Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3506PUBLISHED: 2021-04-19
An out-of-bounds (OOB) memory access flaw was found in fs/f2fs/node.c in the f2fs module in the Linux kernel in versions before 5.12.0-rc4. A bounds check failure allows a local attacker to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information. The hi...
CVE-2021-20208PUBLISHED: 2021-04-19A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.
CVE-2021-27458PUBLISHED: 2021-04-19
If Ethernet communication of the JTEKT Corporation TOYOPUC product series’ (TOYOPUC-PC10 Series: PC10G-CPU TCC-6353: All versions, PC10GE TCC-6464: All versions, PC10P TCC-6372: All versions, PC10P-DP TCC-6726: All versions, PC10P-DP-IO TCC-6752: All versions, PC10B-P TCC-6373: Al...
CVE-2020-27241PUBLISHED: 2021-04-19
An exploitable SQL injection vulnerability exists in ‘getAssets.jsp’ page of OpenClinic GA 5.173.3. The serialnumber parameter in the getAssets.jsp page is vulnerable to unauthenticated SQL injection. An attacker can make an authenticated HTTP request to trigger...
CVE-2021-3497PUBLISHED: 2021-04-19GStreamer before 1.18.4 might access already-freed memory in error code paths when demuxing certain malformed Matroska files.
User Rank: Apprentice
7/19/2017 | 8:27:03 AM
CSO Magazine said this year that worldwide, there are 1 Million unfilled jobs. When you consider women in the network defender community, we find that they are almost non-existent. Forbes said last year that women make up only 11% of the cybersecurity workforce. If you add a minority to that checklist, say a black or Hispanic woman, that number drops to under 1%.
Clearly, if we are to close the gap, women and minorities have to be a source.
And we just can't tell our HR departments to hire more. Facebook, Google and others have all tried and failed.
Part of problem is that many women and minorities lose interest in STEM (Science, technology, engineering and math) subjects before they get to college. There are many reasons for this that have been well documented: male dominated culture turns women off, popular culture pushes women into "traditional" women's roles, minorities do not have access to strong STEM education, and others.
Another part of the problem stems from the cybersecurity old guard (Old white guys). We are the ones doing the hiring. We are the ones that tolerate sexism in the workplace when what we should be doing is stamping it out at every opportunity. We are the ones that are not mentoring the few minorities that do work for us and knocking down the obstacles that prevent them from succeeding.
This is the message that the network defender community should be hearing; especially from the old guard. Presenting that information at one of the most well-attended network defender conferences on the planet is a good place to do it.
Very respectfully,
Rick Howard
CSO
Palo Alto Networks
Full Disclosure: I am on Kelly's panel at Blackhat.