Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security

7/12/2018
05:30 PM
Connect Directly
Google+
Twitter
RSS
E-Mail

What's Cooking With Caleb Sima

Security Pro File: Web app security pioneer dishes on his teenage security career, his love of electric scooters, Ace Ventura - and a new baby food business venture with his wife and famed chef, Kathy Fang.
2 of 2

Photo: Caleb Sima
Photo: Caleb Sima

2 of 2
Comment  | 
Print  | 
Comments
Threaded  |  Newest First  |  Oldest First
Joe F.
100%
0%
Joe F.,
User Rank: Apprentice
7/12/2018 | 11:49:05 PM
Great Story!
I had the privilege of working with Caleb when he was with Armorize, helping him to establish the company in the US. I learned a ton about security in a short time for sure. Great to be able to catch up on what he's doing. Good luck to him and the wife on the new venture. 
MarkSindone
50%
50%
MarkSindone,
User Rank: Moderator
7/17/2018 | 4:46:15 AM
Re: Great Story!
This is how we can get to know that technology has evolved. Security risks have grown and thus needing security experts who are more proficient in the field. Back then, this isn't a major concern so the jobscope of such a personnel does not really entail that much. Today, everyone is afraid and is concerned about the security of their online activities and it is a market that needs professionals.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11498
PUBLISHED: 2020-04-02
Slack Nebula through 1.1.0 contains a relative path vulnerability that allows a low-privileged attacker to execute code in the context of the root user via tun_darwin.go or tun_windows.go. A user can also use Nebula to execute arbitrary code in the user's own context, e.g., for user-level persistenc...
CVE-2020-11499
PUBLISHED: 2020-04-02
Firmware Analysis and Comparison Tool (FACT) 3 has Stored XSS when updating analysis details via a localhost web request, as demonstrated by mishandling of the tags and version fields in helperFunctions/mongo_task_conversion.py.
CVE-2020-7628
PUBLISHED: 2020-04-02
install-package through 1.1.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the device function.
CVE-2020-7629
PUBLISHED: 2020-04-02
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
CVE-2020-7630
PUBLISHED: 2020-04-02
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.