Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Microsoft Windows 10: Three Security Features To Know About
Newest First  |  Oldest First  |  Threaded View
creecreb
creecreb,
User Rank: Apprentice
7/27/2015 | 1:43:07 PM
Re: Biometric Passwords
That is just a myth. Biometric technologies require blood flow through the bodypart being scanned in order to function. Once that person is gone, that information is lost forever.
Madcowpro
Madcowpro,
User Rank: Apprentice
6/8/2015 | 2:57:37 PM
Re: Biometric Passwords
Na you could just cut off the finger.
mutant
mutant,
User Rank: Apprentice
6/8/2015 | 11:52:18 AM
Biometric Passwords
Can't wait until grandma passes away and you have to hold her dead finger to the  computer to get photos and other personal items off the computer.
Lepricon
Lepricon,
User Rank: Apprentice
6/5/2015 | 9:11:48 AM
Re: Device Guard and Developers
Those are certainly valid concerns but I would say that they're focused around a small demographic.  In an enterprise environment this capability will be useful as it allows for granular control and a better protection posture.  For the average home user who doesn't understand the cert warning it provides additional protection as well.

I would suspect that the end user that is going to leverage a legit third party app that wasn't signed probably shouldn't be using that app.  For the savvy user they'll most likely disable the protection. To your point (question) about a processes to get apps accepted that's certainly a critical need because if they don't address that then the capability will most likely just get disabled ala UAC.  
RyanSepe
RyanSepe,
User Rank: Ninja
6/2/2015 | 11:37:58 AM
Device Guard and Developers
When device guard notifies you of a possibly malicious app download, does it allow the user to then download it or is it indefinitely blocked? And what does this mean for third party developers that are not part of those major organizations listed in the article? What process do they have to go through now to get their apps accepted? Or do they not have that option?


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Developing and Testing an Effective Breach Response Plan
Whether or not a data breach is a disaster for the organization depends on the security team's response and that is based on how the team developed a breach response plan beforehand and if it was thoroughly tested. Inside this report, experts share how to: -understand the technical environment, -determine what types of incidents would trigger the plan, -know which stakeholders need to be notified and how to do so, -develop steps to contain the breach, collect evidence, and initiate recovery.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-46411
PUBLISHED: 2022-12-04
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.
CVE-2022-46412
PUBLISHED: 2022-12-04
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. A non-privileged user may escape a restricted shell and execute privileged commands.
CVE-2022-46413
PUBLISHED: 2022-12-04
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Authenticated remote command execution can occur via the management portal.
CVE-2022-46414
PUBLISHED: 2022-12-04
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
CVE-2022-44721
PUBLISHED: 2022-12-04
CrowdStrike Falcon 6.44.15806 allows an administrative attacker to uninstall Falcon Sensor, bypassing the intended protection mechanism in which uninstallation requires possessing a one-time token. (The sensor is managed at the kernel level.)