Application Security News and Articles


Venafi Leverages Generative AI to Manage Machine Identities

Venafi launched a proprietary generative AI model to help with the mammoth, complex, and expanding problem of managing machine identities. The post Venafi Leverages Generative AI to Manage Machine Identities appeared first on SecurityWeek.

Breach and Attack Simulation Helps Pipeline Operators Comply with New TSA Requirements

Breach and attack simulation helps pipeline operators reduce time and effort needed to comply with TSA’s requirements for enhancing cyber resilience. The post Breach and Attack Simulation Helps Pipeline Operators Comply with New TSA ...

‘Cybersecurity Incident’ Hits ICC

The International Criminal Court was hit by what it called "anomalous activity" regarding its IT systems and that it was currently responding to this "cybersecurity incident." The post ‘Cybersecurity Incident’ Hits ICC appeared first ...

npm packages caught exfiltrating Kubernetes config, SSH keys

The Sonatype Security Research team is currently tracking an ongoing campaign on the npm registry that uses npm packages to retrieve and exfiltrate your Kubernetes configuration and SSH keys to an external server. The post npm packages caught ...

Open Systems OT Firewall monitors traffic and detects threats

Open Systems introduced OT firewall service to secure critical infrastructures. The Open Systems OT Firewall provides organizations with a dedicated appliance at the center of operational technology (OT) networks for better visibility and control ...

Exploring SEC’s Cybersecurity Rules – Material Cybersecurity Incident (Part 3)

In today's digitally driven world, where cyber threats are becoming increasingly sophisticated and prevalent, organizations must prioritize robust cybersecurity management and transparent incident disclosure practices. The new SEC Cybersecurity ...

How Security Leaders Think about Data Security Governance

At Cyral, we pride ourselves on working closely with security leaders to see the world as they see it. We conducted multiple interviews and surveys … The post How Security Leaders Think about Data Security Governance appeared first on ...

Clorox Blames Damaging Cyberattack for Product Shortage

Clorox says the recent cyberattack has been contained, but production is still not fully restored and there is a short supply of products.  The post Clorox Blames Damaging Cyberattack for Product Shortage appeared first on SecurityWeek.

Google: Chromebooks Will Get 10 Years of Software, Security Updates

Google next year will begin providing 10 years of automatic security and other software updates for Chromebooks in a move that addresses cyber concerns in the education sector and larger criticism that the popular low-priced systems needed to be ...

OT Attack Path Analysis: A Comprehensive Guide

The convergence of Information technology (IT) and Operational technology (OT) networks, resulting in the exposure of OT networks to threats, paved the way for OT cybersecurity. OT is the use of hardware and software in critical infrastructure ...

Fairwinds Insights: Kyverno Integration, Consolidated Recommendations, Release Notes & Office Hours

This month we have lots to update on, including an integration with Kyverno, how we are reducing cognitive load by consolidating resource recommendations, our release notes, and office hours tomorrow, Wednesday 9/19 at 2 PM ET / 11 AM PT. The ...

Elevate Your Cybersecurity with Imperva Cloud WAF: More Than Just a Checkbox

In the world of digital modernization, having a web application firewall (WAF) isn’t an option – it’s a necessity. But in the endless sea of security solutions, how do you choose the right one? How do you ensure that you’re not merely ...

LogRhythm and Novacoast join forces to identify and counteract malicious actors

LogRhythm announced its partnership with Novacoast, a cybersecurity, identity and access company specializing in managed security, engineering, development, and advisory services. This partnership marks a significant milestone as Novacoast ...

Alcion Raises $21 Million for Backup-as-a-Service Platform

Data management startup Alcion has raised $21 million in a Series A funding round led by Veeam to expand its market presence. The post Alcion Raises $21 Million for Backup-as-a-Service Platform appeared first on SecurityWeek.

Pakistani APT Uses YouTube-Mimicking RAT to Spy on Android Devices

New versions of Pakistan-linked APT Transparent Tribe’s CapraRAT Android trojan mimic the appearance of YouTube. The post Pakistani APT Uses YouTube-Mimicking RAT to Spy on Android Devices appeared first on SecurityWeek.

OneTrust helps organizations manage the complexity of their trust programs

OneTrust unveiled innovations to help organizations manage the complexity of their trust programs, better understand their data to activate and use it, be more resilient against emerging threats, and unlock productivity when navigating ...

Pillars of Cloud Security

Applying on-premises security practices for cloud environments can create more risk. There are differences that must be considered. The post Pillars of Cloud Security appeared first on Security Boulevard.

Thousands of Juniper Appliances Vulnerable to New Exploit 

VulnCheck details a new fileless exploit targeting a recent Junos OS vulnerability that thousands of devices have not been patched against. The post Thousands of Juniper Appliances Vulnerable to New Exploit  appeared first on SecurityWeek.

Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products

Trend Micro has patched CVE-2023-41179, an Apex One zero-day code execution vulnerability that has been exploited in attacks.  The post Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products appeared first on ...

NIST CSF 2.0: What it means for modern software supply chain risk management

The latest draft of the cybersecurity framework proposed by the National Institute of Standards and Technology is receiving kudos from information security professionals. The post NIST CSF 2.0: What it means for modern software supply chain risk ...