Application Security News and Articles


Facebook Messenger accounts targeted in phishing campaign; 240K Social Security numbers exposed in healthcare breach

Phishing campaigns come in all different shapes and sizes. While traditionally phishing attacks often appear in front of us in the shape of an email, cybercriminals have ventured into sending phishing text messages and may even reach out on ...

AI Essential to Secure Dev, Successful DevSecOps—Yet Risks Abound

When finding security vulnerabilities within software built by in-house developers, there’s good reason to believe that development teams, thanks in part to the help of AI tools, are actually “shifting left” when developing ...

Deduce raises $9 million to tackle AI-generated identity fraud

Deduce has raised $9 million in funding led by Freestyle Capital, with additional investment by Foundry and True Ventures. The funding will launch Deduce’s GenAI Identity fraud solution out of stealth and help the company scale to prevent ...

LockBit Affiliate Deploys New 3AM Ransomware in Recent Attack

A LockBit affiliate has deployed the new 3AM ransomware family on a victim’s network, after LockBit’s execution was blocked. The post LockBit Affiliate Deploys New 3AM Ransomware in Recent Attack appeared first on SecurityWeek.

Securing Cloud Applications: Beyond the Perimeter

Introduction: As organizations are rapidly migrating to the cloud, the security landscape has undergone a significant shift. Traditional perimeter defenses are no longer sufficient to protect against sophisticated threats targeting cloud ...

How to Improve Student Mental Health: 7 Strategies for K-12

The stress of being a young person has never been easy. From classwork and relationships to peer pressure and bullying, the awkward years between elementary and high school have always taken a toll on student mental health. Indeed, America’s ...

Ivanti collaborates with Catchpoint to detect and troubleshoot remote connectivity issues

Ivanti announced its strategic partnership with Catchpoint. The partnership expands the Digital Experience Score with application and network visibility to continuously detect and troubleshoot remote connectivity issues before they impact the ...

North Korean Hackers Steal $53 Million in Cryptocurrency From CoinEx

North Korean hackers stole $53 million in cryptocurrency from crypto exchange CoinEx after the hot wallet private key was leaked. The post North Korean Hackers Steal $53 Million in Cryptocurrency From CoinEx appeared first on SecurityWeek.

Report Surfaces Root Causes of Cloud Security Issues

Palo Alto Networks found that half of the critical exposures discovered in cloud computing environments can be traced back to recently added or updated cloud services. The post Report Surfaces Root Causes of Cloud Security Issues appeared first ...

Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack

A known ransomware gang has taken credit for the highly disruptive cyberattack on MGM Resorts, and the company has yet to restore impacted systems. The post Ransomware Gang Takes Credit for Disruptive MGM Resorts Cyberattack appeared first on ...

Lacework expands partnership with Snowflake to drive secure cloud growth

Lacework and Snowflake announced an expanded partnership that advances the future of cloud infrastructure and further automates cloud security at scale. The extended partnership empowers security teams with direct access to their Lacework cloud ...

Real-time Security Alerts via Microsoft Teams

Enhance Kubernetes security through seamless ARMO Platform and Microsoft Teams integration. Click here to learn how! The post Real-time Security Alerts via Microsoft Teams appeared first on ARMO. The post Real-time Security Alerts via Microsoft ...

Attackers use fallback ransomware if LockBit gets blocked

Your security solutions might stave off a LockBit infection, but you might still end up with encrypted files: according to Symantec’s threat researchers, some affiliates are using the 3AM ransomware as a fallback option in case LockBit gets ...

SecurityScorecard and Measured Analytics and Insurance strengthen proactive cybersecurity strategies

SecurityScorecard announced an alliance with Measured Analytics and Insurance, the AI-powered cyber insurance provider. The initiative delivers a cyber insurance premium incentive (e.g., discounts) for Security Ratings. “Together with ...

CISO Global 2023-09-14 06:00:00

Author: Samuel Lewis, Senior Security Consultant, CISO Global Over the past several years, an increasingly fluid work environment has followed trends of modern globalization in the workplace. Leveraging cloud solutions, many companies have let go ...

Access control in cloud-native applications in multi-location environments (NIST SP 800-207)

NIST released Special Publication (SP) 800-207A – “A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Location Environments.” Enterprise application environments consist of geographically ...

5 Strategies for Reliable Protection Against BEC Scams

The recent Cloudflare 2023 Phishing Threats Report unravels many interesting statistics about the global landscape of business email compromise (BEC) attacks. BEC is now one of the top cybersecurity threats worldwide. And per the report, 71% of ...

Librem 11 tablet sets new standard for privacy and security with Linux-based PureOS

Purism introduced the new Librem 11 tablet running secure PureBoot and Linux kernel-based PureOS. Librem 11 is made for individuals, organizations, government agencies, law enforcement agencies, and businesses that need security and privacy with ...

Great security training is a real challenge

All employees need security training, yet it’s generally a resented afterthought. A variety of studies over years show that human error is generally felt to be the largest vulnerability in organizations. For technology companies like SaaS ...

The critical role of authorization in safeguarding financial institutions

According to a recent Cost of Data Breach report, the financial industry has the second highest average cost for a data breach, making the value well worth financial institutions investing more into authorization. In this Help Net Security video, ...