Comments
72% of Government Agencies Hit with Security Incidents
Newest First  |  Oldest First  |  Threaded View
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
8/29/2017 | 8:09:23 AM
Re: Endpoint Security
No kidding on this one - right now our malware forensics group is tackling a download campaign, looking for "doc.pdf" openings!!!!!
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/28/2017 | 4:47:20 PM
Re: Endpoint Security
"Typically users don't understand the potential ramifications of their downloads." I agree, it comes back to awareness trainings, it should be an ongoing process.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/28/2017 | 4:46:15 PM
Re: Endpoint Security
"opening unknown compromised DOC and PDF attachments " That is really true, why would anybody open a document from an unknown source, that is no upside on it.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/28/2017 | 4:44:45 PM
Re: Endpoint Security
" If users could simply understand the DANGER of downloading and installing malicious software" That makes sense. Main problem are the users downloading malware from their emails mainly.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/28/2017 | 4:43:25 PM
Re: Endpoint Security
"include regular User Awareness Training" I would agree, awareness would be the key for it.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
8/28/2017 | 4:42:34 PM
72% of Government Agencies
This number seems so big and surprising. It shows the government is seen as a target for many, mainly other governments I would guess.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
8/25/2017 | 7:02:51 AM
Re: Endpoint Security
That's a great point. Typically users don't understand the potential ramifications of their downloads. Many won't until they have been personally burnt by the stove themselves. Reminds me of a statement my father makes, smart people learn from their mistakes but brilliant people learn from others'. Makes me hopeful that this sentiment could be utilized from a security perspective through user awareness.
REISEN1955
50%
50%
REISEN1955,
User Rank: Ninja
8/24/2017 | 3:05:06 PM
Re: Endpoint Security
Agree totally - you hit the three concentric rings of endpoint.  Training which should be mandatory and updated every six months.  A good security department (few firms have a dedicated one), search engine like Carbon Black and firm rules on user access to data (which prevents that other posted subject - data theft).  If users could simply understand the DANGER of downloading and installing malicious software AND opening unknown compromised DOC and PDF attachments --- JUST THOSE 2 THINGS  --- our security world would be MUCH BETTER off.  
RyanSepe
0%
100%
RyanSepe,
User Rank: Ninja
8/24/2017 | 7:24:51 AM
Endpoint Security
So action items moving forward need to include regular User Awareness Training, some type of SOC either onsite or third party, a heuristics malware detection engine, and limiting of user access (both administrative and internet based).


White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
Mueller Probe Yields Hacking Indictments for 12 Russian Military Officers
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/13/2018
10 Ways to Protect Protocols That Aren't DNS
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/16/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Siri??  You're a guy?
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-10727
PUBLISHED: 2018-07-20
camel/providers/imapx/camel-imapx-server.c in the IMAPx component in GNOME evolution-data-server before 3.21.2 proceeds with cleartext data containing a password if the client wishes to use STARTTLS but the server will not use STARTTLS, which makes it easier for remote attackers to obtain sensitive ...
CVE-2018-8018
PUBLISHED: 2018-07-20
Apache Ignite 2.5 and earlier serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a spe...
CVE-2018-14415
PUBLISHED: 2018-07-20
An issue was discovered in idreamsoft iCMS before 7.0.10. XSS exists via the fourth and fifth input elements on the admincp.php?app=prop&do=add screen.
CVE-2018-14418
PUBLISHED: 2018-07-20
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
CVE-2018-14419
PUBLISHED: 2018-07-20
MetInfo 6.0.0 allows XSS via a modified name of the navigation bar on the home page.