Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

News & Commentary
AWS CISO Talks Risk Reduction, Development, Recruitment
Kelly Sheridan, Staff Editor, Dark ReadingNews
Steve Schmidt says limiting access to data has dramatically changed the security posture across Amazon Web Services.
By Kelly Sheridan Staff Editor, Dark Reading, 6/25/2019
Comment1 Comment  |  Read  |  Post a Comment
AWS Makes Control Tower & Security Hub Generally Available
Dark Reading Staff, Quick Hits
Security Hub aims to manage security across an AWS environment; Control Tower handles security and compliance for multi-account environments.
By Dark Reading Staff , 6/25/2019
Comment0 comments  |  Read  |  Post a Comment
How to Avoid Becoming the Next Riviera Beach
Todd Weller, Chief Strategy Officer at Bandura CyberCommentary
Be prepared by following these five steps so you don't have to pay a ransom to get your data back.
By Todd Weller Chief Strategy Officer at Bandura Cyber, 6/25/2019
Comment0 comments  |  Read  |  Post a Comment
A Socio-Technical Approach to Cybersecurity's Problems
Kelly Sheridan, Staff Editor, Dark ReadingNews
Researchers explore how modern security problems can be solved with an examination of society, technology, and security.
By Kelly Sheridan Staff Editor, Dark Reading, 6/24/2019
Comment0 comments  |  Read  |  Post a Comment
Never Trust, Always Verify: Demystifying Zero Trust to Secure Your Networks
John Kindervag, Field CTO at Palo Alto NetworksCommentary
The point of Zero Trust is not to make networks, clouds, or endpoints more trusted; it's to eliminate the concept of trust from digital systems altogether.
By John Kindervag Field CTO at Palo Alto Networks, 6/24/2019
Comment0 comments  |  Read  |  Post a Comment
Cyber-Risks Hiding Inside Mobile App Stores
Kelly Sheridan, Staff Editor, Dark ReadingNews
As the number of blacklisted apps on Google Play continues to drop, attackers find new ways to compromise smartphones.
By Kelly Sheridan Staff Editor, Dark Reading, 6/21/2019
Comment0 comments  |  Read  |  Post a Comment
Pledges to Not Pay Ransomware Hit Reality
Robert Lemos, Contributing WriterNews
While risk analysts and security experts continue to urge companies to secure systems against ransomware, they are now also advising that firms be ready to pay.
By Robert Lemos Contributing Writer, 6/21/2019
Comment2 comments  |  Read  |  Post a Comment
Startup Raises $13.7M to Stop Breaches with Behavioral Analytics
Dark Reading Staff, Quick Hits
TrueFort plans to use the funding to expand sales, marketing, R&D, customer support, and go-to-market initiatives.
By Dark Reading Staff , 6/21/2019
Comment1 Comment  |  Read  |  Post a Comment
Florida Town Pays $600K to Ransomware Operators
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
Riviera Beach's decision to pay ransom to criminals might get files back, but it almost guarantees greater attacks against other governments.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 6/20/2019
Comment4 comments  |  Read  |  Post a Comment
Small Businesses May Not Be Security's Weak Link
Dark Reading Staff, Quick Hits
Organizations with 250 or fewer employees often employ a higher percentage of security pros than their larger counterparts.
By Dark Reading Staff , 6/20/2019
Comment1 Comment  |  Read  |  Post a Comment
Cybersecurity Accountability Spread Thin in the C-Suite
Ericka Chickowski, Contributing WriterNews
While cybersecurity discussions have permeated board meetings, the democratization of accountability has a long way to go.
By Ericka Chickowski Contributing Writer, 6/20/2019
Comment0 comments  |  Read  |  Post a Comment
The Hunt for Vulnerabilities
Jim Souders, Chief Executive Officer at AdaptivaCommentary
A road map for improving the update process will help reduce the risks from vulnerabilities.
By Jim Souders Chief Executive Officer at Adaptiva, 6/20/2019
Comment1 Comment  |  Read  |  Post a Comment
With GDPR's 'Right of Access,' Who Really Has Access?
Kelly Sheridan, Staff Editor, Dark ReadingNews
How a security researcher learned organizations willingly hand over sensitive data with little to no identity verification.
By Kelly Sheridan Staff Editor, Dark Reading, 6/19/2019
Comment0 comments  |  Read  |  Post a Comment
Serverless Computing from the Inside Out
Joe Vadakkan, Global Cloud Security Leader, Optiv SecurityCommentary
The biggest 'serverless' risks don't stem from the technology itself. They occur when organizations respond to the adoption from the outside in.
By Joe Vadakkan Global Cloud Security Leader, Optiv Security, 6/19/2019
Comment0 comments  |  Read  |  Post a Comment
Cost per Cyberattack Jumps to $4.6M in 2019
Dark Reading Staff, Quick Hits
From 2018 to 2019, the percentage of cyberattacks costing $10 million or more nearly doubled, hitting 13%.
By Dark Reading Staff , 6/19/2019
Comment1 Comment  |  Read  |  Post a Comment
How Hackers Emptied Church Coffers with a Simple Phishing Scam
Sam Bocetta, Security AnalystCommentary
Cyber thieves aren't bound by a code of ethics. They look for weak targets and high rewards, which is exactly what Saint Ambrose Catholic offered.
By Sam Bocetta Security Analyst, 6/19/2019
Comment0 comments  |  Read  |  Post a Comment
As Cloud Adoption Grows, DLP Remains Key Challenge
Kelly Sheridan, Staff Editor, Dark ReadingNews
As businesses use the cloud to fuel growth, many fail to enforce data loss prevention or control how people share data.
By Kelly Sheridan Staff Editor, Dark Reading, 6/18/2019
Comment0 comments  |  Read  |  Post a Comment
Advertising Alliance Plans Protocols to Reduce Dangerous Content
Dark Reading Staff, Quick Hits
The Global Alliance for Responsible Media will seek ways to clamp down on dangerous and fake content.
By Dark Reading Staff , 6/18/2019
Comment0 comments  |  Read  |  Post a Comment
The Evolution of Identity
Kathleen Peters, SVP & Head of Fraud & Identity, ExperianCommentary
How data and technology can help businesses make the right fraud decisions, protect people's identities, and create an improved customer experience.
By Kathleen Peters SVP & Head of Fraud & Identity, Experian, 6/18/2019
Comment0 comments  |  Read  |  Post a Comment
Can Your Patching Strategy Keep Up with the Demands of Open Source?
 Tim Mackey, Principal Security Strategist, CyRC, at SynopsysCommentary
It's time to reassess your open source management policies and processes.
By Tim Mackey Principal Security Strategist, CyRC, at Synopsys, 6/18/2019
Comment4 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
Florida Town Pays $600K to Ransomware Operators
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/20/2019
Pledges to Not Pay Ransomware Hit Reality
Robert Lemos, Contributing Writer,  6/21/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-12280
PUBLISHED: 2019-06-25
PC-Doctor Toolbox before 7.3 has an Uncontrolled Search Path Element.
CVE-2019-3961
PUBLISHED: 2019-06-25
Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code in a users browse...
CVE-2019-9836
PUBLISHED: 2019-06-25
Secure Encrypted Virtualization (SEV) on Advanced Micro Devices (AMD) Platform Security Processor (PSP; aka AMD Secure Processor or AMD-SP) 0.17 build 11 and earlier has an insecure cryptographic implementation.
CVE-2019-6328
PUBLISHED: 2019-06-25
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329.
CVE-2019-6329
PUBLISHED: 2019-06-25
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6328.