Vulnerabilities / Threats //

Insider Threats

News & Commentary
12 Trends Shaping Identity Management
Sara Peters, Senior Editor at Dark Reading
As IAM companies try to stretch 'identity context' into all points of the cybersecurity market, identity is becoming 'its own solar system.'
By Sara Peters Senior Editor at Dark Reading, 4/26/2018
Comment1 Comment  |  Read  |  Post a Comment
Verizon DBIR: Ransomware Attacks Double for Second Year in a Row
Sara Peters, Senior Editor at Dark ReadingNews
Outside attackers still the biggest problem - except in healthcare.
By Sara Peters Senior Editor at Dark Reading, 4/10/2018
Comment0 comments  |  Read  |  Post a Comment
Privilege Abuse Attacks: 4 Common Scenarios
Michael Fimin, CEO & Co-Founder, NetwrixCommentary
It doesn't matter if the threat comes from a disgruntled ex-employee or an insider anticipating financial gain, privilege abuse patterns are pretty much the same, and they're easy to avoid.
By Michael Fimin CEO & Co-Founder, Netwrix, 3/7/2018
Comment1 Comment  |  Read  |  Post a Comment
CERT.org Goes Away, Panic Ensues
Dark Reading Staff, Quick Hits
Turns out the Carnegie Mellon CERT just moved to a newly revamped CMU Software Engineering Institute website.
By Dark Reading Staff , 3/5/2018
Comment0 comments  |  Read  |  Post a Comment
Why Cryptocurrencies Are Dangerous for Enterprises
David Shefter, Chief Technology Officer at Ziften TechnologiesCommentary
When employees mine coins with work computers, much can go wrong. But there are some ways to stay safe.
By David Shefter Chief Technology Officer at Ziften Technologies, 2/28/2018
Comment1 Comment  |  Read  |  Post a Comment
Leveraging Security to Enable Your Business
Jackson Shaw, VP of Product Management, One IdentityCommentary
When done right, security doesn't have to be the barrier to employee productivity that many have come to expect. Here's how.
By Jackson Shaw VP of Product Management, One Identity, 2/23/2018
Comment0 comments  |  Read  |  Post a Comment
Doh!!! The 10 Most Overlooked Security Tasks
Steve Zurier, Freelance Writer
Heres a list of gotchas that often slip past overburdened security pros.
By Steve Zurier Freelance Writer, 1/16/2018
Comment3 comments  |  Read  |  Post a Comment
NSA Employee Pleads Guilty to Illegally Retaining National Defense Secrets
Jai Vijayan, Freelance writerNews
Nghia Hoang Pho faces up to eight years in prison for removing highly classified NSA data from workplace and storing it at home.
By Jai Vijayan Freelance writer, 12/4/2017
Comment2 comments  |  Read  |  Post a Comment
How Law Firms Can Make Information Security a Higher Priority
Tom Cross, Chief Technology Officer of OPAQ NetworksCommentary
Lawyers always have been responsible for protecting their clients' information, but that was a lot easier to do when everything was on paper. Here are four best practices to follow.
By Tom Cross Chief Technology Officer of OPAQ Networks, 11/8/2017
Comment1 Comment  |  Read  |  Post a Comment
3 Steps to Reduce Risk in Your Supply Chain
Dan Dahlberg, Research Scientist at BitSightCommentary
Many companies have very limited visibility into their vendors' security posture -- and some may have thousands of vendors. Here are steps that every company should take to lock down their supply chains.
By Dan Dahlberg Research Scientist at BitSight, 10/27/2017
Comment1 Comment  |  Read  |  Post a Comment
Security Training & Awareness: 3 Big Myths
Eyal Benishti, CEO & Founder of IRONSCALESCommentary
The once-overwhelming consensus that security awareness programs are invaluable is increasingly up for debate.
By Eyal Benishti CEO & Founder of IRONSCALES, 10/23/2017
Comment6 comments  |  Read  |  Post a Comment
10 Social Engineering Attacks Your End Users Need to Know About
Steve Zurier, Freelance Writer
It's Cybersecurity Awareness Month. Make sure your users are briefed on these 10 attacker techniques that are often overlooked.
By Steve Zurier Freelance Writer, 10/19/2017
Comment0 comments  |  Read  |  Post a Comment
What's Next after the SEC 'Insider Trading' Breach?
