Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Ransomware Surveys Fill In Scope, Scale of Extortion Epidemic
Newest First  |  Oldest First  |  Threaded View
Page 1 / 3   >   >>
Lily652
50%
50%
Lily652,
User Rank: Moderator
12/11/2016 | 1:13:22 PM
prayer times

Nice to see this impressive article and wanna say thanks a lot for providing this much pretty info. I would like to share this with my friends to explore more about this

Lily652
50%
50%
Lily652,
User Rank: Moderator
12/11/2016 | 1:13:05 PM
prayer times

Nice to see this impressive article and wanna say thanks a lot for providing this much pretty info. I would like to share this with my friends to explore more about this 

Benefiter
50%
50%
Benefiter,
User Rank: Apprentice
11/28/2016 | 9:46:54 AM
2 przykazania miłości Modlitwa do Ducha Świętego o wyproszenie łask

It's actually a cool and useful piece of information. I am glad that you shared this helpful information with us.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 11:19:40 PM
Re: Ransomware defense strategy
FWIW, virtualized sandboxing has been shown to be an effective countermeasure against ransomware -- and, indeed, that some forms of modern ransomware even actively scan for virtualized instances and decline to install if they find any (lest they be subjected to reverse engineering).
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 11:01:03 PM
Re: Randsomware industry
@Terry: The only way I see regulation having an impact here is if it regulates businesses in certain sectors (e.g., healthcare, financial services, etc.) to specifically refuse to pay ransoms or set limits on the amounts they can pay -- and make the penalties for paying ransoms so substantial that such businesses would be compelled to not so pay.

And, as such, those regulations would be completely unworkable.  If a hospital's data is held ransom, human lives and limbs are at stake.  If a financial services' firm or even a generic Fortune 50 firm is held hostage, the entire global economy is at stake.

If those working in public policy really want to make a difference here, the solution is not regulation or legislation but rather better investment in improving cybersecurity.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 10:55:36 PM
Re: Randsomware industry
We don't need more regulation or laws here.  This is already covered by existing laws and regulations (standard wire-fraud laws, plus the CFAA, for starters).
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 10:54:30 PM
Re: Ransomware defense strategy
@Dr. T: The whole point goes to understanding.

If you're using an OS based in the command line, whether Unix, old-school MS-DOS, or whatever, you naturally have to know much more about what's going on on your machine than the average MacOSX or Windows user.  As such, you're more of a power user and in general will position yourself better.
ClaireEllison
50%
50%
ClaireEllison,
User Rank: Apprentice
11/27/2016 | 2:47:55 PM
Re: Industry
Excellent article plus its information and I positively bookmark to this site because here I always get an amazing knowledge as I expect.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2016 | 2:39:58 PM
Re: Ransomware defense strategy
"We need legislation to clearly identify responsibility and the limits of that responsibility. " I agree with this. Added to that it needs to clarify accountability for the offenders.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2016 | 2:36:18 PM
Re: Ransomware defense strategy
"one that is solvable through intelligent technology." I agree with this on the basis, however technology would certainly to help to minimize the risk of it.
Page 1 / 3   >   >>


News
Former CISA Director Chris Krebs Discusses Risk Management & Threat Intel
Kelly Sheridan, Staff Editor, Dark Reading,  2/23/2021
Edge-DRsplash-10-edge-articles
Security + Fraud Protection: Your One-Two Punch Against Cyberattacks
Joshua Goldfarb, Director of Product Management at F5,  2/23/2021
News
Cybercrime Groups More Prolific, Focus on Healthcare in 2020
Robert Lemos, Contributing Writer,  2/22/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Building the SOC of the Future
Building the SOC of the Future
Digital transformation, cloud-focused attacks, and a worldwide pandemic. The past year has changed the way business works and the way security teams operate. There is no going back.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-21273
PUBLISHED: 2021-02-26
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to external IP addresses when calculating the key va...
CVE-2021-21274
PUBLISHED: 2021-02-26
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver could redirect requests to their .well-known file to a large file. This can lead to...
CVE-2021-23345
PUBLISHED: 2021-02-26
All versions of package github.com/thecodingmachine/gotenberg are vulnerable to Server-side Request Forgery (SSRF) via the /convert/html endpoint when the src attribute of an HTML element refers to an internal system file, such as <iframe src='file:///etc/passwd'>.
CVE-2021-21297
PUBLISHED: 2021-02-26
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to affect the default beh...
CVE-2021-21298
PUBLISHED: 2021-02-26
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vulnerability which allows arbitrary path traversal via the Projects API. If the Projects feature is enabled, a user with `projects.read` permission is able to access any file via th...