Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Commentary

Content posted in November 2008
<<   <   Page 2 / 2
Adobe Patches PDF Flaw
Commentary  |  11/4/2008  | 
Security firm Core Security Technologies is warning users that Adobe Reader versions 8.1.2 and earlier are vulnerable to specially crafted PDF files that could be used gain access to authorized systems. You might want to check which version of Adobe Reader you're using.
E-Voter In a Swing State
Commentary  |  11/4/2008  | 
When I arrived at the polls at 6 a.m. this morning, those of us at the head of the line watched nervously as election officials frantically tried to calibrate my small town's two e-voting machines after they malfunctioned -- just before the first voters were about to cast their votes.
Hackers May Be Able To Unlock Your Doors As Well As Your Data
Commentary  |  11/4/2008  | 
Now we may have to protect our physical security -- keys and locks -- from hackers. A new experiment suggests that web cam or cell phone images of keys may give crooks all they need to crack your locks.
Laptop Security During the Economic Crash
Commentary  |  11/3/2008  | 
Theft rates go up sharply when you have an economic crash. People are looking for items to take from homes and cars that are easy to transport and easy to sell. Laptops fall into this category because they are both small and easily sold -- especially if new, attractive, and one of the more desirable models. This suggests a number of best practices are necessary to ensure they don't walk off and, if they do, don't compromise the business.
Data Leakage Prevention Products Maturing?
Commentary  |  11/3/2008  | 
With new data loss stories cropping up every few days, it's surprising that the data leakage prevention (DLP) market hasn't blown up over the last year with organizations clamoring to get their hands on DLP technology to prevent their sensitive data from walking out the door, or getting left in a cab, or stolen out of a parked car. In the article "DLP Vendors Grow Up," Symantec's senior
Primary Storage Data Reduction - A Process
Commentary  |  11/3/2008  | 
Primary storage data reduction is a series of steps you can take to reduce the amount of capacity dedicated to Tier 1 storage. The most common techniques are archiving, compression, data deduplication, and the use of intelligent storage systems. The question often comes up, what should I do first?
Windows Update To Get An Update
Commentary  |  11/3/2008  | 
According to the Microsoft Update blog, a substantial update to the Windows Update agent is on the way. The company says this update should increase the speed with which it will scan your system, as well as the number of patches it can download.
The Security Pro's Guide To Thriving In A Down Economy
Commentary  |  11/3/2008  | 
Let's face it: Even if this isn't the worst economic crisis since the Great Depression, the financial engine clearly isn't running on all cylinders. At best we can assume some sort of recovery over the course of the next year or so, and at worst...well, I don't really want to think about that. I think it's safe to say that not only do none of us know where this is headed, but that the picture will remain opaque until after the election and the winners take office. As security professionals, ris
Inspector General Confirms It: Little HIPAA Enforcement
Commentary  |  11/2/2008  | 
The Health Insurance Portability and Accountability Act of 1996 was set into law about 12 years ago, the security rules went into effect earlier this decade. Hospitals knew these regulations were coming long ago, so why is compliance so lax?
<<   <   Page 2 / 2


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-23478
PUBLISHED: 2021-09-22
Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.
CVE-2020-23481
PUBLISHED: 2021-09-22
CMS Made Simple 2.2.14 was discovered to contain a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the Field Definition text field.
CVE-2020-23469
PUBLISHED: 2021-09-22
gmate v0.12+bionic contains a regular expression denial of service (ReDoS) vulnerability in the gedit3 plugin.
CVE-2021-21991
PUBLISHED: 2021-09-22
The vCenter Server contains a local privilege escalation vulnerability due to the way it handles session tokens. A malicious actor with non-administrative user access on vCenter Server host may exploit this issue to escalate privileges to Administrator on the vSphere Client (HTML5) or vCenter Server...
CVE-2021-21992
PUBLISHED: 2021-09-22
The vCenter Server contains a denial-of-service vulnerability due to improper XML entity parsing. A malicious actor with non-administrative user access to the vCenter Server vSphere Client (HTML5) or vCenter Server vSphere Web Client (FLEX/Flash) may exploit this issue to create a denial-of-service ...