Comments
AT&T to Buy AlienVault
Newest First  |  Oldest First  |  Threaded View
Christian Bryant
100%
0%
Christian Bryant,
User Rank: Ninja
7/10/2018 | 8:47:22 PM
Concern With Cybersecurity Acquisitions by Telecoms & ISPs
For months we've been seeing a flurry of cybersecurity sector acquisitions by big money, from ISP management companies to heavy hitter telecoms. I get it - ISP, wireless and cellular service providers are getting hit hard and the key to customers continuing with their current providers - and especially new users signing on - is a sense of security, improved and guaranteed. But this one gives me pause.

AlienVault are the folks behind Open Threat Exchange (OTX). It's one of the coolest communities out there based around threat data sharing and discussion. I jumped on board as soon as I had the opportunity. Part of what made this possible was AlienVault's then independent status, and later collaboration with Intel and HP brought valuable realtime data into the mix. What if AT&T had acquired AlienVault in 2011? Would OTX have even been released, or would it have carried a hefty subscription fee?

I worry acquisition of forward-thinking cybersecurity firms like AlienVault could have a negative impact on projects like OTX. While not the same setup as AlienVault, I can't imagine what would become of RedTeam Security, for example, if Verizon were to acquire them. I hate to see my favorite cyber warriors getting snatched up, but out of respect for their founders I also wish them the best. We wouldn't be where we are today without them.


White House Cybersecurity Strategy at a Crossroads
Kelly Jackson Higgins, Executive Editor at Dark Reading,  7/17/2018
Lessons from My Strange Journey into InfoSec
Lysa Myers, Security Researcher, ESET,  7/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-14364
PUBLISHED: 2018-07-18
GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab projects import component.
CVE-2018-14387
PUBLISHED: 2018-07-18
An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authenticate against the server using the same session identifier. The attacker can access the user's acco...
CVE-2018-14388
PUBLISHED: 2018-07-18
joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.
CVE-2018-14389
PUBLISHED: 2018-07-18
joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.
CVE-2018-12429
PUBLISHED: 2018-07-18
JEESNS through 1.2.1 allows XSS attacks by ordinary users who publish articles containing a crafted payload in order to capture an administrator cookie.