Dark Reading Article Boards

Message Boards posted in December 2013
Target Breach: 10 Facts
Last Message: 12/30/2013
 |  Comments: 23
How Mobile Security Lags BYOD
Last Message: 12/27/2013
 |  Comments: 6
IT Security Risk Management: Is It Worth The Cost?
Last Message: 12/27/2013
 |  Comments: 7
2013: Rest In Peace, Passwords
Last Message: 12/26/2013
 |  Comments: 16
"File Sync And Sharing: Users Won't Give It Up"
Last Message: 12/25/2013
 |  Comments: 8
The State of IT Security: Its Broken
Last Message: 12/23/2013
 |  Comments: 14
BYOD Bingo
Last Message: 12/23/2013
 |  Comments: 6
Is Mob-Busting RICO Overkill For Combating Cybercrime?
Last Message: 12/23/2013
 |  Comments: 5
Secure Code Starts With Measuring What Developers Know
Last Message: 12/22/2013
 |  Comments: 2
My 5 Wishes For Security In 2014
Last Message: 12/20/2013
 |  Comments: 4
'ChewBacca' Malware Taps Tor Network
Last Message: 12/19/2013
 |  Comments: 2
Bitcoin Hit By Gameover Malware, Chinese Crackdown
Last Message: 12/19/2013
 |  Comments: 3
Safety Equipment
Last Message: 12/19/2013
 |  Comments: 2
Android AV Improves But Still Can't Nuke Malware
Last Message: 12/19/2013
 |  Comments: 4
How To Win A Cartoon Caption Contest (Tech Version)
Last Message: 12/17/2013
 |  Comments: 2
"NSA Vs. Your Smartphone: 5 Facts"
Last Message: 12/17/2013
 |  Comments: 5
NSA Surveillance Fallout Costs IT Industry Billions
Last Message: 12/17/2013
 |  Comments: 20
Advanced Power Botnet: Firefox Users, Beware
Last Message: 12/16/2013
 |  Comments: 1
Time For An Active Defense Against Security Attacks
Last Message: 12/16/2013
 |  Comments: 7
Why Fed Cybersecurity Reboot Plan Fails To Convince
Last Message: 12/13/2013
 |  Comments: 2
"Lessons Learned From N.Y. Times Hack Attack"
Last Message: 12/13/2013
 |  Comments: 1
Cybercrime Milestone: Guilty Plea In RICO Case
Last Message: 12/13/2013
 |  Comments: 5
Microsoft Fails To Nuke ZeroAccess Botnet
Last Message: 12/11/2013
 |  Comments: 1
White House Preparing National Online ID Plan
Last Message: 12/10/2013
 |  Comments: 3
Don't Be Overprotective About BYOD
Last Message: 12/10/2013
 |  Comments: 3
DARPA Crowdsources Bug-Spotting Games
Last Message: 12/9/2013
 |  Comments: 2
Application Security: We Still Have A Long Way To Go
Last Message: 12/9/2013
 |  Comments: 13
Juniper Mobile VPN Client Taps iOS Security Changes
Last Message: 12/9/2013
 |  Comments: 3
Online Extortion: The Ethics Of Unpublishing
Last Message: 12/9/2013
 |  Comments: 2
China Slams Bitcoins: What's Next?
Last Message: 12/8/2013
 |  Comments: 5
2 Million Stolen Passwords Recovered
Last Message: 12/7/2013
 |  Comments: 7
Why Security Awareness Is Like An Umbrella
Last Message: 12/6/2013
 |  Comments: 2
NSA Fallout: Microsoft Rethinks Customer Data Controls
Last Message: 12/6/2013
 |  Comments: 7
Bitcoin Password Grab Disguised As DDoS Attack
Last Message: 12/5/2013
 |  Comments: 6
Hardware Hacker Demos Zombie Drone Hijacker
Last Message: 12/4/2013
 |  Comments: 4
Weighing Costs Vs. Benefits Of NSA Surveillance
Last Message: 12/4/2013
 |  Comments: 5
Zero-Day Drive-By Attacks: Accelerating & Expanding
Last Message: 12/3/2013
 |  Comments: 5
Microsoft Office 365 Encrypted Email On Tap
Last Message: 12/2/2013
 |  Comments: 4
Cartoon: You Might Be A Security Expert If...
Last Message: 12/2/2013
 |  Comments: 4
LG Admits Smart TVs Spied On Users
Last Message: 12/2/2013
 |  Comments: 15


More Than Half of Users Reuse Passwords
Curtis Franklin Jr., Senior Editor at Dark Reading,  5/24/2018
Is Threat Intelligence Garbage?
Chris McDaniels, Chief Information Security Officer of Mosaic451,  5/23/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11505
PUBLISHED: 2018-05-26
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
CVE-2018-6409
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database. Modifying the name of the file to serve on the corresponding ap_form table leads to a path traversal vulnerability via the download.php q parameter.
CVE-2018-6410
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
CVE-2018-6411
PUBLISHED: 2018-05-26
An issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous extensions to the filters. If the filter is set to a whitelist, the dangerous extensions can be bypassed through ap_form_elements SQL Injection.
CVE-2018-11500
PUBLISHED: 2018-05-26
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.