Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Write A Caption & Win A Prize
Oldest First  |  Newest First  |  Threaded View
Page 1 / 14   >   >>
RetiredUser
67%
33%
RetiredUser,
User Rank: Ninja
2/13/2016 | 11:09:37 AM
"For the Love" Entry
Linda says:  "Sec. 406 of the Cybersecurity Information Sharing Act of 2015 states multi-factor logical access controls include 'Information that is known to the user, such as a password or personal identification number' but it's pretty vague on how it is known."

Roger has a suspicion hiring Linda does not lend to improved "cybersecurity in the United States through enhanced sharing of information about cybersecurity threats, and for other purposes."

(Note: This is not a contest entry, just for the love of the comic!)
nipsy
50%
50%
nipsy,
User Rank: Apprentice
2/13/2016 | 12:48:26 PM
caption
Is the six upper or lower case?

 

 

(seriously ive been asked this more than once)
doorstepman
25%
75%
doorstepman,
User Rank: Apprentice
2/13/2016 | 3:15:07 PM
remembering your pin
You're not going to remember your pin by looking at the sky.
JohnD22901
96%
4%
JohnD22901,
User Rank: Apprentice
2/13/2016 | 3:15:32 PM
Contest Entry
"I can't believe these password reminders are still being sent in plane-text"
hewenthatway
33%
67%
hewenthatway,
User Rank: Strategist
2/13/2016 | 7:28:34 PM
caption
Well, as you can see, we've been pwned.
dale_stout
0%
100%
dale_stout,
User Rank: Strategist
2/13/2016 | 10:40:07 PM
Write a Caption
You'd better get your boarding pass.
dale_stout
0%
100%
dale_stout,
User Rank: Strategist
2/13/2016 | 10:40:07 PM
Write a Caption
You'd better get your boarding pass.
MarkN684
50%
50%
MarkN684,
User Rank: Apprentice
2/14/2016 | 1:35:28 AM
Caption
The latest security upgrade to the OPM site
Whoopty
0%
100%
Whoopty,
User Rank: Ninja
2/15/2016 | 7:47:34 AM
Well
"I have a fool proof way of remembering mine. No-one will ever catch on."
ecote068
0%
100%
ecote068,
User Rank: Strategist
2/15/2016 | 9:59:35 AM
Write a Caption
Well, we have tremendously decreased the time to reset a user's password!  Now we have to work on limiting who gets to see it.
Page 1 / 14   >   >>


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-3830
PUBLISHED: 2021-09-26
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-21742
PUBLISHED: 2021-09-25
There is an information leak vulnerability in the message service app of a ZTE mobile phone. Due to improper parameter settings, attackers could use this vulnerability to obtain some sensitive information of users by accessing specific pages.
CVE-2020-20508
PUBLISHED: 2021-09-24
Shopkit v2.7 contains a reflective cross-site scripting (XSS) vulnerability in the /account/register component, which allows attackers to hijack user credentials via a crafted payload in the E-Mail text field.
CVE-2020-20514
PUBLISHED: 2021-09-24
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.
CVE-2016-6555
PUBLISHED: 2021-09-24
OpenNMS version 18.0.1 and prior are vulnerable to a stored XSS issue due to insufficient filtering of SNMP trap supplied data. By creating a malicious SNMP trap, an attacker can store an XSS payload which will trigger when a user of the web UI views the events list page. This issue was fixed in ver...