Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Products and Releases

Content posted in January 2017
PCI SECURITY STANDARDS COUNCIL ISSUES BEST PRACTICES FOR SECURING E-COMMERCE
Products and Releases  |  1/31/2017  | 
E-commerce Security More Important Than Ever For Merchants
Illumio Brings Adaptive Segmentation to Cisco, Arista, AWS, and Azure
Products and Releases  |  1/31/2017  | 
Cybersecurity leader now programs security policy into leading infrastructure players.
94 Percent of CISOs Concerned About Publicly Facing Asset Breaches in 2017
Products and Releases  |  1/31/2017  | 
Todays AppSec teams facing resourcing issues that are making them vulnerable.
Arctic Wolf Networks Survey Reveals Mid-Market Cybersecurity Dissonance: Highlights Disparity Between Perception vs. Reality
Products and Releases  |  1/30/2017  | 
Half of respondents say they dont know where to start to improve security posture
IBM acquires Agile 3
Products and Releases  |  1/26/2017  | 
Expansion of Capabilities for IBM Guardium and Data Security Services
Launch of Breakthrough Iris and Face Recognition System
Products and Releases  |  1/26/2017  | 
Combination of performance and design to enable next generation of multimodal biometric applications in travel, identity, and access
Wanted: Women in Cybersecurity
Products and Releases  |  1/26/2017  | 
Raytheon and Center for Cyber Safety and Education expand cybersecurity scholarships for women
How to Stay Truly Anonymous Online in 2017
Products and Releases  |  1/26/2017  | 
NordVPN gives advice on how to enhance your anonymity online.
HackerOne Expands Hacker Education, Acquires Web Security Training Startup
Products and Releases  |  1/24/2017  | 
HackerOne adds new free-to-use online training curriculum for ethical hackers to make the internet safer.
Businesses See High Levels Of Fraud And Risk Incidents In 2016
Products and Releases  |  1/20/2017  | 
82% of executives surveyed worldwide experienced a fraud incident in the past year compared to 75% in 2015, according to the Kroll Annual Global Fraud and Risk Report
Strategic Cyber Ventures Invests $3M in ID DataWeb
Products and Releases  |  1/20/2017  | 
New funding will allow dynamic identity verification firm to further innovate its technology and expand growth and sales in new markets


Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19782
PUBLISHED: 2019-12-13
The FTP client in AceaXe Plus 1.0 allows a buffer overflow via a long EHLO response from an FTP server.
CVE-2019-19777
PUBLISHED: 2019-12-13
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
CVE-2019-19778
PUBLISHED: 2019-12-13
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
CVE-2019-16777
PUBLISHED: 2019-12-13
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of pa...
CVE-2019-16775
PUBLISHED: 2019-12-13
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publi...