLTRe Acquisition
Dark Reading Staff, Quick Hits
The acquisition solidifies KnowBe4's European presence and shows a focus on building and measuring security culture.
By Dark Reading Staff , 5/21/2019
Comment0 comments  |  Read  |  Post a Comment
Old Threats Are New Again
Liron Barak, CEO of BitDamCommentary
They may look familiar to you, and that isn't a coincidence. New threats are often just small twists on old ones.
By Liron Barak CEO of BitDam, 5/21/2019
Comment0 comments  |  Read  |  Post a Comment
Data Security: Think Beyond the Endpoint
Kelly Sheridan, Staff Editor, Dark ReadingNews
A strong data protection strategy is essential as data moves across endpoints and in the cloud.
By Kelly Sheridan Staff Editor, Dark Reading, 5/21/2019
Comment0 comments  |  Read  |  Post a Comment
TeamViewer Admits Breach from 2016
Dark Reading Staff, Quick Hits
The company says it stopped the attack launched by a Chinese hacking group.
By Dark Reading Staff , 5/20/2019
Comment3 comments  |  Read  |  Post a Comment
DHS Warns of Data Theft via Chinese-Made Drones
Dark Reading Staff, Quick Hits
The drones are reportedly built with parts that can compromise organizations' data and share it on a server accessible to the Chinese government.
By Dark Reading Staff , 5/20/2019
Comment0 comments  |  Read  |  Post a Comment
New Trickbot Variant Uses URL Redirection to Spread
Jai Vijayan, Contributing WriterNews
Switch in tactic is the latest attempt by operators of the prolific banking Trojan to slip past detection mechanisms.
By Jai Vijayan Contributing Writer, 5/20/2019
Comment0 comments  |  Read  |  Post a Comment
97% of Americans Cant Ace a Basic Security Test
Steve Zurier, Contributing WriterNews
Still, a new Google study uncovers a bit of good news, too.
By Steve Zurier Contributing Writer, 5/20/2019
Comment5 comments  |  Read  |  Post a Comment
Financial Sector Under Siege
Marc Wilczek, Digital Strategist & CIO AdvisorCommentary
The old take-the-money-and-run approach has been replaced by siege tactics such as DDOS attacks and land-and-expand campaigns with multiple points of persistence and increased dwell time.
By Marc Wilczek Digital Strategist & CIO Advisor, 5/20/2019
Comment0 comments  |  Read  |  Post a Comment
Killer SecOps Skills: Soft Is the New Hard
Edy Almer, VP Product, CyberbitCommentary
The sooner we give mindsets and tool sets equal bearing, the better. We must put SOC team members through rigorous training for emergency situations.
By Edy Almer VP Product, Cyberbit, 5/20/2019
Comment0 comments  |  Read  |  Post a Comment
7 Signs of the Rising Threat of Magecart Attacks in 2019
Ericka Chickowski, Contributing Writer
Magecart attacks continue to grow in momentum. Here are the stats and stories that show what's behind the mayhem.
By Ericka Chickowski Contributing Writer, 5/20/2019
Comment0 comments  |  Read  |  Post a Comment
How a Manufacturing Firm Recovered from a Devastating Ransomware Attack
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
The infamous Ryuk ransomware slammed a small company that makes heavy-duty vehicle alternators for government and emergency fleet. Here's what happened.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 5/20/2019
Comment3 comments  |  Read  |  Post a Comment
Black Hat Q&A: Bruce Schneier Calls For Public-Interest Technologists
Black Hat Staff,  News
Ahead of his 2019 Black Hat USA talk, cybersecurity luminary Bruce Schneier explains why its so important for tech experts to be actively involved in setting public policy.
By Alex Wawro, Special to Dark Reading , 5/20/2019
Comment0 comments  |  Read  |  Post a Comment
Artist Uses Malware in Installation
Dark Reading Staff, Quick Hits
A piece of 'art' currently up for auction features six separate types of malware running on a vulnerable computer.
By Dark Reading Staff , 5/17/2019
Comment1 Comment  |  Read  |  Post a Comment
Q1 2019 Smashes Record For Most Reported Vulnerabilities in a Quarter
Jai Vijayan, Contributing WriterNews
Once again, a high-proportion of the reported flaws have no current fix, according to Risk Based Security.
By Jai Vijayan Contributing Writer, 5/17/2019
Comment0 comments  |  Read  |  Post a Comment
DevOps Repository Firms Establish Shared Analysis Capability
Robert Lemos, Contributing WriterNews
Following an attack on their users, and their shared response, Atlassian, GitHub, and GitLab decide to make the sharing of attack information a permanent facet of their operations.
By Robert Lemos Contributing Writer, 5/17/2019
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
97% of Americans Can't Ace a Basic Security Test
Steve Zurier, Contributing Writer,  5/20/2019
TeamViewer Admits Breach from 2016
Dark Reading Staff 5/20/2019
How a Manufacturing Firm Recovered from a Devastating Ransomware Attack
Kelly Jackson Higgins, Executive Editor at Dark Reading,  5/20/2019
Register for Dark Reading Newsletters
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Could you pass the hash, I really have to use the bathroom!
White Papers
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-9892
PUBLISHED: 2019-05-22
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0.17, and 7.x through 7.0.6. An attacker who is logged into OTRS as an agent user with appropriate permissions may try to import carefully crafted Report Statistics XML that will result in reading of arbit...
CVE-2019-10066
PUBLISHED: 2019-05-22
An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6, Community Edition 6.0.x through 6.0.17, and OTRSAppointmentCalendar 5.0.x through 5.0.12. An attacker who is logged into OTRS as an agent with appropriate permissions may create a carefully crafted calendar appointment i...
CVE-2019-10067
PUBLISHED: 2019-05-22
An issue was discovered in Open Ticket Request System (OTRS) 7.x through 7.0.6 and Community Edition 5.0.x through 5.0.35 and 6.0.x through 6.0.17. An attacker who is logged into OTRS as an agent user with appropriate permissions may manipulate the URL to cause execution of JavaScript in the context...
CVE-2019-6513
PUBLISHED: 2019-05-21
An issue was discovered in WSO2 API Manager 2.6.0. It is possible for a logged-in user to upload, as API documentation, any type of file by changing the extension to an allowed one.
CVE-2019-12270
PUBLISHED: 2019-05-21
OpenText Brava! Enterprise and Brava! Server 7.5 through 16.4 configure excessive permissions by default on Windows. During installation, a displaylistcache file share is created on the Windows server with full read and write permissions for the Everyone group at both the NTFS and Share levels. The ...
Flash Poll
Video
Slideshows
Twitter Feed