News & Commentary

Content tagged with Compliance posted in August 2011
Endpoint Freedoms Leaving Businesses Vulnerable To Attack
Quick Hits  |  8/30/2011  | 
New survey finds IT professionals concerned about targeted attacks, but doing little to lock down weak links in their endpoints
Unifying Compliance Initiatives To Make Budgets Last
News  |  8/29/2011  | 
Don't reinvent the wheel with fragmented compliance initiatives
PCI QSA Status Revocation A Shot Across The Bow For QSAs?
Commentary  |  8/24/2011  | 
The PCI Security Council's move spells trouble for unscrupulous QSAs and shows that the Council means business in enforcing its quality standards
Seven Mistakes That Make Compliance Efforts Fail
News  |  8/15/2011  | 
The most common mistakes that can lead to flagged audits
Dark Reading Launches New Tech Center On Security And Compliance
Commentary  |  8/15/2011  | 
New Compliance Tech Center will cover relationship between security initiatives and compliance initiatives
LinkedIn Dropping User Pictures From Ads
News  |  8/12/2011  | 
Incident underscores the uneasy cohabitation of honest communication and calculated commerce on social networks
Study: Cybercrime Becoming More Costly, More Frequent For Enterprises
News  |  8/2/2011  | 
In survey of 50 companies, Ponemon finds average annual cost of cybercrime is $5.9 million


'PowerSnitch' Hacks Androids via Power Banks
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/8/2018
Higher Education: 15 Books to Help Cybersecurity Pros Be Better
Curtis Franklin Jr., Senior Editor at Dark Reading,  12/12/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
10 Best Practices That Could Reshape Your IT Security Department
This Dark Reading Tech Digest, explores ten best practices that could reshape IT security departments.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-6705
PUBLISHED: 2018-12-12
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.
CVE-2018-15717
PUBLISHED: 2018-12-12
Open Dental before version 18.4 stores user passwords as base64 encoded MD5 hashes.
CVE-2018-15718
PUBLISHED: 2018-12-12
Open Dental before version 18.4 transmits the entire user database over the network when a remote unathenticated user accesses the command prompt. This allows the attacker to gain access to usernames, password hashes, privilege levels, and more.
CVE-2018-15719
PUBLISHED: 2018-12-12
Open Dental before version 18.4 installs a mysql database and uses the default credentials of "root" with a blank password. This allows anyone on the network with access to the server to access all database information.
CVE-2018-6704
PUBLISHED: 2018-12-12
Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.