Vulnerabilities / Threats //

Vulnerability Management

News & Commentary
Oracle Fixes 20 Remotely Exploitable Java SE Vulns
Jai Vijayan, Freelance writerNews
Quarterly update for October is the smallest of the year: only 252 flaws to fix! Oracle advises to apply patches 'without delay.'
By Jai Vijayan Freelance writer, 10/18/2017
Comment0 comments  |  Read  |  Post a Comment
Reuters: Microsoft's 2013 Breach Hit Bug Repository, Insiders Say
Dark Reading Staff, Quick Hits
Five anonymous former Microsoft employees tell Reuters that Microsoft's database of internally discovered vulnerabilities was compromised in 2013, but Microsoft will not confirm it occurred.
By Dark Reading Staff , 10/17/2017
Comment0 comments  |  Read  |  Post a Comment
Private, Public, or Hybrid? Finding the Right Fit in a Bug Bounty Program
Jason Haddix, Head of Trust & Security, BugcrowdCommentary
How can a bug bounty not be a bug bounty? There are several reasons. Here's why you need to understand the differences.
By Jason Haddix Head of Trust & Security, Bugcrowd, 10/5/2017
Comment1 Comment  |  Read  |  Post a Comment
Security's #1 Problem: Economic Incentives
Dimitri Stiliadis, CEO of AporetoCommentary
The industry rewards cutting corners rather than making software safe. Case in point: the Equifax breach.
By Dimitri Stiliadis CEO of Aporeto, 9/25/2017
Comment15 comments  |  Read  |  Post a Comment
SecureAuth to Merge with Core Security
Dawn Kawamoto, Associate Editor, Dark ReadingNews
K1 Investment Management, which owns Core Security, plans to acquire the identity management and authentication company for more than $200 million.
By Dawn Kawamoto Associate Editor, Dark Reading, 9/20/2017
Comment1 Comment  |  Read  |  Post a Comment
The 'Team of Teams' Model for Cybersecurity
Matthew Doan and Gary Barnabo, Commerical Cyber  Strategists, Booz Allen HamiltonCommentary
Security leaders can learn some valuable lessons from a real-life military model.
By Matthew Doan and Gary Barnabo Commerical Cyber Strategists, Booz Allen Hamilton, 9/12/2017
Comment0 comments  |  Read  |  Post a Comment
How to Use Purple Teaming for Smarter SOCs
Sara Peters, Senior Editor at Dark ReadingCommentaryVideo
Justin Harvey explains why the standard blue team vs. red team can be improved upon, and provides tips on doing purple teaming right.
By Sara Peters Senior Editor at Dark Reading, 9/7/2017
Comment0 comments  |  Read  |  Post a Comment
Is Your Organization Merely PCI-Compliant or Is It Actually Secure?
Jeff Hussey, President & CEO, Tempered NetworksCommentary
The Host Identity Protocol might be the answer to inadequate check-the-box security standards.
By Jeff Hussey President & CEO, Tempered Networks, 9/6/2017
Comment0 comments  |  Read  |  Post a Comment
Using Market Pressures to Improve Cybersecurity
Sara Peters, Senior Editor at Dark ReadingCommentaryVideo
Post-MedSec, Chris Wysopal discusses what impact the investor community -- if not consumers -- can have on squashing vulnerabilities and improving cybersecurity.
By Sara Peters Senior Editor at Dark Reading, 8/31/2017
Comment0 comments  |  Read  |  Post a Comment
St. Jude Pacemaker Gets Firmware Update 'Intended as a Recall'
Sara Peters, Senior Editor at Dark ReadingNews
The devices that were the subject of a vulnerability disclosure debate last summer now have an FDA-approved fix.
By Sara Peters Senior Editor at Dark Reading, 8/30/2017
Comment2 comments  |  Read  |  Post a Comment
New York's Historic FinSec Regulation Covers DDoS, Not Just Data
Sara Peters, Senior Editor at Dark ReadingNews
Starting today, New York banks and insurers must report to authorities within 72 hours on any security event that has a 'reasonable likelihood' of causing material harm to normal operations.
