Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Dark Reading Article Boards

Message Boards posted in March 2018
Page 1 / 2   >   >>
Tracking Bitcoin Wallets as IOCs for Ransomware
Last Message: 3/31/2018
 |  Comments: 1
Privacy: Do We Need a National Data Breach Disclosure Law?
Last Message: 3/30/2018
 |  Comments: 15
MITRE Evaluates Tools for APT Detection
Last Message: 3/30/2018
 |  Comments: 1
Accused Yahoo Hacker May Comply with US Extradition
Last Message: 3/30/2018
 |  Comments: 1
Attacking Data Integrity & Hacking Radiation Monitoring Devices
Last Message: 3/30/2018
 |  Comments: 1
8 Security Spring Cleaning Tips for the Home Office
Last Message: 3/29/2018
 |  Comments: 1
Critical Start to Buy Advanced Threat Analytics
Last Message: 3/29/2018
 |  Comments: 1
A Look at Cybercrime's Banal Nature
Last Message: 3/29/2018
 |  Comments: 3
How Measuring Security for Risk & ROI Can Empower CISOs
Last Message: 3/29/2018
 |  Comments: 1
AI and Machine Learning: Breaking Down Buzzwords
Last Message: 3/29/2018
 |  Comments: 2
Preparing Security For Windows 7 End-Of-Life Support
Last Message: 3/29/2018
 |  Comments: 2
UVA Defeats UMBC, in Stunning Upset
Last Message: 3/28/2018
 |  Comments: 1
Attackers Shift From Adobe Flaws to Microsoft Products
Last Message: 3/28/2018
 |  Comments: 1
Anthem Hit with Data Breach of 18,580 Medicare Members
Last Message: 3/27/2018
 |  Comments: 2
Looking Back to Look Ahead: Cyber Threat Trends to Watch
Last Message: 3/26/2018
 |  Comments: 1
City of Atlanta Hit with Ransomware Attack
Last Message: 3/26/2018
 |  Comments: 3
How Cybercriminals Attack The Cloud
Last Message: 3/26/2018
 |  Comments: 1
Who Does What in Cybersecurity at the C-Level
Last Message: 3/24/2018
 |  Comments: 10
Online Ads vs. Security: An Invisible War
Last Message: 3/23/2018
 |  Comments: 2
SOC in Translation: 4 Common Phrases & Why They Raise Flags
Last Message: 3/23/2018
 |  Comments: 1
Is Application Security Dead?
Last Message: 3/22/2018
 |  Comments: 1
The Case for Integrating Physical Security & Cybersecurity
Last Message: 3/22/2018
 |  Comments: 2
Cyber Intelligence: Defining What You Know
Last Message: 3/21/2018
 |  Comments: 2
Death of the Tier 1 SOC Analyst
Last Message: 3/21/2018
 |  Comments: 3
First Example Of SAP Breach Surfaces
Last Message: 3/21/2018
 |  Comments: 1
7 Spectre/Meltdown Symptoms That Might Be Under Your Radar
Last Message: 3/20/2018
 |  Comments: 1
Connected Cars Pose New Security Challenges
Last Message: 3/20/2018
 |  Comments: 3
5 Steps to Improve Your Software Supply Chain Security
Last Message: 3/20/2018
 |  Comments: 1
Cybercriminals Launder Up to $200B in Profit Per Year
Last Message: 3/19/2018
 |  Comments: 1
How Security Metrics Fail Us & How We Fail Them
Last Message: 3/18/2018
 |  Comments: 5
Top 8 Cybersecurity Skills IT Pros Need in 2018
Last Message: 3/17/2018
 |  Comments: 2
Microsoft Report Details Different Forms of Cryptominers
Last Message: 3/16/2018
 |  Comments: 2
Segmentation: The Neglected (Yet Essential) Control
Last Message: 3/16/2018
 |  Comments: 1
Google Chrome Patch Released
Last Message: 3/15/2018
 |  Comments: 1
Pragmatic Security: 20 Signs You Are 'Boiling the Ocean'
Last Message: 3/14/2018
 |  Comments: 11
Name That Toon: Disappearing Act
Last Message: 3/14/2018
 |  Comments: 86
How Guccifer 2.0 Got 'Punk'd' by a Security Researcher
Last Message: 3/12/2018
 |  Comments: 6
Page 1 / 2   >   >>


When It Comes To Security Tools, More Isn't More
Lamont Orange, Chief Information Security Officer at Netskope,  1/11/2021
US Capitol Attack a Wake-up Call for the Integration of Physical & IT Security
Seth Rosenblatt, Contributing Writer,  1/11/2021
IoT Vendor Ubiquiti Suffers Data Breach
Dark Reading Staff 1/11/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2020: The Year in Security
Download this Tech Digest for a look at the biggest security stories that - so far - have shaped a very strange and stressful year.
Flash Poll
Assessing Cybersecurity Risk in Today's Enterprises
Assessing Cybersecurity Risk in Today's Enterprises
COVID-19 has created a new IT paradigm in the enterprise -- and a new level of cybersecurity risk. This report offers a look at how enterprises are assessing and managing cyber-risk under the new normal.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25533
PUBLISHED: 2021-01-15
An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct ...
CVE-2021-3162
PUBLISHED: 2021-01-15
Docker Desktop Community before 2.5.0.0 on macOS mishandles certificate checking, leading to local privilege escalation.
CVE-2021-21242
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability which can lead to pre-auth remote code execution. AttachmentUploadServlet deserializes untrusted data from the `Attachment-Support` header. This Servlet does not enforce any authentication or a...
CVE-2021-21245
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, AttachmentUploadServlet also saves user controlled data (`request.getInputStream()`) to a user specified location (`request.getHeader("File-Name")`). This issue may lead to arbitrary file upload which can be used to u...
CVE-2021-21246
PUBLISHED: 2021-01-15
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, the REST UserResource endpoint performs a security check to make sure that only administrators can list user details. However for the `/users/` endpoint there are no security checks enforced so it is possible to retrieve ar...