Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Vulnerabilities / Threats posted in May 2009
Report Identifies The Most Dangerous -- And Safest -- Search Terms
Quick Hits  |  5/29/2009  | 
"Viagra" is surprisingly safe, but "screensaver" is a dangerous search, McAfee report says
Cybersecurity Review Finds U.S. Networks 'Not Secure'
News  |  5/29/2009  | 
The report dovetails with President Obama's call for the creation of a cybersecurity coordinator who will orchestrate and integrate federal cybersecurity policies and agendas.
Microsoft Warns Of 'Browse-And-Get-Owned' DirectX Flaw
News  |  5/28/2009  | 
The flaw could allow a remote attacker to execute malicious code by convincing or duping a user to open a specially crafted QuickTime media file.
Security Experts Raise Alarm Over Insider Threats
News  |  5/26/2009  | 
Economic troubles raising the stakes on potential threats, FIRST members say
Microsoft Issues IIS Security Advisory
News  |  5/19/2009  | 
An exploit of the vulnerability could give an attacker access to a directory that normally requires authentication.
Schools' Cybersecurity Needs Improvement
News  |  5/18/2009  | 
While more than half of surveyed schools reported a breach last year, 75% say their security infrastructure is adequate.
Tech Insight: Keeping Server Virtualization Secure
News  |  5/15/2009  | 
Don't let security worries stop you from virtualizing your servers -- but know the risks and ways to protect your systems and data
'Kramer' Is In The Building
Commentary  |  5/15/2009  | 
My firm, Secure Network Technologies, was recently hired by a large healthcare provider to perform a security assessment. As part of the job, my partner, Bob Clary, posed as an employee, similar to the "Seinfeld" episode in which Kramer shows up and works at a company where he was never actually hired.
DHS Disaster Recovery Plans Lacking, Report Finds
News  |  5/14/2009  | 
Eight of the Department of Homeland Security's 27 critical systems don't have an identified alternate processing site.
Microsoft Patches PowerPoint Flaws, But Not For Mac
News  |  5/12/2009  | 
One of the 14 Patch Tuesday bulletins is rated "critical" and the rest are rated "important." All of them could lead to remote code execution.
Report: Zeus Flips Kill Switch On More Than 100,000 PCs
Quick Hits  |  5/11/2009  | 
Botnet reportedly triggered a little-used capability called "Kill OS," rendering a blue screen on 100,000-plus PCs and making them difficult to reboot
Air Traffic Control System Repeatedly Hacked
News  |  5/7/2009  | 
A security audit finds a total of 763 high-risk, 504 medium-risk, and 2,590 low-risk vulnerabilities, such as weak passwords and unprotected folders.
Mass. Criminal Database Deemed Public Safety Risk
News  |  5/7/2009  | 
The 25-year-old system cannot reconcile arrests with court dispositions or use fingerprints to verify criminal history, state auditor Joe DeNucci finds.
Data Loss Prevention Rolling Review: Safend Safeguards At The Endpoint
News  |  5/7/2009  | 
Low-cost endpoint specialist gets the job done -- most of the time.
Google Chrome Update Scheme Beats Firefox, Safari, Opera
News  |  5/6/2009  | 
By automatically updating the browser every five hours, Google Chrome provides greater security than its competitors, according to a new study.
Viral Art: A Gallery Of Security Threats
News  |  5/5/2009  | 
Visually, online threats such as viruses, worms, and Trojans can be as beautiful as they are menacing to individual PC users, enterprises, and IT security professionals.
McAfee Report: Bot Infections Jump 50 Percent Over Last Year
Quick Hits  |  5/5/2009  | 
Botnets have added nearly 12 million new IP addresses since January, with Conficker malware representing only around 1 percent of all infections
NoScript Developer Apologizes For Meddling With AdBlock
News  |  5/4/2009  | 
His methods caused a furor in the Mozilla community over the weekend because he did not provide clear notification about what his software was doing.
Virginia Health Data Potentially Held Hostage
News  |  5/4/2009  | 
An extortion demand seeks $10 million to return more than 8 million patient records allegedly stolen from Virginia Department of Health Professions.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-32788
PUBLISHED: 2021-07-27
Discourse is an open source discussion platform. In versions prior to 2.7.7 there are two bugs which led to the post creator of a whisper post being revealed to non-staff users. 1: Staff users that creates a whisper post in a personal message is revealed to non-staff participants of the personal mes...
CVE-2021-32796
PUBLISHED: 2021-07-27
xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.6.0 and older do not correctly escape special characters when serializing elements removed from their ancestor. This may lead to unexpected syntactic changes durin...
CVE-2021-32748
PUBLISHED: 2021-07-27
Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP check. Whilst th...
CVE-2021-34432
PUBLISHED: 2021-07-27
In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.
CVE-2021-20399
PUBLISHED: 2021-07-27
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196073.