Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security //

Database Security

News & Commentary
Data from 5.2M Marriott Loyalty Program Members Hit by Breach
Dark Reading Staff, Quick Hits
The data was breached through the credentials of two franchisee employees.
By Dark Reading Staff , 3/31/2020
Comment2 comments  |  Read  |  Post a Comment
Insurance Giant Chubb Might Be Ransomware Victim
Curtis Franklin Jr., Senior Editor at Dark ReadingQuick Hits
A ransomware operator claims to have successfully attacked Chubb Insurance databases.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 3/26/2020
Comment0 comments  |  Read  |  Post a Comment
538 Million Weibo Users' Info for Sale on Dark Web
Dark Reading Staff, Quick Hits
The user data, which does not include passwords, purportedly comes from a mid-2019 breach.
By Dark Reading Staff , 3/23/2020
Comment0 comments  |  Read  |  Post a Comment
200M Records of US Citizens Leaked in Unprotected Database
Kelly Sheridan, Staff Editor, Dark ReadingNews
Researchers have not determined who owns the database, which was one of several large exposed instances disclosed this week.
By Kelly Sheridan Staff Editor, Dark Reading, 3/20/2020
Comment2 comments  |  Read  |  Post a Comment
Misconfigured Elasticsearch Instance Exposes More Than 5 Billion Records
Dark Reading Staff, Quick Hits
The collections contained information collected by a UK research firm on data breaches from the years 2012 to 2019.
By Dark Reading Staff , 3/19/2020
Comment1 Comment  |  Read  |  Post a Comment
500,000 Documents Exposed in Open S3 Bucket Incident
Dark Reading Staff, Quick Hits
The open database exposed highly sensitive financial and business documents related to two financial organizations.
By Dark Reading Staff , 3/18/2020
Comment0 comments  |  Read  |  Post a Comment
3 Data Breaches Disclosed This Week: J.Crew, T-Mobile, and Carnival
Dark Reading Staff, Quick Hits
The separate incidents show how data theft knows no market-based limits.
By Dark Reading Staff , 3/5/2020
Comment3 comments  |  Read  |  Post a Comment
Cathay Pacific Hit with Fine for Long-Lasting Breach
Dark Reading Staff, Quick Hits
The breach, which was active for four years, resulted in the theft of personal information on more than 9 million people.
By Dark Reading Staff , 3/4/2020
Comment0 comments  |  Read  |  Post a Comment
Walgreens' Mobile App Exposes Customers' Info
Dark Reading Staff, Quick Hits
An error in the app allowed some secure chat users to see medical information that wasn't theirs.
By Dark Reading Staff , 3/2/2020
Comment1 Comment  |  Read  |  Post a Comment
How to Prevent an AWS Cloud Bucket Data Leak
Curtis Franklin Jr., Senior Editor at Dark Reading
Misconfigured AWS buckets have led to huge data breaches. Following a handful of practices will help keep you from becoming the next news story.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 2/26/2020
Comment1 Comment  |  Read  |  Post a Comment
Israel's Entire Voter Registry Exposed in Massive Incident
Dark Reading Staff, Quick Hits
Personal details of nearly 6.5 million Israelis were out in the open after the entire registry was uploaded to an notably insecure app.
By Dark Reading Staff , 2/10/2020
Comment0 comments  |  Read  |  Post a Comment
Google Takeout Serves Up Video Files to Strangers
Dark Reading Staff, Quick Hits
A limited number of user videos were shared with others in a five-day incident from November.
By Dark Reading Staff , 2/7/2020
Comment0 comments  |  Read  |  Post a Comment
Ashley Madison Breach Returns with Extortion Campaign
Dark Reading Staff, Quick Hits
The recent attack messages use new techniques to extort Bitcoin payments from Ashley Madison users hit in massive 2015 data breach.
By Dark Reading Staff , 1/31/2020
Comment3 comments  |  Read  |  Post a Comment
Configuration Error Reveals 250 Million Microsoft Support Records
Dark Reading Staff, Quick Hits
Some the records, found on five identically configured servers, might have contained data in clear text.
By Dark Reading Staff , 1/22/2020
Comment1 Comment  |  Read  |  Post a Comment
FBI Seizes Domain That Sold Info Stolen in Data Breaches
Dark Reading Staff, Quick Hits
The website, WeLeakData.com, claimed to have more than 12 billion records gathered from over 10,000 breaches.
By Dark Reading Staff , 1/17/2020
Comment0 comments  |  Read  |  Post a Comment
CCPA Kickoff: What Businesses Need to Know
Kelly Sheridan, Staff Editor, Dark ReadingNews
The California Consumer Privacy Act is in full effect, prompting organizations to think about how they'll remain compliant.
By Kelly Sheridan Staff Editor, Dark Reading, 1/2/2020
Comment0 comments  |  Read  |  Post a Comment
'Honoring' CCPA's Binding Principles Nationally Won't Be Easy
Dr. Salvatore Stolfo, Founder & CTO, Allure SecurityCommentary
Even companies with the reach, capital, and innovative capacity of Microsoft or Google will struggle to adhere to the tenets of California's new consumer privacy law.
By Dr. Salvatore Stolfo Founder & CTO, Allure Security, 12/26/2019
Comment1 Comment  |  Read  |  Post a Comment
Ambiguity Around CCPA Will Lead to a Slow Start in 2020
Anurag Kahol, CTO, BitglassCommentary
But longer term, compliance to California's new privacy law represents an opportunity for companies to increase customer trust and market share.
By Anurag Kahol CTO, Bitglass, 12/20/2019
Comment0 comments  |  Read  |  Post a Comment
15 Million Patient Records Exposed Attack on Canadian Lab
Dark Reading Staff, Quick Hits
A cyberattack against LifeLabs exposed personal information on patients in Ontario and British Columbia.
By Dark Reading Staff , 12/17/2019
Comment0 comments  |  Read  |  Post a Comment
Data Security Startup Satori Cyber Launches with $5.25M Seed Round
Kelly Sheridan, Staff Editor, Dark ReadingNews
Satori Cyber aims to help businesses better protect and govern their information with its Secure Data Access Cloud.
By Kelly Sheridan Staff Editor, Dark Reading, 12/17/2019
Comment0 comments  |  Read  |  Post a Comment
More Stories
Current Conversations
Posted by Jeremmy11
Current Conversations This is really scary..=((
In reply to: oh..no
Post Your Own Reply
More Conversations
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
State of Cybersecurity Incident Response
State of Cybersecurity Incident Response
Data breaches and regulations have forced organizations to pay closer attention to the security incident response function. However, security leaders may be overestimating their ability to detect and respond to security incidents. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11509
PUBLISHED: 2020-04-07
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows remote attackers to upload page templates containing arbitrary JavaScript via the c37_wpl_import_template admin-post action (which will execute in an administrator's browser if the template is used to create a page).
CVE-2020-6647
PUBLISHED: 2020-04-07
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.
CVE-2020-9286
PUBLISHED: 2020-04-07
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebooting the system.
CVE-2020-11508
PUBLISHED: 2020-04-07
An XSS vulnerability in the WP Lead Plus X plugin through 0.98 for WordPress allows logged-in users with minimal permissions to create or replace existing pages with a malicious page containing arbitrary JavaScript via the wp_ajax_core37_lp_save_page (aka core37_lp_save_page) AJAX action.
CVE-2013-7488
PUBLISHED: 2020-04-07
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.