Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
WannaCry? Youre Not Alone: The 5 Stages of Security Grief
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
7/19/2017 | 3:50:18 PM
Re: Do the best you can during the countdown to inevitability
At Aon many years ago in Manhattan, a lawyer checked his wireless connects and saw one just across town - turned to the window and said " Wow - Citibank."  With no buildings inbetween, he could see it plain as day.  
EricT981
50%
50%
EricT981,
User Rank: Author
6/26/2017 | 4:04:38 PM
Re: Anger
Totally agree. The JP Morgan Chase breach should have been a wake-up call. I'm sure their security budgets are enormous and I know they employ some very talented people.
EricT981
50%
50%
EricT981,
User Rank: Author
6/26/2017 | 4:03:21 PM
Re: Reality
Thanks! Appreciate the feedback!
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:26:58 PM
Yahoo case
"which went undetected for four months as attackers siphoned data out of the fortress."

Very important. In Yahoo case it was years, unbelievable.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:25:22 PM
Anger
 

"Your favorite restaurant/ department store /multinational bank gets hacked"

This is where we get agree at our shopping store but never link it back to our own situation.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:22:48 PM
Re: Do the best you can during the countdown to inevitability
"detect / mitigate phishing"

That makes sense, it is difficult since in involves the end users behavioral change. Something hard to do.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:21:06 PM
Re: Do the best you can during the countdown to inevitability
"Career Is Soon Over"

I agree. However CISO keep telling the business that there is high risk, unfortunately they do not get enough attention.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
6/26/2017 | 2:18:48 PM
Reality
Enjoyed reading the article. It reflects the reality on the ground. Most of us do not think we would get hit.
EricT981
50%
50%
EricT981,
User Rank: Author
6/22/2017 | 12:50:46 PM
Re: Do the best you can during the countdown to inevitability
I'd love to see the defenders get to Resolve... unfortunately, as you say, until we find a way to effectively detect / mitigate phishing it's gonna be a long road.
cybersavior
100%
0%
cybersavior,
User Rank: Strategist
6/22/2017 | 12:26:50 PM
Do the best you can during the countdown to inevitability
CISO's know.  They don't call it "Carreer Is Soon Over" for nothing.  It's the hotseat and any ignorant user that gets phished can signal that your time is up.  As you say, there are companies that have been breached and those that will be breached.  Maybe the last stage is Resolve.


Tor Weaponized to Steal Bitcoin
Dark Reading Staff 10/18/2019
Data Privacy Protections for the Most Vulnerable -- Children
Dimitri Sirota, Founder & CEO of BigID,  10/17/2019
State of SMB Insecurity by the Numbers
Ericka Chickowski, Contributing Writer,  10/17/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-9501
PUBLISHED: 2019-10-22
The Artificial Intelligence theme before 1.2.4 for WordPress has XSS because Genericons HTML files are unnecessarily placed under the web root.
CVE-2019-16971
PUBLISHED: 2019-10-22
In FusionPBX up to 4.5.7, the file app\messages\messages_thread.php uses an unsanitized "contact_uuid" variable coming from the URL, which is reflected on 3 occasions in HTML, leading to XSS.
CVE-2019-16972
PUBLISHED: 2019-10-22
In FusionPBX up to 4.5.7, the file app\contacts\contact_addresses.php uses an unsanitized "id" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2019-16973
PUBLISHED: 2019-10-22
In FusionPBX up to 4.5.7, the file app\contacts\contact_edit.php uses an unsanitized "query_string" variable coming from the URL, which is reflected in HTML, leading to XSS.
CVE-2015-9496
PUBLISHED: 2019-10-22
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.