Application Security News and Articles


A Complete Guide to ICS Security Assessment

Did you know that the average cost of data breaches worldwide was $4.35 million in 2022, with phishing being the most common form of attack? Demand for ransom, locking critical data files, stealing sensitive data, etc., are common forms of ...

“That’s Out of Scope,” Said No Attacker Ever

Organizations need to go to the same lengths as attackers, but that’s a long way… When Ellopunk found this in her backpack (℅ Sarah Young) and posted it to Twitter[X] (thank you!), it won the Internet for today, got me thinking, and ...

Microsoft 365 accounts of execs, managers hijacked through EvilProxy

A phishing campaign leveraging the EvilProxy phishing-as-a-service (PhaaS) tool has been spotted targeting Microsoft 365 user accounts of C-level executives and managers at over 100 organizations around the world. The rise of ...

Why School Safety Is Important: A Guide For K-12 Districts

Why school safety is important goes beyond securing buildings. Here, we’ll look at different dimensions of school safety and what they mean for students. There’s no doubt that safety is top of mind for school administrators. But, ...

ConcealSherpaAI identifies potentially harmful webpages

Conceal introduced the ConcealSherpaAI engine, a secure browser extension powered by AI to identify potentially harmful webpages autonomously. By examining and evaluating metadata signals on a webpage, ConcealSherpaAI determines whether to ...

European Startup Pistachio Raises €3.25 Million for Cybersecurity Training Platform

Norway-based startup Pistachio has raised €3.25 million ($3.5 million) for its AI-based cybersecurity training platform. The post European Startup Pistachio Raises €3.25 Million for Cybersecurity Training Platform appeared first on SecurityWeek.

Adaptive Shield’s ITDR capabilities help users detect identity-related security threats

Adaptive Shield announced its Identity Threat Detection and Response (ITDR) capabilities to help organizations mitigate identity-related threats. When paired with its SaaS Security Posture Management (SSPM) solution, ITDR addresses the complete ...

The Week in Security: Cloudflare Tunnels abuse ramps up, U.K. voter data exposed

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond. This week: More and more hackers ...

Adopting Zero Trust: The Illusion of Passwordless

Listen now (51 mins) | Season two, episode 14: The illusion of going passwordless with Derek Hanson, Vice President Solutions Architecture and Alliances at Yubico + Yubikey giveaway. The post Adopting Zero Trust: The Illusion of Passwordless ...

Russia Prime Suspect for UK Electoral Commission Cyber Attack

A cyber attack targeting the UK’s Electoral Commission, which resulted in the exposure of data belonging to 40 million voters over two years, is believed to have been orchestrated by Russia. This breach was initially detected in October 2022 ...

PowerDMARC Receives Stellastra Award for Best DMARC Company in Summer 2023

Stellastra - PowerDMARC beat over 40 competing DMARC companies in Summer 2023, winning best DMARC company award. The post PowerDMARC Receives Stellastra Award for Best DMARC Company in Summer 2023 appeared first on Security Boulevard.

LastPass removes the master password from customers’ login with FIDO2 authenticators

LastPass announced the availability of FIDO2 authenticators, including biometrics, such as finger print or face ID, and hardware keys, for its Passwordless Login solution. This innovation allows LastPass customers to experience a seamless ...

Ten Ways Organizations Can Improve Security Posture

A decuplet of best practices to help organizations improve security posture   In the 21st century, security isn’t just a concern; it’s a necessity. Organizations must constantly adapt to evolving cybersecurity minefield. The challenges are ...

White House launches AI Cyber Challenge to make software more secure

The Biden-Harris Administration has launched a major two-year competition using AI to protect the United States’ most important software, such as code that helps run the internet and critical infrastructure. The AI Cyber Challenge (AIxCC) will ...

CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio 

CISA has added CVE-2023-38180, a zero-day vulnerability affecting .NET and Visual Studio, to its Known Exploited Vulnerabilities Catalog. The post CISA Warns Organizations of Exploited Vulnerability Affecting .NET, Visual Studio  appeared first ...

Mastering Vulnerability Management: Best Practices for Cybersecurity Success

Unpatched Vulnerabilities Cause Massive Breaches Vulnerability management can be the difference between safeguarding your organization or setting up your business for a professional disaster. Think T-Mobile, and Twitter, and that’s just the ...

Will AI kill cybersecurity jobs?

Some ten years ago, the authors of The Second Machine Age wrote that “computers and other digital advances are doing for mental power—the ability to use our brains to understand and shape our environments—what the steam engine and its ...

Learning from past healthcare breaches to fortify future cybersecurity strategies

In the face of rising cyber threats, the healthcare sector has become a hotbed for cyberattacks. Given the gravity of this situation, we sat down with Shenny Sheth, Deputy CISO at Centura Health, who sheds light on the contributing factors making ...

What to know about FedRAMP Rev. 5 Baselines

In this Help Net Security video, Kaus Phaltankar, CEO at Caveonix, discusses how the recent approval of the FedRAMP Rev. 5 Baselines is a significant step forward in the cloud security and compliance domain. The implications for CSPs and ...

Private network adoption grows as enterprises seek greater control and security

Enterprises are turning to private networks to enhance security and resiliency, according to Spirent. “Private networks are emerging as a viable alternative to traditional enterprise networks, offering a wide range of benefits,” said ...