Cloud Misconceptions Are Pervasive Across Enterprises
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Shadow IT is rampant at many organizations that rely upon cloud-delivered tools and services to enable remote work, according to a new study. Here's what security teams need to do about it.
By Paul Martini The CEO, co-founder and chief architect of iboss, 4/25/2018
Comment0 comments  |  Read  |  Post a Comment
How to Leverage Artificial Intelligence for Cybersecurity
Joe Cosmano, Senior Vice President of Engineering Services, ibossCommentary
AI and predictive analytics should be used to augment a companys security team, not replace it. Here's why.
By Joe Cosmano Senior Vice President of Engineering Services, iboss, 4/18/2018
Comment0 comments  |  Read  |  Post a Comment
Avoiding the Ransomware Mistakes that Crippled Atlanta
Chris Park, Chris Park, CIO, ibossCommentary
What made Atlanta an easy target was its outdated use of technology: old computers running on non-supported platforms, which are also a characteristic of many municipalities and most major cities.
By Chris Park Chris Park, CIO, iboss, 4/11/2018
Comment8 comments  |  Read  |  Post a Comment
Securing Retail Networks for an Omnichannel Future
Peter Martini, President and Co-FounderCommentary
Retailers who haphazardly move to digital from a brick-and-mortar environment can leave their businesses open to significant cybersecurity vulnerabilities. Here's how to avoid the pitfalls.
By Peter Martini President and Co-Founder, 4/4/2018
Comment1 Comment  |  Read  |  Post a Comment
Getting Ahead of Internet of Things Security in the Enterprise
Simon Eappariello, Senior VP Product & Engineering, EMEIA, ibossCommentary
In anticipation of an IoT-centric future, CISOs must be rigorous in shoring up defenses that provide real-time insights across all network access points.
By Simon Eappariello Senior VP Product & Engineering, EMEIA, iboss, 3/28/2018
Comment0 comments  |  Read  |  Post a Comment
Cybersecurity Spring Cleaning: 3 Must-Dos for 2018
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Why 'Spectre' and 'Meltdown,' GDPR, and the Internet of Things are three areas security teams should declutter and prioritize in the coming months.
By Paul Martini The CEO, co-founder and chief architect of iboss, 3/21/2018
Comment0 comments  |  Read  |  Post a Comment
How to Interpret the SECs Latest Guidance on Data Breach Disclosure
Peter Martini, President and Co-FounderCommentary
Forward-looking organizations should view this as an opportunity to reevaluate their cybersecurity posture and install best practices that should have already been in place.
By Peter Martini President and Co-Founder, 3/14/2018
Comment0 comments  |  Read  |  Post a Comment
Virtual Private Networks: Why Their Days Are Numbered
Chris Park, Chris Park, CIO, ibossCommentary
As companies move to the cloud and depend less on physical servers and network connections, their reliance on VPNs for security will eventually evolve, if not disappear altogether.
By Chris Park Chris Park, CIO, iboss, 2/28/2018
Comment0 comments  |  Read  |  Post a Comment
Getting Started with IoT Security in Healthcare
Chris Park, Chris Park, CIO, ibossCommentary
Theres a hazard that comes with introducing any new element into patient care whether it's a new drug or a connected device. These four steps will help keep patients safe.
By Chris Park Chris Park, CIO, iboss, 2/21/2018
Comment0 comments  |  Read  |  Post a Comment
The GDPR Clock Is Running Out. Now What?
Simon Eappariello, Senior VP Product & Engineering, EMEIA, ibossCommentary
Many organizations impacted by new European Union data privacy rules that go into effect May 25 are still blind to some of the basics.
By Simon Eappariello Senior VP Product & Engineering, EMEIA, iboss, 2/14/2018
Comment0 comments  |  Read  |  Post a Comment
Top Cloud Security Misconceptions Plaguing Enterprises
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Contrary to popular opinion, there is no one single cloud. There are a wealth of cloud-based providers that own dedicated server space across the globe. Heres how to find the best fit for your company.
By Paul Martini The CEO, co-founder and chief architect of iboss, 2/7/2018
Comment0 comments  |  Read  |  Post a Comment
Data Encryption: 4 Common Pitfalls
Joe Cosmano, Senior Vice President of Engineering Services, ibossCommentary
To maximize encryption effectiveness you must minimize adverse effects in network performance and complexity. Here's how.
By Joe Cosmano Senior Vice President of Engineering Services, iboss, 1/31/2018
Comment0 comments  |  Read  |  Post a Comment
Selling Cloud-Based Cybersecurity to a Skeptic
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
When it comes to security, organizations dont need to look at cloud as an either/or proposition. But there are misconceptions that need to be addressed.
By Paul Martini The CEO, co-founder and chief architect of iboss, 1/26/2018
Comment0 comments  |  Read  |  Post a Comment
Applying Defense-in-Depth to the Digital Battlefield
Chris Park, Chris Park, CIO, ibossCommentary
How a layered security strategy can minimize the threat and impact of a data breach.
By Chris Park Chris Park, CIO, iboss, 1/18/2018
Comment0 comments  |  Read  |  Post a Comment
Top 3 Pitfalls of Securing the Decentralized Enterprise
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Doubling down on outdated security practices while the number of users leveraging your enterprise network grows is a race to the bottom for businesses moving to distributed workflows.
By Paul Martini The CEO, co-founder and chief architect of iboss, 1/16/2018
Comment0 comments  |  Read  |  Post a Comment
'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
How Well Is Your Organization Investing Its Cybersecurity Dollars?
Jack Jones, Chairman, FAIR Institute,  12/11/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-1480
PUBLISHED: 2018-12-12
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly' attribute on authorization tokens or session cookies. If a Cross-Site Scripting vulnerability also existed attackers may be able to get the cookie values via malicious JavaScript and then hijack the user sessi...
CVE-2018-1481
PUBLISHED: 2018-12-12
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 140763.
CVE-2018-1484
PUBLISHED: 2018-12-12
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent...
CVE-2018-1485
PUBLISHED: 2018-12-12
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable after a successful authentication which could lead to session fixation/hijacking vulnerability. This could force a user to utilize a cookie that may be known to an attacker. IBM X-Force ID: 140970.
CVE-2018-1901
PUBLISHED: 2018-12-12
IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to temporarily gain elevated privileges on the system, caused by incorrect cached value being used. IBM X-Force ID: 152530.