Application Security News and Articles


DEF CON 31 – Allison Young’s, Diane Akerman’s ‘Private Until Presumed Guilty ‘

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Casio Says Personal Information Accessed in Web Application Server Hack

Hackers access the personal information of Casio customers after compromising the server for an education web application. The post Casio Says Personal Information Accessed in Web Application Server Hack appeared first on SecurityWeek.

Numbers turned weapons: DoS in Osmosis’ math library

By Sam Alws Trail of Bits is publicly disclosing a vulnerability in the Osmosis chain that allows an attacker to craft a transaction that takes up a disproportionate amount of compute time on Osmosis nodes compared to the amount of gas it ...

Rockwell Automation Acquires ICS/OT Security Firm Verve Industrial

Rockwell Automation has acquired ICS/OT cybersecurity firm Verve Industrial Protection to expand its offering. The post Rockwell Automation Acquires ICS/OT Security Firm Verve Industrial appeared first on SecurityWeek.

SolarWinds Patches High-Severity Flaws in Access Rights Manager

SolarWinds patches high-severity flaws in its Access Rights Manager product, including three unauthenticated remote code execution issues. The post SolarWinds Patches High-Severity Flaws in Access Rights Manager appeared first on SecurityWeek.

Okta Hacked Yet Again: 2FA Firm Failed to 2FA

You had one job: Once is happenstance, twice is coincidence, FIVE TIMES is sheer incompetence. The post Okta Hacked Yet Again: 2FA Firm Failed to 2FA appeared first on Security Boulevard.

Randall Munroe’s XKCD ‘Black Holes vs. Regular Holes’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD! Permalink The post Randall Munroe’s XKCD ‘Black Holes vs. Regular Holes’ appeared first on Security Boulevard.

EU Wants Details from Meta, TikTok About Disinformation Measures

The European Union is putting more pressure on social media companies to crack down on disinformation that has been spreading rapidly on their platforms since the start of fighting between Israel and Hamas. The European Commission – the EU’s ...

Enterprise Browser Startup Island Banks $100M in Funding

Since 2020, Island has raised a total of $325 million to help protect corporate data flowing through SaaS and internal web applications. The post Enterprise Browser Startup Island Banks $100M in Funding appeared first on SecurityWeek.

DC Board of Elections Says Full Voter Roll Compromised in Data Breach

The District of Columbia Board of Elections says full voter roll compromised in a recent data breach at hosting provider DataNet. The post DC Board of Elections Says Full Voter Roll Compromised in Data Breach appeared first on SecurityWeek.

Facebook – abysmal algorithms and customer disservice

Facecrooks nails Facebook/Meta on (at least) two of its less attractive attributes. Firstly, its reliance on artificial intelligence, in this case using a faulty algorithm to correct a faulty algorithm. Presumably because AI works out cheaper ...

Examining Predator Mercenary Spyware

HYAS Labs, the R&D arm of HYAS, has been following the research by CitizenLab and Sekoia on the mercenary spyware “Predator,” made by Cytrox. Recently, as reported by CitizenLab, the malware was discovered targeting an Egyptian former MP ...

Deep Instinct Prevention for Storage fills gaps in data protection left by legacy tools

Deep Instinct launched Deep Instinct Prevention for Storage (DPS). The new offering applies a prevention-first approach to storage protection, wherever data is stored – Network Attached Storage (NAS), hybrid, or public cloud environments – ...

Realistic attacks for useful results

Critical Endpoint Protection Evaluations Endpoint protection is a critical component of any organisation’s cybersecurity strategy. And if it’s critical then you should test it and additionally, have others run assessments too. How we test ...

Reusable Persona stores PII for reuse across any device or browser

Persona launched a new addition to its suite of identity solutions, “Reusable Personas”. Leveraging Passkeys, the new release enables users to securely store their Personal Identity Information (PII) for reuse across any device or ...

DEF CON 31 – Frank ‘D9’ DiGiovanni’s ‘Packet Hacking Village – Pwning The Pwners With Mindware’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Microsoft Rolls Out Early Access Process Program for Security Copilot

Microsoft is giving more organizations access to its months-old Copilot generative-AI security tool through an early access program. The IT giant in March introduced Security Copilot, the latest iteration of the Copilot technology that Microsoft ...

AI-Powered Cybersecurity: Fortifying Against Data Breaches

AI: The game-changer in cybersecurity, empowering organizations to defend against data breaches and cyberattacks proactively The post AI-Powered Cybersecurity: Fortifying Against Data Breaches appeared first on Security Boulevard.

Veritas 360 Defense protects enterprise data and applications across clouds

Veritas Technologies announced Veritas 360 Defense, an extensible architecture in its space that brings together leading data protection, data governance, and data security capabilities. Veritas 360 Defense delivers a set of cyber resilience ...

Centific and Prove Identity partner to bridge cybersecurity and fraud protection gap

Centific and Prove Identity have partnered to bridge the gap between cybersecurity and fraud protection. This initiative will redefine the digital security landscape by offering a holistic solution for ensuring data privacy, identity ...