Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Latest Security News From RSAC 2021
10 Security Awareness Training Mistakes to Avoid
7 Modern-Day Cybersecurity Realities
Critical Infrastructure Under Attack
News & Commentary
Researchers Create Covert Channel Over Apple AirTag Network
Robert Lemos, Contributing WriterNews
Small amounts of data could be sent from nearly anywhere using Apple's "Find My" network, hidden in the large volume of traffic as AirTags become widely used, two researchers say.
By Robert Lemos Contributing Writer, 5/18/2021
Comment0 comments  |  Read  |  Post a Comment
How to Mitigate Against Domain Credential Theft
Zur Ulianitzky & Yaron Shani, Head of Security Research , XM Cyber / Senior Cybersecurity Researcher, XM CyberCommentary
Attackers routinely reuse stolen domain credentials. Here are some ways to thwart their access.
By Zur Ulianitzky & Yaron Shani Head of Security Research , XM Cyber / Senior Cybersecurity Researcher, XM Cyber, 5/18/2021
Comment0 comments  |  Read  |  Post a Comment
Cisco Plans to Create 'Premium' SecureX Offering With Kenna Security Features
Kelly Jackson Higgins, Executive Editor at Dark ReadingNews
Executives from Cisco share insights on the networking giant's ambitious security strategy.
By Kelly Jackson Higgins Executive Editor at Dark Reading, 5/18/2021
Comment0 comments  |  Read  |  Post a Comment
Latest Security News From RSAC 2021
Dark Reading Staff, News
Check out Dark Reading's updated, exclusive coverage of the news and security themes that are dominating RSA Conference 2021.
By Dark Reading Staff , 5/18/2021
Comment0 comments  |  Read  |  Post a Comment
DarkSide Ransomware Variant Targets Disk Partitions
Dark Reading Staff, Quick Hits
A newly discovered DarkSide ransomware variant can detect and compromise partitioned hard drives, researchers report.
By Dark Reading Staff , 5/17/2021
Comment0 comments  |  Read  |  Post a Comment
47% of Criminals Buying Exploits Target Microsoft Products
Kelly Sheridan, Staff Editor, Dark ReadingNews
Researchers examine English- and Russian-language underground exploits to track how exploits are advertised and sold.
By Kelly Sheridan Staff Editor, Dark Reading, 5/17/2021
Comment0 comments  |  Read  |  Post a Comment
DDoS Attacks Up 31% in Q1 2021: Report
Dark Reading Staff, Quick Hits
If pace continues, DDoS attack activity could surpass last year's 10-million attack threshold.
By Dark Reading Staff , 5/17/2021
Comment0 comments  |  Read  |  Post a Comment
Rapid7 Is the Latest Victim of a Software Supply Chain Breach
Jai Vijayan, Contributing WriterNews
Security vendor says attackers accessed some of its source code using a previously compromised Bash Uploader script from Codecov.
By Jai Vijayan Contributing Writer, 5/17/2021
Comment0 comments  |  Read  |  Post a Comment
RSAC 2021: What Will SolarWinds' CEO Reveal?
Joan Goodchild, Staff Editor
In a keynote conversation with Forrester analyst Laura Koetzle, Sudhakar Ramakrishna will get candid about the historic breach.
By Joan Goodchild Staff Editor, 5/17/2021
Comment0 comments  |  Read  |  Post a Comment
Agility Broke AppSec. Now It's Going to Fix It.
Chen Gour-Arie, Chief Architect, Enso SecurityCommentary
Outnumbered 100 to 1 by developers, AppSec needs a new model of agility to catch up and protect everything that needs to be secured.
By Chen Gour-Arie Chief Architect, Enso Security, 5/17/2021
Comment0 comments  |  Read  |  Post a Comment
Name That Toon: Road Trip
John Klossner, CartoonistCommentary
Feeling creative? Submit your caption in the comments, and our panel of experts will reward the winner with a $25 Amazon gift card.
By John Klossner Cartoonist, 5/17/2021
Comment2 comments  |  Read  |  Post a Comment
Rapid7 Source Code Accessed in Supply Chain Attack
Dark Reading Staff, Quick Hits
An investigation of the Codecov attack revealed intruders accessed Rapid7 source code repositories containing internal credentials and alert-related data.
