Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Perimeter posted in March 2012
Forensic Approach To Mobile App Vulnerability Research
Commentary  |  3/30/2012  | 
Intro to a unique approach for vulnerability research on mobile apps using traditional PC forensic tools
Someone Left The Keys In Your Compliance System
Commentary  |  3/29/2012  | 
Information security is at the mercy of your entire staff's habits
A Single 'Pain' Of Glass?
Commentary  |  3/27/2012  | 
Is the often-pitched 'single pane of glass' a benefit to security monitoring tools or yet another point of contention?
Technology Cannot Solve All Your People Problems
Commentary  |  3/22/2012  | 
Too many in business assume compliance is primarily a technology issue
Keep Your Friends Close, Especially If They Are Anonymous
Commentary  |  3/22/2012  | 
Sabu's traitorous ways reminds us of the sage advice to keep your friends close and your enemies closer
Fun With REMnux -- And New Malware Analysis Book
Commentary  |  3/22/2012  | 
"Practical Malware Analysis" provides in-depth knowledge on malware analysis and includes useful lab exercises. We take REMnux for a spin with the labs
Alert Logic Announces Security For Amazon EC2
News  |  3/20/2012  | 
Subscribers gain access to fully managed network intrusion detection solution for Amazon Web Services
Nobody Cares About HIPAA
Commentary  |  3/15/2012  | 
Compliance in many organizations is seen as only a costly inconvenience
Ron Was Wrong, Whit Is Right, And What You Need To Know
Commentary  |  3/13/2012  | 
Clarifying the technical findings on a weakness in RSA crypto keys and some recommendations on how to prepare and protect your assets from the next inevitable crypto weakness discovery
Big Data Security Or SIEM Buzzword Parity?
Commentary  |  3/9/2012  | 
If you attended the 2012 RSA Security Conference, BSides San Francisco, or the America’s Growth Capital Summit, you no doubt noticed claims of SIEM vendors jumping on the 'big data security' bandwagon
Six Things Management Needs To Better Understand About Compliance
Commentary  |  3/8/2012  | 
It may be boring or scary to management, but compliance is ultimately their burden to bear
Doing Tech Evangelism Right
Commentary  |  3/8/2012  | 
Kaspersky Lab's public request for help on an unsolved mystery surrounding Duqu serves as a case study about the power of technology evangelism
Rogue AV Campaign Infects More Than 200,000 Web Pages
News  |  3/7/2012  | 
Websense has detected a massive infection campaign targeting users with rogue antivirus
WikiLeaks And Anonymous: A Forced Standard Of Corporate Accountability?
News  |  3/5/2012  | 
The Anonymous-WikiLeaks alliance will amplify the call for public disclosures of private data. For security professionals, the lesson is to not give in


Attackers Leave Stolen Credentials Searchable on Google
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2021
How to Better Secure Your Microsoft 365 Environment
Kelly Sheridan, Staff Editor, Dark Reading,  1/25/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23901
PUBLISHED: 2021-01-25
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML ...
CVE-2020-17532
PUBLISHED: 2021-01-25
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5
CVE-2020-12512
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting
CVE-2020-12513
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
CVE-2020-12514
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd