Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Compliance posted in December 2009
Twitter Acquires GeoAPI Creator Mixer Labs
News  |  12/24/2009  | 
Software allows users to map their Twitter posts to specific locations, though some worry about privacy
Smartphone Security Startup Offers Free Beta
News  |  12/21/2009  | 
Product to mix lightweight mobile client with cloud-based security, backup, and anti-theft features
Product Watch: IBM Replaces Passwords With Palm-Vein Biometrics In Single Sign-On
News  |  12/17/2009  | 
Fujitsu's PalmSecure LOGONDIRECTOR is integrated with IBM Tivoli Access Manager for Single Sign-On
Shadowserver Global Data Shows 'No One Is Immune' From Conficker
Quick Hits  |  12/16/2009  | 
Russia, U.S., and Ukraine are home to highest numbers of Conficker-infected IP addresses
Old-School Botnet Still Thriving
Quick Hits  |  12/11/2009  | 
New Trend Micro report details how IRC-based SDBOT is going strong with a new mission
Droid Smartphone Hacked
News  |  12/10/2009  | 
Exploit lets phone users gain administrative root access to Google Android-based phones
Microsoft Targets Enterprise Endpoint With New Products
News  |  12/3/2009  | 
New Web gateway leverages the cloud, and remote access gateway draws on identity
US-CERT Warns Of VPN Attack That Bypasses Browser Security
Quick Hits  |  12/1/2009  | 
SSL VPN products from Cisco, Juniper Networks, SafeNet, and SonicWALL all vulnerable to attack that has "no solution"


News
Inside the Ransomware Campaigns Targeting Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/2/2021
Commentary
Beyond MITRE ATT&CK: The Case for a New Cyber Kill Chain
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  3/30/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3243
PUBLISHED: 2021-04-15
Wfilter ICF 5.0.117 contains a cross-site scripting (XSS) vulnerability. An attacker in the same LAN can craft a packet with a malicious User-Agent header to inject a payload in its logs, where an attacker can take over the system by through its plugin-running function.
CVE-2021-29448
PUBLISHED: 2021-04-15
Pi-hole is a Linux network-level advertisement and Internet tracker blocking application. The Stored XSS exists in the Pi-hole Admin portal, which can be exploited by the malicious actor with the network access to DNS server. See the referenced GitHub security advisory for patch details.
CVE-2021-30138
PUBLISHED: 2021-04-15
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2021-27112
PUBLISHED: 2021-04-15
LightCMS v1.3.5 contains a remote code execution vulnerability in /app/Http/Controllers/Admin/NEditorController.php during the downloading of external images.
CVE-2021-20288
PUBLISHED: 2021-04-15
An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associa...