Author

 Graham Cluley

Profile of Graham Cluley

News & Commentary Posts: 77
Articles by Graham Cluley

Worker Who Planted Malware Time Bomb At Fannie Mae Faces Prison

10/7/2010
As belts tighten and the credit crunch continues to hit around the world, more and more companies will be making the difficult decision to make staff and contractors redundant. But what happens when a disaffected former employee decides to leave your company a parting gift - in the form of data-destroying malware?

Post a Comment

TechCrunch Hacked

1/26/2010
The immensely popular blog TechCrunch has been compromised by hackers who posted an offensive message on its home page.

Post a Comment

West African 419 Scammers Exploit Dilbert

7/29/2009
The Dilbert comic strip is loved around the world for its satirical look at life in the corporate office. But now identity thieves and scammers are exploiting the popular Dilbert.com Website in their hunt for potential victims.

Post a Comment

Erin Andrews Video: Get A Life Or Get A Virus

7/20/2009
It was early Sunday morning British time when I first heard the name "Erin Andrews." I didn't have a clue who she was -- I don't follow the American sports scene -- but one thing was certain: She was creating an enormous buzz on the Internet.

Post a Comment

Suspected Child Porn Hub Taken Offline

6/4/2009
Internet service provider Pricewert -- which trades under names such as 3FN and APS Telecom -- has been shut down and disconnected from cyberspace following allegations it was knowingly involved in major spam attacks, phishing campaigns, malware distribution, and child abuse.

Post a Comment

Why Twitter Security Needs To Grow Up

5/1/2009
Twitter is growing at phenomenal speed -- but this week's breach by a French hacker who accessed the accounts of Britney Spears, Barack Obama, and others proves it's time for the service to show a more mature attitude to security.

Post a Comment

Write A Twitter Worm, Get A Job?

4/18/2009
The teenage author of the Mikeyy and StalkDaily worms that hit Twitter users hard one weekend ago appears to have struck lucky. As a result of his infamy, he has a brand new job.

Post a Comment

StalkDaily Attack Hits Twitter Users

4/11/2009
If anyone was in any doubt that social networks are the new battleground for cybercriminals, then just log in to Twitter right now. The hugely popular micro-blogging network is overrun with warnings about messages referring to a website called StalkDaily.com, said to be spreading through compromised Twitter accounts.

Post a Comment

Will They Ever Catch Conficker's Authors?

3/31/2009
While the world is holding its breath, wondering whether the Conficker worm is going to do anything dramatic on April 1st (I'm placing money that no computers are reported to have melted by the end of the day, and the Internet won't have turned to blancmange), perhaps a more important question is: Are we ever going to catch the pond life who wrote it?

Post a Comment
WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-8023
PUBLISHED: 2018-09-21
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT implementation used is vulnerable to a timin...
CVE-2018-14643
PUBLISHED: 2018-09-21
An authentication bypass flaw was found in the smart_proxy_dynflow component used by Foreman. A malicious attacker can use this flaw to remotely execute arbitrary commands on machines managed by vulnerable Foreman instances, in a highly privileged context.
CVE-2018-14645
PUBLISHED: 2018-09-21
A flaw was discovered in the HPACK decoder of HAProxy, before 1.8.14, that is used for HTTP/2. An out-of-bounds read access in hpack_valid_idx() resulted in a remote crash and denial of service.
CVE-2018-1685
PUBLISHED: 2018-09-21
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.
CVE-2018-1710
PUBLISHED: 2018-09-21
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364.