Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

12/18/2007
10:17 AM
Keith Ferrell
Keith Ferrell
Commentary
50%
50%

New Cisco Security Report: The Scary World We Work In Is Getting Scarier

A new state of the cybersecurity globe from Cisco (a bMighty sponsor) is plenty detailed -- and plenty scary. And it's a look at this year. Next year may be worse.

A new state of the cybersecurity globe from Cisco (a bMighty sponsor) is plenty detailed -- and plenty scary. And it's a look at this year. Next year may be worse.The company's "2007 Annual Security Report" covers the gamut of security issues and threats, including identity, vulnerabilities, physical, legal and geopolitical aspects of "Understanding Security in an Insecure World."

But it's the lead-in to the report's detailed point-by-point review that caught my attention, and should catch yours' and your employees'.

Characterizing the security year as one of "unprecedented innovation and adaptability in the realm of security threats," the report makes clear that traditional approaches to security -- while remaining essential -- are no longer sufficient.

Constant innovation, mixes and re-mixes of multi-faceted security strategies, technologies and approaches will be required of everyone, from those of us in the small and midsize business space to the bigbiz behemoths. And required from here on.

The thing about the crooks' "unprecedented innovation and adaptability" this year is that the precedent has now been set -- next year's report, I'll wager now, will measure 2008's badguy innovation against this year's.

Grab the Cisco Security Report and read it.

And the revamped Cisco Security Center is worth a close look too.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "I feel safe, but I can't understand a word he's saying."
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11111
PUBLISHED: 2020-03-31
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
CVE-2020-11112
PUBLISHED: 2020-03-31
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).
CVE-2020-11113
PUBLISHED: 2020-03-31
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-10374
PUBLISHED: 2020-03-30
A webserver component in Paessler PRTG Network Monitor 19.2.50 to PRTG 20.1.56 allows unauthenticated remote command execution via a crafted POST request or the what parameter of the screenshot function in the Contact Support form.
CVE-2020-11104
PUBLISHED: 2020-03-30
An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable into a BinaryArchive or PortableBinaryArchive leaks several bytes of stack or heap memory, from which sensitive information (such as memory layout or private keys) can be gleaned if...