News & Commentary

Content tagged with Compliance posted in December 2010
Happy Holidays From Dark Reading
Quick Hits  |  12/23/2010  | 
Dark Reading staff takes brief hiatus; rebooting on Jan. 3
Password Diversity Urged In Wake Of Gawker Attack
News  |  12/17/2010  | 
One of biggest threats is reuse of hacked credentials on other websites
Compliance Means Getting A Handle On Insider Threats
News  |  12/16/2010  | 
When the auditors come, they'll be looking at your internal controls as well as your external defenses. Will you be ready?
Tech Insight: Two-Factor Authentication Alone Isn't Enough
News  |  12/10/2010  | 
Protecting online banking customers entails a more holistic approach by banks that includes risk-based authentication, browser protection, and fraud monitoring
Holiday Rush Leaves Smartphones At Risk
Quick Hits  |  12/9/2010  | 
Symantec study finds smartphone users planning to use their mobile devices for work, personal purposes during the holidays
Google Ready To Test Chrome OS
News  |  12/9/2010  | 
Program participants will receive a Google-commissioned netbook, designated Cr-48, with Chrome OS installed
Endpoints More At Risk Than Ever, Study Says
Quick Hits  |  12/8/2010  | 
Threat of malware, application vulnerabilities continues to increase, Ponemon finds
Lost Laptops Cost Companies Billions, Study Says
Quick Hits  |  12/3/2010  | 
Cost of data exposure dwarfs the cost of lost equipment, according to Intel/Ponemon report


Crowdsourced vs. Traditional Pen Testing
Alex Haynes, Chief Information Security Officer, CDL,  3/19/2019
BEC Scammer Pleads Guilty
Dark Reading Staff 3/20/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
5 Emerging Cyber Threats to Watch for in 2019
Online attackers are constantly developing new, innovative ways to break into the enterprise. This Dark Reading Tech Digest gives an in-depth look at five emerging attack trends and exploits your security team should look out for, along with helpful recommendations on how you can prevent your organization from falling victim.
Flash Poll
The State of Cyber Security Incident Response
The State of Cyber Security Incident Response
Organizations are responding to new threats with new processes for detecting and mitigating them. Here's a look at how the discipline of incident response is evolving.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-10016
PUBLISHED: 2019-03-25
GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.
CVE-2019-10018
PUBLISHED: 2019-03-25
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case.
CVE-2019-10019
PUBLISHED: 2019-03-25
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PSOutputDev::checkPageSlice at PSOutputDev.cc for nStripes.
CVE-2019-10020
PUBLISHED: 2019-03-25
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function Splash::scaleImageYuXu at Splash.cc for x Bresenham parameters.
CVE-2019-10021
PUBLISHED: 2019-03-25
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nComps.