Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Boldest Cybersecurity Predictions For 2016
Newest First  |  Oldest First  |  Threaded View
Sagiss, LLC
Sagiss, LLC,
User Rank: Strategist
1/25/2016 | 4:13:44 PM
Re: CISOs or Security Investments?
I agree with you, Jason. We're already beginning to see a shift in focus as businesses devote more resources to security. However, CISO's won't be the "It Girl" of IT anytime soon due to the large gap in understanding between end-users and their IT departments when it comes to the importance of a comprehensive IT policy. Perhaps when employees begin to think of I.T. as a part of their day-to-day routines rather than a separate entity, CISOs will finally earn the title of "It Girl".
Jason Echols
Jason Echols,
User Rank: Apprentice
1/11/2016 | 11:01:14 AM
CISOs or Security Investments?
Ericka, this is easily one of the best prediction posts around, thanks for putting it together. 

While I share your hope that CISOs become the "It Girl" of I.T., I think that revolution will take a bit more time. I do think 2016 will see more investment in security (not a bold prediction), and that this investment in the coming years will eventually make the CISO role more powerful as application, network, and data security are brought into a unified team in the enterprise, possibly under the CISO. Either way, here's hoping security practice continues to be brought to the forefront of the priorities list!
macker490
macker490,
User Rank: Ninja
1/1/2016 | 7:18:48 AM
Re: Balkanization of the Internet
if we cannot control your behavior then we must limit your access

operating software that allows itself to be corrupted by the activity of an application program fails in the premise and leaves the conclusion as the necessary alternative
RyanSepe
RyanSepe,
User Rank: Ninja
12/31/2015 | 10:23:14 AM
Data Weaponization Means Extortapalooza
I agree with this one most heavily and for other reasons than the ones cited. Not only are phishing campaigns and Drive by Downloads effective at the corporate level but also at the individual level. With ransomware becoming more and more prevalent due to its modularity and ease of use, I see this prediction continuing the incline of the current trend.
RyanSepe
RyanSepe,
User Rank: Ninja
12/31/2015 | 10:12:48 AM
Balkanization of the Internet
Not sure this will come to pass on a global scale. Maybe setting up lines between "non-friendly" countries. But the idea of the Internet is the free flow of information, setting up walls is not the way to go....


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Black Hat USA 2022 Attendee Report
Black Hat attendees are not sleeping well. Between concerns about attacks against cloud services, ransomware, and the growing risks to the global supply chain, these security pros have a lot to be worried about. Read our 2022 report to hear what they're concerned about now.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-36312
PUBLISHED: 2022-08-16
Airspan AirVelocity 1500 software version 15.18.00.2511 lacks CSRF protections in the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.
CVE-2022-38216
PUBLISHED: 2022-08-16
An integer overflow exists in Mapbox's closed source gl-native library prior to version 10.6.1, which is bundled with multiple Mapbox products including open source libraries. The overflow is caused by large image height and width values when creating a new Image and allows for out of bounds writes,...
CVE-2022-36306
PUBLISHED: 2022-08-16
An authenticated attacker can enumerate and download sensitive files, including the eNodeB's web management UI's TLS private key, the web server binary, and the web server configuration file. These vulnerabilities were found in AirVelocity 1500 running software version 9.3.0.01249, were still presen...
CVE-2022-36307
PUBLISHED: 2022-08-16
The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 software version 15.18.00.2511 and may affect other AirVelocity and AirSpeed models.
CVE-2022-36308
PUBLISHED: 2022-08-16
Airspan AirVelocity 1500 web management UI displays SNMP credentials in plaintext on software versions older than 15.18.00.2511, and stores SNMPv3 credentials unhashed on the filesystem, enabling anyone with web access to use these credentials to manipulate the eNodeB over SNMP. This issue may affec...