Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Page 1 / 5   >   >>
A Cybersecurity Christmas Story
Ned Miller, Intel Security, Chief Technology Strategist for Public Sector
Automation and orchestration will be essential components of security in 2017.
By Ned Miller Intel Security, Chief Technology Strategist for Public Sector, 12/23/2016
Comment1 Comment  |  Read  |  Post a Comment
Investments In Security Operations Centers Are Paying Off, Study Finds
Barbara Kay, Senior Director of Marketing
SOCs help organizations reduce security incidents and improve operational maturity.
By Barbara Kay Senior Director of Marketing, 12/19/2016
Comment0 comments  |  Read  |  Post a Comment
Are Unconscious Biases Weakening Your Security Posture?
Lynda Grindstaff, Senior Director of the Innovation Pipeline, Intel Security
Proactively addressing your biases can help you build a resilient and adaptable security foundation.
By Lynda Grindstaff Senior Director of the Innovation Pipeline, Intel Security, 12/15/2016
Comment0 comments  |  Read  |  Post a Comment
Its Time For Organizations To Automate Security
Josh Thurston, Security Strategist - Americas, Office of the CTO, Intel Security
Security automation makes more efficient use of scarce security resources, freeing them up for more proactive tasks.
By Josh Thurston Security Strategist - Americas, Office of the CTO, Intel Security, 12/14/2016
Comment1 Comment  |  Read  |  Post a Comment
PoisonTap USB Device Can Hack A Locked PC In A Minute
Matthew Rosenquist, Cybersecurity Strategist
This is just one example of an emerging technology that enables anyone with physical access to a computers USB port to potentially harvest data and gain access by spoofing an Internet ecosystem.
By Matthew Rosenquist Cybersecurity Strategist, 12/6/2016
Comment1 Comment  |  Read  |  Post a Comment
Protect Your Company From Hackable Holiday Gifts
Jonathan Anderson, Chief Technology Officer of IoT Security, Intel Security
This holiday season promises to be full of devices, apps, and connectivity. Planning and executing appropriate security precautions now will save your business from a serious breach later.
By Jonathan Anderson Chief Technology Officer of IoT Security, Intel Security, 12/5/2016
Comment0 comments  |  Read  |  Post a Comment
Cybercriminals Next Target: Long-Term Prizes (Part 2 of 2)
Matthew Rosenquist, Cybersecurity Strategist
Attacks of a more strategic nature will test early blockchain implementations and continue to explore ways to monetize weak IoT devices.
By Matthew Rosenquist Cybersecurity Strategist, 12/1/2016
Comment0 comments  |  Read  |  Post a Comment
Cybercriminals' Next Target: Short-Term Dangers (Part 1 of 2)
Matthew Rosenquist, Cybersecurity Strategist
With the holidays approaching, the focus will be on lucrative online shopping, email ransomware, phishing for credentials, and infection by holiday-lurking malware.
By Matthew Rosenquist Cybersecurity Strategist, 11/30/2016
Comment0 comments  |  Read  |  Post a Comment
Beware: Scalable Vector Graphics Files Are A New Ransomware Threat
Matthew Rosenquist, Cybersecurity Strategist
SVG files offer many advantages as far as graphics go, but hackers looking to embed malware on websites can exploit them.
By Matthew Rosenquist Cybersecurity Strategist, 11/29/2016
Comment2 comments  |  Read  |  Post a Comment
Every Minute Of Security Planning Will Save You 10 Minutes In Execution
Ned Miller, Intel Security, Chief Technology Strategist for Public Sector
Leveraging automation, orchestration, and interoperability in your cybersecurity plans now will save you significant time later.
By Ned Miller Intel Security, Chief Technology Strategist for Public Sector, 11/8/2016
Comment0 comments  |  Read  |  Post a Comment
Automate And Orchestrate Workflows For Better Security
Brett Kelsey, VP & Chief Technology Officer, Americas, Intel Security
Security automation has become a central goal for many organizations as they try to respond faster to more threats with limited resources.
By Brett Kelsey VP & Chief Technology Officer, Americas, Intel Security, 11/4/2016
Comment0 comments  |  Read  |  Post a Comment
We Must Become Good Digital Citizens
David O'Berry, Worldwide Strategic Technologies, Intel Security
Digital citizenship carries many capabilities and benefits, but there also have to be some rules and responsibilities.
