Application Security News and Articles


Microsoft DCU’s Takedown of RaccoonO365

 When I saw the name of the Microsoft Digital Crime Unit's latest target, "RaccoonO365" I probably reacted to it differently than most.  With the help of a friend in Lagos, we've been watching the money launderers and things have reached a ...

Anton’s Security Blog Quarterly Q3 2025

Amazingly, Medium has fixed the stats so my blog / podcast quarterly is back to life. As before, this covers both Anton on Security and my posts from Google Cloud blog, Google Cloud community blog, and our Cloud Security Podcast (subscribe on ...

European Airport Disruptions Caused by Ransomware: EU Cyber Office

The EU's cybersecurity agency says the widespread disruptions at airports in Belgium, England, and Germany were the result of a ransomware attack on third-party on-boarding software from Collins Aerospace that was used at all three airports. The ...

Achieving Certainty in Data Security Measures

How Can Non-Human Identities Enhance Data Security Certainty? One question persists: how can organizations enhance data security certainty while managing non-human identities (NHIs) effectively? NHIs—machine identities that operate within our ...

Analysis Surfaces High Degree to Which Malware Evades Detection

An analysis of 769 public threat reports published by Stairwell, a provider of file analysis tools, finds they contained 16,104 more undetected variants of malware beyond the 10,262 instances first discovered by legacy cybersecurity tools and ...

TDL 005 | A Defender’s Journey: From Passion Project to Protecting Children Online

Summary A Defender’s Journey: From Passion Project to Protecting Children Online In a recent episode of “The Defender’s Log,” host David Redekop sat down with cybersecurity expert Will Earp to discuss his unconventional path into the ...

Google One Tap Login with MojoAuth

Learn how to integrate Google One Tap with MojoAuth for a secure, passwordless login that boosts user conversions and simplifies onboarding. The post Google One Tap Login with MojoAuth appeared first on Security Boulevard.

DEF CON 33: Mar Williams

Creators, Authors and Presenters: Dreadwear, Mar Williams Our sincere appreciation to DEF CON, and the Creators/Presenters/Authors for publishing their timely DEF CON 33 outstanding content. Originating from the conference's events located at the ...

Closing the Visibility Gap: Corporate Exposure Analytics in the Infostealer Era

Co-authored by Constella Intelligence and Kineviz As infostealer malware continues to scale in reach, automation, and precision, organizations face an increasingly urgent challenge: a lack of comprehensive visibility across their identity ...

Randall Munroe’s XKCD ‘’Cursed Number”

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘’Cursed Number” appeared first on Security Boulevard.

Technical Analysis of Zloader Updates

IntroductionZloader (a.k.a. Terdot, DELoader, or Silent Night) is a Zeus-based modular trojan that emerged in 2015. Zloader was originally designed to facilitate banking, but has since been repurposed for initial access, providing an entry point ...

6 Ways CISOs Are Using AI to Prioritize Critical Vulnerabilities

Just like AI is transforming business operations, it’s revolutionizing how CISOs handle vulnerabilities. AI-powered vulnerability prioritization helps reduce alert noise, focus on high-risk issues, and automate remediation, enabling security ...

DEF CON 33: Darren Kitchen Hak5 Pager

Creators, Authors and Presenters: Ryan, Darren Kitchen Our sincere appreciation to DEF CON, and the Creators/Presenters/Authors for publishing their timely DEF CON 33 outstanding content. Originating from the conference's events located at the ...

Malicious GitHub pages lure MacOS users into installing Atomic infostealer

MacOS users looking to download popular software such as LastPass, 1Password, After Effects, Gemini, and many others are in danger of getting saddled with the Atomic infostealer instead, LastPass has warned. The malware delivery campaign is ...

The Complete Guide to Analyst Research Firms: How Innovative Companies Navigate the Landscape

90% of enterprise buyers consult analysts before purchasing. Yet most startups struggle with analyst relations. Here's your complete roadmap to navigating Gartner, Forrester, and 20+ top research firms—from a serial entrepreneur who's been on ...

Stellar Cyber 6.1 equips SecOps teams with multi-layer AI

Stellar Cyber announced Stellar Cyber 6.1, designed to help customers and partners advance toward a human-augmented autonomous SOC. With Stellar Cyber 6.1, organizations gain new levels of visibility, speed, and control. Powered by multi-layer ...

EXPLICATION SAST, SCA & CONTAINER SCAN

1. 🔍 SAST (Static Application Security Testing)Continue reading on Medium »

Sumo Logic Adds AI Agents to Automate Security Operations Tasks

Sumo Logic introduces AI agents powered by AWS Nova LLMs to query and summarize cybersecurity data, reducing manual toil and helping SecOps counter AI-driven attacks. The post Sumo Logic Adds AI Agents to Automate Security Operations Tasks ...

Mycroft Raises $3.5 Million for AI-Powered Security and Compliance Platform

The Canada-based company has emerged from stealth with autonomous AI agents designed to manage and operate the security and IT stack. The post Mycroft Raises $3.5 Million for AI-Powered Security and Compliance Platform appeared first on SecurityWeek.

Researchers Earn $150,000 for L1TF Exploit Leaking Data From Public Cloud

L1TF Reloaded is a vulnerability combining the old L1TF and half-Spectre hardware flaws to bypass deployed software mitigations. The post Researchers Earn $150,000 for L1TF Exploit Leaking Data From Public Cloud appeared first on SecurityWeek.