Application Security News and Articles


COURT DOC: Russian Nationals Charged With Hacking One Cryptocurrency Exchange And Illicitly Operating Another

Officials announced the unsealing of charges against Alexey Bilyuchenko and Aleksandr Verner, both Russian nationals.  Bilyuchenko and Verner are charged with conspiring to launder approximately 647,000 bitcoins from the 2011 hack of Mt. Gox. ...

It’s time to patch your MOVEit Transfer solution again!

Progress Software customers who use the MOVEit Transfer managed file transfer solution might not want to hear it, but they should quickly patch their on-prem installations again: With the help of researchers from Huntress, the company has ...

The multiplying impact of BEC attacks

The 2023 Verizon Data Breach Investigations Report (DBIR) has confirmed what FBI’s Internet Crime Complaint Center has pointed out earlier this year: BEC scammers are ramping up their social engineering efforts to great success. BEC ...

Stellar Cyber collaborates with Mimecast to minimize email-based attack impacts

Stellar Cyber announced a new technology partnership with Mimecast, an email and collaboration security company. This powerful technology integration makes it easy for Stellar Cyber and Mimecast customers to swiftly mitigate the risk of damaging ...

SaaS Challenges and Security Risks

SaaS is driving the journey to digital transformation, with cloud application services dominating end-user spending. And by the end of 2023, Gartner predicts that spending for SaaS will top $195 billion. But while SaaS applications create ...

US Government Provides Guidance on Software Security Guarantee Requirements

OMB has published new guidance on federal agencies obtaining security guarantees from software vendors. The post US Government Provides Guidance on Software Security Guarantee Requirements appeared first on SecurityWeek.

US Charges Russians With Hacking Cryptocurrency Exchange

Two Russian nationals are charged in the US with hacking a cryptocurrency exchange and conspiring to launder the proceeds. The post US Charges Russians With Hacking Cryptocurrency Exchange appeared first on SecurityWeek.

Announcing Apptega Edge: The End-to-End Cybersecurity Compliance Platform Purpose-Built for MSPs

There are more than 150,000 MSPs globally, and the vast majority of them have traditionally been walled off from cybersecurity compliance due to its cost, complexity, and specialized knowledge.  The post Announcing Apptega Edge: The End-to-End ...

13 Essential Linux Security Commands

Basic Linux security commands that all IT security pros should know  Linux, known for its power, flexibility, and security, is a staple in the world of operating systems. We love Linux, like a raccoon loves shiny things. Especially for personal ...

AI-Generated Steganography

New research suggests that AIs can produce perfectly secure steganographic images: Abstract: Steganography is the practice of encoding secret information into innocuous content in such a manner that an adversarial third party would not realize ...

Intellihartx Informs 490k Patients of GoAnywhere-Related Data Breach

Intellihartx says the personal information of roughly 490,000 individuals was compromised in the GoAnywhere zero-day attack earlier this year. The post Intellihartx Informs 490k Patients of GoAnywhere-Related Data Breach appeared first on ...

Software Supply Chain: The Golden Container Ship

By having a golden image you will put a process in place that allows you to quickly take action when a vulnerability is found within your organization. The post Software Supply Chain: The Golden Container Ship appeared first on SecurityWeek.

The Different Forms of Online Abuse

Fighting fraud is serious business for companies, even when they have clear rules and steps to follow. However, its evil twin abuse can show up in different ways - from out-and-out illegal actions to things that just go against a website's rules ...

New MOVEit Vulnerabilities Found as More Zero-Day Attack Victims Come Forward

Researchers discover new MOVEit vulnerabilities related to the zero-day, just as more organizations hit by the attack are coming forward. The post New MOVEit Vulnerabilities Found as More Zero-Day Attack Victims Come Forward appeared first on ...

Swiss Fear Government Data Stolen in Cyberattack

Switzerland said government operational data might have been stolen in a ransomware attack on a technology firm that provides software for several departments. The post Swiss Fear Government Data Stolen in Cyberattack appeared first on SecurityWeek.

Fortinet Patches Critical FortiGate SSL VPN Vulnerability

Fortinet has patched CVE-2023-27997, a critical FortiGate SSL VPN vulnerability that can be exploited for unauthenticated remote code execution. The post Fortinet Patches Critical FortiGate SSL VPN Vulnerability appeared first on SecurityWeek.

GUEST ESSAY: The key differences between ‘information privacy’ vs. ‘information security’

Information privacy and information security are two different things. Related: Tapping hidden pools of security talent Information privacy is the ability to control who (or what) can view or access information that is collected about you or your ...

WordPress SEO: How to Optimize Your Website for Search Engines

WordPress website SEO has become a central requirement of the hour. With the increasing competition, every firm wants to reach the targeted audience and boost its revenue. And as a WordPress development agency, we consider search engine ...

Comprehensive Guide to Threat Modeling: Enhancing Security in the Digital Age

In today's digital landscape, cybersecurity is a top concern for businesses and individuals. As technology evolves, so do the threats that can compromise the security of our systems and data. To address these challenges proactively, organizations ...

Building a culture of security awareness in healthcare begins with leadership

With the rise of modern trends such as cloud computing and remote work, healthcare institutions strive to balance accessibility, convenience, and robust security. In this Help Net Security interview, Ken Briggs, General Counsel at Salucro, ...