Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Opinion

posted in April 2007
E-Gold's Chairman Spoke Out Against Cybercrime, Until He Got Caught
Commentary  |  4/30/2007  | 
I read with great interest about a Washington, D.C., federal grand jury's decision late last week to indict E Gold Ltd, Gold & Silver Reserve Inc., and the owners of these digital currency businesses on charges of money laundering, conspiracy, and operating an unlicensed money transmitting business. I recently served on a grand jury in Brooklyn, so I know the joke about being able to indict a ham sandwich to
You Aren't Safe. Get Over It
Commentary  |  4/26/2007  | 
The latest news to add to the list of online perils to be paranoid about comes courtesy of the Washington Post. Virus writers apparently have a new scheme for distributing malicious code: purchasing popular Google keywords and publishing ads that purport to lead users to legitimate Websites. Some of the keywords the tricksters bought include "BBB" (for Better Business Bureau) and "Cars.com."
Pop Quiz: Who's Got Access To The Government's Student Loan Data?
Commentary  |  4/20/2007  | 
It wouldn't surprise me if Sen. Edward ("Ted") Kennedy--well, his staff, really--had a bad case of writer's cramp. The senator's office this week alone issued four public statements criticizing the misuse of student data by student loan lenders, guarantors, and other members of that $85 billion-a-year industry. He's also made very speci
Data Dumpster Diving, Anyone?
Commentary  |  4/19/2007  | 
Do you know where your paper customer records are? Better yet, does the state attorney general's office know? As both RadioShack and CVS/Caremark Corp. have found out this year, being in control of the former situation is so much better than ceding control in the latter.
7 Security Myths Busted
Commentary  |  4/12/2007  | 
In the coming weeks, expect to see several stories in InformationWeek and at InformationWeek.com that explain and analyze the role that a chief information security officer has come to play within companies. This coverage will include profiles of some of the industry's leading security chiefs who share their experiences, expertise, and frustrations while protecting corporate and customer data in an increasingly
Should IT Departments Oversee Spying Operations?
Commentary  |  4/6/2007  | 
Wal-Mart always seems to be in the news for one reason or another. Supporters tout its pioneering marketing model and groundbreaking success in offering low-cost goods to consumers and keeping operational costs low. And then there is Wal-Mart's leading-edge IT department and its cutting-edge use and investigation of bleeding-edge technology -- ever in the pursuit of keeping costs low and maximizing profit.


Attackers Leave Stolen Credentials Searchable on Google
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2021
How to Better Secure Your Microsoft 365 Environment
Kelly Sheridan, Staff Editor, Dark Reading,  1/25/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: I can't find the back door.
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-21272
PUBLISHED: 2021-01-25
ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a "zip-slip" vulnerability. The directory support feature allows the ...
CVE-2021-23901
PUBLISHED: 2021-01-25
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML ...
CVE-2020-17532
PUBLISHED: 2021-01-25
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5
CVE-2020-12512
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting
CVE-2020-12513
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.