Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Name That Toon: The Advanced Persistent Threat
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 7 / 7
waltonob
100%
0%
waltonob,
User Rank: Strategist
3/11/2019 | 5:04:37 PM
New Species!
It looks like the genetic engineering team and the data gathering team have successfully merged.
acampbell448
80%
20%
acampbell448,
User Rank: Ninja
3/11/2019 | 8:05:41 AM
Forget about Fancy Bear
I thought Fancy Bear was our biggest problem, but wait until you see this!
jeffmaley
87%
13%
jeffmaley,
User Rank: Strategist
3/8/2019 | 1:41:46 PM
Cartoon Caption
Phishing Level: Cthulhu
mepplin
100%
0%
mepplin,
User Rank: Apprentice
3/8/2019 | 1:41:44 PM
Advanced?
It may not be advanced, but it sure is persistent.
wfishburne
75%
25%
wfishburne,
User Rank: Strategist
3/8/2019 | 11:34:00 AM
Hooked a big one
"I told you that 'reverse phishing' was a bad idea."
Window Geek
100%
0%
Window Geek,
User Rank: Apprentice
3/8/2019 | 10:56:46 AM
Caption
Nevermind the blockchain!  Get me a sword!
<<   <   Page 7 / 7


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Enterprise Cybersecurity Plans in a Post-Pandemic World
Download the Enterprise Cybersecurity Plans in a Post-Pandemic World report to understand how security leaders are maintaining pace with pandemic-related challenges, and where there is room for improvement.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-40309
PUBLISHED: 2021-09-24
A SQL injection vulnerability exists in the Take Attendance functionality of OS4Ed's OpenSIS 8.0. allows an attacker to inject their own SQL query. The cp_id_miss_attn parameter from TakeAttendance.php is vulnerable to SQL injection. An attacker can make an authenticated HTTP request as a user with ...
CVE-2021-40310
PUBLISHED: 2021-09-24
OpenSIS Community Edition version 8.0 is affected by a cross-site scripting (XSS) vulnerability in the TakeAttendance.php via the cp_id_miss_attn parameter.
CVE-2021-28130
PUBLISHED: 2021-09-24
Dr.Web Firewall 12.5.2.4160 on Windows incorrectly restricts applications signed by Dr.Web. A DLL for a custom payload within a legitimate binary (e.g., frwl_svc.exe) bypasses firewall filters.
CVE-2021-40099
PUBLISHED: 2021-09-24
An issue was discovered in Concrete CMS through 8.5.5. Fetching the update json scheme over HTTP leads to remote code execution.
CVE-2021-40100
PUBLISHED: 2021-09-24
An issue was discovered in Concrete CMS through 8.5.5. Stored XSS can occur in Conversations when the Active Conversation Editor is set to Rich Text.