Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Author

 Graham Cluley
RSS
E-Mail

Profile of Graham Cluley

News & Commentary Posts: 77
Articles by Graham Cluley

Worker Who Planted Malware Time Bomb At Fannie Mae Faces Prison

10/7/2010
As belts tighten and the credit crunch continues to hit around the world, more and more companies will be making the difficult decision to make staff and contractors redundant. But what happens when a disaffected former employee decides to leave your company a parting gift - in the form of data-destroying malware?

Post a Comment

TechCrunch Hacked

1/26/2010
The immensely popular blog TechCrunch has been compromised by hackers who posted an offensive message on its home page.

Post a Comment

West African 419 Scammers Exploit Dilbert

7/29/2009
The Dilbert comic strip is loved around the world for its satirical look at life in the corporate office. But now identity thieves and scammers are exploiting the popular Dilbert.com Website in their hunt for potential victims.

Post a Comment

Erin Andrews Video: Get A Life Or Get A Virus

7/20/2009
It was early Sunday morning British time when I first heard the name "Erin Andrews." I didn't have a clue who she was -- I don't follow the American sports scene -- but one thing was certain: She was creating an enormous buzz on the Internet.

Post a Comment

Suspected Child Porn Hub Taken Offline

6/4/2009
Internet service provider Pricewert -- which trades under names such as 3FN and APS Telecom -- has been shut down and disconnected from cyberspace following allegations it was knowingly involved in major spam attacks, phishing campaigns, malware distribution, and child abuse.

Post a Comment

Why Twitter Security Needs To Grow Up

5/1/2009
Twitter is growing at phenomenal speed -- but this week's breach by a French hacker who accessed the accounts of Britney Spears, Barack Obama, and others proves it's time for the service to show a more mature attitude to security.

Post a Comment

Write A Twitter Worm, Get A Job?

4/18/2009
The teenage author of the Mikeyy and StalkDaily worms that hit Twitter users hard one weekend ago appears to have struck lucky. As a result of his infamy, he has a brand new job.

Post a Comment

StalkDaily Attack Hits Twitter Users

4/11/2009
If anyone was in any doubt that social networks are the new battleground for cybercriminals, then just log in to Twitter right now. The hugely popular micro-blogging network is overrun with warnings about messages referring to a website called StalkDaily.com, said to be spreading through compromised Twitter accounts.

Post a Comment

Will They Ever Catch Conficker's Authors?

3/31/2009
While the world is holding its breath, wondering whether the Conficker worm is going to do anything dramatic on April 1st (I'm placing money that no computers are reported to have melted by the end of the day, and the Internet won't have turned to blancmange), perhaps a more important question is: Are we ever going to catch the pond life who wrote it?

Post a Comment
News
US Formally Attributes SolarWinds Attack to Russian Intelligence Agency
Jai Vijayan, Contributing Writer,  4/15/2021
News
Dependency Problems Increase for Open Source Components
Robert Lemos, Contributing Writer,  4/14/2021
News
FBI Operation Remotely Removes Web Shells From Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7856
PUBLISHED: 2021-04-20
A vulnerability of Helpcom could allow an unauthenticated attacker to execute arbitrary command. This vulnerability exists due to insufficient authentication validation.
CVE-2021-28793
PUBLISHED: 2021-04-20
vscode-restructuredtext before 146.0.0 contains an incorrect access control vulnerability, where a crafted project folder could execute arbitrary binaries via crafted workspace configuration.
CVE-2021-25679
PUBLISHED: 2021-04-20
** UNSUPPORTED WHEN ASSIGNED ** The AdTran Personal Phone Manager software is vulnerable to an authenticated stored cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed....
CVE-2021-25680
PUBLISHED: 2021-04-20
** UNSUPPORTED WHEN ASSIGNED ** The AdTran Personal Phone Manager software is vulnerable to multiple reflected cross-site scripting (XSS) issues. These issues impact at minimum versions 10.8.1 and below but potentially impact later versions as well since they have not previously been disclosed. Only...
CVE-2021-25681
PUBLISHED: 2021-04-20
** UNSUPPORTED WHEN ASSIGNED ** AdTran Personal Phone Manager 10.8.1 software is vulnerable to an issue that allows for exfiltration of data over DNS. This could allow for exposed AdTran Personal Phone Manager web servers to be used as DNS redirectors to tunnel arbitrary data over DNS. NOTE: The aff...