Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Analytics //

Security Monitoring

News & Commentary
Cyber Is the New Cold War & AI Is the Arms Race
Nancy Grady, Chief Data Scientist & Solutions ArchitectCommentary
Continual cyberattacks have pushed us into a new kind of Cold War, with artificial intelligence the basis of this new arms race.
By Nancy Grady Chief Data Scientist & Solutions Architect, 6/10/2021
Comment0 comments  |  Read  |  Post a Comment
Modern SOCs a 'Painful' Challenge Amid Growing Complexity: Report
Dark Reading Staff, Quick Hits
A new study examines the tools and technologies driving investment and activities for security operations centers.
By Dark Reading Staff , 5/28/2021
Comment0 comments  |  Read  |  Post a Comment
Devo: SIEM Continues to Evolve with Tech Trends and Emerging Threats
Terry Sweeney, Contributing EditorCommentary
SPONSORED: WATCH NOW -- Some organizations split the difference with a hybrid of premises- and cloud-based SIEM, says Ted Julian, senior VP of product at Devo. As security data volumes continue to increase, SIEM's evolution will only continue.
By Terry Sweeney Contributing Editor, 5/26/2021
Comment0 comments  |  Read  |  Post a Comment
Rise in Opportunistic Hacks and Info-Sharing Imperil Industrial Networks
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Security researchers at Mandiant have seen an increasing wave of relatively simplistic attacks involving ICS systems - and attackers sharing their finds with one another - since 2020.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 5/25/2021
Comment0 comments  |  Read  |  Post a Comment
Lack of Skills, Maturity Hamper Threat Hunting at Many Organizations
Jai Vijayan, Contributing WriterNews
When implemented correctly, threat hunting can help organizations stay head of threats, researcher says at RSA Conference.
By Jai Vijayan Contributing Writer, 5/20/2021
Comment0 comments  |  Read  |  Post a Comment
Cobalt Strike Becomes a Preferred Hacking Tool by Cybercrime, APT Groups
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Incident response cases and research show how the red-team tool has become a become a go-to for attackers.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 5/19/2021
Comment0 comments  |  Read  |  Post a Comment
SOC Teams Burdened by Alert Fatigue Explore XDR
Joan Goodchild, Staff EditorQuick Hits
ESG research finds a complex attack surface and threat landscape make alerts too overwhelming to monitor accurately
By Joan Goodchild Staff Editor, 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
Dragos & IronNet Partner on Critical Infrastructure Security
Dark Reading Staff, Quick Hits
The IT and OT security providers will integrate solutions aimed at improving critical infrastructure security
By Dark Reading Staff , 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
A Startup With NSA Roots Wants Silently Disarming Cyberattacks on the Wire to Become the Norm
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Trinity Cyber takes a new spin on some traditional network-security techniques, but can its approach catch on widely?
By Kelly Jackson Higgins Executive Editor at Dark Reading, 5/11/2021
Comment1 Comment  |  Read  |  Post a Comment
Do Cyberattacks Affect Stock Prices? It Depends on the Breach
Kelly Sheridan, Staff Editor, Dark ReadingNews
A security researcher explores how data breaches, ransomware attacks, and other types of cybercrime influence stock prices.
By Kelly Sheridan Staff Editor, Dark Reading, 4/27/2021
Comment0 comments  |  Read  |  Post a Comment
XDR: A Game-Changer in Enterprise Threat Detection
Eric Parizo, Principal Analyst, Security Operations, OmdiaCommentaryVideo
Omdia's Eric Parizo highlights four capabilities that show how XDR technology is reinventing enterprise threat detection.
By Eric Parizo Principal Analyst, Security Operations, Omdia, 4/27/2021
Comment0 comments  |  Read  |  Post a Comment
Name That Toon: Greetings, Earthlings
John Klossner, CartoonistCommentary
Caption time! Come up with something out of this world for Dark Reading's latest contest, and our panel of experts will reward the winner with a $25 Amazon gift card.
