Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Compliance posted in July 2009
'MonkeyFist' Launches Dynamic CSRF Web Attacks
News  |  7/30/2009  | 
Researchers release tool that automates cross-site request forgery attacks
Exploits Take Advantage Of Hot News, Search Queries
Quick Hits  |  7/28/2009  | 
Attackers look to attach their malware to hot Google searches, report says
Two Newly Disclosed Hacks Prey On Browser, Web Security
News  |  7/20/2009  | 
New cross-site request forgery (CSRF) proof-of-concept and Firefox 3.5 hacking tool released
Least-Privilege Technology Still Swimming Upstream, But Making Progress
News  |  7/10/2009  | 
Fundamental shift in endpoint security might be easier with rollout of Windows 7, experts say
Research: A Day In the Life of A Spamming Bot
Quick Hits  |  7/9/2009  | 
ESET researchers discover that a Waledac-infected bot spams out 150,000 messages a day
Oracle Report: Consumers Fickle About Ecommerce Security Controls
Quick Hits  |  7/7/2009  | 
Nearly one-third of U.K.'s online shoppers don't trust online security measures, but most don't want additional controls if it affects ease and speed of transactions
New Tool And Managed Service 'Penetration-Test' End Users
News  |  7/6/2009  | 
New User Attack Framework (UAF) could eventually work with Metasploit's hacking tool, researchers say


Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-32615
PUBLISHED: 2021-05-13
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
CVE-2021-33026
PUBLISHED: 2021-05-13
The Flask-Caching extension through 1.10.1 for Flask relies on Pickle for serialization, which may lead to remote code execution or local privilege escalation. If an attacker gains access to cache storage (e.g., filesystem, Memcached, Redis, etc.), they can construct a crafted payload, poison the ca...
CVE-2021-31876
PUBLISHED: 2021-05-13
Bitcoin Core 0.12.0 through 0.21.1 does not properly implement the replacement policy specified in BIP125, which makes it easier for attackers to trigger a loss of funds, or a denial of service attack against downstream projects such as Lightning network nodes. An unconfirmed child transaction with ...
CVE-2019-10062
PUBLISHED: 2021-05-13
The HTMLSanitizer class in html-sanitizer.ts in all released versions of the Aurelia framework 1.x repository is vulnerable to XSS. The sanitizer only attempts to filter SCRIPT elements, which makes it feasible for remote attackers to conduct XSS attacks via (for example) JavaScript code in an attri...
CVE-2020-23995
PUBLISHED: 2021-05-13
An information disclosure vulnerability in ILIAS before 5.3.19, 5.4.12 and 6.0 allows remote authenticated attackers to get the upload data path via a workspace upload.