Application Security News and Articles


Details Disclosed for Critical SAP Vulnerabilities, Including Wormable Exploit Chain

Details have been disclosed for critical SAP vulnerabilities, including a wormable exploit chain, that can expose organizations to attacks. The post Details Disclosed for Critical SAP Vulnerabilities, Including Wormable Exploit Chain appeared ...

Perception Point introduces AI model to detect and prevent BEC attacks

Perception Point reveals its latest detection innovation, developed to counter the emergent wave of AI-generated email threats. The AI-powered technology leverages Large Language Models (LLMs) and Deep Learning architecture to effectively detect ...

Post-Quantum Cryptography Advances…Under the Hood

A typical scene at a car enthusiasts motorhead event involves souped-up cars with their hoods... The post Post-Quantum Cryptography Advances…Under the Hood appeared first on Entrust Blog. The post Post-Quantum Cryptography Advances…Under the ...

Keepit launches backup and recovery service for Microsoft Azure DevOps

Keepit launched new backup and recovery service for Microsoft Azure DevOps. “Azure DevOps has limited disaster recovery coverage. If a company loses its Azure DevOps data, it loses access to development operations, which means it loses the ...

Daon introduces AI.X technology to combat deepfake threats

Daon announces the addition of AI.X technology to expand the capabilities of its IdentityX and TrustX platforms. Designed for emerging identity threats from generative AI technology, AI.X includes pioneering technology that protects against ...

Serious Vulnerability Exposes Admin Interface of Arcserve UDP Backup Solution

Researchers publish PoC for a high-severity authentication bypass vulnerability in the Arcserve UDP data backup solution. The post Serious Vulnerability Exposes Admin Interface of Arcserve UDP Backup Solution appeared first on SecurityWeek.

DOE CIO Talks to SecurityWeek About Cybersecurity, Digital Transformation

SecurityWeek talks to Ann Dunkin, CIO at the Department of Energy, about cybersecurity and digital transformation. The post DOE CIO Talks to SecurityWeek About Cybersecurity, Digital Transformation appeared first on SecurityWeek.

4 Ways To Categorize Web DDoS Tsunami Attacks — Part 2

There is an array of dimensions that can be used to characterize botnets launching Web DDoS Tsunamis floods. The following are dimensions relevant primarily for attack detection and mitigation. Other dimensions (like botnet owners’ political or ...

A Guide to Articulating Risk: Speaking the Language of the Stakeholder

The role of the modern CISO today is just as much about managing technical solutions as it is about communicating risk to key decision-making stakeholders. In their daily roles, most C-suite executives and board members are too heads-down on ...

Skyhigh Security enables organizations to adopt AI applications in a secure manner

Skyhigh Security announced it’s enabling organizations to adopt artificial intelligence applications in a secure manner that protects sensitive, confidential, and business critical information through its Security Service Edge (SSE) portfolio. ...

Unmasking HMRC Self-Assessment Phish: How Attackers Outsmart Secure Email Gateways (SEGs)

Found in Environments Protected By: Microsoft    By Tej Tulachan, Phishing Defense Center (PDC)  During the busy self-assessment season in the UK, threat actors take advantage of the heightened online activity to deceive unsuspecting ...

Nokod Snags $8M to Secure Low Code/No-Code Custom Apps

Tel Aviv startup scores investment to build technology to secure in-house low-code/no-code custom applications. The post Nokod Snags $8M to Secure Low Code/No-Code Custom Apps appeared first on SecurityWeek.

Deconstructing Killnet’s Video Cyber Threat and Attack

Major Incident or Major Yawn?  In early June of this year, the cybersecurity community was shaken by a video released on Telegram and Twitter, allegedly by Pro-Russia cyber threat actors. The video, which featured a series of ominous talking ...

What is FIPS 140-2: Why It’s Important?

Know About the Federal Information Processing Standard (FIPS) 140-2 The… Continue reading What is FIPS 140-2: Why It’s Important? The post What is FIPS 140-2: Why It’s Important? appeared first on SSLWiki. The post What is FIPS 140-2: Why ...

New MIT Framework Evaluates Side-Channel Attack Mitigations

The framework helps evaluate the effectiveness of obfuscation side-channel mitigation schemes against data leaks. The post New MIT Framework Evaluates Side-Channel Attack Mitigations appeared first on SecurityWeek.

Immuta simplifies data security and monitoring in Snowflake with platform updates

Immuta launched its latest platform enhancements to deliver simplified data security and monitoring in Snowflake so that joint customers can unlock more value, reduce costs, and speed up innovation. These new features include strengthened data ...

The Art of Protecting Secrets: Eight Essential Concepts for SecOps Practitioners

Secrets management is an art, and mastering it requires a deep understanding of security protocols, meticulous attention to detail, and a proactive approach to staying ahead of threats. In this blog, we present you with eight essential concepts ...

Twilio partners with Frame AI to uplevel contact center experiences with AI

Twilio and Frame AI announced a partnership to leverage AI to enhance customer engagement delivered within Twilio Flex. With the help of Frame AI’s platform, Twilio Flex (the cloud-based digital engagement solution for personalized interactions ...

Enterprises Unprepared to Defend Against MITRE ATT&CK Techniques

Enterprises lack detections for more than three-quarters of all MITRE ATT&CK techniques, while 12% of SIEM rules are broken and will never fire due to data quality issues including misconfigured data sources and missing fields. These were ...

White House Outlines Cybersecurity Budget Priorities for Fiscal 2025

The White House has released a memorandum outlining the cybersecurity investment priorities for government departments and agencies for fiscal year 2025. The post White House Outlines Cybersecurity Budget Priorities for Fiscal 2025 appeared first ...