Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Dark Reading Article Boards

Message Boards posted in October 2015
Page 1 / 2   >   >>
Target Breach: Why Smartcards Won’t Stop Hackers
Last Message: 10/31/2015
 |  Comments: 21
CrowdStrike Spots Chinese APTs Targeting US Firms Post-Pact
Last Message: 10/30/2015
 |  Comments: 1
Mandia: US-China No-Hack Pact Could Be Game Changer
Last Message: 10/30/2015
 |  Comments: 3
Chinese Military Behind South China Sea Cyber Espionage Attacks
Last Message: 10/30/2015
 |  Comments: 2
Why China Wants Your Sensitive Data
Last Message: 10/30/2015
 |  Comments: 18
Millennials Not Pursuing Cybersecurity Careers
Last Message: 10/30/2015
 |  Comments: 22
Startup 'Stealth Worker' Matches Businesses With Security Talent
Last Message: 10/30/2015
 |  Comments: 3
Endpoint Security: Putting The Focus On What Matters
Last Message: 10/29/2015
 |  Comments: 1
Digital Certificate Security Fail
Last Message: 10/29/2015
 |  Comments: 1
The Internet of Things: It’s All About Trust
Last Message: 10/28/2015
 |  Comments: 1
State Of Employee Security Behavior
Last Message: 10/27/2015
 |  Comments: 2
Passing the Sniff Test: Security Metrics and Measures
Last Message: 10/26/2015
 |  Comments: 2
Attackers Demand Ransom Following Massive Hack on TalkTalk
Last Message: 10/26/2015
 |  Comments: 1
Why DevOps Fails At Application Security
Last Message: 10/24/2015
 |  Comments: 3
Next On Dark Reading Radio: Endpoint Security Transformed
Last Message: 10/24/2015
 |  Comments: 1
Undermining Security By Attacking Computer Clocks
Last Message: 10/23/2015
 |  Comments: 1
New Technology Won't Remove Endpoint From The Bullseye
Last Message: 10/23/2015
 |  Comments: 1
Likeliest Fraudsters Are, Or Claim To Be, 85-90 Years Old
Last Message: 10/22/2015
 |  Comments: 1
Survey Shows Little Accord On Responsibility For Cloud Security
Last Message: 10/21/2015
 |  Comments: 3
From 55 Cents to $1,200: The Value Chain For Stolen Data
Last Message: 10/21/2015
 |  Comments: 2
Endpoint Security Transformed
Last Message: 10/21/2015
 |  Comments: 54
Building A Winning Security Team From The Top Down
Last Message: 10/20/2015
 |  Comments: 1
Former White House Advisor: Marry Infosec To Economics
Last Message: 10/20/2015
 |  Comments: 3
Enterprises Are Leaving Cloud Security Policies To Chance
Last Message: 10/20/2015
 |  Comments: 1
Run, Jump, Shoot, Infect: Trojanized Games Invade Google Play
Last Message: 10/19/2015
 |  Comments: 4
Cybersecurity Insurance: 4 Practical Considerations
Last Message: 10/16/2015
 |  Comments: 3
Pawn Storm Flashes A New Flash Zero-Day
Last Message: 10/16/2015
 |  Comments: 2
The Evolution Of Malware
Last Message: 10/15/2015
 |  Comments: 1
Researchers Warn Against Continuing Use Of SHA-1 Crypto Standard
Last Message: 10/14/2015
 |  Comments: 2
Believe It Or Not, Millennials Do Care About Privacy, Security
Last Message: 10/14/2015
 |  Comments: 1
Japan's Cybercrime Underground On The Rise
Last Message: 10/14/2015
 |  Comments: 1
Why Everybody Loves (And Hates) Security
Last Message: 10/12/2015
 |  Comments: 2
'Evil' Kemoge Serves Androids Ads And Rootkits
Last Message: 10/12/2015
 |  Comments: 2
Jailbreaking Mobile Devices: That’s Not The Real Problem
Last Message: 10/12/2015
 |  Comments: 1
Healthcare Organizations Twice As Likely To Experience Data Theft
Last Message: 10/11/2015
 |  Comments: 12
The Unintended Attack Surface Of The Internet Of Things
Last Message: 10/11/2015
 |  Comments: 9
A Father’s Perspective On The Gender Gap In Cybersecurity
Last Message: 10/11/2015
 |  Comments: 18
Darknet Is Full Of Criminals & Governments Giving TOR A Bad Name
Last Message: 10/10/2015
 |  Comments: 4
State Trooper Vehicles Hacked
Last Message: 10/10/2015
 |  Comments: 22
Corporate VPNs In The Bullseye
Last Message: 10/9/2015
 |  Comments: 1
Data Deletion: A Disconnect Between Perception And Reality
Last Message: 10/9/2015
 |  Comments: 2
CISOs Spend Too Much Time On Tech, Not Enough On Strategy
Last Message: 10/7/2015
 |  Comments: 3
How Tactical Security Works At LinkedIn
Last Message: 10/6/2015
 |  Comments: 2
Nuclear Plants' Cybersecurity Is Bad, & Hard To Fix
Last Message: 10/5/2015
 |  Comments: 1
DHS Funds Project For Open Source 'Invisible Clouds'
Last Message: 10/5/2015
 |  Comments: 2
Page 1 / 2   >   >>


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Everything You Need to Know About DNS Attacks
It's important to understand DNS, potential attacks against it, and the tools and techniques required to defend DNS infrastructure. This report answers all the questions you were afraid to ask. Domain Name Service (DNS) is a critical part of any organization's digital infrastructure, but it's also one of the least understood. DNS is designed to be invisible to business professionals, IT stakeholders, and many security professionals, but DNS's threat surface is large and widely targeted. Attackers are causing a great deal of damage with an array of attacks such as denial of service, DNS cache poisoning, DNS hijackin, DNS tunneling, and DNS dangling. They are using DNS infrastructure to take control of inbound and outbound communications and preventing users from accessing the applications they are looking for. To stop attacks on DNS, security teams need to shore up the organization's security hygiene around DNS infrastructure, implement controls such as DNSSEC, and monitor DNS traffic
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2023-33196
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
CVE-2023-33185
PUBLISHED: 2023-05-26
Django-SES is a drop-in mail backend for Django. The django_ses library implements a mail backend for Django using AWS Simple Email Service. The library exports the `SESEventWebhookView class` intended to receive signed requests from AWS to handle email bounces, subscriptions, etc. These requests ar...
CVE-2023-33187
PUBLISHED: 2023-05-26
Highlight is an open source, full-stack monitoring platform. Highlight may record passwords on customer deployments when a password html input is switched to `type="text"` via a javascript "Show Password" button. This differs from the expected behavior which always obfuscates `ty...
CVE-2023-33194
PUBLISHED: 2023-05-26
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was...
CVE-2023-2879
PUBLISHED: 2023-05-26
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file