Dark Reading Article Boards

Message Boards posted in September 2014
Page 1 / 2   >   >>
New Bash Bugs Surface
Last Message: 9/30/2014
 |  Comments: 1
Hacking Humans
Last Message: 9/30/2014
 |  Comments: 2
Making Sense Of Shellshock Attack Chaos
Last Message: 9/30/2014
 |  Comments: 4
Data Privacy Etiquette: It's Not Just For Kids
Last Message: 9/30/2014
 |  Comments: 10
Shellshocked: A Future Of Hair On Fire Bugs
Last Message: 9/30/2014
 |  Comments: 22
Apple: Majority Of Mac OS X Users Not At Risk To 'Shellshock'
Last Message: 9/30/2014
 |  Comments: 5
How SaaS Adoption Is Changing Cloud Security
Last Message: 9/29/2014
 |  Comments: 6
When Layers On Layers Of Security Equals LOL Security
Last Message: 9/29/2014
 |  Comments: 3
Breached Retailers Harden PoS, For Now
Last Message: 9/29/2014
 |  Comments: 8
Malvertising Could Rival Exploit Kits
Last Message: 9/26/2014
 |  Comments: 2
Bash Bug May Be Worse Than Heartbleed
Last Message: 9/26/2014
 |  Comments: 10
InfoSec Book Club: Whats On Your Fall Reading List?
Last Message: 9/25/2014
 |  Comments: 8
Study: 15 Million Devices Infected With Mobile Malware
Last Message: 9/25/2014
 |  Comments: 1
Jimmy John's Gourmet Sandwiches POS Systems Hacked
Last Message: 9/25/2014
 |  Comments: 4
5 Top Tips For Outsourced Security
Last Message: 9/25/2014
 |  Comments: 5
Incident Response Fail
Last Message: 9/24/2014
 |  Comments: 1
Mobile-Only Employee Trend Could Break Security Models
Last Message: 9/24/2014
 |  Comments: 10
ISIS Cyber Threat To US Under Debate
Last Message: 9/24/2014
 |  Comments: 7
Hot Issues in Application Security
Last Message: 9/24/2014
 |  Comments: 58
Creating A DDoS Response Playbook
Last Message: 9/24/2014
 |  Comments: 1
'Hand-To-Hand Digital Combat' With Threat Actors
Last Message: 9/23/2014
 |  Comments: 2
An AppSec Report Card: Developers Barely Passing
Last Message: 9/23/2014
 |  Comments: 11
US Military In The Dark On Cyberattacks Against Contractors
Last Message: 9/23/2014
 |  Comments: 2
5 Ways To Think Outside The PCI Checkbox
Last Message: 9/23/2014
 |  Comments: 6
Mobile Device Security Isn't All About Devices
Last Message: 9/22/2014
 |  Comments: 2
The Truth About Ransomware: Youre On Your Own
Last Message: 9/22/2014
 |  Comments: 1
Is Enterprise IT Security Ready For iOS 8?
Last Message: 9/22/2014
 |  Comments: 4
DR Radio: A Grown-Up Conversation About Passwords
Last Message: 9/19/2014
 |  Comments: 7
Google Backs New Effort To Simplify Security
Last Message: 9/19/2014
 |  Comments: 12
6 Tips For Securing Social Media In The Workplace
Last Message: 9/19/2014
 |  Comments: 11
Meet The Next Next-Gen Firewall
Last Message: 9/18/2014
 |  Comments: 3
Cyberspies Resuscitate Citadel Trojan For Petrochemical Attacks
Last Message: 9/18/2014
 |  Comments: 5
In Defense Of Passwords
Last Message: 9/17/2014
 |  Comments: 12
A Grown-Up Conversation About Passwords
Last Message: 9/17/2014
 |  Comments: 118
Weak Password Advice From Microsoft
Last Message: 9/17/2014
 |  Comments: 16
Worm Illuminates Potential NAS Nightmare
Last Message: 9/17/2014
 |  Comments: 6
Google: No Breach In Latest Online Dump Of Credentials
Last Message: 9/17/2014
 |  Comments: 3
Hacking Password Managers
Last Message: 9/16/2014
 |  Comments: 13
Privacy, Security & The Geography Of Data Protection
Last Message: 9/16/2014
 |  Comments: 6
Apple Pay: A Necessary Push To Transform Consumer Payments
Last Message: 9/15/2014
 |  Comments: 16
Page 1 / 2   >   >>


Want Your Daughter to Succeed in Cyber? Call Her John
John De Santis, CEO, HyTrust,  5/16/2018
Don't Roll the Dice When Prioritizing Vulnerability Fixes
Ericka Chickowski, Contributing Writer, Dark Reading,  5/15/2018
Why Enterprises Can't Ignore Third-Party IoT-Related Risks
Charlie Miller, Senior Vice President, The Santa Fe Group,  5/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Security through obscurity"
Current Issue
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-11311
PUBLISHED: 2018-05-20
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.
CVE-2018-11319
PUBLISHED: 2018-05-20
Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to ...
CVE-2018-11242
PUBLISHED: 2018-05-20
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.
CVE-2018-11315
PUBLISHED: 2018-05-20
The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can result in remote device temperature control, as demonstrated by a tstat t_heat request that accesses a device purchased in the Spring of 2018, and sets a ho...
CVE-2018-11239
PUBLISHED: 2018-05-19
An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets by providing a _to argument in conjunction with a large _value argument, as exploited in the wild in ...