Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Compliance posted in February 2007
Government Targets Insider Threat
News  |  2/28/2007  | 
Defense, Justice, and HUD developing new strategies for stopping internal security leaks
Black Hat Cancels RFID Demo
News  |  2/27/2007  | 
Badge, smartcard patent holder threatens lawsuit over cloning presentation
A Virtual Post-It, Perhaps
News  |  2/26/2007  | 
Keeping all those passwords straight - not to mention secure - can suck up a lot of brain power
Black Hats Focus on Apps
News  |  2/23/2007  | 
DC convention shows security researchers are shifting away from network infrastructure - and toward applications
Top 10 Admin Passwords to Avoid
News  |  2/22/2007  | 
Don't want hackers to guess the password for that critical server or application? Stay away from these
Cisco's Web Security Play
News  |  2/21/2007  | 
Acquisition of Reactivity could pave way to network-based solutions for Web 2.0, SOA
VMs Create Potential Risks
News  |  2/21/2007  | 
Convenient and efficient, virtual machines can also increase your security exposure
Insider Tries to Steal $400 Million at DuPont
News  |  2/16/2007  | 
Unusual computer activity is tipoff in successful case against chemist who tried to steal intellectual property for his new employer
3G Card Secures Laptops
News  |  2/15/2007  | 
3G cellular-based add-on secures data in the event of malware infection, laptop loss, or theft
Are 'Sealed' Websites Any Safer?
News  |  2/9/2007  | 
Website seals are designed to make buyers feel safer. But are sites with seals really more secure?
IBM's Stealthy Security Play
News  |  2/8/2007  | 
After being acquired by IBM in August, ISS is doubling in size, tripling its customer pipeline, and laying the groundwork for a major security push by Big Blue, top exec says
Microsoft Vision Raises Questions
News  |  2/6/2007  | 
Past developments suggest that Microsoft's future security road may be a bumpy ride
NAC: Can't Get No Satisfaction
News  |  2/2/2007  | 
Vendors prepare to shore up the shortcomings of network access control at RSA conference next week
EMC Kicks Off With Security
News  |  2/2/2007  | 
'Robust' product refresh cycle begins, with RSA security built into Symmetrix
To Enter, Act Like Yourself
News  |  2/1/2007  | 
Behavior-based biometrics to ID you by the way you speak, type, move your mouse, and more
Microsoft Debuts VPN Appliance
News  |  2/1/2007  | 
SSL-based Intelligent Application Gateway is latest offering in its Forefront security product line
ID Management: A Matter of Entitlement
News  |  2/1/2007  | 
The need for compliance is driving authorization, integration, and automation in identity management


When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25533
PUBLISHED: 2021-01-15
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...
CVE-2021-3162
PUBLISHED: 2021-01-15
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
CVE-2021-21242
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or a...
CVE-2021-21245
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary file upload which can be used to u...
CVE-2021-21246
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the `/users/` endpoint there are no security checks enforced so it is possible to retrieve ar...