Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

News & Commentary
'Box Shield' Brings New Security Controls
Kelly Sheridan, Staff Editor, Dark ReadingNews
New controls and threat detection capabilities built into Box aim to prevent accidental data leakage and misuse.
By Kelly Sheridan Staff Editor, Dark Reading, 8/21/2019
Comment0 comments  |  Read  |  Post a Comment
7 Big Factors Putting Small Businesses At Risk
Kelly Sheridan, Staff Editor, Dark Reading
Small organizations still face a long list of security threats. These threats and vulnerabilities should be top of mind.
By Kelly Sheridan Staff Editor, Dark Reading, 8/21/2019
Comment0 comments  |  Read  |  Post a Comment
68% of Companies Say Red Teaming Beats Blue Teaming
Dark Reading Staff, Quick Hits
The majority of organizations surveyed find red team exercises more effective than blue team testing, research shows.
By Dark Reading Staff , 8/15/2019
Comment0 comments  |  Read  |  Post a Comment
Stronger Defenses Force Cybercriminals to Rethink Strategy
Kelly Sheridan, Staff Editor, Dark ReadingNews
Researchers see the rise of new relationships and attack techniques as criminals put companies' resilience to the test.
By Kelly Sheridan Staff Editor, Dark Reading, 8/14/2019
Comment0 comments  |  Read  |  Post a Comment
Microsoft Patches Wormable RCE Vulns in Remote Desktop Services
Kelly Sheridan, Staff Editor, Dark ReadingNews
Similar to the now-patched 'BlueKeep' vulnerability, two flaws fixed today could let malware spread across vulnerable computers.
By Kelly Sheridan Staff Editor, Dark Reading, 8/13/2019
Comment3 comments  |  Read  |  Post a Comment
2019 Pwnie Award Winners (And Those Who Wish They Weren't)
Jai Vijayan, Contributing Writer
This year's round-up includes awards into two new categories: most under-hyped research and epic achievement.
By Jai Vijayan Contributing Writer, 8/13/2019
Comment0 comments  |  Read  |  Post a Comment
Rethinking Website Spoofing Mitigation
Dr. Salvatore Stolfo, Fouder & CTO, Allure SecurityCommentary
Deception technology is evolving rapidly, making it easier for organizations to turn the tables on their attackers. Here's how.
By Dr. Salvatore Stolfo Fouder & CTO, Allure Security, 8/7/2019
Comment5 comments  |  Read  |  Post a Comment
Russian Attack Group Uses Phones & Printers to Breach Corporate Networks
Dark Reading Staff, Quick Hits
Microsoft spotted Strontium, also known as APT28 or Fancy Bear, using IoT devices to breach businesses and seek high-value data.
By Dark Reading Staff , 8/6/2019
Comment1 Comment  |  Read  |  Post a Comment
Destructive Malware Attacks Up 200% in 2019
Kelly Sheridan, Staff Editor, Dark ReadingNews
Organizations hit with destructive malware can lose more than 12,000 machines and face $200 million or more in costs, IBM X-Force reports.
By Kelly Sheridan Staff Editor, Dark Reading, 8/5/2019
Comment0 comments  |  Read  |  Post a Comment
Capital One: What We Should Learn This Time
Kelly Sheridan, Staff Editor, Dark ReadingNews
Where Capital One went wrong, what the bank did right, and more key takeaways from the latest mega-breach.
By Kelly Sheridan Staff Editor, Dark Reading, 8/2/2019
Comment2 comments  |  Read  |  Post a Comment
Google Cloud Debuts New Security Capabilities
Dark Reading Staff, Quick Hits
Updates include Advanced Protection Program for the enterprise and general availability of password vaulted apps in Cloud Identity and G Suite.
By Dark Reading Staff , 7/31/2019
Comment3 comments  |  Read  |  Post a Comment
Why the Network Is Central to IoT Security
Jon Green, President & CTO for Security at Aruba Networks, a Hewlett Packard EnterpriseCommentary
Is there something strange about your network activity? Better make sure all of your IoT devices are under control.