By Sara Peters Senior Editor at Dark Reading, 8/28/2017
Comment1 Comment  |  Read  |  Post a Comment
The Changing Face & Reach of Bug Bounties
Vincent Liu, Partner, Bishop FoxCommentary
HackerOne CEO Mrten Mickos reflects on the impact of vulnerability disclosure on today's security landscape and leadership.
By Vincent Liu Partner, Bishop Fox, 8/23/2017
Comment1 Comment  |  Read  |  Post a Comment
How Bad Teachers Ruin Good Machine Learning
Sara Peters, Senior Editor at Dark ReadingCommentaryVideo
Sophos data scientist Hillary Sanders explains how security suffers when good machine learning models are trained on bad testing data.
By Sara Peters Senior Editor at Dark Reading, 8/18/2017
Comment0 comments  |  Read  |  Post a Comment
DoJ Launches Framework for Vulnerability Disclosure Programs
Dark Reading Staff, Quick Hits
The Department of Justice releases a set of guidelines to help businesses create programs for releasing vulnerabilities.
By Dark Reading Staff , 8/3/2017
Comment1 Comment  |  Read  |  Post a Comment
Facebook Offers $1 Million for New Security Defenses
Dawn Kawamoto, Associate Editor, Dark ReadingNews
The social media giant has increased the size of its Internet Defense Prize program in order to spur more research into ways to defend users against the more prevalent and common methods of attack.
By Dawn Kawamoto Associate Editor, Dark Reading, 7/26/2017
Comment2 comments  |  Read  |  Post a Comment
Using DevOps to Move Faster than Attackers
Ericka Chickowski, Contributing Writer, Dark ReadingNews
Black Hat USA talk will discuss the practicalities of adjusting appsec tooling and practices in the age of DevOps.
By Ericka Chickowski Contributing Writer, Dark Reading, 7/20/2017
Comment0 comments  |  Read  |  Post a Comment
Cloud AV Can Serve as an Avenue for Exfiltration
Ericka Chickowski, Contributing Writer, Dark ReadingNews
Black Hat USA researchers show how bad guys can use cloud AV connections to bypass air-gaps and extremely segmented networks to keep stolen data flowing.
By Ericka Chickowski Contributing Writer, Dark Reading, 7/14/2017
Comment0 comments  |  Read  |  Post a Comment
New SQL Injection Tool Makes Attacks Possible from a Smartphone
Ericka Chickowski, Contributing Writer, Dark ReadingNews
Recorded Future finds new hacking tool that's cheap and convenient to carry out that old standby attack, SQL injection.
By Ericka Chickowski Contributing Writer, Dark Reading, 7/12/2017
Comment0 comments  |  Read  |  Post a Comment
Microsoft Patches Critical Zero-Day Flaw in Windows Security Protocol
Kelly Sheridan, Associate Editor, Dark ReadingNews
Researchers at Preempt uncovered two critical vulnerabilities in the Windows NTLM security protocols, one of which Microsoft patched today.
By Kelly Sheridan Associate Editor, Dark Reading, 7/11/2017
Comment2 comments  |  Read  |  Post a Comment
How Code Vulnerabilities Can Lead to Bad Accidents
Jeff Williams, CTO, Contrast SecurityCommentary
The software supply chain is broken. To prevent hackers from exploiting vulnerabilities, organizations need to know where their applications are, and whether they are built using trustworthy components.
By Jeff Williams CTO, Contrast Security, 7/10/2017
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
20 Questions to Ask Yourself before Giving a Security Conference Talk
Joshua Goldfarb, Co-founder & Chief Product Officer, IDDRA,  10/16/2017
Printers: The Weak Link in Enterprise Security
Kelly Sheridan, Associate Editor, Dark Reading,  10/16/2017
Hyatt Hit With Another Credit Card Breach
Dark Reading Staff 10/13/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.