Application Security News and Articles


Unlocking the Secrets of Hardened Secure Endpoint in 2023

Introduction Endpoint security is a critical component of a comprehensive cybersecurity strategy, especially for small businesses. It focuses on safeguarding various endpoints in a network from potential cyber threats. Endpoints include devices ...

Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw

Rapid7 says attackers are targeting a critical pre-authentication flaw in Progress Software’s WS_FTP server just days after disclosure. The post Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw appeared first on ...

FedRAMP and Federal Cybersecurity Market Roundup September 2023

It’s been a few weeks now since Carahsoft’s FedRAMP Headliner Summit, but there is no shortage of moments to recall from it. For instance, Robert Costello commemorated his two-year anniversary as CIO at the Cybersecurity and Infrastructure ...

Threat Groups Accelerating the Use of Dual Ransomware Attacks

Ransomware groups are shrinking the time between attacks on the same victim, sometimes targeting the same company twice within 48 hours using different malware variants, according to the FBI. In a notice late last month, the agency noted that ...

Don’t Say ‘Skynet’ — NSA’s AI Security Center is New Hub for Agency Efforts

COME WITH ME IF YOU WANT TO LIVE: Nothing suspicious to see here—move along. The post Don’t Say ‘Skynet’ — NSA’s AI Security Center is New Hub for Agency Efforts appeared first on Security Boulevard.

GUEST ESSAY: Has shielding and blocking electromagnetic energy become the new normal?

Surrounded by the invisible hum of electromagnetic energy, we’ve harnessed its power to fuel our technological marvels for decades. Related: MSFT CEO calls for regulating facial recognition tech Tesla’s visionary insights from 1900 hinted at ...

ManageEngine launches Identity360 to address workforce IAM complexities

ManageEngine has launched Identity360, its cloud-native identity management platform that addresses identity and access management (IAM) complexities arising within enterprise workforces. ManageEngine also announced the addition of access ...

DEF CON 31 – STÖK’s ‘Weaponizing Plain Text ANSI Escape Sequences As A Forensic Nightmare’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Network Security Firm IronNet Ends Operations, Plans for Bankruptcy

IronNet, the once high-flying network security vendor founded in 2014 by a former U.S. intelligence agency official, is shutting down operations after almost two years of financial struggles. The company, whose money problems began to emerge last ...

European Telecommunications Standards Institute Discloses Data Breach

Hackers stole a database containing the list of the European Telecommunications Standards Institute’s online users. The post European Telecommunications Standards Institute Discloses Data Breach appeared first on SecurityWeek.

Eclypsium’s threat detection capabilities defend network infrastructure from cybercriminals

Eclypsium launches new threat detection capabilities for network appliances to its Eclypsium supply chain security platform. Over the past summer, ransomware groups including Akira, CACTUS, FIN8, and LockBit have been observed attacking network ...

Number of Internet-Exposed ICS Drops Below 100,000: Report

The number of internet-exposed ICS has dropped below 100,000, a significant decrease from the 140,000 in 2019. The post Number of Internet-Exposed ICS Drops Below 100,000: Report appeared first on SecurityWeek.

Proactive Security Practices for Digital Banking

The post Proactive Security Practices for Digital Banking appeared first on Digital Defense. The post Proactive Security Practices for Digital Banking appeared first on Security Boulevard.

Visa collaborates with Expel to protect clients from cyberthreats

Visa announced a strategic partnership with Expel, extending Visa’s Value-Added Services offering in the emerging Managed Detection and Response (MDR) segment to clients globally. Global cybercrime costs are expected to reach $10.5 trillion ...

How to Talk So Your CISO Will Listen

To communicate effectively with your CISO, you’ll need to speak their language. Here's how you can do that. The post How to Talk So Your CISO Will Listen appeared first on Security Boulevard.

Critical zero-days in Exim revealed, only 3 have been fixed

Six zero-days in Exim, the most widely used mail transfer agent (MTA), have been revealed by Trend Micro’s Zero Day Initiative (ZDI) last Wednesday. Due to what seems to be insufficient information and poor communication, fixes for only ...

Duality Technologies joins AWS Partner Network to provide secure data collaboration

Duality Technologies has joined the Amazon Web Services (AWS) Partner Network (APN) and launched its secure data collaboration platform in AWS Marketplace. Duality Technologies underwent the comprehensive AWS Foundational Technical Review (FTR) ...

Boards are Finally Taking Cybersecurity Seriously

It's time to ensure boards' interest in cybersecurity goes beyond just conversation and into real action. The post Boards are Finally Taking Cybersecurity Seriously appeared first on Security Boulevard.

Survey Sees More Cyberattacks Targeting APIs

Despite increased vigilance, most organizations suffered an API security incident in the last 12 months. The post Survey Sees More Cyberattacks Targeting APIs appeared first on Security Boulevard.

SymphonyAI accelerates financial crime investigations with generative AI technology

SymphonyAI announced the Sensa Investigation Hub, a generative AI-enabled investigation and case management platform that propels financial institutions into the future of financial crime management. The Sensa Investigation Hub uses predictive ...