Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Dark Reading Article Boards

Message Boards posted in May 2014
Page 1 / 2   >   >>
SNMP DDoS Attacks Spike
Last Message: 5/31/2014
 |  Comments: 4
Cartoon: What Your Toaster Now Needs
Last Message: 5/30/2014
 |  Comments: 2
Indicting Chinese Military Officers Is A Huge Mistake
Last Message: 5/30/2014
 |  Comments: 2
Cyber Security Skills
Last Message: 5/30/2014
 |  Comments: 1
Why IT Security RFPs Are Like Junk Food
Last Message: 5/30/2014
 |  Comments: 3
7 Facts: eBay Fumbles Password Reset Warning
Last Message: 5/30/2014
 |  Comments: 5
eBay Breach: Is Your Identity Up For Auction?
Last Message: 5/29/2014
 |  Comments: 10
Privileged Use Also a State of Mind, Report Finds
Last Message: 5/28/2014
 |  Comments: 3
No More Jail Time: LulzSec's Sabu Sentenced to Time Served
Last Message: 5/28/2014
 |  Comments: 8
Women In Security: We've Still Got A Long Way To Go, Baby
Last Message: 5/28/2014
 |  Comments: 15
The Real Reason You Can't Fill Vacant Security Jobs
Last Message: 5/28/2014
 |  Comments: 85
Apple Users Fend Off Ransom Attacks Against iPhones & Macs
Last Message: 5/28/2014
 |  Comments: 2
Target, Neiman Marcus Malware Creators Identified
Last Message: 5/28/2014
 |  Comments: 8
DevOps Role In Application Security
Last Message: 5/27/2014
 |  Comments: 1
State of IT Security
Last Message: 5/27/2014
 |  Comments: 2
New Vulnerability In IE8 Remains Unpatched
Last Message: 5/26/2014
 |  Comments: 5
Zeus 'Gameover' Trojan Expands Global Reach
Last Message: 5/25/2014
 |  Comments: 1
Tech Insight: Free Tools For Offensive Security
Last Message: 5/25/2014
 |  Comments: 6
"Dropbox Admits Hack, Adds More Security Features"
Last Message: 5/24/2014
 |  Comments: 4
The Only 2 Things Every Developer Needs To Know About Injection
Last Message: 5/23/2014
 |  Comments: 3
Dark Reading To Launch Weekly Internet Radio Show
Last Message: 5/22/2014
 |  Comments: 2
eBay Database Hacked With Stolen Employee Credentials
Last Message: 5/22/2014
 |  Comments: 6
On The Trail of An Iranian Hacking Operation
Last Message: 5/22/2014
 |  Comments: 2
LifeLock Pulls Apps Over PCI Compliance Failure
Last Message: 5/22/2014
 |  Comments: 1
Sloppy Software Dev Exposes Google Hacker Holes
Last Message: 5/22/2014
 |  Comments: 1
After Heartbleed, Tech Giants Fund Open Source Security
Last Message: 5/22/2014
 |  Comments: 9
The Snowden Effect: Who Controls My Data?
Last Message: 5/22/2014
 |  Comments: 9
Black Hat USA 2014: Focus on Mobile
Last Message: 5/21/2014
 |  Comments: 1
Outlook.com Android App Leaves Email Messages Exposed
Last Message: 5/21/2014
 |  Comments: 5
Strong Passwords
Last Message: 5/21/2014
 |  Comments: 6
How To Talk About InfoSec To Your Board Of Directors
Last Message: 5/21/2014
 |  Comments: 4
Beware Cognitive Bias
Last Message: 5/21/2014
 |  Comments: 9
Microsoft: Deception Dominates Windows Attacks
Last Message: 5/21/2014
 |  Comments: 5
Senators Slam Online Advertisers As 'Malvertising' Spikes
Last Message: 5/19/2014
 |  Comments: 1
NSA Reportedly Adds Backdoors To US-Made Routers
Last Message: 5/19/2014
 |  Comments: 6
OpenDNS Receives $35M Investment in Enterprise Security Vision
Last Message: 5/19/2014
 |  Comments: 1
Gawker Attacker Turned FBI Informant, Pursued Other Hackers
Last Message: 5/19/2014
 |  Comments: 1
Microsoft Blocks Zero-Day Attacks Targeting IE, Office
Last Message: 5/19/2014
 |  Comments: 1
Dispelling The Myths Of Cyber Security
Last Message: 5/19/2014
 |  Comments: 3
Study: Data Breaches Make Huge Impact On Brand Reputation
Last Message: 5/18/2014
 |  Comments: 9
Breach At Bit.ly Blamed On Offsite Backup Storage Provider
Last Message: 5/16/2014
 |  Comments: 2
Into The Breach: The Limits Of Data Security Technology
Last Message: 5/16/2014
 |  Comments: 8
A New Approach to Endpoint Security: Think Positive
Last Message: 5/16/2014
 |  Comments: 10
Page 1 / 2   >   >>


COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/4/2020
Abandoned Apps May Pose Security Risk to Mobile Devices
Robert Lemos, Contributing Writer,  5/29/2020
How AI and Automation Can Help Bridge the Cybersecurity Talent Gap
Peter Barker, Chief Product Officer at ForgeRock,  6/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: What? IT said I needed virus protection!
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13768
PUBLISHED: 2020-06-04
In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19861, CVE-2018-19862, and CVE-2019-17601. NOTE: this product is discontinued.
CVE-2020-13849
PUBLISHED: 2020-06-04
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.
CVE-2020-13848
PUBLISHED: 2020-06-04
Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c.
CVE-2020-11682
PUBLISHED: 2020-06-04
Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request ...
CVE-2020-12847
PUBLISHED: 2020-06-04
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console� that is available to users with an administrator role. This console provides an administrator user with the possibility of changing several settings, including the applicat...