David L. Axelrod and Terence M. Grugan, Partner, Ballard SpahrCommentary
Last month's hack of the Securities and Exchange Commission may prove to be the most high-profile corporate gatekeeper attack to date. But it definitely won't be the last.
By David L. Axelrod and Terence M. Grugan Partner, Ballard Spahr, 10/19/2017
Comment0 comments  |  Read  |  Post a Comment
Game Change: Meet the Mach37 Fall Startups
Ericka Chickowski, Contributing Writer, Dark Reading
CEOs describe how they think their fledgling ventures will revolutionize user training, privacy, identity management and embedded system security.
By Ericka Chickowski Contributing Writer, Dark Reading, 10/18/2017
Comment2 comments  |  Read  |  Post a Comment
Ransomware Grabs Headlines but BEC May Be a Bigger Threat
Marc Wilczek, Digital Strategist & CIO AdvisorCommentary
With social media, gathering information has never been easier, making Business Email Compromise the land of milk and honey for cybercriminals.
By Marc Wilczek Digital Strategist & CIO Advisor, 10/12/2017
Comment4 comments  |  Read  |  Post a Comment
Rise in Insider Threats Drives Shift to Training, Data-Level Security
Tom Thomassen, Senior Staff Engineer of Security, MarkLogicCommentary
As the value and volume of data grows, perimeter security is not enough to battle internal or external threats.
By Tom Thomassen Senior Staff Engineer of Security, MarkLogic, 10/6/2017
Comment2 comments  |  Read  |  Post a Comment
Automated Lateral Movement: Targeted Attack Tools for the Masses
Sara Peters, Senior Editor at Dark ReadingCommentaryVideo
Tal Be'ery and Tal Maor explain that the most pervasive, worst defended tactic of sophisticated attackers will soon be ready for script kiddies, and release GoFetch: a new lateral movement automation tool.
By Sara Peters Senior Editor at Dark Reading, 9/1/2017
Comment0 comments  |  Read  |  Post a Comment
GoT & the Inside Threat: Compromised Insiders Make Powerful Adversaries
Orion Cassetto, Senior Product Maester, ExabeamCommentary
What Game of Thrones' Arya Stark and the Faceless Men can teach security pros about defending against modern malware and identity theft.
By Orion Cassetto Senior Product Maester, Exabeam, 8/24/2017
Comment14 comments  |  Read  |  Post a Comment
The Changing Face & Reach of Bug Bounties
Vincent Liu, Partner, Bishop FoxCommentary
HackerOne CEO Mrten Mickos reflects on the impact of vulnerability disclosure on today's security landscape and leadership.
By Vincent Liu Partner, Bishop Fox, 8/23/2017
Comment1 Comment  |  Read  |  Post a Comment
Why Most Security Awareness Training Fails (And What To Do About It)
Tim Wilson, Editor in Chief, Dark Reading, CommentaryVideo
Arun Vishwanath discusses why awareness training shouldn't apply the same cure to every ailment then blame the patient when the treatment doesn't work.
By Tim Wilson, Editor in Chief, Dark Reading , 8/22/2017
Comment2 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
Meet 'Bro': The Best-Kept Secret of Network Security
Greg Bell, CEO, Corelight,  6/14/2018
Four Faces of Fraud: Identity, 'Fake' Identity, Ransomware & Digital
David Shefter, Chief Technology Officer at Ziften Technologies,  6/14/2018
Containerized Apps: An 8-Point Security Checklist
Jai Vijayan, Freelance writer,  6/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-5236
PUBLISHED: 2018-06-20
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 may be susceptible to a race condition (or race hazard). This type of issue occurs in software where the output is dependent on the sequence or timing of other uncontrollable events.
CVE-2018-5237
PUBLISHED: 2018-06-20
Symantec Endpoint Protection prior to 14 RU1 MP1 or 12.1 RU6 MP10 could be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.
CVE-2018-6211
PUBLISHED: 2018-06-20
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, OS command injection is possible as a result of incorrect processing of the res_buf parameter to index.cgi.
CVE-2018-6212
PUBLISHED: 2018-06-20
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, a reflected Cross-Site Scripting (XSS) attack is possible as a result of missed filtration for special characters in the "Search" field and incorrect proc...
CVE-2018-6213
PUBLISHED: 2018-06-20
In the web server on D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4.0, and 2.0.22, there is a hardcoded password of anonymous for the admin account.