Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Ransomware Surveys Fill In Scope, Scale of Extortion Epidemic
Newest First  |  Oldest First  |  Threaded View
Page 1 / 3   >   >>
Lily652
50%
50%
Lily652,
User Rank: Moderator
12/11/2016 | 1:13:22 PM
prayer times

Nice to see this impressive article and wanna say thanks a lot for providing this much pretty info. I would like to share this with my friends to explore more about this

Lily652
50%
50%
Lily652,
User Rank: Moderator
12/11/2016 | 1:13:05 PM
prayer times

Nice to see this impressive article and wanna say thanks a lot for providing this much pretty info. I would like to share this with my friends to explore more about this 

kasstri
50%
50%
kasstri,
User Rank: Strategist
11/28/2016 | 11:12:26 AM
Re: keydown
Thanks for your post, BPID... we hear this same refrain with each new threat type that emerges: Vendors can fix this in software without involving the user. And yet here we are again!
Benefiter
50%
50%
Benefiter,
User Rank: Apprentice
11/28/2016 | 9:46:54 AM
2 przykazania miłości Modlitwa do Ducha Świętego o wyproszenie łask

It's actually a cool and useful piece of information. I am glad that you shared this helpful information with us.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 11:19:40 PM
Re: Ransomware defense strategy
FWIW, virtualized sandboxing has been shown to be an effective countermeasure against ransomware -- and, indeed, that some forms of modern ransomware even actively scan for virtualized instances and decline to install if they find any (lest they be subjected to reverse engineering).
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 11:01:03 PM
Re: Randsomware industry
@Terry: The only way I see regulation having an impact here is if it regulates businesses in certain sectors (e.g., healthcare, financial services, etc.) to specifically refuse to pay ransoms or set limits on the amounts they can pay -- and make the penalties for paying ransoms so substantial that such businesses would be compelled to not so pay.

And, as such, those regulations would be completely unworkable.  If a hospital's data is held ransom, human lives and limbs are at stake.  If a financial services' firm or even a generic Fortune 50 firm is held hostage, the entire global economy is at stake.

If those working in public policy really want to make a difference here, the solution is not regulation or legislation but rather better investment in improving cybersecurity.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 10:55:36 PM
Re: Randsomware industry
We don't need more regulation or laws here.  This is already covered by existing laws and regulations (standard wire-fraud laws, plus the CFAA, for starters).
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 10:54:30 PM
Re: Ransomware defense strategy
@Dr. T: The whole point goes to understanding.

If you're using an OS based in the command line, whether Unix, old-school MS-DOS, or whatever, you naturally have to know much more about what's going on on your machine than the average MacOSX or Windows user.  As such, you're more of a power user and in general will position yourself better.
ClaireEllison
50%
50%
ClaireEllison,
User Rank: Apprentice
11/27/2016 | 2:47:55 PM
Re: Industry
Excellent article plus its information and I positively bookmark to this site because here I always get an amazing knowledge as I expect.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2016 | 2:39:58 PM
Re: Ransomware defense strategy
"We need legislation to clearly identify responsibility and the limits of that responsibility. " I agree with this. Added to that it needs to clarify accountability for the offenders.
Page 1 / 3   >   >>


COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/4/2020
Abandoned Apps May Pose Security Risk to Mobile Devices
Robert Lemos, Contributing Writer,  5/29/2020
How AI and Automation Can Help Bridge the Cybersecurity Talent Gap
Peter Barker, Chief Product Officer at ForgeRock,  6/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: What? IT said I needed virus protection!
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13842
PUBLISHED: 2020-06-05
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (June 2020).
CVE-2020-13843
PUBLISHED: 2020-06-05
An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial of service because checking of the userdata partition is mishandled. The LG ID is LVE-SMP-200014 (June 2020).
CVE-2020-13839
PUBLISHED: 2020-06-05
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200007 (June 2020).
CVE-2020-13840
PUBLISHED: 2020-06-05
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command handler buffer overflow. The LG ID is LVE-SMP-200008 (June 2020).
CVE-2020-13841
PUBLISHED: 2020-06-05
An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command handler allows attackers to bypass intended access restrictions. The LG ID is LVE-SMP-200009 (June 2020).