By John Klossner Cartoonist, 4/22/2021
Comment17 comments  |  Read  |  Post a Comment
Rapid7 Acquires Velociraptor Open Source Project
Dark Reading Staff, Quick Hits
The company plans to use Velociraptor's technology and insights to build out its own incident response capabilities.
By Dark Reading Staff , 4/21/2021
Comment0 comments  |  Read  |  Post a Comment
Pandemic Drives Greater Need for Endpoint Security
Dark Reading Staff, Quick Hits
Endpoint security has changed. Can your security plan keep up?
By Dark Reading Staff , 4/16/2021
Comment0 comments  |  Read  |  Post a Comment
Pandemic Pushes Bot Operators to Redirect Efforts
Robert Lemos, Contributing WriterNews
As demand for travel, lodging, and concerts plummeted in 2020, bot traffic moved to more popular activities, such as e-commerce, healthcare, and government sites.
By Robert Lemos Contributing Writer, 4/15/2021
Comment0 comments  |  Read  |  Post a Comment
Microsoft Uses Machine Learning to Predict Attackers' Next Steps
Robert Lemos, Contributing WriterNews
Researchers build a model to attribute attacks to specific groups based on tactics, techniques, and procedures, and then figure out their next move.
By Robert Lemos Contributing Writer, 4/12/2021
Comment0 comments  |  Read  |  Post a Comment
CISA Launches New Threat Detection Dashboard
Dark Reading Staff, Quick Hits
Aviary is a new dashboard that works with CISA's Sparrow threat detection tool.
By Dark Reading Staff , 4/9/2021
Comment0 comments  |  Read  |  Post a Comment
Kaseya Buys Managed SOC Provider
Dark Reading Staff, Quick Hits
Purchase extends offerings for MSP and SMB customers
By Dark Reading Staff , 2/24/2021
Comment0 comments  |  Read  |  Post a Comment
An Observability Pipeline Could Save Your SecOps Team
Nick Heudecker, Senior Director of Market Strategy, CriblCommentary
Traditional monitoring approaches are proving brittle as security operations teams need better visibility into dynamic environments.
By Nick Heudecker Senior Director of Market Strategy, Cribl, 2/3/2021
Comment0 comments  |  Read  |  Post a Comment
Strengthening Zero-Trust Architecture
Carolyn Crandall, Chief Security Advocate and CMO at Attivo NetworksCommentary
Organizations that want to stay ahead of cybercriminals will find that going beyond user trust and device trust is critical for outwitting their adversaries.
By Carolyn Crandall Chief Security Advocate and CMO at Attivo Networks, 2/1/2021
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
Cyberattacks Are Tailored to Employees ... Why Isn't Security Training?
Tim Sadler, CEO and co-founder of Tessian,  6/17/2021
7 Powerful Cybersecurity Skills the Energy Sector Needs Most
Pam Baker, Contributing Writer,  6/22/2021
Microsoft Disrupts Large-Scale BEC Campaign Across Web Services
Kelly Sheridan, Staff Editor, Dark Reading,  6/15/2021
Register for Dark Reading Newsletters
White Papers
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
PUBLISHED: 2021-06-24
Cross Site Scripting (XSS) vulnerability in gnuboard5 <=v5.3.2.8 via the url parameter to bbs/login.php.
PUBLISHED: 2021-06-24
CRMEB 3.1.0+ is vulnerable to File Upload Getshell via /crmeb/crmeb/services/UploadService.php.
PUBLISHED: 2021-06-24
In CRMEB 3.1.0+ strict domain name filtering leads to SSRF(Server-Side Request Forgery). The vulnerable code is in file /crmeb/app/admin/controller/store/CopyTaobao.php.
PUBLISHED: 2021-06-24
All versions of package react-bootstrap-table are vulnerable to Cross-site Scripting (XSS) via the dataFormat parameter. The problem is triggered when an invalid React element is returned, leading to dangerouslySetInnerHTML being used, which does not sanitize the output.
PUBLISHED: 2021-06-24
An issue was discovered in JFinal framework v4.9.10 and below. The "set" method of the "Controller" class of jfinal framework is not strictly filtered, which will lead to XSS vulnerabilities in some cases.