Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Products and Releases

Content posted in November 2020
CompTIA PenTest+ Approved by U.S. Department of Defense
Products and Releases  |  11/30/2020  | 
Certification meets requirements for military personnel and defense contractors who work with sensitive information.
Abnormal Security Raises $50M in Series B Funding
Products and Releases  |  11/23/2020  | 
Funding, led by Menlo Ventures, will be used to accelerate enterprise adoption of AI-driven email security platform.
Digital Shadows Launches Sensitive Document Alerts With Added Context
Products and Releases  |  11/23/2020  | 
New capabilities within SearchLight to detect exposed sensitive but not protectively-marked technical and commercial documents, including product designs and payroll data
Claroty Partners with CrowdStrike to Protect Industrial Control System Environments
Products and Releases  |  11/20/2020  | 
Integration provides full-spectrum IT/OT visibility and threat detection coverage.
Rubrik's Pioneering Cloud Data Management Platform Gets Major Update
Products and Releases  |  11/19/2020  | 
With the Andes 5.3 release, Rubrik delivers up to 10X faster SQL Server backups for large enterprises and reduced cloud archiving costs by up to 95%
Arctic Wolf Expands Operations to Toronto and San Antonio
Products and Releases  |  11/19/2020  | 
Company to open centers of excellence focused on R&D and security operations.
Unbound Tech Raises $20M in Series B Funding to Support Global Growth
Products and Releases  |  11/19/2020  | 
Cryptographic security software provider will strengthen its global positioning following significant funding from Evolution Equity Partners.
Open Raven Launches Cloud-Native Data Protection Platform to Automate Security and Privacy Operations
Products and Releases  |  11/18/2020  | 
Platform secures data lakes built on Amazon Web Services and S3.
Kaspersky Opens New Transparency Center in North America & Completes Data-Processing Relocation to Switzerland
Products and Releases  |  11/18/2020  | 
The opening marks the realization of major measures initially announced within the Global Transparency Initiative.
Bugcrowd's Crowdsourced Cybersecurity Platform Helps Pay Over $2M to Researchers for Samsung Mobile Rewards Program
Products and Releases  |  11/18/2020  | 
Company fortifies researcher partnerships by delivering timely and secure payments.
Farsight Security Integrates with Palo Alto Networks Cortex XSOAR to Provide Automated, DNS Intelligence For Cyber Investigations
Products and Releases  |  11/17/2020  | 
Integration combines Farsight Security DNSDB with Cortex XSOAR to automate contextualization and correlation of DNS-related artifacts used in cybercrimes.
Concentric Resolves Unaddressed Data Security Threats with AI-based Data Access Governance Solution
Products and Releases  |  11/17/2020  | 
Companys Risk Distance deep learning functionality autonomously identifies access and activity risks in unstructured data.
Telos Corporation Announces Launch of IPO
Products and Releases  |  11/11/2020  | 
New Tool Detects Unsafe Security Practices in Android Apps
Products and Releases  |  11/9/2020  | 
Open source CRYLOGGER detects cryptographic misuses by running the Android app instead of analyzing its code.
HackNotice Releases Risk Explorer
Products and Releases  |  11/6/2020  | 
HackNotice Risk Explorer reveals cyberthreats with easy-to-understand visuals.
Vulcan Cyber Adds Remediation Analytics to Provide Full Visibility Into Remediation Efficacy
Products and Releases  |  11/4/2020  | 
New Vulcan remediation analytics provides security and IT executives with unfettered visibility into the state of remediation campaigns.
Vulcan Cyber Launches Remedy Cloud, Providing Free Access to Thousands of Vulnerability Fixes
Products and Releases  |  11/4/2020  | 
Providing remediation solutions on demand, Vulcan Remedy Cloud helps security and IT teams collaboratively "get fix done."
Survey: Biggest Concerns About Securing Digital Infrastructure Include COVID, Unsanctioned Apps, Collaboration Platforms, Marketing Technology
Products and Releases  |  11/3/2020  | 
New SafeGuard Cyber Poll Suggests Enterprises Should Harden Systems Against Unconventional Attack Vectors
Ping Identity Unveils Advanced Passwordless Features
Products and Releases  |  11/3/2020  | 
PingZero provides frictionless login experiences with passwordless authentication, including support for the FIDO2 open standard.
ForAllSecure Announces First Fintech Customer
Products and Releases  |  11/3/2020  | 
Marqeta selects ForAllSecure's fuzz testing security solution to proactively secure API code base.


Edge-DRsplash-10-edge-articles
7 Old IT Things Every New InfoSec Pro Should Know
Joan Goodchild, Staff Editor,  4/20/2021
News
Cloud-Native Businesses Struggle With Security
Robert Lemos, Contributing Writer,  5/6/2021
Commentary
Defending Against Web Scraping Attacks
Rob Simon, Principal Security Consultant at TrustedSec,  5/7/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-20092
PUBLISHED: 2021-05-13
File Upload vulnerability exists in ArticleCMS 1.0 via the image upload feature at /admin by changing the Content-Type to image/jpeg and placing PHP code after the JPEG data, which could let a remote malicious user execute arbitrary PHP code.
CVE-2020-21342
PUBLISHED: 2021-05-13
Insecure permissions issue in zzcms 201910 via the reset any user password in /one/getpassword.php.
CVE-2020-25713
PUBLISHED: 2021-05-13
A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
CVE-2020-27823
PUBLISHED: 2021-05-13
A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
CVE-2020-27830
PUBLISHED: 2021-05-13
A vulnerability was found in Linux Kernel where in the spk_ttyio_receive_buf2() function, it would dereference spk_ttyio_synth without checking whether it is NULL or not, and may lead to a NULL-ptr deref crash.