Application Security News and Articles


How Legacy URL Reputation Evasion (LURE) attacks easily bypass current security tech

Whether it’s the push for fully remote work, in-office work, or a hybrid workstyle, the conversation around how and where employees will work continues. But guess what? To cybercriminals, this conversation doesn’t really matter. Not one bit. ...

4 Ways to Improve Long Term Kubernetes Capacity & Cloud Costs in Kubernetes

Today, who isn’t looking for ways to minimize costs and increase efficiency? The uncertain economic environment is causing many organizations to take another look at cloud costs and consider how to make it more efficient. As cloud computing and ...

SAP Security Patch Day: July 2023

SAP Security Patch Day: July 2023 ltabo Tue, 07/11/2023 - 12:38 Important Patches for IS-OIL, Solution Manager, Web Dispatcher, and ICM Highlights of July SAP Security Notes analysis include: July Summary - Eighteen new and updated SAP ...

Today’s ZTNA is not enough for diverse applications

Authentication & Authorization comes in various colors The Zero Trust Network Access (ZTNA) component of SASE is designed to provide secure inbound access to enterprise private applications. In line with the core principle of identity-based ...

Worried About Identity Theft? There’s a Reason for That. 

What is identity theft, and what’s happening to increase the impact so dramatically? Read what enterprises can do to make positive change. The post Worried About Identity Theft? There’s a Reason for That.  appeared first on Enzoic. The post ...

Netskope collaborates with Wipro to help users protect sensitive data

Netskope announced a new partnership with Wipro to deliver cloud-native Managed Secure Access Service Edge (SASE) and Managed Zero Trust Network Access (ZTNA) services to Wipro’s extensive global enterprise client portfolio. “As the ...

White House Cybersecurity Budget Prioritizes Defense, Resilience

The White House cybersecurity budget priorities include strengthening the software supply chain, protecting critical infrastructure and defense against ransomware. The post White House Cybersecurity Budget Prioritizes Defense, Resilience appeared ...

Personal Information of 11 Million Patients Stolen in Data Breach at HCA Healthcare

HCA Healthcare says the personal information of roughly 11 million patients was stolen in a data breach. The post Personal Information of 11 Million Patients Stolen in Data Breach at HCA Healthcare appeared first on SecurityWeek.

Russia-Linked RomCom Hackers Targeting NATO Summit Guests

A recent RomCom cyber operation has been targeting NATO Summit guests and other entities supporting Ukraine. The post Russia-Linked RomCom Hackers Targeting NATO Summit Guests appeared first on SecurityWeek.

Alteryx Analytics Automation powered by AWS allows CFOs to modernize financial processes

Alteryx announced decision intelligence and intelligent automation capabilities on AWS designed to empower chief financial officers (CFOs) and finance leaders to embrace cloud and data analytics as strategic tools for their modernization goals. ...

Apple pushes out emergency fix for actively exploited zero-day (CVE-2023-37450)

Apple has patched an actively exploited zero-day vulnerability (CVE-2023-37450) by releasing Rapid Security Response updates for iPhones, iPads and Macs running the latest versions of its operating systems. The vulnerability has also been fixed ...

AWS WAF vs. Cloudflare

In this article, we’ll discuss the similarities, differences, pros, and cons of AWS WAF and Cloudflare. The post AWS WAF vs. Cloudflare appeared first on Indusface. The post AWS WAF vs. Cloudflare appeared first on Security Boulevard.

European Commission adopts adequacy decision for safe EU-U.S. data flows

Today, the European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework. The decision concludes that the United States ensures an adequate level of protection – comparable to that of the European Union – for ...

Bolster vs Zerofox: Comparing Brand Protection Solutions

In today’s age of extensive digital transformation and expanded online presence, organizations must have robust solutions to protect their digital assets. Two prominent players in this space are Bolster and ZeroFox. We’ve put together a ...

Owncast, EaseProbe security vulnerabilities revealed

Oxeye has uncovered two critical security vulnerabilities and recommends immediate action to mitigate risk. The vulnerabilities were discovered in Owncast (CVE-2023-3188) and EaseProbe (CVE-2023-33967), two open-source platforms written in Go. ...

Advantages and Disadvantages of Homomorphic Encryption 2023

Four years after our first blog on homomorphic encryption, we revisit the technology to see what's changed to make it viable for enterprises. The short answer: not much. The post Advantages and Disadvantages of Homomorphic Encryption 2023 ...

Threat Modeling Unveiled: Enhancing Security in the Digital Age

In the fast-paced digital landscape, security breaches and data compromises have become prevalent. To counter these threats, organizations are turning to a powerful technique known as threat modeling. This blog explores the diverse use cases of ...

Microsoft Fixes NoAuth Flaws, Prevents Account Takeover

Microsoft has admitted that a vulnerability has been discovered in its Azure Active Directory (AD) Open Authorization (OAuth) process which facilitates hackers a complete account takeover. Researchers from Descope, a California-based identity and ...

CISO perspective on why Boards don’t fully grasp cyber attack risks

Due to their distinct perspectives, Board members and CISOs often have differing views on cyber attack risks. The discrepancy arises when Boards need cybersecurity expertise, need help comprehending technical jargon, or when CISOs need to ...

Cybersecurity best practices while working in the summer

IT teams need help to monitor and enforce BYOD policies during summer months when more employees often travel or work remotely. In this Help Net Security video, Jeremy Ventura, Director, Security Strategy & Field CISO at ThreatX, discusses ...