By Jon Green President & CTO for Security at Aruba Networks, a Hewlett Packard Enterprise, 7/31/2019
Comment1 Comment  |  Read  |  Post a Comment
Former Twitter CISO Launches Startup to Secure Cloud Collaboration
Kelly Sheridan, Staff Editor, Dark ReadingNews
Altitude Networks, led by Michael Coates and Amir Kavousian, aims to prevent accidental and malicious file sharing.
By Kelly Sheridan Staff Editor, Dark Reading, 7/31/2019
Comment0 comments  |  Read  |  Post a Comment
8 Free Tools to Be Showcased at Black Hat and DEF CON
Ericka Chickowski, Contributing Writer
Expect a full slate of enterprise-class open source tools to take the spotlight when security researchers share their bounties with the community at large.
By Ericka Chickowski Contributing Writer, 7/31/2019
Comment0 comments  |  Read  |  Post a Comment
Capital One Breach Affects 100M US Citizens, 6M Canadians
Kelly Sheridan, Staff Editor, Dark ReadingNews
The breach exposed credit card application data, Social Security numbers, and linked bank accounts, among other information.
By Kelly Sheridan Staff Editor, Dark Reading, 7/30/2019
Comment10 comments  |  Read  |  Post a Comment
4 Network Security Mistakes Bound to Bite You
Shane Buckley, President & Chief Operating Officer, GigamonCommentary
It's Shark Week again! Are you ready to outmaneuver sharks of the cyber variety? These tips can help.
By Shane Buckley President & Chief Operating Officer, Gigamon, 7/29/2019
Comment1 Comment  |  Read  |  Post a Comment
FormGet Storage Bucket Leaks Passport Scans, Bank Details
Dark Reading Staff, Quick Hits
Exposed files include mortgage and loan information, passport and driver's license scans, internal corporate files, and shipping labels.
By Dark Reading Staff , 7/26/2019
Comment1 Comment  |  Read  |  Post a Comment
Johannesburg Ransomware Attack Leaves Residents in the Dark
Kelly Sheridan, Staff Editor, Dark ReadingNews
The virus affected the network, applications, and databases at City Power, which delivers electricity to the South African financial hub.
By Kelly Sheridan Staff Editor, Dark Reading, 7/25/2019
Comment7 comments  |  Read  |  Post a Comment
VPNs' Future: Less Reliant on Users, More Transparent, And Smarter
Terry Sweeney, Contributing Editor
Virtual private networking is poised to become more automated and intelligent, especially as endpoints associated with cloud services and the IoT need protection.
By Terry Sweeney Contributing Editor, 7/24/2019
Comment2 comments  |  Read  |  Post a Comment
New IPS Architecture Uses Network Flow Data for Analysis
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
Can a stream of data intended for network performance monitoring be the basis of network security? One company says the answer is 'yes.'
By Curtis Franklin Jr. Senior Editor at Dark Reading, 7/23/2019
Comment1 Comment  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
The Flaw in Vulnerability Management: It's Time to Get Real
Jim Souders, Chief Executive Officer at Adaptiva,  8/15/2019
Tough Love: Debunking Myths about DevOps & Security
Jeff Williams, CTO, Contrast Security,  8/19/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5638
PUBLISHED: 2019-08-21
Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated credential leak, that user accou...
CVE-2019-6177
PUBLISHED: 2019-08-21
A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standard locations, potentially leading to privilege escalation. Lenovo ended support for Lenovo Solution Center and recommended that customers migrate to Le...
CVE-2019-10687
PUBLISHED: 2019-08-21
KBPublisher 6.0.2.1 has SQL Injection via the admin/index.php?module=report entry_id[0] parameter, the admin/index.php?module=log id parameter, or an index.php?View=print&id[]= request.
CVE-2019-11601
PUBLISHED: 2019-08-21
A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location.
CVE-2019-11602
PUBLISHED: 2019-08-21
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.