Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Vulnerabilities / Threats posted in November 2014
Why We Need Better Cyber Security: A Graphical Snapshot
Slideshows  |  11/28/2014  | 
By 2022, demand for security industry professionals will grow 37%.
Dangers Of Shopping Are Evolving
Quick Hits  |  11/26/2014  | 
Point-of-sale malware is making brick-and-mortar shopping more dangerous. Online, attackers are beginning to value user accounts with payment information attached more than credit card details themselves.
6 Million+ Email Accounts Worldwide Exposed In Past 3 Months
Quick Hits  |  11/25/2014  | 
Spike in number of stolen accounts likely due to uptick in major data breaches, researchers say.
Underground Carders Abusing Charities To Verify Stolen Payment Data
News  |  11/25/2014  | 
Charities' weak fraud controls make things easier on donors and criminals alike.
Don't Discount XSS Vulnerabilities
News  |  11/24/2014  | 
XSS flaws are more serious than you'd think.
Cyber Security Needs Its Ralph Nader
Commentary  |  11/24/2014  | 
It took thousands of unnecessary traffic fatalities to create an environment for radical transformation of the auto industry. What will it take for a similar change to occur in data security?
Cloud Security By The Numbers
Slideshows  |  11/21/2014  | 
Quantifying the perceptions around cloud security practices.
The Week When Attackers Started Winning The War On Trust
Commentary  |  11/21/2014  | 
The misuse of keys and certificates is not exotic or hypothetical. Its a real threat that could undermine most, if not all, critical security controls, as recent headlines strongly show.
Russian Cyber Espionage Under The Microscope
News  |  11/20/2014  | 
New report shows level of coordination and strategy by three main groups of cyberspies out of Russia.
New Citadel Attack Targets Password Managers
News  |  11/20/2014  | 
IBM researchers have found signs that the prolific data steal Trojan is now being used to attack widely used password managers.
Surveillance Cameras Next On The Insecure IoT List
News  |  11/20/2014  | 
Three buffer overflow vulnerabilities leave HikVision video recorders open to remote code execution.
Internet Architecture Board Calls For Net Encryption By Default
News  |  11/19/2014  | 
The Internet Architecture Board (IAB) urges encryption across the protocol stack to usher in an era where encrypted traffic is the norm. But there are possible security tradeoffs.
Machine Learning: A Solution to Today's Security Threats & One Step Closer to AI
Partner Perspectives  |  11/19/2014  | 
Algorithms can identify threats that have been missed by traditional security mechanisms.11/19/2014 11:44:00 AM
The Rise Of The Resilient Mobile Botnet
News  |  11/19/2014  | 
New report on what researchers call one of the 'most sophisticated mobile botnets online' shows how profitable mobile malware has become.
Microsoft Issues Emergency Patch Amid Targeted Attacks
News  |  11/18/2014  | 
Windows Kerberos authentication bug "critical."
Is Security Awareness Training Really Worth It?
News  |  11/18/2014  | 
Experts weigh in on the value of end-user security training, and how to make education more effective.
Deconstructing The Cyber Kill Chain
Commentary  |  11/18/2014  | 
As sexy as it is, the Cyber Kill Chain model can actually be detrimental to network security because it reinforces old-school, perimeter-focused, malware-prevention thinking.
Why Cyber Security Starts At Home
Commentary  |  11/17/2014  | 
Even the grandmas on Facebook need to know and practice basic security hygiene, because what happens anywhere on the Internet can eventually affect us all.
Microsoft Fixes Critical SChannel & OLE Bugs, But No Patches For XP
News  |  11/14/2014  | 
No patches released for the now-unsupported XP even though the 19-year-old OLE bug is critical and "Winshock" bug in Windows' SSL/TLS installation could be worse than Heartbleed.
Rethinking Security With A System Of 'Checks & Balances'
Commentary  |  11/14/2014  | 
For too long, enterprises have given power to one branch of security governance -- prevention -- at the expense of the other two: detection and response.
Time To Turn The Tables On Attackers
Commentary  |  11/13/2014  | 
As a security industry, we need to arm business with innovative technologies that provide visibility, analysis, and action to prevent inevitable breaches from causing irreparable damage.
