Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Dark Reading Article Boards

Message Boards posted in May 2019
Page 1 / 2   >   >>
Google Alerts Admins to Unhashed Password Storage
Last Message: 5/31/2019
 |  Comments: 2
SANS Launches Security Awareness Certification
Last Message: 5/31/2019
 |  Comments: 2
GandCrab Gets a SQL Update
Last Message: 5/31/2019
 |  Comments: 1
To Manage Security Risk, Manage Data First
Last Message: 5/31/2019
 |  Comments: 1
Why Fostering Flexibility Is a Win for Women & Cybersecurity
Last Message: 5/31/2019
 |  Comments: 3
GDPRs First-Year Impact By the Numbers
Last Message: 5/31/2019
 |  Comments: 1
Flipboard Confirms Two Hacks, Prompts Password Resets
Last Message: 5/31/2019
 |  Comments: 1
Insight Partners Acquires Recorded Future
Last Message: 5/31/2019
 |  Comments: 1
Palo Alto Networks Confirms PureSec Acquisition
Last Message: 5/31/2019
 |  Comments: 1
Palo Alto Networks Said to Buy Twistlock
Last Message: 5/31/2019
 |  Comments: 1
Impersonation Attacks Up 67% for Corporate Inboxes
Last Message: 5/30/2019
 |  Comments: 1
FireEye Buys Verodin for $250 Million
Last Message: 5/29/2019
 |  Comments: 1
Emotet Made Up 61% of Malicious Payloads in Q1
Last Message: 5/29/2019
 |  Comments: 1
FirstAm Leak Highlights Importance of Verifying the Basics
Last Message: 5/29/2019
 |  Comments: 7
NSS Labs Admits Its Test of CrowdStrike Falcon Was 'Inaccurate'
Last Message: 5/29/2019
 |  Comments: 6
Google's Origin & the Danger of Link Sharing
Last Message: 5/29/2019
 |  Comments: 6
TeamViewer Admits Breach from 2016
Last Message: 5/29/2019
 |  Comments: 3
Attackers Used Red-Team, Pen-Testing Tools to Hack Wipro
Last Message: 5/28/2019
 |  Comments: 1
Moody's Outlook Downgrade of Equifax: A Wake-up Call to Boards
Last Message: 5/28/2019
 |  Comments: 1
10 Tips for More Secure Mobile Devices
Last Message: 5/28/2019
 |  Comments: 4
Election Security Isn't as Bad as People Think
Last Message: 5/26/2019
 |  Comments: 2
Incident Response: 3 Easy Traps & How to Avoid Them
Last Message: 5/24/2019
 |  Comments: 2
97% of Americans Cant Ace a Basic Security Test
Last Message: 5/24/2019
 |  Comments: 8
Learn to Hack Non-Competes & Sell 0-Days at Black Hat USA
Last Message: 5/22/2019
 |  Comments: 1
To Narrow the Cyber Skills Gap with Attackers, Cut the Red Tape
Last Message: 5/22/2019
 |  Comments: 2
Satan Ransomware Adds More Evil Tricks
Last Message: 5/22/2019
 |  Comments: 1
Pfizer: Strike Three
Last Message: 5/21/2019
 |  Comments: 1
Artist Uses Malware in Installation
Last Message: 5/21/2019
 |  Comments: 1
World Password Day or Groundhog Day?
Last Message: 5/21/2019
 |  Comments: 3
Windows 10 Migration: Getting It Right
Last Message: 5/18/2019
 |  Comments: 1
Crowdsourced vs. Traditional Pen Testing
Last Message: 5/18/2019
 |  Comments: 10
We Must Become Good Digital Citizens
Last Message: 5/17/2019
 |  Comments: 2
Get Ready for 'WannaCry 2.0'
Last Message: 5/15/2019
 |  Comments: 1
Why AI Will Create Far More Jobs Than It Replaces
Last Message: 5/14/2019
 |  Comments: 2
78% of Consumers Say Online Companies Must Protect Their Info
Last Message: 5/13/2019
 |  Comments: 1
How to Close the Critical Cybersecurity Talent Gap
Last Message: 5/13/2019
 |  Comments: 2
Hackers Still Outpace Breach Detection, Containment Efforts
Last Message: 5/13/2019
 |  Comments: 1
7 Types of Experiences Every Security Pro Should Have
Last Message: 5/10/2019
 |  Comments: 1
How the Skills Gap Strains and Constrains Security Pros
Last Message: 5/10/2019
 |  Comments: 1
Airports & Operational Technology: 4 Attack Scenarios
Last Message: 5/10/2019
 |  Comments: 1
Security Doesn't Trust IT and IT Doesn't Trust Security
Last Message: 5/9/2019
 |  Comments: 2
In Security, All Logs Are Not Created Equal
Last Message: 5/9/2019
 |  Comments: 1
Page 1 / 2   >   >>


COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/4/2020
Abandoned Apps May Pose Security Risk to Mobile Devices
Robert Lemos, Contributing Writer,  5/29/2020
How AI and Automation Can Help Bridge the Cybersecurity Talent Gap
Peter Barker, Chief Product Officer at ForgeRock,  6/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: What? IT said I needed virus protection!
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13768
PUBLISHED: 2020-06-04
In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19861, CVE-2018-19862, and CVE-2019-17601. NOTE: this product is discontinued.
CVE-2020-13849
PUBLISHED: 2020-06-04
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.
CVE-2020-13848
PUBLISHED: 2020-06-04
Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c.
CVE-2020-11682
PUBLISHED: 2020-06-04
Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request ...
CVE-2020-12847
PUBLISHED: 2020-06-04
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console� that is available to users with an administrator role. This console provides an administrator user with the possibility of changing several settings, including the applicat...