Application Security News and Articles


Like Any Other Software, AI Needs Security Built In, CISA Says

The nation’s top cybersecurity agency is reminding developers and organizations alike that AI innovations are not immune to the larger IT security initiatives the government is putting in place. AI and machine learning might be fueling much of ...

Visualizing Trust Assurance

Customers come to us for many reasons: to spend less time preparing for audits and answering security questionnaires, to prove their impact to their boss and board, to log into fewer systems, to save money, to strengthen their security posture, ...

What is Cyber Asset and Attack Surface Management?

Gartner analysts have been busy recently publishing several Hype Cycles. If you’re not familiar with the Gartner Hype Cycle, it is a graphic representation of the maturity lifecycle of new technologies, and there are several key reports to help ...

Mastering API Exploitation: Crafting Reverse Shells via cURL

Learn how to leverage a command injection vulnerability found in an API to gain a reverse shell to a server with nothing more than cURL. The post Mastering API Exploitation: Crafting Reverse Shells via cURL appeared first on Dana Epp's Blog. The ...

BSidesTLV 2023 – Yuval Adam – Decoding The Black Magic Of Radio Waves

Many thanks to BSidesTLV for publishing their presenter’s erudite BSidesTLV 2023 security content on the organizations’ YouTube channel. Permalink The post BSidesTLV 2023 – Yuval Adam – Decoding The Black Magic Of Radio Waves ...

Cybersecurity Heats Up in the Summer

The post Cybersecurity Heats Up in the Summer appeared first on Digital Defense. The post Cybersecurity Heats Up in the Summer appeared first on Security Boulevard.

TP-Link Smart Bulb Vulnerabilities Expose Households to Hacker Attacks

Vulnerabilities in the TP-Link Tapo L530E smart bulb and accompanying mobile application can be exploited to obtain the local Wi-Fi password. The post TP-Link Smart Bulb Vulnerabilities Expose Households to Hacker Attacks appeared first on ...

Ekran System to Participate in StrategyDays IT Security 2023

Ekran System is excited to announce its participation in the upcoming StrategyDays IT Security 2023 event which will take place September 18–19, 2023 in Bergisch, Germany. Visit the conference to gain actionable security recommendations and ...

Enhanced VMware Cloud helps customers modernize, optimize, and protect their businesses

VMware has enhanced VMware Cloud, empowering customers with new editions and capabilities that will help them modernize, optimize, and better protect their organizations. With VMware Cloud, customers innovate faster, operate more efficiently, ...

Kyndryl becomes a VMware Cross-Cloud managed services provider

Kyndryl has become a VMware Cross-Cloud managed services provider. Kyndryl has achieved the VMware Managed Services Specialization and has completed a Validated Service Offering (VSO) for VMware Cloud on AWS. Through this expanded collaboration, ...

Tesla Says Massive Data Breach was an Inside Job

The huge data breach that affected more than 75,000 Tesla employees was an insider job perpetrated by two ex-employees who leaked the information to a German business newspaper, according to the company. In a notice to the Maine attorney ...

Hacker Conversations: Cris Thomas (AKA Space Rogue) From Lopht Heavy Industries

Cris Thomas, also known as Space Rogue, was a founding member of the Lopht Heavy Industries hacker collective. The post Hacker Conversations: Cris Thomas (AKA Space Rogue) From Lopht Heavy Industries appeared first on SecurityWeek.

Top Takeaways from the 2023 Gartner® Hype Cycle™ for Security Operations 

It’s official—the Gartner® 2023 Hype Cycle™ for Security Operations is here. As always, this year’s research reflects the changing dynamics of the threat landscape. Let’s delve into the technologies and practices revolutionizing ...

US Military Targeted in Recent HiatusRAT Attack

The threat actor behind HiatusRAT was seen performing reconnaissance against a US military procurement system in June 2023. The post US Military Targeted in Recent HiatusRAT Attack appeared first on SecurityWeek.

Five Pitfalls to Avoid on the Road to Passwordless

The move to passwordless authentication is gaining momentum. One study shows that 92% of businesses believe that passwordless is the wave of the future and for good reason. Passwordless speeds access to resources, delivers a better user ...

MITRE appoints Deborah Youmans as CIO

MITRE has named Deborah Youmans as its new chief information officer (CIO). Youmans will oversee more than 400 IT professionals in MITRE’s Enterprise Computing and Information Systems division in areas including innovation and experimentation, ...

Ransomware Group Starts Leaking Data From Japanese Watchmaking Giant Seiko

The BlackCat/ALPHV ransomware group has started publishing data allegedly stolen from Japanese watchmaking giant Seiko. The post Ransomware Group Starts Leaking Data From Japanese Watchmaking Giant Seiko appeared first on SecurityWeek.

Press Release: The Cyber Hut Release Report on ITDR

MANCHESTER, UNITED KINGDOM, August 22, 2023 — The Cyber Hut, a leading boutique industry analyst and advisory firm focused on the global identity and access management market, announced today it has released a new research report. “Identity ...

Akira Ransomware, 8Base Ransomware, and more: Hacker’s Playbook Threat Coverage Round-up: August 22, 2023

New and updated coverage for ransomware and malware variants, including Akira ransomware, 8Base ransomware, and others. The post Akira Ransomware, 8Base Ransomware, and more: Hacker’s Playbook Threat Coverage Round-up: August 22, 2023 appeared ...

Australian Energy Software Firm Energy One Hit by Cyberattack

Energy One, an Australian company that provides software products and services to the energy sector, has been hit by a cyberattack. The post Australian Energy Software Firm Energy One Hit by Cyberattack appeared first on SecurityWeek.