Application Security News and Articles


Securing the kingdom: Privileged Access Management (PAM) and compliance – ISO 27001

In this article, we'll delve into the compliance aspects of privileged access management, with focus on ISO 27001. The post Securing the kingdom: Privileged Access Management (PAM) and compliance – ISO 27001 appeared first on Scytale. The post ...

JumpCloud Says Sophisticated Nation-State Hackers Targeted Specific Customers

JumpCloud says a sophisticated nation-state threat actor breached its systems, targeting specific customers. The post JumpCloud Says Sophisticated Nation-State Hackers Targeted Specific Customers appeared first on SecurityWeek.

Anviz IntelliSight helps users identify and categorize suspicious activity

Anviz launched IntelliSight, its latest video surveillance offering that harnesses the power of distributed cloud and 4G technology to create an all-in-one security solution that delivers versatility, security, and data analytical capabilities. ...

Cisco Nexus 9000 Users Must Disable Encryption to Dodge Vuln

There is no workaround or patch for a high-severity vulnerability—and none will be forthcoming—in Cisco’s Nexus 9000 series switches. The post Cisco Nexus 9000 Users Must Disable Encryption to Dodge Vuln appeared first on Security Boulevard.

How IoT Is Powering Smart Cities

Smart cities can create a utopia of smooth infrastructure and upgraded efficiency, improving the quality of life in urban areas and boosting local economies. Its impacts The post How IoT Is Powering Smart Cities appeared first on FirstPoint. The ...

MOVEit Hack: Number of Impacted Organizations Exceeds 340

The number of entities impacted by the MOVEit hack — either directly or indirectly — reportedly exceeds 340 organizations and 18 million individuals. The post MOVEit Hack: Number of Impacted Organizations Exceeds 340 appeared first on ...

Critical XSS vulnerability in Zimbra exploited in the wild (CVE-2023-34192)

A critical cross site scripting (XSS) vulnerability (CVE-2023-34192) in popular open source email collaboration suite Zimbra is being exploited by attackers. About the vulnerability (CVE-2023-34192) CVE-2023-34192 could allow a remote ...

Tracking Down a Suspect through Cell Phone Records

Interesting forensics in connection with a serial killer arrest: Investigators went through phone records collected from both midtown Manhattan and the Massapequa Park area of Long Island—two areas connected to a “burner phone” they had ...

Federal CI/CD security guidance: Been there, done that

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) are telling development organizations to tighten up the security of their development pipelines or face the risk of damaging software supply ...

SecurityWeek Analysis: Over 210 Cybersecurity M&A Deals Announced in First Half of 2023

An analysis conducted by SecurityWeek shows that more than 210 cybersecurity-related mergers and acquisitions were announced in the first half of 2022. The post SecurityWeek Analysis: Over 210 Cybersecurity M&A Deals Announced in First Half ...

Why the new AI cybercrime tool is just the tip of the iceberg

Recent reports about the appearance of a new generative AI tool point to the levels of maturity that hackers have attained as far as leveraging AI is concerned. In the latest edition of our IoT and OT threat landscape report, we had predicted ...

Exploitation of ColdFusion Vulnerability Reported as Adobe Patches Another Critical Flaw

Adobe patches critical code execution vulnerability in ColdFusion for which a proof-of-concept (PoC) blog exists. The post Exploitation of ColdFusion Vulnerability Reported as Adobe Patches Another Critical Flaw appeared first on SecurityWeek.

How to Prevent Account Sharing Like Netflix

For an early stage company, the focus often lies in attracting users and expanding the customer base. Land and expand. During this phase, account sharing may not be perceived as a significant problem. However, as the business matures and revenue ...

New Feature: Risk Evaluation | Kovrr blog

Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post New Feature: Risk Evaluation | Kovrr blog appeared first on Security Boulevard.

Security Risks of Manual Certificate Lifecycle Management

Digital certificates are a critical component in any cybersecurity strategy. They help mitigate organizations' ever-growing risk exposure by establishing digital trust and acting as a barrier to unauthorized access, fraudulent online activities, ...

How to use Wi-Fi to get your mother-in-law to go to therapy

You may have witnessed the social media trend of people talking to their significant others’ phones to influence their ad algorithms. Believe it or not, it isn’t that far-fetched, even if the exact method of talking to someone’s phone ...

Steps Forward: Can ‘CNAPP’ solutions truly unify cloud, on-premises best cybersecurity practices?

A fledgling security category referred to as Cloud-Native Application Protection Platforms (CNAPP) is starting to reshape the cybersecurity landscape. Related: Computing workloads return on-prem CNAPP solutions assemble a varied mix of security ...

Guide to Building a Cybersecurity Incident Response Plan [Part 2]

Having a cybersecurity incident response plan is essential for any organization that wants to be prepared for a security incident. By being prepared for an incident, your organisation is able to align and respond quickly if and when one ...

CISOs under pressure: Protecting sensitive information in the age of high employee turnover

In this Help Net Security interview, Charles Brooks, Adjunct Professor at Georgetown University’s Applied Intelligence Program and graduate Cybersecurity Programs, talks about how zero trust principles, identity access management, and ...

CJIS

What is the CJIS framework? The CJIS (Criminal Justice Information Services) framework is a comprehensive set of security policies and guidelines established by the Federal Bureau of Investigation (FBI) in the United States. It aims to ensure the ...