Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Products and Releases

Content posted in May 2018
Facebook Sites Dominate Social Network Phishing in Q1 2018: Kaspersky Lab
Products and Releases  |  5/23/2018  | 
The findings come from Kaspersky Labs new Spam and Phishing in Q1 2018 report.
Okta Announces Project Onramp for One-Click App Setup
Products and Releases  |  5/23/2018  | 
One click from the Okta dashboard can enable customers to find, set up, and provide workers access to Box, Workplace by Facebook, OrgWiki, PagerDuty, RingCentral, McAfee, Zscaler and Zylo.
Okta Launches 'Sign In with Okta,' Business Authentication for App Providers
Products and Releases  |  5/23/2018  | 
'Sign in with Okta' is designed to give developers a faster alternative to SAML, simplify single sign-on for IT admins, and help eliminate app passwords for users.
Valimail Raises $25 Million in Series B Funding
Products and Releases  |  5/22/2018  | 
TransUnion Announces Agreement to Acquire iovation
Products and Releases  |  5/21/2018  | 
Combined capabilities will help customers stay ahead of new and evolving fraud threats
PCI SSC Publishes Minor Revision to PCI Data Security Standard
Products and Releases  |  5/21/2018  | 
PCI DSS Version 3.2.1 includes minor updates to account for SSL/Early TLS dates that have passed
Research Conducted By Comodo Ca Reveals That More Than 1 Million Distrusted Website Certificates From Symantec Remain In Use
Products and Releases  |  5/16/2018  | 
Certificate Authority Aims to Help Businesses and Consumers Worldwide Increase Security of Professional and Personal Internet Usage and Prevent Potential Loss of Business
Onapsis Launches New Functionality to Lock Down SAP Systems
Products and Releases  |  5/14/2018  | 
Business-critical application security leader enables organizations to enforce compliance and maintain a continuous secure state against the threat of configuration drift
Black Box Debuts New Secure KVM Switches
Products and Releases  |  5/9/2018  | 


More SolarWinds Attack Details Emerge
Kelly Jackson Higgins, Executive Editor at Dark Reading,  1/12/2021
Vulnerability Management Has a Data Problem
Tal Morgenstern, Co-Founder & Chief Product Officer, Vulcan Cyber,  1/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-35128
PUBLISHED: 2021-01-19
Mautic before 3.2.4 is affected by stored XSS. An attacker with permission to manage companies, an application feature, could attack other users, including administrators. For example, by loading an externally crafted JavaScript file, an attacker could eventually perform actions as the target user. ...
CVE-2020-35129
PUBLISHED: 2021-01-19
Mautic before 3.2.4 is affected by stored XSS. An attacker with access to Social Monitoring, an application feature, could attack other users, including administrators. For example, an attacker could load an externally drafted JavaScript file that would allow them to eventually perform actions on th...
CVE-2020-23342
PUBLISHED: 2021-01-19
A CSRF vulnerability exists in Anchor CMS 0.12.7 anchor/views/users/edit.php that can change the Delete admin users.
CVE-2020-20950
PUBLISHED: 2021-01-19
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable li...
CVE-2020-23522
PUBLISHED: 2021-01-19
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.