Application Security News and Articles


Total Assure launches to provide SMBs with managed security services

Total Assure announced its spinout from IBSS. Total Assure partners with its customers to identify security gaps, develop attainable cybersecurity objectives, and deliver comprehensive cybersecurity solutions that protect their businesses from ...

Samsung Phone Flaws Added to CISA ‘Must Patch’ List Likely Exploited by Spyware Vendor

CISA adds 6 Samsung mobile device flaws to its known exploited vulnerabilities catalog and they have likely been exploited by a spyware vendor. The post Samsung Phone Flaws Added to CISA ‘Must Patch’ List Likely Exploited by Spyware ...

Nokod Security raises $8 million to enhance low-code/no-code app security

Nokod Security announced its $8 million seed round, which will be used to establish a presence in the United States market, as well as to expand the R&D teams and support novel research of security vulnerabilities in the low-code/no-code ...

FIRESIDE CHAT: Outrageous phone bills stun businesses targeted for ‘SMS toll fraud’

SMS toll fraud is spiking. I learned all about the nuances of deploying – and defending – these insidious attacks in a recent visit with Arkose Labs CEO, Kevin Gosschalk, who explained how the perpetrators victimize businesses that use … ...

The Role of MLOps in Streamlining Machine Learning Workflows

Machine learning (ML) has emerged as a transformative technology that enables organizations to extract valuable insights from data and make informed decisions. However, the process of developing and deploying ML models involves numerous ...

MITRE Updates CWE Top 25 Most Dangerous Software Weaknesses

Use-after-free and OS command injection vulnerabilities reach the top five most dangerous software weaknesses in the 2023 CWE Top 25 list. The post MITRE Updates CWE Top 25 Most Dangerous Software Weaknesses appeared first on SecurityWeek.

Proton Launches Open Source Password Manager

Proton makes its open source Proton Pass password manager globally available for major browsers and mobile devices. The post Proton Launches Open Source Password Manager appeared first on SecurityWeek.

Why is DevSecOPS important in 2023?

Why is DevSecOPS important in 2023? Why is DevSecOPS important in 2023? Introduction Introduction DevSecOps is the next step in software development. It’s a way of working that combines DevOps and security teams, and it’s essential for your ...

TSMC Says Supplier Hacked After Ransomware Group Claims Attack on Chip Giant

LockBit ransomware group claims to have hacked TSMC and is asking for a $70 million ransom, but the chip giant says only a supplier was breached. The post TSMC Says Supplier Hacked After Ransomware Group Claims Attack on Chip Giant appeared first ...

Health Insurance Portability and Accountability Act (HIPAA) Best Practices

Highlighting the key elements of The Health Insurance Portability and Accountability Act to ensure HIPAA best practices  The Health Insurance Portability and Accountability Act (HIPAA) is a vital piece of legislation that safeguards the privacy ...

How Injection Attacks Can Cripple Your Business?

Injection attacks distinguish themselves among these threats as devastating exploitation. Businesses face a variety of cyber risks in today’s interconnected digital environment that might jeopardize their operations. This also compromises ...

New infosec products of the week: June 30, 2023

Here’s a look at the most interesting products from the past week, featuring releases from Cequence Security, Delinea, Index Engines, and NetApp. Delinea Privilege Manager enhancements reduce phishing effectiveness Based on Delinea’s deep ...

Unlocking internet’s secrets via monitoring, data collection, and analysis

In this Help Net Security interview, Ryan Woodley, CEO of Netcraft, discusses the importance of monitoring, collecting, and analyzing internet data to gain a profound understanding of the internet. This insight plays a vital role in protecting ...

Businesses are ignoring third-party security risks

In the dynamic business landscape where third-party relationships assume a critical role, organizations confront various risks that can profoundly affect their security and compliance requirements, according to Panorays. Even amidst tough ...

Employees worry less about cybersecurity best practices in the summer

IT teams are struggling to monitor and enforce BYOD (Bring Your Own Device) policies during summer months when more employees are often traveling or working remotely, according to ThreatX. With more endpoints and applications in use, and often ...

How MSSPs Can Leverage Security Automation

The post How MSSPs Can Leverage Security Automation appeared first on Low-Code Security Automation & SOAR Platform | Swimlane. The post How MSSPs Can Leverage Security Automation appeared first on Security Boulevard.

Log Centralization: The End Is Nigh?

So I woke up the other day [A.C. — well, the other year as this blog has lingered] with the scary thought: what if we will run out of the opportunities to centralize logs for security (and compliance) purposes at some point in ...

Cactus Ransomware, BlackSuit, and more: Hacker’s Playbook Threat Coverage Round-up: June 29, 2023

Cactus ransomware, Blacksuit ransomware, JackaclControl malware, and others. This threat roundup highlights coverage from SafeBreach, leaders in BAS. The post Cactus Ransomware, BlackSuit, and more: Hacker’s Playbook Threat Coverage Round-up: ...