LIVE EVENTS

INsecurity: A Dark Reading Conference

October 22-25, 2018 | Sheraton Grand Chicago

INsecurity is a 2-day conference for learning, skill building and networking. Whether you're an IT manager looking to flesh out an enterprise-wide security operations program, a security staffer who needs to learn best practices for incident response or endpoint protection, or a risk manager seeking ways to measure potential cyber risk and insurance, you will find critical best practices, advice, and technology tips at INsecurity.

Trending Hot Topics include:

  • Cloud Security: Automate or Die
  • AI: Boon or Boondoggle?
  • Non-Lethal Active Defense for Enterprises: A Better Alternative to "Hacking Back"

Learn More Here!

 

ONLINE EVENTS

Check out these online events that are available from the comfort of your computer!  View our complete list of Upcoming Webinars so you can attend a live session or our Webinar Archives for webinars that are available On-Demand!

Upcoming Online Events

08/16
AI & Machine Learning - How to Improve Enterprise Security With Them

08/21
The Latest Social Engineering Attacks and How To Understand and Prevent Them

08/22
How to End Phishing

09/04
Strategies for Monitoring & Measuring Cloud Security

Don't forget to view our complete list of Webinar Archives for webinars that are available On-Demand!

Google Engineering Lead on Lessons Learned From Chrome's HTTPS Push
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
White Hat to Black Hat: What Motivates the Switch to Cybercrime
Kelly Sheridan, Staff Editor, Dark Reading,  8/8/2018
PGA of America Struck By Ransomware
Dark Reading Staff 8/9/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-3937
PUBLISHED: 2018-08-14
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00. A specially crafted GET request can cause arbitrary commands to be executed. An attacker can send an HTTP request to trigger this vulnerability...
CVE-2018-3938
PUBLISHED: 2018-08-14
An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5 firmware 1.87.00. A specially crafted POST can cause a stack-based buffer overflow, resulting in remote code execution. An attacker can send a malicious POST r...
CVE-2018-12537
PUBLISHED: 2018-08-14
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.
CVE-2018-12539
PUBLISHED: 2018-08-14
In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows,...
CVE-2018-3615
PUBLISHED: 2018-08-14
Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.