Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News & Commentary

Content tagged with Vulnerability Management posted in August 2015
Mad World: The Truth About Bug Bounties
Commentary  |  8/13/2015  | 
What Oracle CSO Mary Ann Davidson doesnt get about modern security vulnerability disclosure.
Software Security Is Hard But Not impossible
Commentary  |  8/12/2015  | 
New Interactive Application Security Testing products produce an interesting result under the right conditions, but they cant, by themselves, find all the security vulnerabilities you need to fix.
Windows 10 Gets Patch Tuesday Treatment, With 4 Critical Bugs Fixed
Quick Hits  |  8/12/2015  | 
Office, Edge, Internet Explorer, and graphics components all ripe for remote code execution.
New SMB Relay Attack Steals User Credentials Over Internet
News  |  8/5/2015  | 
Researchers found a twist to an older vulnerability that lets them launch SMB relay attacks from the Internet.
From The Black Hat Keynote Stage: Jennifer Granick
News  |  8/5/2015  | 
World famous defender of hackers, privacy, and civil liberties exhorts attendees to preserve the dream of an open Internet.


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-34570
PUBLISHED: 2021-09-27
Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.
CVE-2021-41580
PUBLISHED: 2021-09-27
** DISPUTED ** The passport-oauth2 package before 1.6.1 for Node.js mishandles the error condition of failure to obtain an access token. This is exploitable in certain use cases where an OAuth identity provider uses an HTTP 200 status code for authentication-failure error reports, and an application...
CVE-2021-40981
PUBLISHED: 2021-09-27
ASUS ROG Armoury Crate Lite before 4.2.10 allows local users to gain privileges by placing a Trojan horse file in the publicly writable %PROGRAMDATA%\ASUS\GamingCenterLib directory.
CVE-2021-41329
PUBLISHED: 2021-09-27
Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not constrained by their view filter. This information exposure, caused by an internal cache key collision, occurs when the user's view filter includes an array or IN clause, and when anot...
CVE-2021-41385
PUBLISHED: 2021-09-27
The third party intelligence connector in Securonix SNYPR 6.3.1 Build 184295_0302 allows an authenticated user to obtain access to server configuration details via SSRF.