Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Careers & People

News & Commentary
Could Foster Kids Help Solve the Security Skills Shortage?
Neal O'Farrell, Founder, Foster WarriorsCommentary
Foster Warriors is a new nonprofit initiative focused on helping foster kids find a place in the world, and especially in the world of security. Join us!
By Neal O'Farrell Founder, Foster Warriors, 6/26/2019
Comment0 comments  |  Read  |  Post a Comment
Florida Town Pays $600K to Ransomware Operators
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
Riviera Beach's decision to pay ransom to criminals might get files back, but it almost guarantees greater attacks against other governments.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 6/20/2019
Comment4 comments  |  Read  |  Post a Comment
'Democratizing' Machine Learning for Fraud Prevention & Payments Intelligence
Cleber Martins, Head of Payments Intelligence, ACI WorldwideCommentary
How fraud experts can fight cybercrime by 'downloading' their knowledge and experience into computer models.
By Cleber Martins Head of Payments Intelligence, ACI Worldwide, 6/20/2019
Comment0 comments  |  Read  |  Post a Comment
Cybersecurity Accountability Spread Thin in the C-Suite
Ericka Chickowski, Contributing WriterNews
While cybersecurity discussions have permeated board meetings, the democratization of accountability has a long way to go.
By Ericka Chickowski Contributing Writer, 6/20/2019
Comment0 comments  |  Read  |  Post a Comment
How Hackers Emptied Church Coffers with a Simple Phishing Scam
Sam Bocetta, Security AnalystCommentary
Cyber thieves aren't bound by a code of ethics. They look for weak targets and high rewards, which is exactly what Saint Ambrose Catholic offered.
By Sam Bocetta Security Analyst, 6/19/2019
Comment0 comments  |  Read  |  Post a Comment
The Evolution of Identity
Kathleen Peters, SVP & Head of Fraud & Identity, ExperianCommentary
How data and technology can help businesses make the right fraud decisions, protect people's identities, and create an improved customer experience.
By Kathleen Peters SVP & Head of Fraud & Identity, Experian, 6/18/2019
Comment0 comments  |  Read  |  Post a Comment
Sensory Overload: Filtering Out Cybersecurity's Noise
Joshua Goldfarb, Independent ConsultantCommentary
No organization can prioritize and mitigate hundreds of risks effectively. The secret lies in carefully filtering out the risks, policies, and processes that waste precious time and resources.
By Joshua Goldfarb Independent Consultant, 6/14/2019
Comment1 Comment  |  Read  |  Post a Comment
New Funding Values KnowBe4 at $1 Billion
Dark Reading Staff, Quick Hits
The $300 million investment is being led by KKR.
By Dark Reading Staff , 6/12/2019
Comment0 comments  |  Read  |  Post a Comment
Tomorrow's Cybersecurity Analyst Is Not Who You Think
Chris Schueler, Senior VP, Managed Security Services, TrustwaveCommentary
Organizations can't just rely on diverse and cutting-edge technologies to fight adversaries. They will also need people with diverse expertise and backgrounds.
By Chris Schueler Senior VP, Managed Security Services, Trustwave, 6/12/2019
Comment1 Comment  |  Read  |  Post a Comment
What 3 Powerful GoT Women Teach Us about Cybersecurity
Orion Cassetto, Senior Product Maester, ExabeamCommentary
Imagine Game of Thrones' Daenerys Targaryen, Arya Stark, and Cersei Lannister on the front lines in the real-world battleground of enterprise security.
By Orion Cassetto Senior Product Maester, Exabeam, 6/11/2019
Comment0 comments  |  Read  |  Post a Comment
Unmixed Messages: Bringing Security & Privacy Awareness Together
Tom Pendergast & Jeff Morgenroth, Chief Learning Officer at MediaPRO/Instructional Designer at MediaPROCommentary
Security and privacy share the same basic goals, so it just makes sense to combine efforts in those two areas. But that can be easier said than done.
By Tom Pendergast & Jeff Morgenroth Chief Learning Officer at MediaPRO/Instructional Designer at MediaPRO, 6/10/2019
Comment0 comments  |  Read  |  Post a Comment
Cyber Talent Gap? Don't Think Like Tinder!
Lysa Myers, Security Researcher, ESETCommentary
If your company truly is a great place to work, make sure your help-wanted ads steer clear of these common job-listing clichs.
By Lysa Myers Security Researcher, ESET, 6/6/2019
Comment0 comments  |  Read  |  Post a Comment
When Security Goes Off the Rails
Adam Shostack, Consultant, Entrepreneur, Technologist, Game DesignerCommentary
Cyber can learn a lot from the highly regulated world of rail travel. The most important lesson: the value of impartial analysis.
By Adam Shostack Consultant, Entrepreneur, Technologist, Game Designer, 6/6/2019
Comment0 comments  |  Read  |  Post a Comment
CISOs & CIOs: Better Together
Leo Taddeo, CISO, Cyxtera, and former FBI SAC of cyber and special operations for the NY region Commentary
An overview of three common organizational structures illustrates how NOT to pit chief security and IT execs against each other.
By Leo Taddeo CISO, Cyxtera, and former FBI SAC of cyber and special operations for the NY region , 6/5/2019
Comment0 comments  |  Read  |  Post a Comment
What Cyber Skills Shortage?
Andy Ellis, Chief Security Officer, AkamaiCommentary
Employers can solve the skills gap by first recognizing that there isn't an archetypal "cybersecurity job" in the same way that there isn't an archetypal "automotive job." Heres how.
By Andy Ellis Chief Security Officer, Akamai, 6/4/2019
Comment2 comments  |  Read  |  Post a Comment
SANS Launches Security Awareness Certification
Dark Reading Staff, Quick Hits
The SANS Security Awareness Professional (SSAP) will be available this summer to professionals focused on measuring and mitigating human risk.
By Dark Reading Staff , 5/31/2019
Comment2 comments  |  Read  |  Post a Comment
Why Fostering Flexibility Is a Win for Women & Cybersecurity
Nineveh Madsen, Executive, OpenVPNCommentary
Creating a culture of supporting and advancing women is no small feat, but it's worth the challenge. Start with yourself. Here's how.
By Nineveh Madsen Executive, OpenVPN, 5/29/2019
Comment3 comments  |  Read  |  Post a Comment
How Security Vendors Can Address the Cybersecurity Talent Shortage
Rob Rashotte, VP of Global Training and Technical Field Enablement at FortinetCommentary
The talent gap is too large for any one sector, and cybersecurity vendors have a big role to play in helping to close it.
By Rob Rashotte VP of Global Training and Technical Field Enablement at Fortinet, 5/24/2019
Comment7 comments  |  Read  |  Post a Comment
Researcher Publishes Four Zero-Day Exploits in Three Days
Robert Lemos, Contributing WriterNews
The exploits for local privilege escalation vulnerabilities in Windows could be integrated into malware before Microsoft gets a chance to fix the issues.
By Robert Lemos Contributing Writer, 5/23/2019
Comment0 comments  |  Read  |  Post a Comment
Proving the Value of Security Awareness with Metrics that 'Deserve More'
Ira Winkler, CISSP, President, Secure MentemCommentary
Without metrics that matter to the business, awareness programs will continue to be the bastard child of security.
By Ira Winkler CISSP, President, Secure Mentem, 5/22/2019
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
Florida Town Pays $600K to Ransomware Operators
Curtis Franklin Jr., Senior Editor at Dark Reading,  6/20/2019
Pledges to Not Pay Ransomware Hit Reality
Robert Lemos, Contributing Writer,  6/21/2019
AWS CISO Talks Risk Reduction, Development, Recruitment
Kelly Sheridan, Staff Editor, Dark Reading,  6/25/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-10164
PUBLISHED: 2019-06-26
PostgreSQL versions 10.x before 10.9 and versions 11.x before 11.4 are vulnerable to a stack-based buffer overflow. Any authenticated user can overflow a stack-based buffer by changing the user's own password to a purpose-crafted value. This often suffices to execute arbitrary code as the PostgreSQL...
CVE-2019-11583
PUBLISHED: 2019-06-26
The issue searching component in Jira before version 8.1.0 allows remote attackers to deny access to Jira service via denial of service vulnerability in issue search when ordering by "Epic Name".
CVE-2019-4234
PUBLISHED: 2019-06-26
IBM PureApplication System 2.2.3.0 through 2.2.5.3 weakness in the implementation of locking feature in pattern editor. An attacker by intercepting the subsequent requests can bypass business logic to modify the pattern to unlocked state. IBM X-Force ID: 159416.
CVE-2019-4235
PUBLISHED: 2019-06-26
IBM PureApplication System 2.2.3.0 through 2.2.5.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 159417.
CVE-2019-4241
PUBLISHED: 2019-06-26
IBM PureApplication System 2.2.3.0 through 2.2.5.3 could allow an authenticated user with local access to bypass authentication and obtain administrative access. IBM X-Force ID: 159467.