The Enemy Who Is Us: DoD Puts Contractors On Notice For Insider Threats
Commentary  |  11/13/2014  | 
New rule requires US government contractors to gather and report information on insider threat activity on classified networks.
Expired Antivirus Software No. 1 Cause Of Unprotected Windows 8 PCs
News  |  11/13/2014  | 
New data from Microsoft shows that nearly 10% of Windows 8 users are running expired AV software on their systems, making them four times more likely to get infected.
Better Together: Why Cyber Security Vendors Are Teaming Up
Commentary  |  11/12/2014  | 
Alliances, mergers, and acquisitions are ushering in an era of unprecedented co-opetition among former rivals for your point solution business.
POS Malware Continues To Evolve
News  |  11/11/2014  | 
New report out today details three prevalent families.
Small-to-Midsized Businesses Targeted In More Invasive Cyberattacks
News  |  11/11/2014  | 
How notorious remote access tools Predator Pain and Limitless have evolved into bargain-basement tools accessible to masses of cybercriminals.
How Enterprises Can Get The Most From Threat Intelligence
News  |  11/11/2014  | 
Understanding the threats faced by your organization can improve your defenses. Here are some tips for choosing tools and services -- and maximizing their impact.
Walk & Stalk: A New Twist In Cyberstalking
Commentary  |  11/11/2014  | 
How hackers can turn Wifi signals from smartphones and tablets into a homing beacon that captures users' online credentials and follows them, undetected, throughout the course of the day.
New Attack Method Can Hit 95% Of iOS Devices
News  |  11/10/2014  | 
Masque Attack replaces legit apps with malware using the same bundle identifier names.
The Staggering Complexity of Application Security
Commentary  |  11/10/2014  | 
During the past few decades of high-speed coding we have automated our businesses so fast that we are now incapable of securing what we have built.
Stop Trusting Signed Malware: 3 Steps
Commentary  |  11/7/2014  | 
Cybercriminals who manipulate valid signatures and certificates to get malware into an organization is a more common tactic than you think.
Privacy Versus The 'Tyranny Of The Algorithm'
News  |  11/5/2014  | 
Health, social media, buying trends, and other data and activity are routinely bartered for profit, but at what cost to the consumer or user?
iOS 8 Vs. Android: How Secure Is Your Data?
Commentary  |  11/5/2014  | 
With iOS 8, the lines between iOS and Android are blurring. No longer is iOS the heavily fortified environment and Android the wide-open one.
Breach Fatigue Sets In With Consumers
News  |  11/4/2014  | 
Report from Ponemon and RSA shows that consumers aren't really adjusting behavior due to mega breaches.
Preparing For A Data Breach: Think Stop, Drop & Roll
Commentary  |  11/3/2014  | 
Breaches are going to happen, which is why we need to treat incident response readiness like fire drills, practicing time and time again until the response is practically instinctive.


Attackers Leave Stolen Credentials Searchable on Google
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2021
How to Better Secure Your Microsoft 365 Environment
Kelly Sheridan, Staff Editor, Dark Reading,  1/25/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: We need more votes, check the obituaries.
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-4889
PUBLISHED: 2021-01-26
IBM Spectrum Scale 5.0.0 through 5.0.5.4 and 5.1.0 could allow a local user to poison log files which could impact support and development efforts. IBM X-Force ID: 190971.
CVE-2020-4949
PUBLISHED: 2021-01-26
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192025.
CVE-2021-21275
PUBLISHED: 2021-01-25
The MediaWiki "Report" extension has a Cross-Site Request Forgery (CSRF) vulnerability. Before fixed version, there was no protection against CSRF checks on Special:Report, so requests to report a revision could be forged. The problem has been fixed in commit f828dc6 by making use of Medi...
CVE-2021-21272
PUBLISHED: 2021-01-25
ORAS is open source software which enables a way to push OCI Artifacts to OCI Conformant registries. ORAS is both a CLI for initial testing and a Go Module. In ORAS from version 0.4.0 and before version 0.9.0, there is a "zip-slip" vulnerability. The directory support feature allows the ...
CVE-2021-23901
PUBLISHED: 2021-01-25
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML external entity injection (also known as XXE) is a web security vulnerability that allows an attacker to interfere with an application's processing of XML ...