Application Security News and Articles


Why DevOps Engineers are the Superheroes of the Tech World

Have you ever wondered how your favorite superhero manages to swoop in at the right moment, saving the day with a flick of their cape? In the ever-transforming realm of technology, a different kind of superhero is quietly donning their digital ...

Google Workspace Introduces New AI-Powered Security Controls

Google has announced new AI-powered zero trust, digital sovereignty, and threat defense controls for Workspace customers. The post Google Workspace Introduces New AI-Powered Security Controls appeared first on SecurityWeek.

Nearly 1,000 Organizations, 60 Million Individuals Impacted by MOVEit Hack

Nearly 1,000 organizations and 60 million individuals are impacted by the MOVEit hack, and the Cl0p ransomware gang is leaking stolen data. The post Nearly 1,000 Organizations, 60 Million Individuals Impacted by MOVEit Hack appeared first on ...

Cybersecurity insurance is missing the risk

Cybersecurity insurance is a rapidly growing market, swelling from approximately $13B in 2022 to an estimated $84B in 2030 (26% CAGR), but insurers are struggling with quantifying the potential risks of offering this type of insurance. The ...

Google Workspace: New account security, DLP capabilities announced

New capabilities in Google Workspace will help enterprises improve account and data security, by making unauthorized takeover of admin and user accounts and exfiltration of sensitive data more difficult. Some of these options are already ...

New infosec products of the week: August 25, 2023

Here’s a look at the most interesting products from the past week, featuring releases from Security Onion, OffSec, ImmuniWeb, LOKKER, Kingston Digital and Bitwarden. Security Onion 2.4: Free, open platform for defenders gets huge update ...

IEEE 802.11az provides security enhancements, solves longstanding problems

In this Help Net Security interview, Jonathan Segev, IEEE 802.11 Task Group (TG) Chair of next-generation positioning (TGaz) at IEEE, discusses IEEE 802.11az. The new standard will enable accuracy to less than 0.1 meters, which is a significant ...

Ransomware dwell time hits new low

Median attacker dwell time—the time from when an attack starts to when it’s detected—shrunk from 10 to eight days for all attacks, and to five days for ransomware attacks during the first half of 2023, according to Sophos. In 2022, the ...

Unrealistic expectations exacerbate the cybersecurity talent shortage

Consumers believe today’s cybersecurity talent shortage is in large part due to limited exposure to the profession and a lack of cybersecurity education and training at a younger age within school systems, according to ThreatX. 90% of consumers ...

Too good to be true? That online auction price could be triangulation fraud

Do you crave the hunt for an online deal? When you decide that you want to buy a thing, is part of the satisfaction of acquiring it how good of a deal you can find?    The post Too good to be true? That online auction price could be ...

Hacker in Residence, on Black Hat USA 2023

Attending many of the HackerSummerCamp activities involves attending a bunch of small meetups and social gatherings. Much of my peer group have become leadership within the organizations where they work and often, we discuss hard problems to ...

Chinese-backed APT ‘Flax Typhoon’ Hacks Taiwan with Minimal Malware Footprint

Microsoft warns that Chinese spies are hacking into Taiwanese organizations with minimal use of malware and by abusing legitimate software. The post Chinese-backed APT ‘Flax Typhoon’ Hacks Taiwan with Minimal Malware Footprint ...

Do we really need another cybersecurity tool?

It's time to ask tough questions and carefully scrutinize new cybersecurity tools before pulling the trigger on purchases. The post Do we really need another cybersecurity tool? appeared first on SafeBreach. The post Do we really need another ...

BSidesTLV 2023 – Keren Elazari BSidesTLV 2023: Closing Words

Many thanks to BSidesTLV for publishing their presenter’s erudite BSidesTLV 2023 security content on the organizations’ YouTube channel. Permalink The post BSidesTLV 2023 – Keren Elazari BSidesTLV 2023: Closing Words appeared first on ...

Deepfactor 3.3 Includes Enhanced Prioritization of SCA Findings and New Free-Trial Offer

... Read more » The post Deepfactor 3.3 Includes Enhanced Prioritization of SCA Findings and New Free-Trial Offer appeared first on Deepfactor. The post Deepfactor 3.3 Includes Enhanced Prioritization of SCA Findings and New Free-Trial Offer ...

Ransomware Surges in Nuspire’s Q2 2023 Threat Report

Nuspire’s latest threat report, which analyzes threat data from Q2 2023, reveals a jump in ransomware activity. In fact, the report identified a whopping 65% increase in activity from CL0P, an emerging player among the top ransomware ...

The Travel Bug: NetSec Edition

As a network admin, Mal Fitzgerald used tools for network monitoring, but all had the glaring weakness of blind spots. His new blog discusses how Netography lets network security engineers monitor their entire network from the same portal and ...

Spreadsheet Risk Management: Four Things To Do Now

Generative AI and other low-code/no-code solutions may get most of the media coverage. However, in many businesses, the spreadsheet is still a dominant data manipulation and analysis tool. This makes spreadsheet risk management a critical success ...

University of Minnesota Confirms Data Breach, Says Ransomware Not Involved

University of Minnesota confirms data was stolen from its systems, says no malware infection or file encryption has been identified. The post University of Minnesota Confirms Data Breach, Says Ransomware Not Involved appeared first on SecurityWeek.