Application Security News and Articles


SpyHunter Web Security blocks dangerous sites and web-based threats

EnigmaSoft Limited has released SpyHunter Web Security – a browser extension that helps users block dangerous sites and web-based threats. SpyHunter Web Security offers enhanced protection against online security risks. SpyHunter Web Security ...

Utilizing Artificial Intelligence Effectively in Cybersecurity

Several AI approaches are used in cybersecurity, but it’s hard to make sense of the noise, especially when vendors say the same thing. In our newest eBook, we’ll explore what they are and the pros and cons of each one. The post Utilizing ...

N-able and SentinelOne help MSPs boost endpoint security services

N-able is deepening its ties with SentinelOne by announcing new and enhanced joint endpoint security solutions that will help MSPs capitalize on opportunities to grow their business through enterprise-grade security services delivery. Through ...

Ekran System to Speak and Exhibit at SIM Boston Technology Leadership Summit

Ekran System announces its participation in the SIM Boston Technology Leadership Summit, the premier single-day event for IT executives and solution providers. The summit takes place on October 25, 2023, at Gillette Stadium, 1 Patriot Pl, ...

SAP Releases 7 New Notes on October 2023 Patch Day

SAP has released seven new notes as part of its October 2023 Security Patch Day, all rated ‘medium severity’. The post SAP Releases 7 New Notes on October 2023 Patch Day appeared first on SecurityWeek.

Verato and CLEAR join forces to accelerate the adoption of digital identity in healthcare

Verato announced a partnership with CLEAR to accelerate the adoption of digital identity in healthcare. By joining forces, Verato’s proven, purpose-built-for-healthcare hMDM approach to enterprise identity data management and CLEAR’s ...

Heads Up: Patch for ‘Worst Curl Security Flaw’ Coming This Week

Developers who use the popular curl open-source data transfer tool will be able to patch two vulnerabilities in the software on October 11, one of which the lead developer called the “worst curl security flaw in a long time.” Daniel Stenberg, ...

SecurityWeek to Host 2023 ICS Cybersecurity Conference October 23-26 in Atlanta

SecurityWeek will host its 2023 Industrial Control Systems (ICS) Cybersecurity Conference from October 23 – 26, 2023 at the InterContinental Atlanta Buckhead. The post SecurityWeek to Host 2023 ICS Cybersecurity Conference October 23-26 in ...

‘HTTP/2 Rapid Reset’ Zero-Day Exploited to Launch Largest DDoS Attacks in History

A zero-day vulnerability named HTTP/2 Rapid Reset has been exploited to launch some of the largest DDoS attacks in history. The post ‘HTTP/2 Rapid Reset’ Zero-Day Exploited to Launch Largest DDoS Attacks in History appeared first on SecurityWeek.

Dangerous vulnerability can be exploited to carry out massive DDoS attacks (CVE-2023-44487)

Cloudflare, Google, and Amazon AWS revealed that a zero-day vulnerability in the HTTP/2 protocol has been used to mount massive, high-volume DDoS attacks, which they dubbed HTTP/2 Rapid Reset. Decoding HTTP/2 Rapid Reset (CVE-2023-44487) In late ...

Here’s Why You Can’t Wait to Buy a CIEM

Reading Time: 8 minutes You can’t wait to buy a Cloud Infrastructure Entitlements Management (CIEM) solution.  Yes, we mean you can’t wait as in time is of the essence and critical threats are imminent, but we’ll leave room for the ...

Why Every Startup Should Consider Adopting a DevOps Approach

Discover the transformative power of DevOps for startups with insights from the leading AWS DevOps consulting company. Learn how a DevOps approach can boost scalability, security, and competitiveness. The post Why Every Startup Should Consider ...

The Latest Trends in API Security: The 2023 OWASP API Security Top Ten

Discover the main findings in the OWASP 2023 API Security Top Ten and their importance for application security. The post The Latest Trends in API Security: The 2023 OWASP API Security Top Ten appeared first on Mend. The post The Latest Trends in ...

Why Are APIs so Easy for Threat Actors to Exploit?

Lax API security creates the perfect window of opportunity, often with a low barrier to entry. Cybercriminals are eager to exploit it. The post Why Are APIs so Easy for Threat Actors to Exploit? appeared first on Security Boulevard.

Pulumi ESC gives organizations a central way to define and scale cloud applications

Pulumi announced Pulumi ESC, a new solution to manage environments, secrets, and configurations for cloud infrastructure and applications. Pulumi ESC enables developers to define reusable environments that combine secrets from multiple sources, ...

One Solution to Rule Them All: Browser Security Redefined

Let’s admit it, the cybersecurity industry is in need of an overhaul. For far too many years, organizations have been lured into a relentless cycle of piling on more and more capabilities and coverage every time a new threat emerges. This idea ...

Twistlock Founders Score Whopping $51M Seed Funding for Gutsy

Serial entrepreneurs bank an unusually large seed round to apply process mining techniques to solve security governance problems. The post Twistlock Founders Score Whopping $51M Seed Funding for Gutsy appeared first on SecurityWeek.

New ‘Grayling’ APT Targeting Organizations in Taiwan, US

A previously unknown APT group is targeting organizations in biomedical, IT, and manufacturing sectors in Taiwan. The post New ‘Grayling’ APT Targeting Organizations in Taiwan, US appeared first on SecurityWeek.

One-Click GNOME Exploit Could Pose Serious Threat to Linux Systems

A one-click exploit targeting the Libcue component of the GNOME desktop environment could pose a serious threat to Linux systems. The post One-Click GNOME Exploit Could Pose Serious Threat to Linux Systems appeared first on SecurityWeek.

Fortanix adds data sovereignty to enhance DSM for global data security and privacy compliance

Fortanix has unveiled new capabilities for Fortanix Data Security Manager (DSM) to help public and private organizations address growing data sovereignty requirements globally. Available now, the existing and new features deliver several key ...