Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

11 Security Certifications to Seek Out This Summer
Ukraine Police Disrupt Cl0p Ransomware Operation
Attackers Find New Way to Exploit Google Docs for Phishing
4 Habits of Highly Effective Security Operators
News & Commentary
79% of Third-Party Libraries in Apps Are Never Updated
Jai Vijayan, Contributing WriterNews
A lack of contextual information and concerns over application disruption among contributing factors.
By Jai Vijayan Contributing Writer, 6/23/2021
Comment0 comments  |  Read  |  Post a Comment
VMs Help Ransomware Attackers Evade Detection, But It's Uncommon
Kelly Sheridan, Staff Editor, Dark ReadingNews
Some ransomware attackers use virtual machines to bypass security detection, but adoption is slow for the complicated technique.
By Kelly Sheridan Staff Editor, Dark Reading, 6/23/2021
Comment0 comments  |  Read  |  Post a Comment
Microsoft Tracks New BazaCall Malware Campaign
Dark Reading Staff, Quick Hits
Attackers use emails to prompt victims to call a fraudulent call center, where attackers instruct them to download a malicious file.
By Dark Reading Staff , 6/23/2021
Comment0 comments  |  Read  |  Post a Comment
New DNS Name Server Hijack Attack Exposes Businesses, Government Agencies
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Researchers found a "novel" class of DNS vulnerabilities in AWS Route53 and other DNS-as-a-service offerings that leak sensitive information on corporate and government customers, with one simple registration step.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 6/23/2021
Comment0 comments  |  Read  |  Post a Comment
Survey Seeks to Learn How 2020 Changed Security
Dark Reading Staff, Quick Hits
Respondents to a new Dark Reading/Omdia survey will be entered into a drawing for a Black Hat Black Card.
By Dark Reading Staff , 6/23/2021
Comment0 comments  |  Read  |  Post a Comment
When Will Cybersecurity Operations Adopt the Peter Parker Principle?
Robert Boudreaux, Field CTO, Deep InstinctCommentary
Having a prevention mindset means setting our prevention capabilities to "prevent" instead of relying on detection and response.
By Robert Boudreaux Field CTO, Deep Instinct, 6/23/2021
Comment0 comments  |  Read  |  Post a Comment
Expecting the Unexpected: Tips for Effectively Mitigating Ransomware Attacks in 2021
Luke Tenery & Ross Rustici, Partner, StoneTurn / Managing Director, StoneTurnCommentary
Cybercriminals continually innovate to thwart security protocols, but organizations can take steps to prevent and mitigate ransomware attacks.
By Luke Tenery & Ross Rustici Partner, StoneTurn / Managing Director, StoneTurn, 6/23/2021
Comment0 comments  |  Read  |  Post a Comment
Despite Heightened Cyber-Risks, Few Security Leaders Report to CEO
Jai Vijayan, Contributing WriterNews
A new report suggests that top management at most companies still don't get security.
By Jai Vijayan Contributing Writer, 6/22/2021
Comment0 comments  |  Read  |  Post a Comment
Transmit Security Announces $543M Series A Funding Round
Dark Reading Staff, Quick Hits
The passwordless technology provider says the funding will be used to increase its reach and expand primary business functions.
By Dark Reading Staff , 6/22/2021
Comment0 comments  |  Read  |  Post a Comment
NSA Funds Development & Release of D3FEND Framework
Dark Reading Staff, Quick Hits
The framework, now available through MITRE, provides countermeasures to attacks.
By Dark Reading Staff , 6/22/2021
Comment0 comments  |  Read  |  Post a Comment
Identity Eclipses Malware Detection at RSAC Startup Competition
Paul Shomo, Cybersecurity AnalystCommentary
All 10 finalists in the Innovation Sandbox were focused on identity, rather than security's mainstay for the last 20 years: Malware detection.
By Paul Shomo Cybersecurity Analyst, 6/22/2021
Comment0 comments  |  Read  |  Post a Comment
Majority of Web Apps in 11 Industries Are Vulnerable All the Time
Robert Lemos, Contributing WriterNews
Serious vulnerabilities exist every day in certain industries, including utilities, public administration, and professional services, according to testing data.
By Robert Lemos Contributing Writer, 6/22/2021
Comment0 comments  |  Read  |  Post a Comment
7 Powerful Cybersecurity Skills the Energy Sector Needs Most
Pam Baker, Contributing Writer
Those looking to join the fight might want to polish up or acquire some (or all) of these hottest skills on the market.
By Pam Baker Contributing Writer, 6/22/2021
Comment0 comments  |  Read  |  Post a Comment
Does Your Cyberattack Plan Include a Crisis Communications Strategy? 5 Tips to Get Started
Ted Birkhahn, President, HPL CyberCommentary
Don't overlook crisis communications in your cybersecurity incident response planning.
By Ted Birkhahn President, HPL Cyber, 6/22/2021
Comment0 comments  |  Read  |  Post a Comment
Did Companies Fail to Disclose Being Affected by SolarWinds Breach?
Jai Vijayan, Contributing WriterNews
The SEC has sent out letters to some investment firms and publicly listed companies seeking information, Reuters says.
By Jai Vijayan Contributing Writer, 6/21/2021
Comment1 Comment  |  Read  |  Post a Comment
Software-Container Supply Chain Sees Spike in Attacks
Robert Lemos, Contributing WriterNews
Attackers target companies' container supply chain, driving a sixfold increase in a year, aiming to steal processing time for cryptomining and compromise cloud infrastructure.
By Robert Lemos Contributing Writer, 6/21/2021
Comment0 comments  |  Read  |  Post a Comment
Data Leaked in Fertility Clinic Ransomware Attack
Dark Reading Staff, Quick Hits
Reproductive Biology Associates says the data of 38,000 patients may have been compromised in the April cyberattack.
By Dark Reading Staff , 6/21/2021
Comment0 comments  |  Read  |  Post a Comment
Baltimore County Public Schools' Ransomware Recovery Tops $8M
Dark Reading Staff, Quick Hits
The school district has spent seven months and a reported $8.1 million recovering from the November attack.
By Dark Reading Staff , 6/21/2021
Comment0 comments  |  Read  |  Post a Comment
Are Ransomware Attacks the New Pandemic?
Bill Harrod, Federal CTO, IvantiCommentary
Ransomware has been a problem for decades, so why is government just now beginning to address it?
By Bill Harrod Federal CTO, Ivanti, 6/21/2021
Comment0 comments  |  Read  |  Post a Comment
Attackers Find New Way to Exploit Google Docs for Phishing
Jai Vijayan, Contributing WriterNews
Tactic continues recent trend by attackers to use trusted cloud services to send and host malicious content.
By Jai Vijayan Contributing Writer, 6/18/2021
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
Dark Reading Is Getting an Upgrade!

Find out more about our plans to improve the look, functionality, and performance of the Dark Reading site in the coming months.

Those looking to join the fight might want to polish up or acquire some (or all) of these hottest skills on the market.
The more you know, the more you grow. The Edge takes a fresh look at leading security certifications that can help advance your career.
Register for Dark Reading Newsletters
Cartoon
White Papers
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-25655
PUBLISHED: 2021-06-24
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
CVE-2021-25656
PUBLISHED: 2021-06-24
Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive information. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).
CVE-2021-25649
PUBLISHED: 2021-06-24
** UNSUPPORTED WHEN ASSIGNED ** An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be availab...
CVE-2021-25650
PUBLISHED: 2021-06-24
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility Services.
CVE-2021-25651
PUBLISHED: 2021-06-24
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services.
Flash Poll
Video
Slideshows
Twitter Feed