Application Security News and Articles


How to Secure Online Email Transactions for Trading Platforms with Email Authentication

Uncover email authentication's what, why & how for trading platforms. Raise trust for smooth, secure transactions. The post How to Secure Online Email Transactions for Trading Platforms with Email Authentication appeared first on Security ...

CommScope SYSTIMAX Constellation allows enterprises to build and augment IP networks

CommScope launched SYSTIMAX Constellation edge-based platform for connecting and powering tomorrow’s hyperconnected enterprise. The system combines fault-managed power, hybrid power/data fiber and ceiling-based “Constellation Points” in a ...

Cybersecurity Insights with Contrast CISO David Lindner | 8/11

Insight #1  The Biden Administration's requirement for SBOMs has driven more and more organizations (76%) to have SBOM plans. This is a great step in the right direction toward transparency. The post Cybersecurity Insights with Contrast CISO ...

India Passes Data Protection Legislation in Parliament. Critics Fear Privacy Violation

Indian lawmakers approved a data protection legislation that “seeks to better regulate big tech firms and penalize companies for data breaches” as several groups expressed concern over citizens’ privacy rights. The post India Passes Data ...

MoustachedBouncer: Foreign Embassies in Belarus Likely Targeted via ISPs

MoustachedBouncer is a cyberespionage group that targets foreign diplomats in Belarus via ISP adversary-in-the-middle attacks. The post MoustachedBouncer: Foreign Embassies in Belarus Likely Targeted via ISPs appeared first on SecurityWeek.

Guide to Kratikal’s Compliance Services for Startups

Kratikal Introduces Compliance Services specially designed for Startups. We understand the significance of security and compliance within startups regardless of monetary constraints or other barriers. Kratikal for Startups, has crafted a ...

What Are the Different Roles in Cybersecurity and Which Expert Do You Need

As cybercrime continues its relentless rise, businesses in every sector face a pressing need to hire cyber security developers and professionals to safeguard their networks, systems, and data from potential threats. However, with various types of ...

Why Do SMEs Need to Adopt Emerging Technologies?

Small-medium enterprises are the backbone of any economy. Starting off with the most important aspect, the statistics about the small-medium enterprise, today, SMEs account for...Read More The post Why Do SMEs Need to Adopt Emerging Technologies? ...

7 Machine Identity Management Best Practices For Strengthening API Security

As organizations continue to adopt digital transformation, the reliance on Application Programming Interfaces (APIs) has grown exponentially. APIs play a pivotal role in enabling seamless communication between different systems and facilitating ...

How to handle API sprawl and the security threat it poses

The proliferation of APIs has marked them as prime targets for malicious attackers. With recent reports indicating that API vulnerabilities are costing businesses billions of dollars annually, it’s no wonder they are at the top of mind of many ...

New infosec products of the week: August 11, 2023

Here’s a look at the most interesting products from the past week, featuring releases from Adaptive Shield, LastPass, NetSPI, Solvo, ThreatConnect, and Vicarius. NetSPI launches ML/AI Pentesting solution to help organizations build more secure ...

Photos: Black Hat USA 2023

Black Hat USA 2023 returned to the Mandalay Bay Convention Center in Las Vegas and Help Net Security was on-site. The conference featured over 100 selected Briefings, open-source tool demos in the Arsenal, a Business Hall, networking events, and ...

How digital content security stays resilient amid evolving threats

With threats evolving and multiplying, it’s essential to understand how technological advancements can serve as both a challenge and an opportunity to safeguard digital content. In this Help Net Security interview, Rusty Cumpston, CEO at ...

Threat intelligence’s key role in mitigating malware threats

Malware, being one of the most prevalent and pervasive initial threat vectors, continues to adapt and become more sophisticated, according to OPSWAT. Crucial role of threat intelligence Threat actors leverage malware as an initial foothold to ...

How to accelerate and access DDoS protection services using GRE

As we entered 2023, the cybersecurity landscape witnessed an increase in sophisticated, high-volume attacks, according to Gcore. The maximum attack power rose from 600 to 800 Gbps. UDP flood attacks were most common and amounted to 52% of total ...

How executives’ personal devices threaten business security

Today, individual people – not businesses or government entities as a whole – are the primary targets, or entry points, for all major cyberattacks, according to Agency. Yet, while the cyber threat landscape has seen this major shift, ...

Cybersecurity as a global, multi-sector activity with Mihoko Matsubara

Like many leaders in the cybersecurity space, the professional journey of Mihoko Matsubara did not necessarily begin with securing devices or technology. However, once she discovered it, she was hooked. Discussing her career path with the Left to ...

Agents are a Dead-End for IoT Security

Yesterday I did a webinar that raised a question I was not expecting – isn’t debating agent-based versus agentless solutions for IoT security a pretty esoteric point, and aren’t there a lot more important things to be discussing on the ...

One Drive, Double Agent: Clouded OneDrive Turns Sides

See how a SafeBreach Labs researcher leveraged Microsoft OneDrive to develop a new undetectable-by-design ransomware variant. The post One Drive, Double Agent: Clouded OneDrive Turns Sides appeared first on SafeBreach. The post One Drive, Double ...

Lexmark Command Injection Vulnerability ZDI-CAN-19470 Pwn2Own Toronto 2022

Introduction In December 2022, we competed at our first pwn2own. We were able to successfully exploit the Lexmark MC3224i using a command injection 0-day. This post will detail the process we used to discover, weaponize, and have some fun with ...