Application Security News and Articles


Embracing ESG Risk Management: It’s Simpler Than You Imagine

Everywhere business executives look these days, the discussion is turning to “ESG” — environmental, social, and governance issues — and how a company can demonstrate that it has its own ESG house in order.  ESG risks might seem a bit ...

runZero unveils CAASM Platform for IT and OT visibility

runZero has unveiled the availability of of their new runZero Platform, which introduces a number of new features, most notably the addition of native passive discovery. This functionality positions runZero as the CAASM (cyber asset attack ...

Is Your Workforce Ready for Passwordless MFA?

Innovations in cybersecurity have typically taken hold on the business side before making their way to consumers as controls gained broad acceptance. However, with passwordless multi-factor authentication, or MFA, the script is flipped. Consumers ...

Timely security awareness news stories & anecdotes

The post Timely security awareness news stories & anecdotes appeared first on Click Armor. The post Timely security awareness news stories & anecdotes appeared first on Security Boulevard.

LiveAction updates LiveWire to provide visibility for NetOps and SecOps teams

LiveAction has released the latest LiveWire updates, enhancing network visibility, empowering SecOps and NetOps teams, and boosting packet analysis capabilities. This latest release delivers three major advancements: Do more: the new LiveWire ...

Mastering API Security: Learn the 3 Key Principles at Kong API Summit 2023

In an era where APIs (Application Programming Interfaces) are the lifeblood of digital interactions, the need for robust API security has never been more critical.  According to Gartner research, a staggering 90% of web-enabled applications are ...

Censys Internet Map helps organizations identify, understand and mitigate threats

Censys announced the Censys Internet Map. As the data foundation that powers the Censys Internet Intelligence Platform, the Censys Internet Map provides users with the most comprehensive, up-to-date collection of global internet infrastructure to ...

Long Live the Pwn Request: Hacking Microsoft GitHub Repositories and More

Software supply chain attacks have been increasing both in frequency and severity in recent months. In response to these attacks, the CISA has even released a cybersecurity information sheet (CSI) on how organizations can secure their CI/CD ...

How To Secure Your Lost & Forgotten Access Keys

Reading Time: 7 minutes What criminal wouldn’t take advantage of a pair of house keys left lying around a cafe table? Those keys give entryway to your home, any valuable possessions inside, and even the ability to live in the home as if they ...

Building Your Incident Response Team

When the inevitable breach happens, an incident response team is a key asset. Here’s how to build one. The post Building Your Incident Response Team appeared first on Security Boulevard.

Crypto Quantique introduces SaaS platform QuarkLink Ignite

Crypto Quantique has released QuarkLink Ignite, a Software-as-a-Service (SaaS) platform that enables developers and engineers to achieve secure connectivity management free-of-charge for up to 50 ESP32 devices. QuarkLink Ignite is a toolset that ...

UAE-Linked APT Targets Middle East Government With New ‘Deadglyph’ Backdoor

UAE-linked APT group Stealth Falcon has used the new Deadglyph backdoor in an attack targeting a governmental entity in the Middle East. The post UAE-Linked APT Targets Middle East Government With New ‘Deadglyph’ Backdoor appeared ...

Luxury Hotels Remain Major Target of Ongoing Social Engineering Attack

By Dylan Duncan 85% of phishing emails from current campaign have come in the last 60 days; Hospitality Industry Still Very at Risk of Advanced Malware Capable of Ransomware Delivery Tweet This Cofense Intelligence has been tracking a ...

Sony Investigating After Hackers Offer to Sell Stolen Data

Sony has launched an investigation after a ransomware group claimed to have compromised all systems and offered to sell stolen data. The post Sony Investigating After Hackers Offer to Sell Stolen Data appeared first on SecurityWeek.

Microsoft AI Researchers Exposed 38TB Private Info

The rush to embrace AI has increased the potential for security problems. Microsoft is just the latest example. The post Microsoft AI Researchers Exposed 38TB Private Info appeared first on Security Boulevard.

Immersive Labs Workforce Exercising allows cyber leaders to identify and fill skills gaps

Immersive Labs unveiled the expansion of its AI-ready platform, now with coverage across the entire organization through its new Workforce Exercising solution. With comprehensive cyber skills development for all roles, leaders can confidently ...

Cl0p’s MOVEit attack tally surpasses 2,000 victim organizations

The number of victim organizations hit by Cl0p via vulnerable MOVEit installations has surpassed 2,000, and the number of affected individuals is now over 60 million. The victim organizations are overwhelmingly based in the US. “The most ...

The CISO Carousel and its Effect on Enterprise Cybersecurity

CISO churn is a hidden cybersecurity threat. Major security initiatives or implementations can take longer than the residency of a single CISO, and constant churn can leave cracks or gaps in security. The post The CISO Carousel and its Effect on ...

Xenomorph Android Banking Trojan Targeting Users in US, Canada

The Xenomorph Android banking trojan can now mimic financial institutions in the US and Canada and is also targeting crypto wallets. The post Xenomorph Android Banking Trojan Targeting Users in US, Canada appeared first on SecurityWeek.

EPSS vs. CVSS: Exploit prediction could change the game on software risk management

Security teams are faced with more alerts than they can handle. SecurityScorecard and the Cyentia Institute estimate that organizations fix only 10% of the vulnerabilities in their software each month. That's not a good outcome for software ...