Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Compliance posted in May 2010
Researchers Uncover Bot Sales Network
Quick Hits  |  5/28/2010  | 
Internet portal offers bots designed for a variety of activities at a wide range of prices, PandaLabs says
Product Watch: New Patents Help Upstart Make A Ruckus In Wireless Security Management
News  |  5/25/2010  | 
New technologies promise to simplify the configuration and administration of Wi-Fi security
IE 6 Accounts For More Than One-Fourth Of All Enterprise Web Traffic
Quick Hits  |  5/25/2010  | 
But use of the aged and vulnerable version of Internet Explorer gradually declining, report says
Apple Safari 'Carpet Bomb' Flaw Remains Unfixed Two Years Later
News  |  5/24/2010  | 
Google Chrome also prone to similar attacks
New Threat For Wireless Networks: Typhoid Adware
Quick Hits  |  5/21/2010  | 
Some users could become "carriers," unknowingly passing infections to others, university researchers say
ID Theft Victims Spending Less In Cleanup Aftermath
News  |  5/21/2010  | 
New Identity Theft Resource Center (ITRC) report shows victims spending less time, money to clear their names
Symantec To Buy VeriSign's Authentication Business For $1.28 Billion
News  |  5/19/2010  | 
VeriSign will refocus business on Internet infrastructure, naming services
Facebook Readies Simpler Privacy Options
News  |  5/19/2010  | 
Possibilities include changing default settings on the site
Product Watch: AT&T Launches New Cloud-Based Email Security Offering
News  |  5/17/2010  | 
New AT&T Secure E-mail Gateway Service uses McAfee's global threat intelligence technology
Product Watch: Facebook Adds New Anti-Hacking Protections
News  |  5/14/2010  | 
Security feature blocks suspicious logins
Report: U.S. Internet Registrars Continue To Host Phony Online Pharmacy
Quick Hits  |  5/4/2010  | 
How a major fake online pharmacy out of Russia is able to continue selling drugs despite evidence of criminal operations


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Creating an Effective Incident Response Plan
Security teams are realizing their organizations will experience a cyber incident at some point. An effective incident response plan that takes into account their specific requirements and has been tested is critical. This issue of Tech Insights also includes: -a look at the newly signed cyber-incident law, -how organizations can apply behavioral psychology to incident response, -and an overview of the Open Cybersecurity Schema Framework.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-45909
PUBLISHED: 2022-11-26
drachtio-server 0.8.18 has a heap-based buffer over-read via a long Request-URI in an INVITE request.
CVE-2022-45907
PUBLISHED: 2022-11-26
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
CVE-2022-45908
PUBLISHED: 2022-11-26
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.
CVE-2022-44843
PUBLISHED: 2022-11-25
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setOpenVpnClientCfg function.
CVE-2022-44844
PUBLISHED: 2022-11-25
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.