Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

News & Commentary
First American Financial Corp. Left Mortgage Data Exposed on Website
Dark Reading Staff, Quick Hits
Real estate title firm reportedly has closed a hole in its website that had left hundreds of millions of real estate tile insurance files accessible without authentication, according to KrebsOnSecurity.
By Dark Reading Staff , 5/24/2019
Comment0 comments  |  Read  |  Post a Comment
How Security Vendors Can Address the Cybersecurity Talent Shortage
Rob Rashotte, VP of Global Training and Technical Field Enablement at FortinetCommentary
The talent gap is too large for any one sector, and cybersecurity vendors have a big role to play in helping to close it.
By Rob Rashotte VP of Global Training and Technical Field Enablement at Fortinet, 5/24/2019
Comment4 comments  |  Read  |  Post a Comment
Researcher Publishes Four Zero-Day Exploits in Three Days
Robert Lemos, Contributing WriterNews
The exploits for local privilege escalation vulnerabilities in Windows could be integrated into malware before Microsoft gets a chance to fix the issues.
By Robert Lemos Contributing Writer, 5/23/2019
Comment0 comments  |  Read  |  Post a Comment
To Manage Security Risk, Manage Data First
Kelly Sheridan, Staff Editor, Dark ReadingNews
At Interop 2019, IT and security experts urged attendees to focus on data asset management as a means of mitigating risk.
By Kelly Sheridan Staff Editor, Dark Reading, 5/23/2019
Comment0 comments  |  Read  |  Post a Comment
Mobile Exploit Fingerprints Devices with Sensor Calibration Data
Dark Reading Staff, Quick Hits
Data from routines intended to calibrate motion sensors can identify individual iOS and Android devices in a newly released exploit.
By Dark Reading Staff , 5/23/2019
Comment0 comments  |  Read  |  Post a Comment
Google's Origin & the Danger of Link Sharing
Dr. Salvatore Stolfo, Fouder & CTO, Allure SecurityCommentary
How the act of sharing links to files stored in a public cloud puts organizations at risk, and what security teams can do to safeguard data and PII.
By Dr. Salvatore Stolfo Fouder & CTO, Allure Security, 5/23/2019
Comment1 Comment  |  Read  |  Post a Comment
Incident Response: 3 Easy Traps & How to Avoid Them
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLCCommentary
Sage legal advice about navigating a data breach from a troubleshooting cybersecurity outside counsel.
By Beth Burgin Waller Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC, 5/23/2019
Comment2 comments  |  Read  |  Post a Comment
Alphabet's Chronicle Explores Code-Signing Abuse in the Wild
Kelly Sheridan, Staff Editor, Dark ReadingNews
A new analysis highlights the prevalence of malware signed by certificate authorities and the problems with trust-based security.
By Kelly Sheridan Staff Editor, Dark Reading, 5/22/2019
Comment0 comments  |  Read  |  Post a Comment
New Software Skims Credit Card Info From Online Credit Card Transactions
Dark Reading Staff, Quick Hits
The new exploit builds a fake frame around legitimate portions of an online commerce website.
By Dark Reading Staff , 5/22/2019
Comment3 comments  |  Read  |  Post a Comment
Proving the Value of Security Awareness with Metrics that 'Deserve More'
Ira Winkler, CISSP, President, Secure MentemCommentary
Without metrics that matter to the business, awareness programs will continue to be the bastard child of security.
By Ira Winkler CISSP, President, Secure Mentem, 5/22/2019
Comment0 comments  |  Read  |  Post a Comment
The 3 Cybersecurity Rules of Trust
Ari Singer, CTO at TrustPhiCommentary
Every day, keeping anything secure requires being smart about trust. The rules of trust will keep you and your data safer.
By Ari Singer CTO at TrustPhi, 5/22/2019
Comment0 comments  |  Read  |  Post a Comment
Consumer IoT Devices Are Compromising Enterprise Networks
Ericka Chickowski, Contributing WriterNews
While IoT devices continue to multiply, the latest studies show a dangerous lack of visibility into those connected to enterprise networks.
By Ericka Chickowski Contributing Writer, 5/22/2019
Comment0 comments  |  Read  |  Post a Comment
What You Need to Know About Zero Trust Security
Curtis Franklin Jr., Senior Editor at Dark Reading
The zero trust model might be the answer to a world in which perimeters are made to be breached. Is it right for your organization?
By Curtis Franklin Jr. Senior Editor at Dark Reading, 5/22/2019
Comment0 comments  |  Read  |  Post a Comment
Satan Ransomware Adds More Evil Tricks
Robert Lemos, Contributing WriterNews
The latest changes to the Satan ransomware framework demonstrate attackers are changing their operations while targeting victims more carefully.
By Robert Lemos Contributing Writer, 5/21/2019
Comment1 Comment  |  Read  |  Post a Comment
49 Million Instagram Influencer Records Exposed in Open Database
Dark Reading Staff, Quick Hits
An AWS-hosted database was configured with no username or password required for access to personal data.
By Dark Reading Staff , 5/21/2019
Comment0 comments  |  Read  |  Post a Comment
To Narrow the Cyber Skills Gap with Attackers, Cut the Red Tape
James Hadley, CEO at Immersive LabsCommentary
Attackers are getting further ahead, and entrenched corporate rules shoulder much of the blame.
By James Hadley CEO at Immersive Labs, 5/21/2019
Comment2 comments  |  Read  |  Post a Comment
Old Threats Are New Again
Liron Barak, CEO of BitDamCommentary
They may look familiar to you, and that isn't a coincidence. New threats are often just small twists on old ones.
By Liron Barak CEO of BitDam, 5/21/2019
Comment0 comments  |  Read  |  Post a Comment
TeamViewer Admits Breach from 2016
Dark Reading Staff, Quick Hits
The company says it stopped the attack launched by a Chinese hacking group.
By Dark Reading Staff , 5/20/2019
Comment3 comments  |  Read  |  Post a Comment
DHS Warns of Data Theft via Chinese-Made Drones
Dark Reading Staff, Quick Hits
The drones are reportedly built with parts that can compromise organizations' data and share it on a server accessible to the Chinese government.
By Dark Reading Staff , 5/20/2019
Comment0 comments  |  Read  |  Post a Comment
Financial Sector Under Siege
Marc Wilczek, Digital Strategist & CIO AdvisorCommentary
The old take-the-money-and-run approach has been replaced by siege tactics such as DDOS attacks and land-and-expand campaigns with multiple points of persistence and increased dwell time.
By Marc Wilczek Digital Strategist & CIO Advisor, 5/20/2019
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
97% of Americans Can't Ace a Basic Security Test
Steve Zurier, Contributing Writer,  5/20/2019
How Security Vendors Can Address the Cybersecurity Talent Shortage
Rob Rashotte, VP of Global Training and Technical Field Enablement at Fortinet,  5/24/2019
TeamViewer Admits Breach from 2016
Dark Reading Staff 5/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-7068
PUBLISHED: 2019-05-24
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
CVE-2019-7069
PUBLISHED: 2019-05-24
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution .
CVE-2019-7070
PUBLISHED: 2019-05-24
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .
CVE-2019-7071
PUBLISHED: 2019-05-24
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
CVE-2019-7072
PUBLISHED: 2019-05-24
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .