Application Security News and Articles


10 Million Likely Impacted by Data Breach at French Unemployment Agency

The personal information of roughly 10 million individuals might have been compromised in a data breach at French unemployment agency Pole Emploi. The post 10 Million Likely Impacted by Data Breach at French Unemployment Agency appeared first on ...

Developer Week CloudX 2023 – Better security and accessibility in the cloud

Discover DeveloperWeek CloudX: Uniting Global Cloud Experts! Explore insights from security, accessibility, and DevOps leaders from this year's event. The post Developer Week CloudX 2023 – Better security and accessibility in the cloud ...

Ultimate API Security Checklist for 2023

Follow this list to ensure the security of your APIs and protect your data, users and business from threats and vulnerabilities. The post Ultimate API Security Checklist for 2023 appeared first on Security Boulevard.

Signs of Malware Attack Targeting Rust Developers Found on Crates.io

The Crates.io Rust package registry was targeted in preparation of a malware attack aimed at developers, according to Phylum. The post Signs of Malware Attack Targeting Rust Developers Found on Crates.io appeared first on SecurityWeek.

Protect Active Directory Better

Keeping Active Directory out of Hackers’ Cross-Hairs Active Directory is a prime target for threat actors and companies must act now to eliminate it as a threat vector. Here’s why, and how. What is Active Directory?  Active Directory (AD) is ...

Adding Generative AI as an API Protection Tool

The security world is in the early stages of figuring out how to best use generative AI to enhance cybersecurity—while simultaneously defending against it as an emerging threat vector. Take API security, for example. In a recent Security ...

3 Malware Loaders Detected in 80% of Attacks: Security Firm

QakBot, SocGholish, and Raspberry Robin are the three most popular malware loaders, accounting for 80% of the observed incidents. The post 3 Malware Loaders Detected in 80% of Attacks: Security Firm appeared first on SecurityWeek.

Black Hat Fireside Chat: How to achieve API security — as AI-boosted attacks intensify

API security has arisen as a cornerstone of securing massively interconnected cloud applications. At Black Hat USA 2023, I had a great discussion about API security with Data Theorem COO Doug Dooley and Applovin CISO Jeremiah Kung. For a … ...

Kroll SIM-swap attack: FTX, BlockFi and Genesis clients’ info exposed

Financial and risk advisory firm Kroll has suffered a SIM-swapping attack that allowed a threat actor to access files containing personal information of clients of bankrupt cryptocurrency platforms FTX, BlockFi and Genesis. The Kroll SIM-swapping ...

Two Men Arrested Following Poland Railway Hacking

Polish police have arrested two men suspected of illegally hacking into the national railway's communications network, causing disruption to 20 trains. The post Two Men Arrested Following Poland Railway Hacking appeared first on SecurityWeek.

Back To School Reminder – Keep Your Mac Clean!

Key points from our research: Around early-mid August, we noticed an increase in MacOS malware detections, specifically AdLoad and UpdateAgent in IronDome, in the education sector. This timing correlates with students returning to school, ...

iVerify is now an independent company!

We’re proud to announce that iVerify is now an independent company following its four-year incubation at Trail of Bits. Originally developed in-house to ensure that our personal phones, which store data essential to our work and private lives, ...

Leaseweb Reports Cloud Disruptions Due to Cyberattack 

Dutch cloud company Leaseweb shut down some critical systems last week due to a cyberattack. The post Leaseweb Reports Cloud Disruptions Due to Cyberattack  appeared first on SecurityWeek.

PoC for no-auth RCE on Juniper firewalls released

Researchers have released additional details about the recently patched four vulnerabilities affecting Juniper Networks’ SRX firewalls and EX switches that could allow remote code execution (RCE), as well as a proof-of-concept (PoC) ...

Ohio History Organization Says Personal Information Stolen in Ransomware Attack

Personal information stolen in ransomware attack at Ohio History Connection posted online after organization refuses to pay ransom. The post Ohio History Organization Says Personal Information Stolen in Ransomware Attack appeared first on ...

StorageGuard vs Rapid7 InsightVM: A Comprehensive Comparison

In the world of cybersecurity, staying ahead of threats and vulnerabilities requires a multifaceted approach. Two prominent solutions in this field are StorageGuard and Rapid7 InsightVM. While both tools have distinct focuses, they also ...

3 Cryptocurrency Firms Suffer Data Breach After Kroll SIM Swapping Attack

Three bankrupt cryptocurrency companies — FTX, BlockFi and Genesis — suffered data breaches following a SIM swapping attack at Kroll.  The post 3 Cryptocurrency Firms Suffer Data Breach After Kroll SIM Swapping Attack appeared first on ...

Akamai vs. Imperva WAF

Imperva WAF vs. Akamai WAF compared: Examine advantages, drawbacks, and unique features of the leading WAF solutions. Learn why AppTrana stands out. The post Akamai vs. Imperva WAF appeared first on Indusface. The post Akamai vs. Imperva WAF ...

Maximizing Success: A Guide to Developing and Monitoring Your Risk Management Plan

Organizations around the world are grappling with a fresh array of challenges and risks. From record-breaking inflation and economic slumps to the relentless proliferation of cyberattacks and geopolitical instability, the global landscape has ...

Uncovering a privacy-preserving approach to machine learning

In the era of data-driven decision making, businesses are harnessing the power of machine learning (ML) to unlock valuable insights, gain operational efficiencies, and solidify competitive advantage. Although recent developments in generative ...