News & Commentary

Content tagged with Compliance posted in December 2007
FTC Ups the Ante on Fighting Spam, Phishing
Quick Hits  |  12/31/2007  | 
Federal Trade Commission report calls for authenticated email, reputation services, and better consumer anti-spam reporting tools
The Five Coolest Hacks of 2007
News  |  12/31/2007  | 
Nothing was sacred - not cars, not truckers, not even the stock exchange
ID & Access Management Cures Hospital's Password Pains
News  |  12/28/2007  | 
Lutheran Medical Center's new automated order-entry app sped up its move to single sign-on
Security's Biggest Train Wrecks of 2007
News  |  12/27/2007  | 
We've seen a boxcar o' breaches and break-ins this year, but these were the most grisly - and the hardest to take our eyes from
IT Consultant Hacks Former Client
Quick Hits  |  12/26/2007  | 
Angered over business deal, consultant wipes out former client's customer database
Tech Insight: Microsoft's IPSec
News  |  12/21/2007  | 
Windows' built-in security capabilities offer endpoint alternative to NAP/NAC
Cisco Broadens Threat Picture With New Report
News  |  12/20/2007  | 
First-time annual study offers insights on human, physical aspects of security as well as attacks and vulnerabilities
Amid Confusion, Market for ID Theft Services Grows
News  |  12/19/2007  | 
Baffled by conflicting information, consumers increasingly drawn into web of 'theft prevention' offerings
Disney, Home Depot Get Poor Privacy Marks
Quick Hits  |  12/18/2007  | 
Ralph Lauren is among the best, public interest group says
New Service Detects Backdoors in Software
News  |  12/17/2007  | 
Veracode identifies different types of these hidden programs in applications, adds a 'metal detector' for detecting them
Breaches Cause Skittish Attitudes Among Holiday Shoppers
News  |  12/14/2007  | 
Many consumers no longer sure of the security of their transactions, study says
End Users Flout Enterprise Security Policies
News  |  12/10/2007  | 
Separate studies show many users understand rules, but they break them anyway


'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-7682
PUBLISHED: 2018-06-22
Micro Focus Solutions Business Manager versions prior to 11.4 allows a user to invoke SBM RESTful services across domains.
CVE-2018-12689
PUBLISHED: 2018-06-22
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
CVE-2018-12538
PUBLISHED: 2018-06-22
In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage...
CVE-2018-12684
PUBLISHED: 2018-06-22
Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
CVE-2018-12687
PUBLISHED: 2018-06-22
tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.