Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
DHS-FBI Report Shows Russian Attribution's A Bear
Newest First  |  Oldest First  |  Threaded View
nosmo_king
50%
50%
nosmo_king,
User Rank: Strategist
1/9/2017 | 10:25:56 AM
Re: A treaty with Russia is overdue
Even if such a treaty could be signed, would it have any meaning?

Look at how the Russians violated the various peace treaties they agreed to in Syria.

If they are prepared to flagrantly break their word in such a way that people lose their lives, what is going to stop them from doing the same in regard to hacking and cyber espionage?

The Russians are aware that the US will take no meaningful action against them when a treaty violation occurs. If there are no consequences for those actions, what is the point of having a treaty?

The US needs to "grow a pair" and actually hold their treaty partners accountable for their actions. Not just the Russians and the Chinese, but all treaty partners.

End of rant.
JoeM066
50%
50%
JoeM066,
User Rank: Strategist
1/5/2017 | 10:11:49 AM
A treaty with Russia is overdue
Obama managed to establish a treaty with China over hacking. That seems to be working since the Chinese are not cited much anymore over hacking. A similar treaty is needed with Russia. The blatant attacks with little coverup highlight our broken relationship with Russia. Hopefully Trump can come to terms with his buddy Putin on this issue.


Sodinokibi Ransomware: Where Attackers' Money Goes
Kelly Sheridan, Staff Editor, Dark Reading,  10/15/2019
How to Think Like a Hacker
Dr. Giovanni Vigna, Chief Technology Officer at Lastline,  10/10/2019
7 SMB Security Tips That Will Keep Your Company Safe
Steve Zurier, Contributing Writer,  10/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: The old using of sock puppets for Shoulder Surfing technique. 
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17672
PUBLISHED: 2019-10-17
WordPress before 5.2.4 is vulnerable to a stored XSS attack to inject JavaScript into STYLE elements.
CVE-2019-17673
PUBLISHED: 2019-10-17
WordPress before 5.2.4 is vulnerable to poisoning of the cache of JSON GET requests because certain requests lack a Vary: Origin header.
CVE-2019-17674
PUBLISHED: 2019-10-17
WordPress before 5.2.4 is vulnerable to stored XSS (cross-site scripting) via the Customizer.
CVE-2019-17675
PUBLISHED: 2019-10-17
WordPress before 5.2.4 does not properly consider type confusion during validation of the referer in the admin pages, possibly leading to CSRF.
CVE-2019-17676
PUBLISHED: 2019-10-17
app/system/admin/admin/index.class.php in MetInfo 7.0.0beta allows a CSRF attack to add a user account via a doSaveSetup action to admin/index.php, as demonstrated by an admin/?n=admin&c=index&a=doSaveSetup URI.