Application Security News and Articles


Atlas VPN zero-day allows sites to discover users’ IP address

Atlas VPN has confirmed the existence of a zero-day vulnerability that may allow website owners to discover Linux users’ real IP address. Details about this zero-day vulnerability as well as exploit code have been publicly released on ...

Randall Munroe’s XKCD ‘*Fossil’

via the comic artistry and dry wit of Randall Munroe, maker of XKCD! Permalink The post Randall Munroe’s XKCD ‘*Fossil’ appeared first on Security Boulevard.

Shadow Wizard Registry Gang: Structured Registry Querying

Why Do We Need New Tooling for Registry Collection? The Windows registry, an intricate database storing settings for both the operating system and the applications that run on it, is a treasure trove of valuable information. It is known. For this ...

Flat Card Evolution Continues to Bring Enhanced Issuance, Marketing, and Custom Personalization to Banks and Consumers

Embossed payment cards have been the industry standard since their inception in the 1950s, when... The post Flat Card Evolution Continues to Bring Enhanced Issuance, Marketing, and Custom Personalization to Banks and Consumers appeared first on ...

API Security Testing using AI in Postman

Learn how to use the generative AI models built into Postman to quickly build tests to check for vulnerabilities in the APIs you are testing. The post API Security Testing using AI in Postman appeared first on Dana Epp's Blog. The post API ...

What is Trap Phishing? 9 Ways Your Business Can Be Impacted

Phishing is the most common cybercrime, which lures victims towards malicious software or websites via fraudulent email or social media messages. Phishing attacks are often preferred by hackers because of how individuals still fall for them, and ...

Sourcegraph’s Shocking Screwup: Private Secrets in Public Repo

Credentials create crisis: AI source code navigation LLM leaks PII after DevOps SNAFU. The post Sourcegraph’s Shocking Screwup: Private Secrets in Public Repo appeared first on Security Boulevard.

Cybersecurity > Compliance: Safeguarding critical infrastructure in the digital age

In this blog, we embark on a journey through the intricate realm of cybersecurity within critical infrastructure. As we navigate this multifaceted landscape, we’ll explore the unique challenges it presents, and the strategies required to ...

Pluto Finds Deprecated Kubernetes API Versions — 3 Questions from Users

Pluto is an open source utility that Fairwinds built to help users find deprecated Kubernetes API versions in their code repositories and Helm releases. As many Kubernetes users know, Kubernetes APIs are periodically reorganized or upgraded, and ...

Kingston Digital introduces XS1000 External SSD

Kingston Digital announced the XS1000 External SSD, a small and sleek file backup solution. XS1000 joins XS2000 as a new product offering in Kingston’s external SSD product portfolio. Both drives are extremely compact and under 29 grams to ...

MITRE and CISA Release Open Source Tool for OT Attack Emulation

MITRE and CISA introduce Caldera for OT, a new extension to help security teams emulate attacks targeting operational technology systems. The post MITRE and CISA Release Open Source Tool for OT Attack Emulation appeared first on SecurityWeek.

LockBit leaks sensitive data from maximum security fence manufacturer

The LockBit ransomware group has breached Zaun, a UK-based manufacturer of fencing systems for military sites and critical utilities, by compromising a legacy computer running Windows 7 and using it as an initial point of access to the wider ...

Move over Traditional AppSec: Here Comes Application Security Posture Management

A new Rezilion guide examines the growing trend toward the use of Application Security Posture Management (APSM), which aims to make applications secure and resilient, in turn, significantly reducing business risk. The paper explores the business ...

Cyber Leaders of the World: Chris Lockery, Virtual CISO at Help at Home

Please tell us a bit about yourself, your background, and your journey of becoming a CISO at Help at Home My name is Chris Lockery, I am from the Hartford, CT area and I have been in Cybersecurity for 20 years. I have my undergrad in MIS from the ...

Hornetsecurity releases 365 Total Protection Plan 4 for Microsoft 365 to protect email communications

Hornetsecurity has launched its Plan 4 “Compliance & Awareness” solution of 365 Total Protection Suite, offering a higher level of defence and compliance with new AI tools, security awareness service, and permission management for ...

9 Vulnerabilities Patched in SEL Power System Management Products 

Nine vulnerabilities patched in SEL electric power management products, adding to the 19 other flaws fixed earlier this year. The post 9 Vulnerabilities Patched in SEL Power System Management Products  appeared first on SecurityWeek.

The Future of Work is Remote: How to Prepare for the Security Challenges

Remote work is the future, but potential threats can emerge from the intersection of remote and hybrid working and technology advancements. The post The Future of Work is Remote: How to Prepare for the Security Challenges appeared first on ...

The Microsoft Dynamics 365 Business Central User’s Guide

An efficient cloud-based enterprise resource planning (ERP) tool, Microsoft Dynamics 365 Business Central helps businesses manage their finances, operations, sales, and customer service. Whether you manage a small startup or a large corporation, ...

7 Million Users Possibly Impacted by Freecycle Data Breach

Freecycle.org is prompting millions of users to reset their passwords after their credentials were compromised in a data breach. The post 7 Million Users Possibly Impacted by Freecycle Data Breach appeared first on SecurityWeek.

LiveWire allows users to export their data and use it with the AIs

LiveAction announces that users can now leverage LiveWire in concert with Artificial Intelligence (AI) to better refine network operations. LiveWire will now allow users to export their network packet data for use in AIs to find patterns that ...