Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Cloud

News & Commentary
Dark Reading to Upgrade Site Design, Performance
Tim Wilson, Editor in Chief, Dark Reading, Commentary
Improvements will make site content easier to navigate, faster, and more functional.
By Tim Wilson, Editor in Chief, Dark Reading , 4/13/2021
Comment0 comments  |  Read  |  Post a Comment
5 Objectives for Establishing an API-First Security Strategy
Ryan Nolette, Technical Security Lead at PostmanCommentary
With APIs predicted to be the most common attack vector by 2022, an API-first security strategy is critical now more than ever.
By Ryan Nolette Technical Security Lead at Postman, 4/13/2021
Comment0 comments  |  Read  |  Post a Comment
Omdia Research Spotlight: XDR
Eric Parizo, Senior Analyst, OmdiaCommentary
Few emerging cybersecurity market segments are garnering more attention than XDR. Here, Omdia highlights its recent research on XDR.
By Eric Parizo Senior Analyst, Omdia, 4/12/2021
Comment0 comments  |  Read  |  Post a Comment
8 Security & Privacy Apps to Share With Family and Friends
Kelly Sheridan, Staff Editor, Dark Reading
Mobile apps to recommend to the people in your life who want to improve their online security and privacy.
By Kelly Sheridan Staff Editor, Dark Reading, 4/9/2021
Comment0 comments  |  Read  |  Post a Comment
Cartoon Caption Winner: Something Seems Afoul
John Klossner, CartoonistCommentary
And the winner of Dark Readings's March cartoon caption contest is ...
By John Klossner Cartoonist, 4/7/2021
Comment0 comments  |  Read  |  Post a Comment
Security Falls Short in Rapid COVID Cloud Migration
Dark Reading Staff, Quick Hits
The quick pivot to the cloud for remote support also ushered in risks.
By Dark Reading Staff , 4/6/2021
Comment0 comments  |  Read  |  Post a Comment
7 Security Strategies as Employees Return to the Office
Steve Zurier, Contributing Writer
More sooner than later, employees will be making their way back to the office. Here's how security pros can plan for the next new normal.
By Steve Zurier Contributing Writer, 4/1/2021
Comment0 comments  |  Read  |  Post a Comment
The Role of Visibility in Securing Cloud Applications
Praveen Patnala, Co-Founder, ValtixCommentary
Traditional data center approaches aren't built for securing modern cloud applications.
By Praveen Patnala Co-Founder, Valtix, 4/1/2021
Comment0 comments  |  Read  |  Post a Comment
3 Ways Vendors Can Inspire Customer Trust Amid Breaches
James Pleger, Manager, SpecOps, at Sumo LogicCommentary
As customers rely more on cloud storage and remote workforces, the probability of a breach increases.
By James Pleger Manager, SpecOps, at Sumo Logic, 3/31/2021
Comment0 comments  |  Read  |  Post a Comment
Security on a Shoestring? More Budget Means More Detection
Robert Lemos, Contributing WriterNews
Companies that spend the smallest share of their IT budget on security see fewer threats, but that's not good news.
By Robert Lemos Contributing Writer, 3/30/2021
Comment0 comments  |  Read  |  Post a Comment
In the Rush to Embrace Hybrid Cloud, Don't Forget About Security
Ganesh Pai, CEO, UptycsCommentary
Cloud service providers typically only secure the infrastructure itself, while customers are responsible for their data and application security.
By Ganesh Pai CEO, Uptycs, 3/30/2021
Comment0 comments  |  Read  |  Post a Comment
Moving from DevOps to CloudOps: The Four-Box Problem
Steve Quane, Executive Vice President, Network Defense and Hybrid Cloud Security, Trend MicroCommentary
With SOC teams running services on multiple cloud platforms, their big concern is how to roll up configuration of 200+ servers in a comprehensive way.
By Steve Quane Executive Vice President, Network Defense and Hybrid Cloud Security, Trend Micro, 3/26/2021
Comment0 comments  |  Read  |  Post a Comment
Exec Order Could Force Software Vendors to Disclose Breaches to Federal Gov't Customers
Dark Reading Staff, Quick Hits
A decision on the order, which contains several recommendations, is still forthcoming.
By Dark Reading Staff , 3/25/2021
Comment0 comments  |  Read  |  Post a Comment
The CIO's Shifting Role: Improving Security With Shared Responsibility
Keith Neilson, Technical Evangelist for CloudSphereCommentary
CIOs must create a culture centered around cybersecurity that is easily visible and manageable.
By Keith Neilson Technical Evangelist for CloudSphere, 3/25/2021
Comment0 comments  |  Read  |  Post a Comment
6 Tips for Limiting Damage From Third-Party Attacks
Jai Vijayan, Contributing Writer
The ability to protect your organization from third-party attacks will become increasingly critical as attackers try to maximize the effectiveness of their malicious campaigns.
By Jai Vijayan Contributing Writer, 3/25/2021
Comment0 comments  |  Read  |  Post a Comment
Anti-Spoofing for Email Gains Adoption, but Enforcement Lags
Robert Lemos, Contributing WriterNews
More organizations adopt sender authentication, but strict quarantining or rejection of unauthenticated messages remains uncommon.
By Robert Lemos Contributing Writer, 3/23/2021
Comment2 comments  |  Read  |  Post a Comment
CSA & ISACA Team Up on Cloud Auditing Certificate
Kelly Sheridan, Staff Editor, Dark ReadingNews
The Certificate of Cloud Auditing Knowledge aims to fill a gap in the market for cloud IT auditing as more organizations work in cloud environments.
By Kelly Sheridan Staff Editor, Dark Reading, 3/22/2021
Comment0 comments  |  Read  |  Post a Comment
Qualys CEO Courtot Departs for Health Reasons
Dark Reading Staff, Quick Hits
The well-known security industry entrepreneur initially took a leave of absence in February.
By Dark Reading Staff , 3/22/2021
Comment0 comments  |  Read  |  Post a Comment
Top 3 Cybersecurity Lessons Learned From the Pandemic
Joe McMann, Global Cyber Security Portfolio Leader, CapgeminiCommentary
Defending an enterprise of fully remote employees and their devices at this scale and speed had never been done before. Now, we do it every day.
By Joe McMann Global Cyber Security Portfolio Leader, Capgemini, 3/22/2021
Comment0 comments  |  Read  |  Post a Comment
On the Road to Good Cloud Security: Are We There Yet?
Paula Musich, Research Director, Enterprise Management AssociatesCommentary
Misconfigured infrastructure is IT pros' top cloud security concern, but they're conflicted on how to address it in practice.
By Paula Musich Research Director, Enterprise Management Associates, 3/22/2021
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
PR Newswire
News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-29370
PUBLISHED: 2021-04-13
A UXSS was discovered in the Thanos-Soft Cheetah Browser in Android 1.2.0 due to the inadequate filter of the intent scheme. This resulted in Cross-site scripting on the cheetah browser in any website.
CVE-2021-3460
PUBLISHED: 2021-04-13
The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker.
CVE-2021-3462
PUBLISHED: 2021-04-13
A privilege escalation vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could allow unauthorized access to the driver's device object.
CVE-2021-3463
PUBLISHED: 2021-04-13
A null pointer dereference vulnerability in Lenovo Power Management Driver for Windows 10, prior to version 1.67.17.54, that could cause systems to experience a blue screen error.
CVE-2021-3471
PUBLISHED: 2021-04-13
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.