By David O'Berry Worldwide Strategic Technologies, Intel Security, 11/1/2016
Comment1 Comment  |  Read  |  Post a Comment
Warning: Healthcare Data Under Attack
Raj Samani , Chief Technology Officer of Intel Securitys Europe, Middle East and Africa division
We as an industry must demand greater protection of our medical data.
By Raj Samani Chief Technology Officer of Intel Securitys Europe, Middle East and Africa division, 10/26/2016
Comment0 comments  |  Read  |  Post a Comment
Lets Clean Up The Internet By Taking Responsibility For Our Actions
David O'Berry, Worldwide Strategic Technologies, Intel Security
Imagine an Internet with multiple levels of security that users need to earn.
By David O'Berry Worldwide Strategic Technologies, Intel Security, 10/26/2016
Comment2 comments  |  Read  |  Post a Comment
Why Arent We Talking More Proactively About Securing Smart Infrastructure?
Ned Miller, Intel Security, Chief Technology Strategist for Public Sector
Lets not perpetuate the vicious cycle of security complexity and failure by trying to bolt on security after the fact.
By Ned Miller Intel Security, Chief Technology Strategist for Public Sector, 10/20/2016
Comment2 comments  |  Read  |  Post a Comment
Access, Trust, And The Rise Of Electronic Personal Assistants
Carl Woodward, Principal Engineer and Security Technologist, Intel Security
App and device makers are working hard to deliver user control over privacy.
By Carl Woodward Principal Engineer and Security Technologist, Intel Security, 10/13/2016
Comment0 comments  |  Read  |  Post a Comment
Cybersecurity Economics In Government -- Is Funding The Real Problem?
Ned Miller, Intel Security, Chief Technology Strategist for Public Sector
Government leadership and those chartered with creating budgets could benefit from applying sound value-management practices when considering the cybersecurity budget process.
By Ned Miller Intel Security, Chief Technology Strategist for Public Sector, 10/5/2016
Comment0 comments  |  Read  |  Post a Comment
Cyber-Anything-As-A-Service: Should The Government Just Outsource Everything?
Ned Miller, Intel Security, Chief Technology Strategist for Public Sector
Agencies should be able to select and provision from a variety of cybersecurity services and capabilities to improve their overall effectiveness and efficiency.
By Ned Miller Intel Security, Chief Technology Strategist for Public Sector, 10/4/2016
Comment0 comments  |  Read  |  Post a Comment
Beep Prepared: How Security Economics Can Help The Coyote Catch The Roadrunner
Tom Quillin, Director of Cyber Security Technology & Initiatives, Intel Corporation
The practice of security economics demonstrates how gaps in the security architecture impair business results.
By Tom Quillin Director of Cyber Security Technology & Initiatives, Intel Corporation, 9/28/2016
Comment0 comments  |  Read  |  Post a Comment
Sharing Cybersecurity Threat Intelligence Is The Only Way We Win
Matthew Rosenquist, Cybersecurity Strategist
Security organizations must leverage each others information in order to better predict, prevent, detect, and respond to threats their customers and organizations face.
By Matthew Rosenquist Cybersecurity Strategist, 9/27/2016
Comment1 Comment  |  Read  |  Post a Comment
Page 1 / 5   >   >>
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-42258
PUBLISHED: 2021-10-22
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in the wild in October 2021 for ransomware installation. SQL injection can, for example, use the txtID (aka username) parameter. Successful exploitation can include ...
CVE-2020-28968
PUBLISHED: 2021-10-22
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the username input field.
CVE-2020-28969
PUBLISHED: 2021-10-22
Aplioxio PDF ShapingUp 5.0.0.139 contains a buffer overflow which allows attackers to cause a denial of service (DoS) via a crafted PDF file.
CVE-2020-36485
PUBLISHED: 2021-10-22
Portable Ltd Playable v9.18 was discovered to contain an arbitrary file upload vulnerability in the filename parameter of the upload module. This vulnerability allows attackers to execute arbitrary code via a crafted JPEG file.
CVE-2020-36486
PUBLISHED: 2021-10-22
Swift File Transfer Mobile v1.1.2 and below was discovered to contain a cross-site scripting (XSS) vulnerability via the 'path' parameter of the 'list' and 'download' exception-handling.