Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security //

Database Security

News & Commentary
20M Russians' Personal Tax Records Exposed in Data Leak
Dark Reading Staff, Quick Hits
An unprotected Elasticsearch cluster contained personally identifiable information on Russian citizens from 2009 to 2016.
By Dark Reading Staff , 10/3/2019
Comment1 Comment  |  Read  |  Post a Comment
One Arrested in Ecuador's Mega Data Leak
Dark Reading Staff, Quick Hits
Officials arrest a leader of consulting firm Novaestrat, which owned an unprotected server that exposed 20.8 million personal records.
By Dark Reading Staff , 9/18/2019
Comment0 comments  |  Read  |  Post a Comment
24.3M Unsecured Health Records Expose Patient Data, Images
Dark Reading Staff, Quick Hits
Several hundred servers storing medical data are connected to the Internet without any protection for sensitive information and images.
By Dark Reading Staff , 9/18/2019
Comment0 comments  |  Read  |  Post a Comment
US Companies Unprepared for Privacy Regulations
Dark Reading Staff, Quick Hits
US companies are poorly prepared for even the most rudimentary privacy regulations, a new report says.
By Dark Reading Staff , 9/17/2019
Comment0 comments  |  Read  |  Post a Comment
Oracle Expands Cloud Security Services at OpenWorld 2019
Kelly Sheridan, Staff Editor, Dark ReadingNews
The company broadens its portfolio with new services developed to centralize and automate cloud security.
By Kelly Sheridan Staff Editor, Dark Reading, 9/16/2019
Comment0 comments  |  Read  |  Post a Comment
Data Leak Affects Most of Ecuador's Population
Kelly Sheridan, Staff Editor, Dark ReadingNews
An unsecured database containing 18GB of data exposed more than 20 million records, most of which held details about Ecuadorian citizens.
By Kelly Sheridan Staff Editor, Dark Reading, 9/16/2019
Comment0 comments  |  Read  |  Post a Comment
Job-Seeker Data Exposed in Monster File Leak
Dark Reading Staff, Quick Hits
The job website says it cannot notify users since the exposure occurred on a third-party organization's servers.
By Dark Reading Staff , 9/6/2019
Comment0 comments  |  Read  |  Post a Comment
419M Facebook User Phone Numbers Publicly Exposed
Dark Reading Staff, Quick Hits
It's still unclear who owned the server storing hundreds of millions of records online without a password.
By Dark Reading Staff , 9/5/2019
Comment1 Comment  |  Read  |  Post a Comment
Imperva Customer Database Exposed
Dark Reading Staff, Quick Hits
A subset of customers for the company's Incapsula web application firewall had their email addresses, hashed/salted passwords, and more open to unauthorized access, Imperva announced.
By Dark Reading Staff , 8/27/2019
Comment10 comments  |  Read  |  Post a Comment
6 Ways Airlines and Hotels Can Keep Their Networks Secure
Steve Zurier, Contributing Writer
As recent news can attest, travel and hospitality companies are prime targets for cybercriminals. Here are six privacy and security tips that can help lock down privacy and security.
By Steve Zurier Contributing Writer, 8/27/2019
Comment0 comments  |  Read  |  Post a Comment
IBM Announces Quantum Safe Encryption
Dark Reading Staff, Quick Hits
Techniques too tough for quantum computing solutions will be part of public cloud and tape storage encryption.
By Dark Reading Staff , 8/23/2019
Comment1 Comment  |  Read  |  Post a Comment
MoviePass Leaves Credit Card Numbers, Personal Data Exposed Online
Kelly Sheridan, Staff Editor, Dark ReadingNews
Thousands of customers' credit card numbers, MoviePass card numbers, and sensitive data were left in an unprotected database.
By Kelly Sheridan Staff Editor, Dark Reading, 8/21/2019
Comment1 Comment  |  Read  |  Post a Comment
Capital One: What We Should Learn This Time
Kelly Sheridan, Staff Editor, Dark ReadingNews
Where Capital One went wrong, what the bank did right, and more key takeaways from the latest mega-breach.
By Kelly Sheridan Staff Editor, Dark Reading, 8/2/2019
Comment2 comments  |  Read  |  Post a Comment
Researcher Find Open 'Road Map' to Honda Computers
Dark Reading Staff, Quick Hits
An unprotected database, now secured, contained information on every computer owned by the automobile giant.
By Dark Reading Staff , 8/1/2019
Comment1 Comment  |  Read  |  Post a Comment
Equifax to Pay Up to $700M for Data Breach Damages
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
In a settlement with the FTC, consumers affected by the breach are eligible for up to $20,000 in a cash settlement, depending on damages they can prove.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 7/22/2019
Comment2 comments  |  Read  |  Post a Comment
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, ProtegoCommentary
Despite the great success of the cloud over the last decade, misconceptions continue to persist. Here's why the naysayers are wrong.
By Hillel Solow CTO and Co-founder, Protego, 7/11/2019
Comment4 comments  |  Read  |  Post a Comment
Britain Looks to Levy Record GDPR Fine Against British Airways
Robert Lemos, Contributing WriterNews
The penalty is a sign of things to come, say experts.
By Robert Lemos Contributing Writer, 7/8/2019
Comment0 comments  |  Read  |  Post a Comment
Federal Photos Filched in Contractor Breach
Dark Reading Staff, Quick Hits
Data should never have been on subcontractor's servers, says Customs and Border Protection.
By Dark Reading Staff , 6/10/2019
Comment1 Comment  |  Read  |  Post a Comment
Flipboard Confirms Two Hacks, Prompts Password Resets
Dark Reading Staff, Quick Hits
The company reports two incidents affected a subset of its users and is resetting passwords for involved accounts.
By Dark Reading Staff , 5/29/2019
Comment1 Comment  |  Read  |  Post a Comment
GandCrab Gets a SQL Update
Curtis Franklin Jr., Senior Editor at Dark ReadingNews
A new attack is found that uses MySQL as part of the attack chain in a GandCrab ransomware infection.
By Curtis Franklin Jr. Senior Editor at Dark Reading, 5/28/2019
Comment1 Comment  |  Read  |  Post a Comment
More Stories
Current Conversations
More Conversations
For Cybersecurity to Be Proactive, Terrains Must Be Mapped
Craig Harber, Chief Technology Officer at Fidelis Cybersecurity,  10/8/2019
A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
USB Drive Security Still Lags
Dark Reading Staff 10/9/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17593
PUBLISHED: 2019-10-14
JIZHICMS 1.5.1 allows admin.php/Admin/adminadd.html CSRF to add an administrator.
CVE-2019-17594
PUBLISHED: 2019-10-14
There is a heap-based buffer over-read in the _nc_find_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-17595
PUBLISHED: 2019-10-14
There is a heap-based buffer over-read in the fmt_entry function in tinfo/comp_hash.c in the terminfo library in ncurses before 6.1-20191012.
CVE-2019-14823
PUBLISHED: 2019-10-14
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not properly verify the chain and could be vulnerable to...
CVE-2019-17592
PUBLISHED: 2019-10-14
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.