Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Products and Releases

Content posted in November 2020
CompTIA PenTest+ Approved by U.S. Department of Defense
Products and Releases  |  11/30/2020  | 
Certification meets requirements for military personnel and defense contractors who work with sensitive information.
Abnormal Security Raises $50M in Series B Funding
Products and Releases  |  11/23/2020  | 
Funding, led by Menlo Ventures, will be used to accelerate enterprise adoption of AI-driven email security platform.
Digital Shadows Launches Sensitive Document Alerts With Added Context
Products and Releases  |  11/23/2020  | 
New capabilities within SearchLight to detect exposed sensitive but not protectively-marked technical and commercial documents, including product designs and payroll data
Claroty Partners with CrowdStrike to Protect Industrial Control System Environments
Products and Releases  |  11/20/2020  | 
Integration provides full-spectrum IT/OT visibility and threat detection coverage.
Rubrik's Pioneering Cloud Data Management Platform Gets Major Update
Products and Releases  |  11/19/2020  | 
With the Andes 5.3 release, Rubrik delivers up to 10X faster SQL Server backups for large enterprises and reduced cloud archiving costs by up to 95%
Arctic Wolf Expands Operations to Toronto and San Antonio
Products and Releases  |  11/19/2020  | 
Company to open centers of excellence focused on R&D and security operations.
Unbound Tech Raises $20M in Series B Funding to Support Global Growth
Products and Releases  |  11/19/2020  | 
Cryptographic security software provider will strengthen its global positioning following significant funding from Evolution Equity Partners.
Open Raven Launches Cloud-Native Data Protection Platform to Automate Security and Privacy Operations
Products and Releases  |  11/18/2020  | 
Platform secures data lakes built on Amazon Web Services and S3.
Kaspersky Opens New Transparency Center in North America & Completes Data-Processing Relocation to Switzerland
Products and Releases  |  11/18/2020  | 
The opening marks the realization of major measures initially announced within the Global Transparency Initiative.
Bugcrowd's Crowdsourced Cybersecurity Platform Helps Pay Over $2M to Researchers for Samsung Mobile Rewards Program
Products and Releases  |  11/18/2020  | 
Company fortifies researcher partnerships by delivering timely and secure payments.
Farsight Security Integrates with Palo Alto Networks Cortex XSOAR to Provide Automated, DNS Intelligence For Cyber Investigations
Products and Releases  |  11/17/2020  | 
Integration combines Farsight Security DNSDB with Cortex XSOAR to automate contextualization and correlation of DNS-related artifacts used in cybercrimes.
Concentric Resolves Unaddressed Data Security Threats with AI-based Data Access Governance Solution
Products and Releases  |  11/17/2020  | 
Companys Risk Distance deep learning functionality autonomously identifies access and activity risks in unstructured data.
Telos Corporation Announces Launch of IPO
Products and Releases  |  11/11/2020  | 
New Tool Detects Unsafe Security Practices in Android Apps
Products and Releases  |  11/9/2020  | 
Open source CRYLOGGER detects cryptographic misuses by running the Android app instead of analyzing its code.
HackNotice Releases Risk Explorer
Products and Releases  |  11/6/2020  | 
HackNotice Risk Explorer reveals cyberthreats with easy-to-understand visuals.
Vulcan Cyber Adds Remediation Analytics to Provide Full Visibility Into Remediation Efficacy
Products and Releases  |  11/4/2020  | 
New Vulcan remediation analytics provides security and IT executives with unfettered visibility into the state of remediation campaigns.
Vulcan Cyber Launches Remedy Cloud, Providing Free Access to Thousands of Vulnerability Fixes
Products and Releases  |  11/4/2020  | 
Providing remediation solutions on demand, Vulcan Remedy Cloud helps security and IT teams collaboratively "get fix done."
Survey: Biggest Concerns About Securing Digital Infrastructure Include COVID, Unsanctioned Apps, Collaboration Platforms, Marketing Technology
Products and Releases  |  11/3/2020  | 
New SafeGuard Cyber Poll Suggests Enterprises Should Harden Systems Against Unconventional Attack Vectors
Ping Identity Unveils Advanced Passwordless Features
Products and Releases  |  11/3/2020  | 
PingZero provides frictionless login experiences with passwordless authentication, including support for the FIDO2 open standard.
ForAllSecure Announces First Fintech Customer
Products and Releases  |  11/3/2020  | 
Marqeta selects ForAllSecure's fuzz testing security solution to proactively secure API code base.


Commentary
How SolarWinds Busted Up Our Assumptions About Code Signing
Dr. Jethro Beekman, Technical Director,  3/3/2021
News
'ObliqueRAT' Now Hides Behind Images on Compromised Websites
Jai Vijayan, Contributing Writer,  3/2/2021
News
Attackers Turn Struggling Software Projects Into Trojan Horses
Robert Lemos, Contributing Writer,  2/26/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: George has not accepted that the technology age has come to an end.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-26814
PUBLISHED: 2021-03-06
Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service sc...
CVE-2021-27581
PUBLISHED: 2021-03-05
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
CVE-2021-28042
PUBLISHED: 2021-03-05
Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload feature or the MO Connect component. This can lead to remote code execution.
CVE-2021-28041
PUBLISHED: 2021-03-05
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
CVE-2021-3377
PUBLISHED: 2021-03-05
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.