Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Breach Defense Playbook: Cybersecurity Governance
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
Time to leave the island: Integrate cybersecurity into your risk management strategy.
By Ryan Vela Regional Director, Fidelis Cybersecurity, 6/25/2015
Comment1 Comment  |  Read  |  Post a Comment
Breach Defense Playbook: Incident Response Readiness (Part 2)
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
Will your incident response plan work when a real-world situation occurs?
By Ryan Vela Regional Director, Fidelis Cybersecurity, 6/24/2015
Comment0 comments  |  Read  |  Post a Comment
Breach Defense Playbook: Incident Response Readiness (Part 1)
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
Will your incident response plan work when a real-world situation occurs?
By Ryan Vela Regional Director, Fidelis Cybersecurity, 6/23/2015
Comment0 comments  |  Read  |  Post a Comment
Breach Defense Playbook: Open Source Intelligence
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
Do you know what information out there is putting you at risk?
By Ryan Vela Regional Director, Fidelis Cybersecurity, 6/22/2015
Comment0 comments  |  Read  |  Post a Comment
Breach Defense Playbook: Reviewing Your Cybersecurity Program (Part 2)
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
Cybersecurity requires a combination of people, process, and technology in a coordinated implementation leveraging a defense-in-depth methodology.
By Ryan Vela Regional Director, Fidelis Cybersecurity, 6/18/2015
Comment0 comments  |  Read  |  Post a Comment
Breach Defense Playbook: Reviewing Your Cybersecurity Program (Part 1)
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
How does your cybersecurity program compare to your industry peers?
By Ryan Vela Regional Director, Fidelis Cybersecurity, 6/17/2015
Comment0 comments  |  Read  |  Post a Comment
Breach Defense Playbook: Hunting For Breach Indicators
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
Do you proactively hunt for malware on your network, or do you wait for your tools to tell you?
By Ryan Vela Regional Director, Fidelis Cybersecurity, 6/11/2015
Comment0 comments  |  Read  |  Post a Comment
Breach Defense Playbook: Assessing Your Security Controls
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
Do you include physical security as part of your cybersecurity risk management plan?
By Ryan Vela Regional Director, Fidelis Cybersecurity, 6/10/2015
Comment0 comments  |  Read  |  Post a Comment
Breach Defense Playbook: Assessing Your Cybersecurity Engineering
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
Is your cybersecurity infrastructure robust enough to defend against future attacks?
By Ryan Vela Regional Director, Fidelis Cybersecurity, 6/9/2015
Comment0 comments  |  Read  |  Post a Comment
Drinking from the Malware Fire Hose
John Bambenek , Senior Threat Researcher, Fidelis CybersecurityCommentary
Take a staged approach to processing malware in bulk so that scarce and time-limited resources can be prioritized for only those threats that truly require them.
By John Bambenek Senior Threat Researcher, Fidelis Cybersecurity, 5/15/2015
Comment0 comments  |  Read  |  Post a Comment
Third-Party Risk and Organizational Situational Awareness
Emilio Iasiello, Senior Cyber Intelligence Analyst, Fidelis CybersecurityCommentary
A rigorous risk management approach will help organizations understand the potential risks posed by their partners.
By Emilio Iasiello Senior Cyber Intelligence Analyst, Fidelis Cybersecurity, 4/27/2015
Comment0 comments  |  Read  |  Post a Comment
The Rise of Counterintelligence in Malware Investigations
John Bambenek , Senior Threat Researcher, Fidelis CybersecurityCommentary
The key to operationalizing cybersecurity threat intelligence rests in the critical thinking that establishes that a given indicator is, in fact, malicious.
By John Bambenek Senior Threat Researcher, Fidelis Cybersecurity, 4/22/2015
Comment1 Comment  |  Read  |  Post a Comment
Breach Defense Playbook
Ryan Vela  , Regional Director, Fidelis CybersecurityCommentary
How to be smart about defending against your next attack.
By Ryan Vela Regional Director, Fidelis Cybersecurity, 4/16/2015
Comment0 comments  |  Read  |  Post a Comment
Threat Intelligence Is a Two-Way Street
Emilio Iasiello, Senior Cyber Intelligence Analyst, Fidelis CybersecurityCommentary
Intelligence analysis should be looked upon as less of a service and more of a partnership.
By Emilio Iasiello Senior Cyber Intelligence Analyst, Fidelis Cybersecurity, 4/14/2015
Comment0 comments  |  Read  |  Post a Comment
Principles of Malware Sinkholing
John Bambenek , Senior Threat Researcher, Fidelis CybersecurityCommentary
The process of sinkholing is an important tool to have in your arsenal when dealing with emerging threats.
By John Bambenek Senior Threat Researcher, Fidelis Cybersecurity, 4/6/2015
Comment0 comments  |  Read  |  Post a Comment
Application of Threat Indicators: A Temporal View
Hardik Modi , Director of Threat Research, Fidelis CybersecurityCommentary
Better outcomes will be achieved when were applying temporal considerations to threat indicators.
By Hardik Modi Director of Threat Research, Fidelis Cybersecurity, 4/1/2015
Comment1 Comment  |  Read  |  Post a Comment
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18216
PUBLISHED: 2019-10-20
** DISPUTED ** The BIOS configuration design on ASUS ROG Zephyrus M GM501GS laptops with BIOS 313 relies on the main battery instead of using a CMOS battery, which reduces the value of a protection mechanism in which booting from a USB device is prohibited. Attackers who have physical laptop access ...
CVE-2019-18214
PUBLISHED: 2019-10-19
The Video_Converter app 0.1.0 for Nextcloud allows denial of service (CPU and memory consumption) via multiple concurrent conversions because many FFmpeg processes may be running at once. (The workload is not queued for serial execution.)
CVE-2019-18202
PUBLISHED: 2019-10-19
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to improper access control. A remote attacker can check for the existence of paths and file names via crafted HTTP requests.
CVE-2019-18209
PUBLISHED: 2019-10-19
templates/pad.html in Etherpad-Lite 1.7.5 has XSS when the browser does not encode the path of the URL, as demonstrated by Internet Explorer.
CVE-2019-18198
PUBLISHED: 2019-10-18
In the Linux kernel before 5.3.4, a reference count usage error in the fib6_rule_suppress() function in the fib6 suppression feature of net/ipv6/fib6_rules.c, when handling the FIB_LOOKUP_NOREF flag, can be exploited by a local attacker to corrupt memory, aka CID-ca7a03c41753.