Application Security News and Articles


Cybersecurity Incident Response Plan: How to Mitigate Risks and Protect Your Business

A cybersecurity incident response plan is a set of guidelines, best practices, and procedures for responding to cyber incidents. The post Cybersecurity Incident Response Plan: How to Mitigate Risks and Protect Your Business appeared first on ...

Where Is Anton Nikolaevich Korotchenko (Антон Николаевич Коротченко) Also Known as Koobface Botnet Master KrotReal?

Who's aware of his new VK.com account? Here's his user ID: mb9911 which I obtained using public sources. Happy research. Sample photos: Here's a full list of his VK.com friends: Mikhail ...

US Gov Warns of Foreign Intelligence Cyberattacks Against US Space Industry

The FBI, NCSC, and AFOSI warn US space industry organizations of foreign intelligence targeting and exploitation, including cyberattacks. The post US Gov Warns of Foreign Intelligence Cyberattacks Against US Space Industry appeared first on ...

Why Organizations Struggle to Secure APIs

Until there is a deeper understanding about why API security is such a struggle, they will be vulnerable to attacks. The post Why Organizations Struggle to Secure APIs appeared first on Security Boulevard.

Webinar Tomorrow:  ZTNA Superpowers CISOs Should Know

Join Cloudflare and SecurityWeek for a webinar to discuss “VPN Replacement: Other ZTNA Superpowers CISOs Should Know” The post Webinar Tomorrow:  ZTNA Superpowers CISOs Should Know appeared first on SecurityWeek.

WinRAR vulnerable to remote code execution, patch now! (CVE-2023-40477)

RARLAB has fixed a high-severity RCE vulnerability (CVE-2023-40477) in the popular file archiver tool WinRAR. About CVE-2023-40477 A widely used Windows-only utility, WinRAR can create and extract file archives in various compression formats ...

The 10 Steps to a Successful Cybersecurity Risk Management Plan

For years, the discourse in IT has been centered around cybersecurity. Yet, with the volume of cyber attacks increasing, professionals have developed a more holistic approach to cybersecurity. This development has led to the creation of cyber ...

White House Announces AI Cybersecurity Challenge

At Black Hat last week, the White House announced an AI Cyber Challenge. Gizmodo reports: The new AI cyber challenge (which is being abbreviated “AIxCC”) will have a number of different phases. Interested would-be competitors can now submit ...

Risk modeling initiative aims to expose the ‘hiddenness of knowledge’ in the supply chain

As Google's collaborative project known as the Graph for Understanding Artifact Composition (GUAC) starts to gain steam, the firm is bolstering its investment in dependency mapping by supporting a new project on top of GUAC that is geared toward ...

Brazilian Hacker Claims Bolsonaro Asked Him to Hack Into the Voting System Ahead of 2022 Vote

A Brazilian hacker claims former president Bolsonaro asked him to hack into the voting system ahead of the 2022 election. The post Brazilian Hacker Claims Bolsonaro Asked Him to Hack Into the Voting System Ahead of 2022 Vote appeared first on ...

Advanced Audit Analytics for Digital Platforms

Advanced Audit Analytics for Digital PlatformsLas Vegas, Nevada, August 21, 2023, SafePaaS, the leading Policy-based Access Governance platform and a sponsor of the GRC 2023 Conference announces its advanced audit analytics capabilities for ...

Chrome will tell users when extensions they use are removed from Chrome Web Store

Google will be extending the Safety check feature within the Chrome browser to alert users when a previously installed extension is no longer available in the Chrome Web Store. A safety check for Chrome extensions The Safety check scan can be run ...

Exposing a Currently Active Personally Identifiable Cybercriminals XMPP/Jabber Account IDs Portfolio – Part Three

Folks, This is the third part of the blog posts series where I'm actively data mining publicly and private invite only cybercrime-friendly communities looking for personally identifiable email address accounts and XMPP/Jabber account IDs with the ...

Flaws in Juniper Switches and Firewalls Can Be Chained for Remote Code Execution

Juniper Networks has released Junos OS updates to address J-Web vulnerabilities that can be combined to achieve unauthenticated, remote code execution. The post Flaws in Juniper Switches and Firewalls Can Be Chained for Remote Code Execution ...

Tesla Discloses Data Breach Related to Whistleblower Leak

Tesla has disclosed a data breach impacting 75,000 people, but it’s a result of a whistleblower leak, not a malicious cyberattack. The post Tesla Discloses Data Breach Related to Whistleblower Leak appeared first on SecurityWeek.

TLS 1.2 Handshake vs TLS 1.3 Handshake

Secure communication protocols make the difference between people navigating the internet with confidence and being at the mercy of attackers. Businesses, governments, and other organizations that people trust with their data have a weighty ...

Risks of Hybrid Working: Safeguarding Cybersecurity in the New Era

The global pandemic has undeniably caused significant disruptions in people’s lives and businesses. While business leaders understandably have learned to prioritize crisis management, operational resilience, environmental initiatives, and ...

How EU lawmakers can make mandatory vulnerability disclosure responsible

There is a standard playbook and best practice for when an organization discovers or is notified about a software vulnerability: The organization works quickly to fix the problem and, once a fix is available, discloses that vulnerability for the ...

Network detection and response in the modern era

In this Help Net Security interview, David Gugelmann, CEO at Exeon, sheds light on the current cyber threats and their challenges for network security. He discusses the role of Network Detection and Response (NDR) solutions that leverage machine ...

Business Email Compromise Scams Revisited

In this best of episode from December 2021, we revisit Business Email Compromise (BEC) scams. What are they, how to identify them, and why BEC scams have resulted in well over $3 billion in losses since 2016, more than any other type of fraud in ...