Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Opinion

Content posted in January 2013
Big Data Security Discussion
Commentary  |  1/31/2013  | 
Answers to common big-data security questions
Going Green With Your Ones And Zeros
Commentary  |  1/30/2013  | 
For better security, use less data
Combatting Advanced Threats In 2013 Through Basics
Commentary  |  1/28/2013  | 
Focus on fixing the problems of a past generation before focusing on the next
Security No-Man's Land
Commentary  |  1/28/2013  | 
As the industry descends on the RSA Conference to discuss the latest and greatest in security, the underserved midmarket continues to struggle with basic blocking and tackling. The industry machinery is not built to solve that problem
The Three Worst Words In The English Language: Can't We Just?
Commentary  |  1/25/2013  | 
The road to poor identity and access management architecture is paved with "can't we justs." It's 2013: Find a way
Is Mobile Device Management The Answer?
Commentary  |  1/23/2013  | 
MDM software is being considered by healthcare IT execs concerned about security.
Acing An Audit In 30 Minutes
Commentary  |  1/18/2013  | 
Compliance audits don't have to be chaotic events
Java Security Warnings: Cut Through The Confusion
Commentary  |  1/18/2013  | 
Recent warnings to deactivate Java are raising additional questions: What about JavaScript, EJB, JavaFX, Android and any other use of the programming language?
Uncertain State Of Cyber War
Commentary  |  1/17/2013  | 
Just what does "cyber warfare" mean? We're still figuring out tactics and capabilities.
Cartoon: Forgot Password? Click Here
Commentary  |  1/14/2013  | 
All Your Base Are In An Indeterminate State
Commentary  |  1/14/2013  | 
Or the importance of timeliness in monitoring
How Well Do You Know Your Data?
Commentary  |  1/9/2013  | 
The more you know about your data, the more effectively you can protect it
McAfee Takes Belize: Social Engineering Lesson
Commentary  |  1/9/2013  | 
Eccentric antivirus firm founder John McAfee says he tricked people with spyware -- using free laptops. Social engineering attacks remain cheap, easy and effective.
When Cloud Computing Is The Wrong Fit
Commentary  |  1/9/2013  | 
ROI is the first question to answer when deciding if cloud computing is a good platform for your enterprise. Three others involve compliance, infrastructure, and a strong business case.
What Is It You Would Say That You Do Here?
Commentary  |  1/8/2013  | 
Here is a dangerous question to start the new year: Does your company actually need a security department? If you are doing CYA instead of CIA, the answer is probably no
You Keep Using That Word ...
Commentary  |  1/4/2013  | 
When monitoring doesn't mean what you think it does


News
A Startup With NSA Roots Wants Silently Disarming Cyberattacks on the Wire to Become the Norm
Kelly Jackson Higgins, Executive Editor at Dark Reading,  5/11/2021
Edge-DRsplash-10-edge-articles
Cybersecurity: What Is Truly Essential?
Joshua Goldfarb, Director of Product Management at F5,  5/12/2021
Commentary
3 Cybersecurity Myths to Bust
Etay Maor, Sr. Director Security Strategy at Cato Networks,  5/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Google Maps is taking "interactive" to a whole new level!
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-15279
PUBLISHED: 2021-05-18
An Improper Access Control vulnerability in the logging component of Bitdefender Endpoint Security Tools for Windows versions prior to 6.6.23.320 allows a regular user to learn the scanning exclusion paths. This issue was discovered during external security research.
CVE-2021-3423
PUBLISHED: 2021-05-18
Uncontrolled Search Path Element vulnerability in the openssl component as used in Bitdefender GravityZone Business Security allows an attacker to load a third party DLL to elevate privileges. This issue affects Bitdefender GravityZone Business S...
CVE-2020-18194
PUBLISHED: 2021-05-17
Cross Site Scripting (XSS) in emlog v6.0.0 allows remote attackers to execute arbitrary code by adding a crafted script as a link to a new blog post.
CVE-2020-18195
PUBLISHED: 2021-05-17
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete a specific article via the component " /admin.php?action=page."
CVE-2020-18198
PUBLISHED: 2021-05-17
Cross Site Request Forgery (CSRF) in Pluck CMS v4.7.9 allows remote attackers to execute arbitrary code and delete specific images via the component " /admin.php?action=images."