Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Cloud posted in August 2011
New Free Tools Simplify Analysis Of Android Malware
News  |  8/31/2011  | 
What did you do over your summer break? Two graduate students wrote tools that address heightened concern over eventual attacks against the Android platform
Insulin Pump Hack Controversy Grows
News  |  8/26/2011  | 
Security researcher--and pump user--who found the flaw takes medical device manufacturer Medtronic to task for its response to the security vulnerability.
Salesforce To Acquire Crypto Provider
News  |  8/26/2011  | 
SaaS provider's purchase of Navajo Systems could help allay some cloud security skeptics' concerns, experts say.
HIE Accreditation Service Offered To Software Vendors
News  |  8/25/2011  | 
The Electronic Healthcare Network Accreditation Commission announces a privacy and security testing program to accompany existing health information exchange accreditation.
Fingerprint Readers Boost Healthcare Security
News  |  8/25/2011  | 
Biometrics technology locks up Children's Clinics patient data while cutting down on password-reset requests.
Hacked Medical Device Sparks Congressional Inquiry
News  |  8/23/2011  | 
Legislators demand answers after a security researcher remotely controlled his own insulin pump using a $20 radio frequency transmitter at Black Hat.
EHR Data In Cloud Needs Strong Security Trail
News  |  8/22/2011  | 
Presenters at a recent Legal EHR Summit warn healthcare providers to press their vendors for clear answers on security.
Encrypt Early, Encrypt Often
News  |  8/11/2011  | 
You can't rely on cloud providers for data security.
Cloud Security Certification Not So Simple
Commentary  |  8/9/2011  | 
Current pass rate of CSA's CCSK test is only 53 percent
Cloud Identity Problems Solved By Federating Directories
News  |  8/4/2011  | 
Amazon, Radiant Logic join competition to supply virtual directories that make enterprise identities available in the cloud.
Tennessee BlueCross BlueShield Encrypts All Its Data
News  |  8/1/2011  | 
The insurer claims to be first anywhere to encrypt all "at-rest" data across the enterprise, a project that was put on the fast track after an embarrassing data breach.
LulzSec Intrigue; Hurd Talks Oracle's Real Battle
Commentary  |  8/1/2011  | 
A youthful hacker on a remote island surfaces. Plus Mark Hurd goes one-on-one about what Oracle really wants.


COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/1/2020
Stay-at-Home Orders Coincide With Massive DNS Surge
Robert Lemos, Contributing Writer,  5/27/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-4019
PUBLISHED: 2020-06-01
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.
CVE-2020-4020
PUBLISHED: 2020-06-01
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.
CVE-2020-4021
PUBLISHED: 2020-06-01
Affected versions are: Before 8.5.5, and from 8.6.0 before 8.8.1 of Atlassian Jira Server and Data Center allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the XML export view.
CVE-2020-4023
PUBLISHED: 2020-06-01
The review coverage resource in Atlassian Fisheye and Crucible before version 4.8.2 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the committerFilter parameter.
CVE-2020-4013
PUBLISHED: 2020-06-01
The review resource in Atlassian Fisheye and Crucible before version 4.8.1 allows remote attackers to inject arbitrary HTML or Javascript via a cross site scripting (XSS) vulnerability through the review objectives.