Comments
How NOT To Be The Next Sony: Defending Against Destructive Attacks
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 2
Marilyn Cohodas
100%
0%
Marilyn Cohodas,
User Rank: Strategist
1/9/2015 | 9:11:26 AM
Re: because...
Super analysis, Sara. Your analogy about aproaching destructive attacks more like a physical disaster (flood, explosion, etc.) than a digital one is really apt. And what happened to Sony presents an object lesson in what needs to be in place to support essential services while the damage is being contained. 
McDaveX
100%
0%
McDaveX,
User Rank: Strategist
1/9/2015 | 5:32:24 AM
because...
Every attack was "unprecidented". Even if its the third time you were compromised by the same unpatched bug. :)
<<   <   Page 2 / 2


What We Talk About When We Talk About Risk
Jack Jones, Chairman, FAIR Institute,  7/11/2018
Ticketmaster Breach Part of Massive Payment Card Hacking Campaign
Jai Vijayan, Freelance writer,  7/10/2018
Major International Airport System Access Sold for $10 on Dark Web
Kelly Sheridan, Staff Editor, Dark Reading,  7/11/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Cyberspace is much less secure than my old lamp.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14346
PUBLISHED: 2018-07-17
GNU Libextractor before 1.7 has a stack-based buffer overflow in ec_read_file_func (unzip.c).
CVE-2018-14347
PUBLISHED: 2018-07-17
GNU Libextractor before 1.7 contains an infinite loop vulnerability in EXTRACTOR_mpeg_extract_method (mpeg_extractor.c).
CVE-2018-13858
PUBLISHED: 2018-07-17
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional allows unauthorized remote attackers to reboot or execute other functions via the &quot;/xml/system/control.xml&quot; URL, using the GET request &quot;?action=reboot&quot; for example.
CVE-2018-13859
PUBLISHED: 2018-07-17
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, allow unauthorized remote attackers to reset the authentication via the &quot;/xml/system/setAttribute.xml&quot; URL, using the GET request &quot;?id=0&amp;attr=protectAccess&amp;newV...
CVE-2018-13860
PUBLISHED: 2018-07-17
MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18 allows unauthorized remote attackers to obtain sensitive information via the &quot;/xml/menu/getObjectEditor.xml&quot; URL, using a &quot;?oid=systemSetup&amp;id=_0&quot; or &quot;?oid...