Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
WannaCry? Youre Not Alone: The 5 Stages of Security Grief
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
7/19/2017 | 3:50:18 PM
Re: Do the best you can during the countdown to inevitability
At Aon many years ago in Manhattan, a lawyer checked his wireless connects and saw one just across town - turned to the window and said " Wow - Citibank."  With no buildings inbetween, he could see it plain as day.  
EricT981
50%
50%
EricT981,
User Rank: Author
6/26/2017 | 4:04:38 PM
Re: Anger
Totally agree. The JP Morgan Chase breach should have been a wake-up call. I'm sure their security budgets are enormous and I know they employ some very talented people.
EricT981
50%
50%
EricT981,
User Rank: Author
6/26/2017 | 4:03:21 PM
Re: Reality
Thanks! Appreciate the feedback!
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:26:58 PM
Yahoo case
"which went undetected for four months as attackers siphoned data out of the fortress."

Very important. In Yahoo case it was years, unbelievable.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:25:22 PM
Anger
 

"Your favorite restaurant/ department store /multinational bank gets hacked"

This is where we get agree at our shopping store but never link it back to our own situation.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:22:48 PM
Re: Do the best you can during the countdown to inevitability
"detect / mitigate phishing"

That makes sense, it is difficult since in involves the end users behavioral change. Something hard to do.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:21:06 PM
Re: Do the best you can during the countdown to inevitability
"Career Is Soon Over"

I agree. However CISO keep telling the business that there is high risk, unfortunately they do not get enough attention.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:18:48 PM
Reality
Enjoyed reading the article. It reflects the reality on the ground. Most of us do not think we would get hit.
EricT981
50%
50%
EricT981,
User Rank: Author
6/22/2017 | 12:50:46 PM
Re: Do the best you can during the countdown to inevitability
I'd love to see the defenders get to Resolve... unfortunately, as you say, until we find a way to effectively detect / mitigate phishing it's gonna be a long road.
cybersavior
100%
0%
cybersavior,
User Rank: Strategist
6/22/2017 | 12:26:50 PM
Do the best you can during the countdown to inevitability
CISO's know.  They don't call it "Carreer Is Soon Over" for nothing.  It's the hotseat and any ignorant user that gets phished can signal that your time is up.  As you say, there are companies that have been breached and those that will be breached.  Maybe the last stage is Resolve.


A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
USB Drive Security Still Lags
Dark Reading Staff 10/9/2019
Virginia a Hot Spot For Cybersecurity Jobs
Jai Vijayan, Contributing Writer,  10/9/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17612
PUBLISHED: 2019-10-15
An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.
CVE-2019-17613
PUBLISHED: 2019-10-15
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in...
CVE-2019-17395
PUBLISHED: 2019-10-15
In the Rapid Gator application 0.7.1 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.
CVE-2019-17602
PUBLISHED: 2019-10-15
An issue was discovered in Zoho ManageEngine OpManager before 12.4 build 124089. The OPMDeviceDetailsServlet servlet is prone to SQL injection. Depending on the configuration, this vulnerability could be exploited unauthenticated or authenticated.
CVE-2019-17394
PUBLISHED: 2019-10-15
In the Seesaw Parent and Family application 6.2.5 for Android, the username and password are stored in the log during authentication, and may be available to attackers via logcat.