Application Security News and Articles


Cybersecurity Trends, Notable Vulnerabilities and Threat Hunting Tactics

As part of our ongoing efforts to support our clients, the Pondurance team hosts a webinar to keep clients current on the state of cybersecurity. Over the past few months, the team discussed notable vulnerabilities and trends, provided a threat ...

Island appoints Steve Tchejeyan as President

Island announced the addition of Steve Tchejeyan to its executive team as President. Tchejeyan brings decades of executive leadership experience driving successful business strategies and growth initiatives for some of the world’s leading ...

The Power of Chariot Managed Service

The landscape of cybersecurity is one of constant, rapid change, challenging organizations to keep pace with emerging threats. Organizations search for a tool or product that holistically enhances their cybersecurity program and gives them peace ...

Securing Your Cloud Database: A Practical Guide

In the age of digital transformation, more and more businesses are shifting their operations to the cloud, leading to an increasing reliance on cloud databases. While these offer significant advantages such as scalability and accessibility, they ...

SkyKick Cloud Management Platform upgrades enhance data protection capabilities

SkyKick announced major enhancements to its Cloud Management Platform. New products and updates deliver enhanced data protection capabilities and personalized security insights, enabling ITSPs to meet the growing demand for robust security ...

Two New Vulnerabilities Could affect 40% of Ubuntu Cloud Workloads

Researchers discovered two vulnerabilities in the Ubuntu OverlayFS module: CVE-2023-2640 and CVE-2023-32629 (together dubbed ‘GameOver(lay)’). The post Two New Vulnerabilities Could affect 40% of Ubuntu Cloud Workloads appeared first on ...

CardioComm Takes Systems Offline Following Cyberattack

Canadian medical software provider CardioComm has taken systems offline to contain a cyberattack. The post CardioComm Takes Systems Offline Following Cyberattack appeared first on SecurityWeek.

10 Identity And Access Management Best Practices For Robust Digital Identity Protection

Identity and Access Management (IAM) enhances security by ensuring that only authorized humans and machines have access to sensitive information and resources. By implementing robust authentication and authorization mechanisms, IAM enables ...

Axis Door Controller Vulnerability Exposes Facilities to Physical, Cyber Threats

An Axis network door controller vulnerability can be exploited to target facilities, exposing them to both physical and cyber threats. The post Axis Door Controller Vulnerability Exposes Facilities to Physical, Cyber Threats appeared first on ...

Apple releases new security patches; More than one million people impacted by Tampa Bay data breach

Data breaches continue to come at an alarming rate, and it’s no surprise to learn the cost of these incidents continues to go up. In its’ annual Cost of a Data Breach Report, IBM found the global average data breach cost $4.45 million in ...

Google Cloud Build Flaw Could Enable Supply Chain Attacks

Bad actors could exploit a design flaw, called Bad.Build, in Google Cloud Build to escalate privileges and gain access to Google Artifact Registry code repositories. The post Google Cloud Build Flaw Could Enable Supply Chain Attacks appeared ...

Egnyte’s AI-powered solutions empower users to classify and protect sensitive data

Egnyte announced several new AI-powered solutions being natively integrated into the Egnyte platform. Egnyte customers will now be able to use the latest generative AI models to find and summarize information contained in their company’s ...

How to create an incident response plan: A step-by-step guide for K-12 school districts

You don’t have to be a cybersecurity expert to know it’s always helpful to plan ahead. After all, preparation makes perfect — especially when you’re talking about protecting student data. Never made an incident response plan before? ...

Protect AI raises $35 million to help organizations build safer AI

Protect AI has closed a $35 million Series A round of funding led by Evolution Equity Partners with participation from Salesforce Ventures and existing investors Acrew Capital, boldstart ventures, Knollwood Capital and Pelion Ventures. To date, ...

Adopting Zero Trust: Philosophy of Prevention with iHeartMedia’s Janet Heins

Listen now (44 min) | Season two, episode 13: Cybersecurity prevention on a global scale with Janey Heins, Global CISO for iHeartMedia. The post Adopting Zero Trust: Philosophy of Prevention with iHeartMedia’s Janet Heins appeared first on ...

Protect AI Raises $35 Million to Protect Machine Learning and AI Assets

Machine Learning and Artificial Intelligence security firm Protect AI raised $35 million in Series A funding led by Evolution Equity Partners. The post Protect AI Raises $35 Million to Protect Machine Learning and AI Assets appeared first on ...

Google-Owned VirusTotal Data Leak: Result of Human Error

The recent data leak at Google-owned VirusTotal exposed information on approximately 5,600 of its registered customers. The leak impacted Premium account holders only. Emiliano Martinez, the head of product management at VirusTotal, stressed in a ...

Up to 11 Million People Hit by MOVEit Hack at Government Services Firm Maximus

Maximus Inc says that the personal information of 8 to 11 million individuals was stolen in the MOVEit cyberattack. The post Up to 11 Million People Hit by MOVEit Hack at Government Services Firm Maximus appeared first on SecurityWeek.

Preventing Lateral Movement 101

A step-by-step guide to preventing lateral movement and stopping breaches in their tracks  Lateral movement within an organization’s network is a crippling threat to IT security. Once a cyber attacker has breached the first line of defense and ...

Companies Required by SEC to Disclose Cybersecurity Incidents in 4 Days

The SEC has adopted new rules requiring public companies to disclose cybersecurity breaches that have a material impact within four days. The post Companies Required by SEC to Disclose Cybersecurity Incidents in 4 Days appeared first on ...