Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Perimeter posted in September 2011
TRICARE, SAIC Report Loss Of Data On 4.9 Million
News  |  9/29/2011  | 
Loss of backup tapes puts personal data of military personnel at risk
Eavesdropping Trojans Used In Cell Phone Spying Case
Commentary  |  9/26/2011  | 
Israeli case a reminder of all types of social engineering threats
FBI Arrests Two Suspected LulzSec, Anonymous Members
Quick Hits  |  9/25/2011  | 
Feds look to crack down on AntiSec players
Identity Federation Versus PKI
Commentary  |  9/24/2011  | 
Neither technology alone offers the ultimate user authentication infrastructure
New FFIEC Authentication Guidance Calls For Layers
Commentary  |  9/24/2011  | 
Increased threats and weaknesses in certain accepted authentication mechanisms, FFIEC warns
Identity Federation: Waiting On Access Control
Commentary  |  9/21/2011  | 
Separate authentication by websites will remain the reality until access control is done right in Web apps
Segregating DBA And Admin Duties
Commentary  |  9/19/2011  | 
Keeping platform admins out of your database
Intel Demonstrates Potential Password-Killers
Commentary  |  9/16/2011  | 
Intel presented two possible ways it plans to make passwords obsolete
0-Day SCADA Exploits Released, Publicly Exposed Servers At Risk
Commentary  |  9/16/2011  | 
Italian researcher releases 0-day SCADA exploits leaving companies vulnerable to exploit; Emerging Threats project releases update to help detect attacks
Passwords: Time's Up?
Commentary  |  9/10/2011  | 
Stronger authentication is a major security issue yet to be solved
Metasploit Gets Covert Forensics And PXE Boot Attack Capabilities
Commentary  |  9/9/2011  | 
New Metasploit modules released during the Vegas security conferences add cool, new features, like covert forensics and PXE boot pwnage
DAM In The Cloud
Commentary  |  9/7/2011  | 
Modifications to DAM for use with cloud infrastructure providers
Mitnick's Tale Sheds Light on Social Tactics
News  |  9/6/2011  | 
Lesson from the past: Targeted companies need good security processes to protect their data
Don't Hate The 'Playas' -- Hate The Game
Commentary  |  9/5/2011  | 
If Oracle wants to bitch about anything, it should bitch about how things get done in the halls of government -- Veracode is only trying to accelerate its growth
The Criticality Of Risk Assessments: FISMA, HIPAA, And Other Regs
Commentary  |  9/4/2011  | 
Risk assessments are a critical part of regulatory compliance, but many organizations don't implement them well


Attackers Leave Stolen Credentials Searchable on Google
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2021
How to Better Secure Your Microsoft 365 Environment
Kelly Sheridan, Staff Editor, Dark Reading,  1/25/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23901
PUBLISHED: 2021-01-25
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML ...
CVE-2020-17532
PUBLISHED: 2021-01-25
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5
CVE-2020-12512
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting
CVE-2020-12513
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
CVE-2020-12514
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd