Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud Misconceptions Are Pervasive Across Enterprises
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Shadow IT is rampant at many organizations that rely upon cloud-delivered tools and services to enable remote work, according to a new study. Here's what security teams need to do about it.
By Paul Martini The CEO, co-founder and chief architect of iboss, 4/25/2018
Comment0 comments  |  Read  |  Post a Comment
How to Leverage Artificial Intelligence for Cybersecurity
Joe Cosmano, Senior Vice President of Engineering Services, ibossCommentary
AI and predictive analytics should be used to augment a companys security team, not replace it. Here's why.
By Joe Cosmano Senior Vice President of Engineering Services, iboss, 4/18/2018
Comment0 comments  |  Read  |  Post a Comment
Avoiding the Ransomware Mistakes that Crippled Atlanta
Chris Park, Chris Park, CIO, ibossCommentary
What made Atlanta an easy target was its outdated use of technology: old computers running on non-supported platforms, which are also a characteristic of many municipalities and most major cities.
By Chris Park Chris Park, CIO, iboss, 4/11/2018
Comment8 comments  |  Read  |  Post a Comment
Securing Retail Networks for an Omnichannel Future
Peter Martini, President and Co-FounderCommentary
Retailers who haphazardly move to digital from a brick-and-mortar environment can leave their businesses open to significant cybersecurity vulnerabilities. Here's how to avoid the pitfalls.
By Peter Martini President and Co-Founder, 4/4/2018
Comment1 Comment  |  Read  |  Post a Comment
Getting Ahead of Internet of Things Security in the Enterprise
Simon Eappariello, Senior VP Product & Engineering, EMEIA, ibossCommentary
In anticipation of an IoT-centric future, CISOs must be rigorous in shoring up defenses that provide real-time insights across all network access points.
By Simon Eappariello Senior VP Product & Engineering, EMEIA, iboss, 3/28/2018
Comment0 comments  |  Read  |  Post a Comment
Cybersecurity Spring Cleaning: 3 Must-Dos for 2018
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Why 'Spectre' and 'Meltdown,' GDPR, and the Internet of Things are three areas security teams should declutter and prioritize in the coming months.
By Paul Martini The CEO, co-founder and chief architect of iboss, 3/21/2018
Comment0 comments  |  Read  |  Post a Comment
How to Interpret the SECs Latest Guidance on Data Breach Disclosure
Peter Martini, President and Co-FounderCommentary
Forward-looking organizations should view this as an opportunity to reevaluate their cybersecurity posture and install best practices that should have already been in place.
By Peter Martini President and Co-Founder, 3/14/2018
Comment0 comments  |  Read  |  Post a Comment
Virtual Private Networks: Why Their Days Are Numbered
Chris Park, Chris Park, CIO, ibossCommentary
As companies move to the cloud and depend less on physical servers and network connections, their reliance on VPNs for security will eventually evolve, if not disappear altogether.
By Chris Park Chris Park, CIO, iboss, 2/28/2018
Comment0 comments  |  Read  |  Post a Comment
Getting Started with IoT Security in Healthcare
Chris Park, Chris Park, CIO, ibossCommentary
Theres a hazard that comes with introducing any new element into patient care whether it's a new drug or a connected device. These four steps will help keep patients safe.
By Chris Park Chris Park, CIO, iboss, 2/21/2018
Comment0 comments  |  Read  |  Post a Comment
The GDPR Clock Is Running Out. Now What?
Simon Eappariello, Senior VP Product & Engineering, EMEIA, ibossCommentary
Many organizations impacted by new European Union data privacy rules that go into effect May 25 are still blind to some of the basics.
By Simon Eappariello Senior VP Product & Engineering, EMEIA, iboss, 2/14/2018
Comment0 comments  |  Read  |  Post a Comment
Top Cloud Security Misconceptions Plaguing Enterprises
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Contrary to popular opinion, there is no one single cloud. There are a wealth of cloud-based providers that own dedicated server space across the globe. Heres how to find the best fit for your company.
By Paul Martini The CEO, co-founder and chief architect of iboss, 2/7/2018
Comment0 comments  |  Read  |  Post a Comment
Data Encryption: 4 Common Pitfalls
Joe Cosmano, Senior Vice President of Engineering Services, ibossCommentary
To maximize encryption effectiveness you must minimize adverse effects in network performance and complexity. Here's how.
By Joe Cosmano Senior Vice President of Engineering Services, iboss, 1/31/2018
Comment0 comments  |  Read  |  Post a Comment
Selling Cloud-Based Cybersecurity to a Skeptic
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
When it comes to security, organizations dont need to look at cloud as an either/or proposition. But there are misconceptions that need to be addressed.
By Paul Martini The CEO, co-founder and chief architect of iboss, 1/26/2018
Comment0 comments  |  Read  |  Post a Comment
Applying Defense-in-Depth to the Digital Battlefield
Chris Park, Chris Park, CIO, ibossCommentary
How a layered security strategy can minimize the threat and impact of a data breach.
By Chris Park Chris Park, CIO, iboss, 1/18/2018
Comment0 comments  |  Read  |  Post a Comment
Top 3 Pitfalls of Securing the Decentralized Enterprise
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Doubling down on outdated security practices while the number of users leveraging your enterprise network grows is a race to the bottom for businesses moving to distributed workflows.
By Paul Martini The CEO, co-founder and chief architect of iboss, 1/16/2018
Comment0 comments  |  Read  |  Post a Comment
Attackers Leave Stolen Credentials Searchable on Google
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2021
How to Better Secure Your Microsoft 365 Environment
Kelly Sheridan, Staff Editor, Dark Reading,  1/25/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23901
PUBLISHED: 2021-01-25
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML ...
CVE-2020-17532
PUBLISHED: 2021-01-25
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5
CVE-2020-12512
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting
CVE-2020-12513
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
CVE-2020-12514
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd