Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats //

Vulnerability Management

News & Commentary
3 Steps CISOs Can Take to Convey Strategy for Budget Presentations
Vinay Sridhara, CTO at BalbixCommentary
Answering these questions will help CISOs define a plan and take the organization in a positive direction.
By Vinay Sridhara CTO at Balbix, 11/23/2020
Comment0 comments  |  Read  |  Post a Comment
How Retailers Can Fight Fraud and Abuse This Holiday Season
Sunil Potti, General Manager and Vice President, Google Cloud SecurityCommentary
Online shopping will be more popular than ever with consumers... and with malicious actors too.
By Sunil Potti General Manager and Vice President, Google Cloud Security, 11/23/2020
Comment0 comments  |  Read  |  Post a Comment
The Yellow Brick Road to Risk Management
Andrew Lowe, Senior Information Security Consultant, TalaTekCommentary
Beginning the journey to risk management can be daunting, but protecting your business is worth every step.
By Andrew Lowe Senior Information Security Consultant, TalaTek, 11/19/2020
Comment1 Comment  |  Read  |  Post a Comment
2021 Cybersecurity Spending: How to Maximize Value
Gidi Cohen, Chief Executive Officer & Founder, Skybox SecurityCommentary
This is a pivotal moment for CISOs. As their influence increases, so does the pressure for them to make the right decisions.
By Gidi Cohen Chief Executive Officer & Founder, Skybox Security, 11/19/2020
Comment0 comments  |  Read  |  Post a Comment
Out With the Old Perimeter, in With the New Perimeters
Charlie Winckless, Senior Director, Cybersecurity Solutions, at PresidioCommentary
A confluence of trends and events has exploded the whole idea of "the perimeter." Now there are many perimeters, and businesses must adjust accordingly.
By Charlie Winckless Senior Director, Cybersecurity Solutions, at Presidio, 11/18/2020
Comment0 comments  |  Read  |  Post a Comment
How to Identify Cobalt Strike on Your Network
Zohar Buber, Security AnalystCommentary
Common antivirus systems frequently miss Cobalt Strike, a stealthy threat emulation toolkit admired by red teams and attackers alike.
By Zohar Buber Security Analyst, 11/18/2020
Comment2 comments  |  Read  |  Post a Comment
Vulnerability Prioritization Tops Security Pros' Challenges
David Habusha, VP of Product, WhiteSourceCommentary
Why vulnerability prioritization has become a top challenge for security professionals and how security and development teams can get it right.
By David Habusha VP of Product, WhiteSource, 11/17/2020
Comment0 comments  |  Read  |  Post a Comment
To Pay or Not to Pay: Responding to Ransomware From a Lawyer's Perspective
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLCCommentary
The threat of data extortion adds new layers of risk when determining how to respond to a ransomware attack.
By Beth Burgin Waller Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC, 11/17/2020
Comment0 comments  |  Read  |  Post a Comment
A Call for Change in Physical Security
Fred Burton, Executive Director, Ontic Center for Protective IntelligenceCommentary
We're at an inflection point. The threats we face are dynamic, emerging, and global. Are you ready?
By Fred Burton Executive Director, Ontic Center for Protective Intelligence, 11/16/2020
Comment4 comments  |  Read  |  Post a Comment
A Hacker's Holiday: How Retailers Can Avoid Black Friday Cyber Threats
Matthew McGuirk, Senior Solutions Engineer at Source DefenseCommentary
Starting on Nov. 27, online retailers of all sizes will find out if their e-commerce capabilities are ready for prime time or not.
By Matthew McGuirk Senior Solutions Engineer at Source Defense, 11/13/2020
Comment0 comments  |  Read  |  Post a Comment
7 Cool Cyberattack and Audit Tools to be Highlighted at Black Hat Europe
Ericka Chickowski, Contributing Writer
Platforms, open source tools, and other toolkits for penetration testers and other security practitioners will be showcased at the early December virtual event.
By Ericka Chickowski Contributing Writer, 11/12/2020
Comment0 comments  |  Read  |  Post a Comment
How to Avoid Getting Killed by Ransomware
Karthik Krishnan, Founder & CEO, ConcentricCommentary
Using a series of processes, infosec pros can then tap automated data hygiene to find and fix files that attackers key in on.
By Karthik Krishnan Founder & CEO, Concentric, 11/11/2020
Comment0 comments  |  Read  |  Post a Comment
Flaws in Privileged Management Apps Expose Machines to Attack
Robert Lemos, Contributing WriterNews
The Intel Support Assistant is the latest Windows utility to be found that could expose millions of computers to privilege-escalation attacks through file manipulation and symbolic links.
By Robert Lemos Contributing Writer, 11/10/2020
Comment0 comments  |  Read  |  Post a Comment
How Hackers Blend Attack Methods to Bypass MFA
Alan Bavosa, VP, Security Products, at AppdomeCommentary
Protecting mobile apps requires a multilayered approach with a mix of cybersecurity measures to counter various attacks at different layers.
By Alan Bavosa VP, Security Products, at Appdome, 11/10/2020
Comment4 comments  |  Read  |  Post a Comment
Preventing and Mitigating DDoS Attacks: It's Elementary
Barrett Lyon, Co-Founder & CEO, NetographyCommentary
Following a spate of cyberattacks nationwide, school IT teams need to act now to ensure their security solution makes the grade.
By Barrett Lyon Co-Founder & CEO, Netography, 11/9/2020
Comment0 comments  |  Read  |  Post a Comment
7 Online Shopping Tips for the Holidays
Steve Zurier, Contributing Writer
The holidays are right around the corner, and that means plenty of online shopping. These tips will help keep you safe.
By Steve Zurier Contributing Writer, 11/9/2020
Comment0 comments  |  Read  |  Post a Comment
The Oracle-Walmart-TikTok Deal Is Not Enough
Jimmy Tom, Research Advisor, Info-Tech Research GroupCommentary
The social media deal raises issues involving data custodianship and trusted tech partnerships.
By Jimmy Tom Research Advisor, Info-Tech Research Group, 11/6/2020
Comment1 Comment  |  Read  |  Post a Comment
How COVID-19 Changed the VC Investment Landscape for Cybersecurity Companies
Salvatore Minetti, CEO, Fountech.VenturesCommentary
What trends can startups and investors expect to see going forward?
By Salvatore Minetti CEO, Fountech.Ventures, 11/6/2020
Comment1 Comment  |  Read  |  Post a Comment
Digital Transformation Means Security Must Also Transform
James Hadley, CEO at Immersive LabsCommentary
Being successful in this moment requires the ability to evolve in terms of team management, visibility, and crisis management.
By James Hadley CEO at Immersive Labs, 11/5/2020
Comment0 comments  |  Read  |  Post a Comment
The One Critical Element to Hardening Your Employees' Mobile Security
Alex White, Co-Founder & CTO of GlacierCommentary
COVID-19 has exposed longstanding gaps in enterprise mobile security. Creating a comprehensive mobile security plan and mandating compliance with that plan are essential to closing them.
By Alex White Co-Founder & CTO of Glacier, 11/5/2020
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
COVID-19: Latest Security News & Commentary
Dark Reading Staff 11/19/2020
New Proposed DNS Security Features Released
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/19/2020
How to Identify Cobalt Strike on Your Network
Zohar Buber, Security Analyst,  11/18/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: A GONG is as good as a cyber attack.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25660
PUBLISHED: 2020-11-23
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph...
CVE-2020-25688
PUBLISHED: 2020-11-23
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a...
CVE-2020-25696
PUBLISHED: 2020-11-23
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating sy...
CVE-2020-26229
PUBLISHED: 2020-11-23
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical - it was not possible to actually reproduce the vulnerability...
CVE-2020-28984
PUBLISHED: 2020-11-23
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.