By Dark Reading Staff , 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
How Faster COVID-19 Research Is Being Made Possible by Secure Silicon
Sara Peters, Senior Editor at Dark Reading
When Intel and Leidos set up a "trusted execution environment" to enable a widespread group of researchers to securely share and confidentially compute real-world data, it was no small achievement.
By Sara Peters Senior Editor at Dark Reading, 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
Cisco Confirms Plans to Acquire Kenna Security
Dark Reading Staff, Quick Hits
Cisco plans to integrate Kenna's vulnerability management technology into its SecureX platform.
By Dark Reading Staff , 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
SOC Teams Burdened by Alert Fatigue Explore XDR
Joan Goodchild, Staff EditorQuick Hits
ESG research finds a complex attack surface and threat landscape make alerts too overwhelming to monitor accurately
By Joan Goodchild Staff Editor, 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
Wi-Fi Design, Implementation Flaws Allow a Range of Frag Attacks
Robert Lemos, Contributing WriterNews
Every Wi-Fi product is affected by at least one fragmentation and aggregation vulnerability, which could lead to a machine-in-the-middle attack, researcher says.
By Robert Lemos Contributing Writer, 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
Security Trends to Follow at RSA Conference 2021
Yonit Wiseman, Associate at YL VenturesCommentary
Here are three key categories of sessions that provide an inside look at some of today's most interesting cybersecurity trends.
By Yonit Wiseman Associate at YL Ventures, 5/14/2021
Comment0 comments  |  Read  |  Post a Comment
Software, Incident Response Among Big Focus Areas in Biden's Cybersecurity Executive Order
Jai Vijayan, Contributing WriterNews
Overall objectives are good, but EO may be too prescriptive in parts, industry experts say.
By Jai Vijayan Contributing Writer, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
85% of Data Breaches Involve Human Interaction: Verizon DBIR
Kelly Sheridan, Staff Editor, Dark ReadingNews
Ransomware, phishing, and Web application attacks all increased during a year in which the majority of attacks involved a human element.
By Kelly Sheridan Staff Editor, Dark Reading, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
Firms Struggle to Secure Multicloud Misconfigurations
Robert Lemos, Contributing WriterNews
Half of companies had at least one case of having all ports open to the public, while more than a third had an exposed database.
By Robert Lemos Contributing Writer, 5/13/2021
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
Posted by raenye
Current Conversations "Network congestion ahead."
In reply to: entry
Post Your Own Reply
More Conversations
PR Newswire
Dark Reading Is Getting an Upgrade!

Find out more about our plans to improve the look, functionality, and performance of the Dark Reading site in the coming months.

In a keynote conversation with Forrester analyst Laura Koetzle, Sudhakar Ramakrishna will get candid about the historic breach.
When Intel and Leidos set up a "trusted execution environment" to enable a widespread group of researchers to securely share and confidentially compute real-world data, it was no small achievement.
Majority of global IT decision makers say cybersecurity is extremely or more important now than it was pre-pandemic, according to Cisco.
Register for Dark Reading Newsletters
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: Google Maps is taking "interactive" to a whole new level!
White Papers
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-32238
PUBLISHED: 2021-05-18
Epic Games / Psyonix Rocket League <=1.95 is affected by Buffer Overflow. Stack-based buffer overflow occurs when Rocket League handles UPK object files that can result in code execution and denial of service scenario.
CVE-2020-23851
PUBLISHED: 2021-05-18
A stack-based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c:513:28, which could cause a denial of service by submitting a malicious jpeg image.
CVE-2020-23852
PUBLISHED: 2021-05-18
A heap based buffer overflow vulnerability exists in ffjpeg through 2020-07-02 in the jfif_decode(void *ctxt, BMP *pb) function at ffjpeg/src/jfif.c (line 544 & line 545), which could cause a denial of service by submitting a malicious jpeg image.
CVE-2020-23856
PUBLISHED: 2021-05-18
Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.
CVE-2020-24026
PUBLISHED: 2021-05-18
TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page. The vulnerability may be exploited remotely, resulting in cross-site scripting...
Flash Poll
Video
Slideshows
Twitter Feed