Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Dark Reading Article Boards

Message Boards posted in July 2016
Google Adds New Kernel-Level Protections For Android
Last Message: 7/31/2016
 |  Comments: 1
Russia Likely Behind DNC Breach, Says FBI
Last Message: 7/31/2016
 |  Comments: 5
New Ranscam Ransomware Lowers The Bar But Raises The Stakes
Last Message: 7/30/2016
 |  Comments: 3
How to Roll Your Own Threat Intelligence Team
Last Message: 7/29/2016
 |  Comments: 1
Russia Rejects DNC Breach Allegations As 'Old Trick'
Last Message: 7/29/2016
 |  Comments: 5
Legal Sector's Threat Intel-Sharing Group Grows
Last Message: 7/28/2016
 |  Comments: 1
Ex-Citibank Worker Jailed For Sabotage Of Network
Last Message: 7/28/2016
 |  Comments: 1
Obama Issues Federal Government Policy For Cyberattack Response
Last Message: 7/27/2016
 |  Comments: 6
In Security, Know That You Know Nothing
Last Message: 7/27/2016
 |  Comments: 7
Asia Mulls Europol-Style Agency To Fight Cybercrime
Last Message: 7/26/2016
 |  Comments: 1
Edward Snowden Designs Anti-Spying Smartphone Device
Last Message: 7/26/2016
 |  Comments: 1
Report Finds Healthcare Most Targeted By Ransomware
Last Message: 7/26/2016
 |  Comments: 1
Meet The Teams In DARPA's All-Machine Hacking Tournament
Last Message: 7/25/2016
 |  Comments: 1
Ransomware Victims Rarely Pay The Full Ransom Price
Last Message: 7/21/2016
 |  Comments: 2
Beyond Data: Why CISOs Must Pay Attention To Physical Security
Last Message: 7/20/2016
 |  Comments: 1
Remote Systems Admin Software Rigged With Lurk Trojan
Last Message: 7/20/2016
 |  Comments: 1
The Blind Spot Between The Cloud & The Data Center
Last Message: 7/19/2016
 |  Comments: 2
Context-Rich And Context-Aware Cybersecurity
Last Message: 7/18/2016
 |  Comments: 1
Staying Cyber Safe At The Olympics
Last Message: 7/18/2016
 |  Comments: 1
What SMBs Need To Know About Security But Are Afraid To Ask
Last Message: 7/17/2016
 |  Comments: 1
Purple Teaming: Red & Blue Living Together, Mass Hysteria
Last Message: 7/14/2016
 |  Comments: 1
Ripping Away The Mobile Security Blanket
Last Message: 7/14/2016
 |  Comments: 1
What I Expect to See At Black Hat 2016: 5 Themes
Last Message: 7/13/2016
 |  Comments: 1
Why Aren't There More Women In IT Security?
Last Message: 7/13/2016
 |  Comments: 48
EUs General Data Protection Regulation Is Law: Now What?
Last Message: 7/13/2016
 |  Comments: 2
ICS Mess: US Industrial Systems The Most Exposed
Last Message: 7/13/2016
 |  Comments: 1
EU Approves Revised Pact For Data Transfer With US
Last Message: 7/11/2016
 |  Comments: 1
Hacking A Penetration Tester
Last Message: 7/11/2016
 |  Comments: 1
8 Ways Ethically Compromised Employees Compromise Security
Last Message: 7/11/2016
 |  Comments: 1
How Not To Write A Pen Test RFP
Last Message: 7/8/2016
 |  Comments: 1
A Holistic Approach to Cybersecurity Wellness: 3 Strategies
Last Message: 7/7/2016
 |  Comments: 1
Recalibrating Cybersecurity Spending Projections
Last Message: 7/7/2016
 |  Comments: 1
The Attribution Question: Does It Matter Who Attacked You?
Last Message: 7/7/2016
 |  Comments: 3
One iPhone In Every Large Company Infected With Malware
Last Message: 7/6/2016
 |  Comments: 3
5 Tips For Staying Cyber-Secure On Your Summer Vacation
Last Message: 7/6/2016
 |  Comments: 3
6 Ways to Keep Android Phones Safe
Last Message: 7/5/2016
 |  Comments: 3
The Clinton Email Kerfuffle & Shadow IT
Last Message: 7/5/2016
 |  Comments: 9
Hacker From Oklahoma Pleads Guilty In DDoS Attack Case
Last Message: 7/4/2016
 |  Comments: 1
Passwords To Be Phased Out By 2025, Say InfoSec Pros
Last Message: 7/1/2016
 |  Comments: 6
Over 25,000 IoT CCTV Cameras Used In DDoS Attack
Last Message: 7/1/2016
 |  Comments: 6
6 Recent Real-Life Cyber Extortion Scams
Last Message: 7/1/2016
 |  Comments: 3


COVID-19: Latest Security News & Commentary
Dark Reading Staff 6/4/2020
Abandoned Apps May Pose Security Risk to Mobile Devices
Robert Lemos, Contributing Writer,  5/29/2020
How AI and Automation Can Help Bridge the Cybersecurity Talent Gap
Peter Barker, Chief Product Officer at ForgeRock,  6/1/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: What? IT said I needed virus protection!
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-13768
PUBLISHED: 2020-06-04
In MiniShare before 1.4.2, there is a stack-based buffer overflow via an HTTP PUT request, which allows an attacker to achieve arbitrary code execution, a similar issue to CVE-2018-19861, CVE-2018-19862, and CVE-2019-17601. NOTE: this product is discontinued.
CVE-2020-13849
PUBLISHED: 2020-06-04
The MQTT protocol 3.1.1 requires a server to set a timeout value of 1.5 times the Keep-Alive value specified by a client, which allows remote attackers to cause a denial of service (loss of the ability to establish new connections), as demonstrated by SlowITe.
CVE-2020-13848
PUBLISHED: 2020-06-04
Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and FindServiceEventURLPath in genlib/service_table/service_table.c.
CVE-2020-11682
PUBLISHED: 2020-06-04
Castel NextGen DVR v1.0.0 is vulnerable to CSRF in all state-changing request. A __RequestVerificationToken is set by the web interface, and included in requests sent by web interface. However, this token is not verified by the application: the token can be removed from all requests and the request ...
CVE-2020-12847
PUBLISHED: 2020-06-04
Pydio Cells 2.0.4 web application offers an administrative console named “Cells Console� that is available to users with an administrator role. This console provides an administrator user with the possibility of changing several settings, including the applicat...