Application Security News and Articles


Russian APT Group Caught Hacking Roundcube Email Servers

A Russian hacking group has been caught hacking into Roundcube servers to spy on government institutions and military entities in Ukraine. The post Russian APT Group Caught Hacking Roundcube Email Servers appeared first on SecurityWeek.

SMS Toll Fraud Brace for the Bill

SMS Fraud: Brace for the Bill Many businesses today underestimate the security risks associated with their telephone systems, even though they have vulnerabilities that can lead to significant financial loss. One of the notable threats is SMS ...

Advanced Phishing Attacks: How to Stem the Tide

The problem with phishing is not just its relentless onslaught—it’s that threat actors continue to evolve toward more advanced phishing attacks. The ability to psychologically manipulate and dupe people into taking certain actions helps ...

Putting an End to the Flood-Radware Successfully Stops Record-Breaking 15 Billion Requests During Web DDoS Tsunami Attack Campaign

In the ever-changing world of cybersecurity threats, Layer 7 distributed denial of service (DDoS) attacks continue to be a major challenge for online businesses. These advanced attacks cause significant disruptions, make services unavailable, ...

Fairwinds Insights Release Notes 12.11-12.15 & More

This month we’re excited to share some new capabilities in Fairwinds Insights in addition to other improvements and bug fixes. Last month we officially launched our new Costs page, so this month we deprecated and removed our previous Workloads ...

IRONSCALES boosts email security with generative AI capabilities

IRONSCALES announced the Beta launch of Themis Co-pilot for Microsoft Outlook, a GPT-powered chat assistant for self-service threat reporting. Powering Themis Co-pilot is PhishLLM, a language model (LLM) hosted within the IRONSCALES ...

A “cewl” way for API discovery

Learn how to leverage CeWL to generate custom word lists from release notes, changelogs, and product roadmaps for use in API discovery. The post A “cewl” way for API discovery appeared first on Dana Epp's Blog. The post A “cewl” way for ...

Next DLP Scoped Investigations separates employee identity from their behavioral data

Next DLP announced a new ‘Scoped Investigations’ capability in the Reveal platform that protects privacy by time bounding and restricting access to employee activity to only investigators with an approved and legitimate need to access it. A ...

Norton Parent Says Employee Data Stolen in MOVEit Ransomware Attack

Gen Digital, which owns Avast, Avira, AVG, Norton, and LifeLock, said employee data was compromised in the MOVEit ransomware attack. The post Norton Parent Says Employee Data Stolen in MOVEit Ransomware Attack appeared first on SecurityWeek.

CYE Hyver enhancements empower organizations with real-time risk analysis module

CYE announced a new capability in its Hyver platform that calculates dynamic risk in real-time. Hyver sets a new standard for the industry that will allow CISOs to take mitigation plans to the next level by optimizing real-time data to make both ...

The Future of Email Security: Why Technology Alone Isn’t Enough

Over the past year, the Cofense Intelligence team saw a whopping 569% increase in malicious phishing emails bypassing standard email security solutions. Just when you thought your email was secure, our insights are telling a much different story. ...

Building an Alert System Using Snowflake

During my time here at Silverfort, I was tasked with building an alert system to send messages from our Snowflake database directly to a Slack channel. Easy enough, I thought to myself. But the project expanded quickly and has now evolved into a ...

Cymulate Exposure Analytics provides users with an attacker’s view of their cyber resilience

Cymulate released a new solution for organizations to run an informed continuous threat exposure management (CTEM) program. The CTEM program, which was coined by Gartner is designed to diagnose the severity of exposures, create an action plan for ...

The Evolving World of Cybersecurity and Authentication: A Q&A with David Kennedy

Identity security and authentication are having their time in the spotlight. But what should organizations... The post The Evolving World of Cybersecurity and Authentication: A Q&A with David Kennedy appeared first on Axiad. The post The ...

BSidesSF 2023 – Michael Bargury – Sure, Let Business Users Build Their Own. What Could Go Wrong?

Our thanks to BSidesSF for publishing their presenter’s superlative BSidesSF 2023 content on the organizations’ YouTube channel. Permalink The post BSidesSF 2023 – Michael Bargury – Sure, Let Business Users Build Their Own. What ...

OT:Icefall: Vulnerabilities Identified in Wago Controllers

Forescout Technologies has disclosed the details of vulnerabilities impacting operational technology (OT) products from Wago and Schneider Electric. The post OT:Icefall: Vulnerabilities Identified in Wago Controllers appeared first on SecurityWeek.

New ‘RDStealer’ Malware Targets RDP Connections

Bitdefender finds new malware capable of monitoring incoming RDP connections and infect the connecting clients that have client drive mapping enabled. The post New ‘RDStealer’ Malware Targets RDP Connections appeared first on ...

Orange Business, Orange Cyberdefense and Palo Alto Networks improve security for enterprises

Orange Business, Orange Cyberdefense and Palo Alto Networks have joined forces to deliver a managed Secure Access Service Edge (SASE) solution that meets enterprise customers’ most demanding networking and security requirements with high ...

Photos: Infosecurity Europe 2023

Infosecurity Europe is taking place at ExCeL London from 20-22 June 2023 and Help Net Security is on site. Here’s a closer look at the conference featuring: Island, Crowdstrike, Panorays, ManageEngine, Mazebolt, Cobalt, Intruder, TikTok, ...

The Future of Email Security: Why Technology Alone Isn’t Enough

Over the past year, the Cofense Intelligence team saw a whopping 569% increase in malicious phishing emails bypassing standard email security solutions. Just when you thought your email was secure, our insights are telling a much different story. ...