Application Security News and Articles


IDC launches Future of X Scorecards for optimizing tech’s impact on business

IDC has introduced its Future of X Scorecards, designed to address the need for improved benchmarking in the development and execution of digital business strategies. As enterprises continue to invest in digital technologies and services and ...

Email – The System Running Since 71’

Working remotely is here to stay and businesses should continue to make sure their basic forms of communication are properly configured and secured. The post Email – The System Running Since 71’ appeared first on SecurityWeek.

US Cyber Safety Board to Review Cloud Attacks

The US government's CSRB will conduct a review of cloud security to provide recommendations on improving identity management and authentication. The post US Cyber Safety Board to Review Cloud Attacks appeared first on SecurityWeek.

Almost all VPNs are vulnerable to traffic-leaking TunnelCrack attacks

Several vulnerabilities that affect most VPN products out there can be exploited by attackers to read user traffic, steal user information, or even attack user devices, researchers have discovered. “Our attacks are not computationally ...

11 Requirements for Mobile Network Security

Mobile networks are fantastic things. Not only do they make it possible for consumers to send 6 billion text messages and make 2.4 billion calls per The post 11 Requirements for Mobile Network Security appeared first on FirstPoint. The post 11 ...

Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying

Vulnerabilities in CyberPower and Dataprobe power management products could be exploited in data center attacks, including to cause damage and for spying. The post Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying ...

Building Resilience to Evolving Threats: The Critical Role of PKI in Industrial Cybersecurity

The industrial sector is rapidly evolving, and organizations are accelerating their digitalization efforts with automation, AI, and connected sensors and machines. The post Building Resilience to Evolving Threats: The Critical Role of PKI in ...

Action1 platform update bridges the gap between vulnerability discovery and remediation

Action1 Corporation has released a new version of its solution. The updated Action1 patch management platform brings together vulnerability discovery and remediation, helping enterprises fortify their defenses against threats such as ransomware ...

From Code to Cloud: Security for Developers [cheat sheet included]

In this cheat sheet, we will walk you through the different stages of the software development lifecycle and highlight key security considerations and tools that can help you mitigate risks and protect your code. The post From Code to Cloud: ...

How to Negotiate the Best Cyber Insurance Policy | Kovrr blog

Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post How to Negotiate the Best Cyber Insurance Policy | Kovrr blog appeared first on Security Boulevard.

US Shuts Down Bulletproof Hosting Service LolekHosted, Charges Its Polish Operator

US authorities have announced charges against a Polish national who allegedly operated the LolekHosted.net bulletproof hosting service. The post US Shuts Down Bulletproof Hosting Service LolekHosted, Charges Its Polish Operator appeared first on ...

Complexity of APIs Make Them Harder to Secure

APIs are not only increasingly under attack, but the complexity, consistency and overall number of those attacks are escalating. The post Complexity of APIs Make Them Harder to Secure appeared first on Security Boulevard.

ReversingLabs’ path to success: Staying true to customers and the product was key

Cybersecurity is a lucrative industry, with the market‘s revenue expected to reach $162 billion by the end of this year. But, as history has shown, plentiful capital does not always translate into market success. The post ReversingLabs’ path ...

8 Common Types of Account Abuse

Leading platforms like Canva, Atlassian, Figma, Notion, and Dropbox have completely transformed the modern workspace. They have brought productivity to new heights and made online collaboration effortless. However, the widespread shift towards ...

Macs are getting compromised to act as proxy exit nodes

AdLoad, well-known malware that has been targeting systems running macOS for over half a decade, has been observed delivering a new payload that – unbeknown to the owners – enlisted their systems into a residential proxy botnet. ...

Ford Says Wi-Fi Vulnerability Not a Safety Risk to Vehicles

Ford says a critical vulnerability in the TI Wi-Fi driver of the SYNC 3 infotainment system on certain vehicle models does not pose a safety risk. The post Ford Says Wi-Fi Vulnerability Not a Safety Risk to Vehicles appeared first on SecurityWeek.

Major vulnerabilities discovered in data center solutions

Researchers have discovered serious security vulnerabilities in two widely used data center solutions: CyberPower’s PowerPanel Enterprise Data Center Infrastructure Management (DCIM) platform and Dataprobe’s iBoot Power Distribution ...

Iagona ScrutisWeb Vulnerabilities Could Expose ATMs to Remote Hacking

Several vulnerabilities discovered in Iagona ScrutisWeb ATM fleet monitoring software could be exploited to remotely hack ATMs. The post Iagona ScrutisWeb Vulnerabilities Could Expose ATMs to Remote Hacking appeared first on SecurityWeek.

Can you pass the Rekt test?

One of the biggest challenges for blockchain developers is objectively assessing their security posture and measuring how it progresses. To address this issue, a working group of Web3 security experts, led by Trail of Bits CEO Dan Guido, met ...

APTs use of lesser-known TTPs are no less of a headache

APT (advanced persistent threat) attacks were once considered to be primarily a problem for large corporations, but the number of these (often state-sponsored) attacks against small- and medium-sized businesses has increased significantly. ...