Application Security News and Articles


Proactively Threat Hunting in the Cloud: Why It’s Essential

As organizations continue to pivot towards the cloud, an emergent and dynamic threat landscape follows. The cloud, while offering unprecedented agility and scalability, presents new vulnerabilities and challenges in safeguarding sensitive data. ...

Cyber Security Awareness Month last minute activities & initiatives to use if you didn’t plan ahead

The post Cyber Security Awareness Month last minute activities & initiatives to use if you didn’t plan ahead appeared first on Click Armor. The post Cyber Security Awareness Month last minute activities & initiatives to use if you ...

Academics Devise Cyber Intrusion Detection System for Unmanned Robots

Australian AI researchers teach an unmanned military robot’s operating system to identify MitM cyberattacks. The post Academics Devise Cyber Intrusion Detection System for Unmanned Robots appeared first on SecurityWeek.

AppOmni and KPMG Canada Team Up to Strengthen SaaS Security

Our strategic collaboration will create a streamlined path for KPMG to deploy AppOmni’s comprehensive SaaS security solution to Canada-based customers. The post AppOmni and KPMG Canada Team Up to Strengthen SaaS Security appeared first on ...

Build Vs. Buy: The Unknown Unknowns of FIDO-Based Passkeys

There are many unknown unknowns associated with building a FIDO-based passkey solution versus adopting off-the-shelf solutions. The post Build Vs. Buy: The Unknown Unknowns of FIDO-Based Passkeys appeared first on Security Boulevard.

BlackBerry’s Generative AI powered assistant enhances CISO operations

BlackBerry announced its new Generative AI powered assistant for Security Operations Center (SOC) teams. The enterprise-grade solution acts as a SOC Analyst providing Generative AI based cyberthreat analysis and support to enhance CISO ...

Looney Tunables? CVE-2023-4911? You might be using a vulnerable Linux distribution.

... Read more » The post Looney Tunables? CVE-2023-4911? You might be using a vulnerable Linux distribution. appeared first on Deepfactor. The post Looney Tunables? CVE-2023-4911? You might be using a vulnerable Linux distribution. appeared ...

Microsoft announces AI bug bounty program

Microsoft is offering up to $15,000 to bug hunters that pinpoint vulnerabilities of Critical or Important severity in its AI-powered “Bing experience”. “The new Microsoft AI bounty program comes as a result of key investments ...

Microsoft Improving Windows Authentication, Disabling NTLM

Microsoft is adding new features to the Kerberos protocol, to eliminate the use of NTLM for Windows authentication. The post Microsoft Improving Windows Authentication, Disabling NTLM appeared first on SecurityWeek.

Equifax Fined $13.5 Million Over 2017 Data Breach

UK’s financial watchdog FCA imposes a £11 million (approximately $13.5 million) fine to Equifax over the 2017 data breach. The post Equifax Fined $13.5 Million Over 2017 Data Breach appeared first on SecurityWeek.

How Dynamics 365 is Reshaping the Retail Landscape?

The retail sector faces many difficulties, including managing the complex supply chain and keeping up with the constantly changing demands of tech-savvy customers. Now, let’s talk about Dynamics 365, a Microsoft suite of intelligent business ...

Milesight Industrial Router Vulnerability Possibly Exploited in Attacks

A vulnerability affecting Milesight industrial routers, tracked as CVE-2023-4326, may have been exploited in attacks.  The post Milesight Industrial Router Vulnerability Possibly Exploited in Attacks appeared first on SecurityWeek.

Coin Flips Are Biased

Experimental result: Many people have flipped coins but few have stopped to ponder the statistical and physical intricacies of the process. In a preregistered study we collected 350,757 coin flips to test the counterintuitive prediction from a ...

Spyware Caught Masquerading as Israeli Rocket Alert Applications

A threat actor targets Israelis with spyware masquerading as an Android application for receiving rocket alerts. The post Spyware Caught Masquerading as Israeli Rocket Alert Applications appeared first on SecurityWeek.

EPA Withdraws Water Sector Cybersecurity Rules Due to Lawsuits

Environmental Protection Agency (EPA) withdraws recent water sector cybersecurity rules due to lawsuits by states and water associations. The post EPA Withdraws Water Sector Cybersecurity Rules Due to Lawsuits appeared first on SecurityWeek.

Security Audit | What Are the Common Characteristics of Recent Web3 Attacks, and How Can Projects…

Recently, there have been numerous security attack incidents, and these incidents have had a significant impact on project teams. One of…Continue reading on Medium »

DIY attack surface management: Simple, cost-effective and actionable perimeter insights

Modern-day attack surface management (ASM) can be an intimidating task for most organizations, with assets constantly changing due to new deployments, assets being decommissioned, and ongoing migrations to cloud providers. Assets can be created ...

GUEST ESSAY: A primer on best practices for automating supply chain cybersecurity

Supply chain security grows more crucial daily as cybercriminals attempt to disrupt distribution and transportation. In response, industry professionals must automate their cybersecurity tools to stay ahead. Why so? The 2020 SolarWinds ...

Safeguarding Your Business From Social Media Risks

Social media is the avenue to foster connections, nurture relationships, and amplify your brand’s voice across a global digital stage. Yet, like any powerful digital tool, it carries its risks. Don’t mistake this blog for a call to retreat ...

CISOs and board members are finding a common language

86% of CISOs believe generative AI will alleviate skills gaps and talent shortages on the security team, filling labor-intensive and time-consuming security functions and freeing up security professionals to be more strategic, according to ...