Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Ransomware Surveys Fill In Scope, Scale of Extortion Epidemic
Newest First  |  Oldest First  |  Threaded View
Page 1 / 3   >   >>
Lily652
50%
50%
Lily652,
User Rank: Moderator
12/11/2016 | 1:13:22 PM
prayer times

Nice to see this impressive article and wanna say thanks a lot for providing this much pretty info. I would like to share this with my friends to explore more about this

Lily652
50%
50%
Lily652,
User Rank: Moderator
12/11/2016 | 1:13:05 PM
prayer times

Nice to see this impressive article and wanna say thanks a lot for providing this much pretty info. I would like to share this with my friends to explore more about this 

kasstri
50%
50%
kasstri,
User Rank: Strategist
11/28/2016 | 11:12:26 AM
Re: keydown
Thanks for your post, BPID... we hear this same refrain with each new threat type that emerges: Vendors can fix this in software without involving the user. And yet here we are again!
Benefiter
50%
50%
Benefiter,
User Rank: Apprentice
11/28/2016 | 9:46:54 AM
2 przykazania miłości Modlitwa do Ducha Świętego o wyproszenie łask

It's actually a cool and useful piece of information. I am glad that you shared this helpful information with us.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 11:19:40 PM
Re: Ransomware defense strategy
FWIW, virtualized sandboxing has been shown to be an effective countermeasure against ransomware -- and, indeed, that some forms of modern ransomware even actively scan for virtualized instances and decline to install if they find any (lest they be subjected to reverse engineering).
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 11:01:03 PM
Re: Randsomware industry
@Terry: The only way I see regulation having an impact here is if it regulates businesses in certain sectors (e.g., healthcare, financial services, etc.) to specifically refuse to pay ransoms or set limits on the amounts they can pay -- and make the penalties for paying ransoms so substantial that such businesses would be compelled to not so pay.

And, as such, those regulations would be completely unworkable.  If a hospital's data is held ransom, human lives and limbs are at stake.  If a financial services' firm or even a generic Fortune 50 firm is held hostage, the entire global economy is at stake.

If those working in public policy really want to make a difference here, the solution is not regulation or legislation but rather better investment in improving cybersecurity.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 10:55:36 PM
Re: Randsomware industry
We don't need more regulation or laws here.  This is already covered by existing laws and regulations (standard wire-fraud laws, plus the CFAA, for starters).
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/27/2016 | 10:54:30 PM
Re: Ransomware defense strategy
@Dr. T: The whole point goes to understanding.

If you're using an OS based in the command line, whether Unix, old-school MS-DOS, or whatever, you naturally have to know much more about what's going on on your machine than the average MacOSX or Windows user.  As such, you're more of a power user and in general will position yourself better.
ClaireEllison
50%
50%
ClaireEllison,
User Rank: Apprentice
11/27/2016 | 2:47:55 PM
Re: Industry
Excellent article plus its information and I positively bookmark to this site because here I always get an amazing knowledge as I expect.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/27/2016 | 2:39:58 PM
Re: Ransomware defense strategy
"We need legislation to clearly identify responsibility and the limits of that responsibility. " I agree with this. Added to that it needs to clarify accountability for the offenders.
Page 1 / 3   >   >>


Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
Tor Weaponized to Steal Bitcoin
Dark Reading Staff 10/18/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18218
PUBLISHED: 2019-10-21
cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
CVE-2019-18217
PUBLISHED: 2019-10-21
ProFTPD before 1.3.6b and 1.3.7rc before 1.3.7rc2 allows remote unauthenticated denial-of-service due to incorrect handling of overly long commands because main.c in a child process enters an infinite loop.
CVE-2019-16862
PUBLISHED: 2019-10-21
Reflected XSS in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 allows a remote attacker to execute arbitrary code in the context of a user's session via the pid parameter.
CVE-2019-17409
PUBLISHED: 2019-10-21
Reflected XSS exists in interface/forms/eye_mag/view.php in OpenEMR 5.x before 5.0.2.1 ia the id parameter.
CVE-2019-10715
PUBLISHED: 2019-10-21
There is Stored XSS in Verodin Director before 3.5.4.0 via input fields of certain tooltips, and on the Tags, Sequences, and Actors pages.