Application Security News and Articles


Lawsuit Accuses University of Minnesota of Not Doing Enough to Prevent Data Breach

A lawsuit filed on behalf of a former student and former employee at the University of Minnesota accuses the university of not doing enough to protect personal information from a recent data breach. The post Lawsuit Accuses University of ...

Trojanized Signal, Telegram apps found on Google Play, Samsung Galaxy Store

ESET researchers have identified two active campaigns targeting Android users, where the threat actors behind the tools for Telegram and Signal are attributed to the China-aligned APT group GREF. Most likely active since July 2020 and since July ...

500k Impacted by Data Breach at Fashion Retailer Forever 21

Fashion retailer Forever 21 says that the personal information of more than 500,000 individuals was compromised in a data breach. The post 500k Impacted by Data Breach at Fashion Retailer Forever 21 appeared first on SecurityWeek.

Dangling DNS Used to Hijack Subdomains of Major Organizations 

Dangling DNS records were abused by researchers to hijack subdomains belonging to major organizations, warning that thousands of entities are impacted. The post Dangling DNS Used to Hijack Subdomains of Major Organizations  appeared first on ...

5 Ways to Protect Your Business Against Executive Impersonation Scams

There’s no doubt social media cyber risk attacks are on the rise. While more and more brands rely on social media to gain trust and recognition from their intended buyers, scammers are continuing to innovate new social media scams, including ...

SSL Deprecation: Understanding the Evolution of Security Protocols

Secure Sockets Layer (SSL) is a security protocol that enables encrypted digital communications—between a web browser like Google Chrome or Mozilla Firefox and a web server, for example. SSL certificates authenticate the identity of an online ...

The power of passive OS fingerprinting for accurate IoT device identification

The number of IoT devices in enterprise networks and across the internet is projected to reach 29 billion by the year 2030. This exponential growth has inadvertently increased the attack surface. Each interconnected device can potentially create ...

What does optimal software security analysis look like?

In this Help Net Security interview, Kevin Valk, co-CEO at Codean, discusses the consequences of relying solely on automated tools for software security. He explains how these tools can complement human knowledge to enhance software security ...

Hashcat Tips and Tricks for Hacking Competitions: A CMIYC Writeup Part 3

  I want to know1 and understand1 But I will not1 -- Hashes cracked from the KoreLogic CMIYC 2023 competition In the previous two posts on the CMIYC competition [Part 1, Part 2], I had focused on how to integrate data science tools into ...

ChatGPT on the chopping block as organizations reevaluate AI usage

ChatGPT has attracted hundreds of millions of users and was initially praised for its transformative potential. However, concerns for safety controls and unpredictability have landed it on IT leaders’ list of apps to ban in the workplace. In ...

The secret habits of top-performing CISOs

69% of top-performing CISOs dedicate recurring time on their calendars for personal professional development, according to Gartner. This is compared with just 36% of bottom-performing CISOs who do so. “As the CISO role continues to rapidly ...

HYPR and Yubico: The Power of Passwordless Choice

With cybersecurity threats constantly evolving and becoming more sophisticated, organizations are grappling with the challenge of safeguarding their sensitive data and systems. The rise of AI-strengthened phishing attacks and vulnerabilities ...

Unveiling the Benefits of Identity Verification for Online Retailers

In the dynamic realm of online retail, establishing trust while countering cyber threats is paramount. Identity verification emerges as a game-changer, bolstering security, trust, compliance, and even personalization. Dive into the advantages it ...

Threat-informed or Threat-owned? Classic Practices Will Probably Save You!

So, if you are too busy to read our amazing (duh!) new blog “Revisiting Traditional Security Advice for Modern Threats”, here are the key ideas from it. At some point, a “pre-owned” (compromised before you ever saw it) email security ...

Hyperview Integrates RF Code Technology to Automate IT Asset Tracking

Leading DCIM software provider leverages RF Code CenterScape software to accurately capture and report on critical assets’ location and environmental conditions Austin, TX—August 30, 2023—RF Code, a pioneer of automated, real-time physical ...

The Risks of Non-Compliance with SOX: Penalties and Hidden Threats

Organizations often face significant challenges just keeping pace with cybercriminals. These attackers constantly evolve their strategies and tactics, trying to circumvent a company’s security technology. Unfortunately, for publicly traded ...

In the Alleys of Black Hat and DEF CON 2023: The Quiet API Security Crisis

The neon lights of Black Hat and DEF CON, with their flashing demos and groundbreaking presentations, often dazzle attendees and cyber enthusiasts alike. From AI-driven hacking tools to quantum encryption, the subjects covered span a vast ...

BSides Cheltenham 2023 – Anthony Saich – Using Machine Learning To Detect Phishing Emails

Many thanks to BSides Cheltenham for publishing their presenter’s outstanding BSides Cheltenham 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Cheltenham 2023 – Anthony Saich – Using ...

Qakbot Cracked: FBI and Friends Hack the Hackers

Operation Duck Hunt shoots to kill big botnet. The post Qakbot Cracked: FBI and Friends Hack the Hackers appeared first on Security Boulevard.

LockBit Builder Leak Leads to Flood of Ransomware Variants

The leak 11 months ago of the builder for the LockBit 3.0 ransomware opened the door for any threat actor to create their own customized versions of the malware and they took advantage of the chance. According to researchers with Kaspersky, they ...