Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Compliance posted in May 2008
Comcast Outage Traced to Teenage Hackers
News  |  5/30/2008  | 
DNS attack left service provider down for five hours
Man Arraigned for Setting Up 58,000 Brokerage Accounts
Quick Hits  |  5/30/2008  | 
Comic book and cartoon characters got their own portfolios
Societe Generale Offers Findings on Breach Investigation
News  |  5/28/2008  | 
Trader's creativity, lack of proper controls combined to create perfect storm that lost the company $7 billion
New SQL Injection Attacks Exploit Adobe Flash Flaw
News  |  5/28/2008  | 
And it's not just online gamers who are at risk
Tech Insight: Debian Linux Flaw Threatens SSL Encryption
News  |  5/23/2008  | 
Vulnerability in Debian OpenSSL could allow attackers to decrypt 'secure' Web sessions
Passport to the Web
News  |  5/23/2008  | 
Our system for authenticating international travelers' identities is solid. Why can't we create a similar process online?
Hospital Security Programs Ailing, Study Says
News  |  5/20/2008  | 
Patient data at risk due to lack of attention to policies, regulations
Permanent Denial-of-Service Attack Sabotages Hardware
News  |  5/19/2008  | 
Researcher to demonstrate a permanent denial-of-service (PDOS) attack that remotely wipes out hardware via flash firmware updates
Cisco Alums Launch Security Startup
Quick Hits  |  5/19/2008  | 
Rohati Systems's security appliance uses network-based entitlement control
Can You Pass This Privacy Quiz?
News  |  5/16/2008  | 
Most Californians couldn't, according to newly released research
Hackers Sniff Their Way Into Data From Restaurant Chain
News  |  5/14/2008  | 
Thieves collected 5,000 credit cards - and hundreds of thousands of dollars - from 11 Dave & Buster's locations
Check Point Offers Consumers 'New Level' of Security
News  |  5/13/2008  | 
'Browser virtualization' sandboxes OS, constitutes new category of products, firewall giant says
Tech Insight: Finding & Prioritizing Web Application Vulnerabilities
News  |  5/9/2008  | 
Web app flaws are rapidly becoming the most serious threat to your data. Do you know how to identify them - and which ones to fix first?
Ex-Feds Start Up ID Theft Protection Service
News  |  5/7/2008  | 
iSekurity promises to find out who stole your identity - or pay you $11,000
New Trojan Masquerades as Free MP3 Player
Quick Hits  |  5/7/2008  | 
More than 500,000 users have detected new threat
DR's 10 Most Popular Stories Ever (Second Edition)
News  |  5/2/2008  | 
A look at the top stories from our first two years, including coolest hacks, biggest botnets, and a thumb drive exploit that readers just can't put down
Study: What Happens in Vegas Might Not Stay in Vegas
Quick Hits  |  5/1/2008  | 
Wireless penetration test shows hotels, casinos don't adequately protect their WiFi networks


Attackers Leave Stolen Credentials Searchable on Google
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2021
How to Better Secure Your Microsoft 365 Environment
Kelly Sheridan, Staff Editor, Dark Reading,  1/25/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-23901
PUBLISHED: 2021-01-25
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML ...
CVE-2020-17532
PUBLISHED: 2021-01-25
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between 2.0.0 ~ 2.1.3 and fixed in Apache ServiceComb-Java-Chassis 2.1.5
CVE-2020-12512
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated reflected POST Cross-Site Scripting
CVE-2020-12513
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
CVE-2020-12514
PUBLISHED: 2021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to a NULL Pointer Dereference that leads to a DoS in discoveryd