Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Get Smart About Threat Intelligence
Newest First  |  Oldest First  |  Threaded View
JasonSachowski
JasonSachowski,
User Rank: Author
9/10/2014 | 6:42:21 PM
Re: Disconnect?
I wouldn't go as far to say this is attributed directly to the process aspect. Sure we could enhance our processes to make improvements on the flow of data between the doers and the decision makers; but there's also the challenge of data getting lost in translation. Not so much because of process, but because the doers speaking in a technical language (0&1) and the decision makers speak in a business language ($$$). By improving the way we communicate information, the process disconnect to improve data flow would somewhat fix itself.
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
9/10/2014 | 7:44:46 AM
Re: Disconnect?
@JasonSachowski, So you are saying that there needs to be a better process communicating tactical information from to the analysts who are developing defensive strategies and action plans.... 
JasonSachowski
JasonSachowski,
User Rank: Author
9/9/2014 | 8:22:55 PM
Re: Disconnect?
Sure @MarilynCohodas... As I mentioned before, threat intelligence is a collection of (somewhat) similar information to tactically mitigate individual an threat. And for the most part, those security analysts who are directly involved in taking action from this intelligence aren't necessarily those senior professionals who are involved in decision making. However, the tactical intelligence collected and disseminated by the security analysts can be correlated and become a large contributor to strategic road maps developed by senior professionals.
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
9/8/2014 | 9:26:42 AM
Re: Disconnect?
@JasonSachowski, you wrote that security practitioners need "to take what we learn from threat intelligence and feed that into a larger form of security intelligence.." to move from the tactical to the strategic.  Care to give an example of what that would look like?
JasonSachowski
JasonSachowski,
User Rank: Author
9/6/2014 | 12:38:59 PM
Re: Disconnect?
The way threat intelligence is delivered to us is that it is mostly information about individuals threats. It provide us with the information we need to safeguard against each threat and is mostly tactical. If we really want to get ahead of the game, we need to take what we learn from threat intelligence and feed that into a larger form of security intelligence. This way, we can get away from the tactical/linear approaches and develop more strategic/cyclical methodologies.
RyanSepe
RyanSepe,
User Rank: Ninja
8/31/2014 | 8:44:17 AM
Re: Disconnect?
This is disheartening. One of the main principles of information security is that analysis/scans without action/adaptation is a useless practice. Threats evolve so the security in turn and strategies needs to evolve. A waterfall approach cannot be taken with an agile vector.
Bprince
Bprince,
User Rank: Ninja
8/15/2014 | 8:47:51 PM
Re: Disconnect?
Yeah I find that an interesting stat too. I guess that means the threat intel is confirming what they know already and have already been preparing for. Or it could be that they are not digesting that intelligence well.

BP
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
8/15/2014 | 9:12:34 AM
Re: Threat Intel
Yes, it's overall an encouraging report. I find it interesting (not totally surprising) that socal media is getting scant attention from respondents. jJust 13% of respondents said they are looking at FB, Twitter and blogs. I wonder if that will change over the next year?
PZav
PZav,
User Rank: Author
8/14/2014 | 12:48:41 PM
Threat Intel
Interesting information, it seems like threat intelligence is becoming a more prevelant strategic initiative.  Things are hopefully headed in the right direction!
Marilyn Cohodas
Marilyn Cohodas,
User Rank: Strategist
8/13/2014 | 1:56:13 PM
Disconnect?
85 percent of respondents says threat intellegience plays some role in their security activities but 90% says that threat intel analysis has't changed their defense strategy. What's up with that?


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Improving Enterprise Cybersecurity With XDR
Enterprises are looking at eXtended Detection and Response technologies to improve their abilities to detect, and respond to, threats. While endpoint detection and response is not new to enterprise security, organizations have to improve network visibility, expand data collection and expand threat hunting capabilites if they want their XDR deployments to succeed. This issue of Tech Insights also includes: a market overview for XDR from Omdia, questions to ask before deploying XDR, and an XDR primer.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-27509
PUBLISHED: 2022-06-26
Persistent XSS in Galaxkey Secure Mail Client in Galaxkey up to 5.6.11.5 allows an attacker to perform an account takeover by intercepting the HTTP Post request when sending an email and injecting a specially crafted XSS payload in the 'subject' field. The payload executes when the recipient logs in...
CVE-2022-34491
PUBLISHED: 2022-06-25
In the RSS extension for MediaWiki through 1.38.1, when the $wgRSSAllowLinkTag config variable was set to true, and a new RSS feed was created with certain XSS payloads within its description tags and added to the $wgRSSUrlWhitelist config variable, stored XSS could occur via MediaWiki's template sy...
CVE-2022-29931
PUBLISHED: 2022-06-25
Raytion 7.2.0 allows reflected Cross-site Scripting (XSS).
CVE-2022-31017
PUBLISHED: 2022-06-25
Zulip is an open-source team collaboration tool. Versions 2.1.0 through and including 5.2 are vulnerable to a logic error. A stream configured as private with protected history, where new subscribers should not be allowed to see messages sent before they were subscribed, when edited causes the serve...
CVE-2022-31016
PUBLISHED: 2022-06-25
Argo CD is a declarative continuous deployment for Kubernetes. Argo CD versions v0.7.0 and later are vulnerable to an uncontrolled memory consumption bug, allowing an authorized malicious user to crash the repo-server service, resulting in a Denial of Service. The attacker must be an authenticated A...