Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Cartoon: Password Generation Gap
Threaded  |  Newest First  |  Oldest First
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
6/7/2019 | 11:18:25 AM
New Cartoon!
Love it! 
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
6/11/2019 | 1:56:26 PM
Re: New Cartoon!
Oh don't mind her - cobol programmer. 
Ace2010
100%
0%
Ace2010,
User Rank: Strategist
6/12/2019 | 2:27:57 PM
Re: New Cartoon!
We just need her to generate gibberish in 16 characters or more!
acampbell448
50%
50%
acampbell448,
User Rank: Strategist
6/10/2019 | 11:02:42 AM
Startup to Spinoff!
We are considering this a new startup project with the objective to spin it off in about 18 years!
Tempest2004
50%
50%
Tempest2004,
User Rank: Black Belt
6/10/2019 | 12:03:22 PM
baby talk
It is never to early to start harvesting customer data
vol_sec
100%
0%
vol_sec,
User Rank: Strategist
6/11/2019 | 4:34:37 PM
WannaCry
When WannaCry disrupts business inituitives.
rfarnl
50%
50%
rfarnl,
User Rank: Strategist
6/14/2019 | 10:58:36 AM
re:new cartoon
It's really difficult understanding these new startups 
Ratteau
50%
50%
Ratteau,
User Rank: Strategist
6/18/2019 | 10:49:02 AM
Question
OK, who invited marketing to a dev meeting?
willgetin
50%
50%
willgetin,
User Rank: Guru
6/18/2019 | 2:43:20 PM
Complex passwords?
In a few years, she'e going to phase out complex passwords and start using pass phrases
DavidRandolph
50%
50%
DavidRandolph,
User Rank: Strategist
6/18/2019 | 2:45:27 PM
caption
IDK.  Must be TLS 1.3.
acampbell448
100%
0%
acampbell448,
User Rank: Strategist
6/26/2019 | 9:36:38 AM
Yet another version of Agile
Oh no not another version of Agile with yet another language of it's own to learn!
GWAIN
100%
0%
GWAIN,
User Rank: Strategist
7/3/2019 | 9:49:37 AM
Maybe the rest of us, too.
What the board hears when the CISO dumps the latest Information Security marketing buzzwords.


Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
7 Tips for Infosec Pros Considering A Lateral Career Move
Kelly Sheridan, Staff Editor, Dark Reading,  1/21/2020
For Mismanaged SOCs, The Price Is Not Right
Kelly Sheridan, Staff Editor, Dark Reading,  1/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: I've never actually seen the corporate ladder before.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
How Enterprises are Attacking the Cybersecurity Problem
How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18898
PUBLISHED: 2020-01-23
UNIX Symbolic Link (Symlink) Following vulnerability in the trousers package of SUSE SUSE Linux Enterprise Server 15 SP1; openSUSE Factory allowed local attackers escalate privileges from user tss to root. This issue affects: SUSE SUSE Linux Enterprise Server 15 SP1 trousers versions prior to 0.3.14...
CVE-2019-19837
PUBLISHED: 2020-01-23
Incorrect access control in the web interface in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote information disclosure of bin/web.conf via HTTP requests.
CVE-2020-7210
PUBLISHED: 2020-01-23
Umbraco CMS 8.2.2 allows CSRF to enable/disable or delete user accounts.
CVE-2019-19835
PUBLISHED: 2020-01-23
SSRF in AjaxRestrictedCmdStat in zap in Ruckus Wireless Unleashed through 200.7.10.102.64 allows a remote denial of service via the server attribute to the tools/_rcmdstat.jsp URI.
CVE-2020-5216
PUBLISHED: 2020-01-23
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.9.0, 5.2.0, and 6.3.0. If user-supplied input was passed into append/override_content_security_policy_directives, a newline could be injected leading to limited header injection. Upon seei...