Cloud Misconceptions Are Pervasive Across Enterprises
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Shadow IT is rampant at many organizations that rely upon cloud-delivered tools and services to enable remote work, according to a new study. Here's what security teams need to do about it.
By Paul Martini The CEO, co-founder and chief architect of iboss, 4/25/2018
Comment0 comments  |  Read  |  Post a Comment
How to Leverage Artificial Intelligence for Cybersecurity
Joe Cosmano, Senior Vice President of Engineering Services, ibossCommentary
AI and predictive analytics should be used to augment a companys security team, not replace it. Here's why.
By Joe Cosmano Senior Vice President of Engineering Services, iboss, 4/18/2018
Comment0 comments  |  Read  |  Post a Comment
Avoiding the Ransomware Mistakes that Crippled Atlanta
Chris Park, Chris Park, CIO, ibossCommentary
What made Atlanta an easy target was its outdated use of technology: old computers running on non-supported platforms, which are also a characteristic of many municipalities and most major cities.
By Chris Park Chris Park, CIO, iboss, 4/11/2018
Comment8 comments  |  Read  |  Post a Comment
Securing Retail Networks for an Omnichannel Future
Peter Martini, President and Co-FounderCommentary
Retailers who haphazardly move to digital from a brick-and-mortar environment can leave their businesses open to significant cybersecurity vulnerabilities. Here's how to avoid the pitfalls.
By Peter Martini President and Co-Founder, 4/4/2018
Comment1 Comment  |  Read  |  Post a Comment
Getting Ahead of Internet of Things Security in the Enterprise
Simon Eappariello, Senior VP Product & Engineering, EMEIA, ibossCommentary
In anticipation of an IoT-centric future, CISOs must be rigorous in shoring up defenses that provide real-time insights across all network access points.
By Simon Eappariello Senior VP Product & Engineering, EMEIA, iboss, 3/28/2018
Comment0 comments  |  Read  |  Post a Comment
Cybersecurity Spring Cleaning: 3 Must-Dos for 2018
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Why 'Spectre' and 'Meltdown,' GDPR, and the Internet of Things are three areas security teams should declutter and prioritize in the coming months.
By Paul Martini The CEO, co-founder and chief architect of iboss, 3/21/2018
Comment0 comments  |  Read  |  Post a Comment
How to Interpret the SECs Latest Guidance on Data Breach Disclosure
Peter Martini, President and Co-FounderCommentary
Forward-looking organizations should view this as an opportunity to reevaluate their cybersecurity posture and install best practices that should have already been in place.
By Peter Martini President and Co-Founder, 3/14/2018
Comment0 comments  |  Read  |  Post a Comment
Virtual Private Networks: Why Their Days Are Numbered
Chris Park, Chris Park, CIO, ibossCommentary
As companies move to the cloud and depend less on physical servers and network connections, their reliance on VPNs for security will eventually evolve, if not disappear altogether.
By Chris Park Chris Park, CIO, iboss, 2/28/2018
Comment0 comments  |  Read  |  Post a Comment
Getting Started with IoT Security in Healthcare
Chris Park, Chris Park, CIO, ibossCommentary
Theres a hazard that comes with introducing any new element into patient care whether it's a new drug or a connected device. These four steps will help keep patients safe.
By Chris Park Chris Park, CIO, iboss, 2/21/2018
Comment0 comments  |  Read  |  Post a Comment
The GDPR Clock Is Running Out. Now What?
Simon Eappariello, Senior VP Product & Engineering, EMEIA, ibossCommentary
Many organizations impacted by new European Union data privacy rules that go into effect May 25 are still blind to some of the basics.
By Simon Eappariello Senior VP Product & Engineering, EMEIA, iboss, 2/14/2018
Comment0 comments  |  Read  |  Post a Comment
Top Cloud Security Misconceptions Plaguing Enterprises
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Contrary to popular opinion, there is no one single cloud. There are a wealth of cloud-based providers that own dedicated server space across the globe. Heres how to find the best fit for your company.
By Paul Martini The CEO, co-founder and chief architect of iboss, 2/7/2018
Comment0 comments  |  Read  |  Post a Comment
Data Encryption: 4 Common Pitfalls
Joe Cosmano, Senior Vice President of Engineering Services, ibossCommentary
To maximize encryption effectiveness you must minimize adverse effects in network performance and complexity. Here's how.
By Joe Cosmano Senior Vice President of Engineering Services, iboss, 1/31/2018
Comment0 comments  |  Read  |  Post a Comment
Selling Cloud-Based Cybersecurity to a Skeptic
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
When it comes to security, organizations dont need to look at cloud as an either/or proposition. But there are misconceptions that need to be addressed.
By Paul Martini The CEO, co-founder and chief architect of iboss, 1/26/2018
Comment0 comments  |  Read  |  Post a Comment
Applying Defense-in-Depth to the Digital Battlefield
Chris Park, Chris Park, CIO, ibossCommentary
How a layered security strategy can minimize the threat and impact of a data breach.
By Chris Park Chris Park, CIO, iboss, 1/18/2018
Comment0 comments  |  Read  |  Post a Comment
Top 3 Pitfalls of Securing the Decentralized Enterprise
Paul Martini, The CEO, co-founder and chief architect of ibossCommentary
Doubling down on outdated security practices while the number of users leveraging your enterprise network grows is a race to the bottom for businesses moving to distributed workflows.
By Paul Martini The CEO, co-founder and chief architect of iboss, 1/16/2018
Comment0 comments  |  Read  |  Post a Comment
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-3906
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port 9003. An authenticated remote attacker can use these credentials to access the badge system database and modify its contents.
CVE-2019-3907
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).
CVE-2019-3908
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to the zip is hard-coded and unchangeable. An attacker with access to these backups can decrypt them and obtain sensitive data.
CVE-2019-3909
PUBLISHED: 2019-01-18
Premisys Identicard version 3.1.190 database uses default credentials. Users are unable to change the credentials without vendor intervention.
CVE-2019-3910
PUBLISHED: 2019-01-18
Crestron AM-100 before firmware version 1.6.0.2 contains an authentication bypass in the web interface's return.cgi script. Unauthenticated remote users can use the bypass to access some administrator functionality such as configuring update sources and rebooting the device.