Application Security News and Articles


Netskope Intelligent SSE helps enterprises securely manage employee use of generative AI apps

Netskope has released a comprehensive data protection solution to help enterprises securely manage employee use of ChatGPT and other generative AI applications, such as Google Bard and Jasper. As part of its Intelligent Security Service Edge ...

Malwarebytes launches Reseller Partner Program to drive partner profitability

Malwarebytes launched the Malwarebytes Reseller Partner Program. The revamped program is dedicated to helping partners create profitable and consistent business growth through innovative endpoint security solutions and leading channel incentives ...

Australian Government Says Its Data Was Stolen in Law Firm Ransomware Attack

The Office of the Australian Information Commissioner (OAIC) says some of its files were stolen in a ransomware attack on law firm HWL Ebsworth. The post Australian Government Says Its Data Was Stolen in Law Firm Ransomware Attack appeared first ...

Compromised Linux SSH servers engage in DDoS attacks, cryptomining

Poorly managed Linux SSH servers are getting compromised by unknown attackers and instructed to engage in DDoS attacks while simultaneously mining cryptocurrency in the background. The Tsunami DDoS bot Tsunami, also known as Kaiten, is a type of ...

SUSE Survey Surfaces Multiple Cloud Security Challenges

A survey of 501 IT professionals based in the U.S., United Kingdom and Germany published today found that, on average, organizations were impacted by four cloud-related security incidents in the past year. A majority (88%) noted that if they were ...

What to Know About the CISA Software Bill of Materials Sharing Lifecycle Phases   

As Software Bill of Materials (SBOM) adoption efforts mature, a report recently released by the Cybersecurity and Infrastructure Security Agency (CISA) provides guidance to users in selecting suitable SBOM sharing platforms based on the amount ...

What Business Owners Can Learn from Prudential Malaysia Breach (MOVEit)

Discover what business owners can learn from the recent Prudential Malaysia breach. Protect your reputation and assets by prioritizing data security. The post What Business Owners Can Learn from Prudential Malaysia Breach (MOVEit) appeared first ...

Effective Strategies for Detecting Lateral Movement

Enhancing security posture through detecting lateral movement and unmasking advanced cyber threats  Organizations face the constant challenge of detecting and thwarting sophisticated cyber threats. One critical aspect of threat detection is ...

Zyxel patches critical vulnerability in NAS devices (CVE-2023-27992)

Zyxel has released firmware patches for a critical vulnerability (CVE-2023-27992) in some of its consumer network attached storage (NAS) devices. About CVE-2023-27992 CVE-2023-27992 is an OS command injection flaw that could be triggered remotely ...

Preventing and Managing Secrets Leaks

Discover the importance of preventing secret leaks and the costly consequences organizations face. Learn why existing tooling falls short and how GuardRails can enhance your security posture. The post Preventing and Managing Secrets Leaks ...

Ensuring Secure Remote Access for Industrial Control Systems

You may also be interested in reading: Industrial control systems (ICS) refer to control systems used in a wide range of industrial processes. It’s a component of operation technology that involves hardware, software, and systems that help ...

Understanding and Mitigating the MOVEit Incidents

Over the last several weeks, attackers have taken advantage of vulnerabilities in MOVEit, a popular file transfer application developed by Progress. Cyber attackers have successfully performed ransomware and exfiltrated data by uploading web ...

Indusface Threat Coverage: MOVEit Transfer SQL Injection Vulnerabilities

Protect your business from MOVEit Transfer SQL Injection Vulnerabilities with Indusface Threat Coverage. The post Indusface Threat Coverage: MOVEit Transfer SQL Injection Vulnerabilities appeared first on Indusface. The post Indusface Threat ...

The significance of CIS Control mapping in the 2023 Verizon DBIR

Verizon’s recently released 2023 Data Breach Investigation Report (DBIR) provides organizations with a comprehensive analysis of the evolving threat landscape and valuable insights into incident types and vulnerabilities. This year, the ...

ChatGPT and data protection laws: Compliance challenges for businesses

In this Help Net Security interview, Patricia Thaine, CEO at Private AI, reviews the main privacy concerns when using ChatGPT in a business context, as well as the risks that businesses can face if they betray customers’ trust. Thaine also ...

10 open-source recon tools worth your time

Recon is the initial stage in the penetration testing process. It’s a vital phase allowing the tester to understand their target and strategize their moves. Here are ten open-source recon tools that deserve to be in your arsenal. Altdns ...

People: The Nuclei of Your Insider Risk Management Solution

Every company has them, some more than others. They are at home, across the seas, or down the hall. I am talking about your colleagues, partners, vendors, and customers, all of whom make up the ecosystem of your business success or failure. It ...

The future of passwords and authentication

In this Help Net Security video, Michael Crandell, CEO of Bitwarden, discusses the future of passwords and authentication. Although interest in passwordless technology, which aims to eliminate the need for passwords, is relatively low, 65% of ...

Demand for STEM training skyrockets

The rapid pace of globalization, digital transformation, and AI advancements have created a renewed demand for digital and human skills among US learners, according to Coursera. “The rise of digital jobs and remote work is creating ...

What if the browser was designed for the enterprise?

Bradon Rogers, Chief Customer Officer at Island, provides an overview of the Island Enterprise Browser. Learn more at Infosecurity Europe 2023 – June 20-22, 2023. The post What if the browser was designed for the enterprise? appeared first ...