Application Security News and Articles


Travel Alert: How Bot Attacks Are Exploiting Loyalty Programs

The convenience and allure of online travel websites cannot be overstated. From booking flights to securing accommodations, these platforms offer seamless experiences for travelers worldwide. However, the dark side of this digital realm emerges ...

Browser Security: Key Threats and Best Practices

As the primary interface between employees and the internet, web browsers play a vital role in the IT ecosystems of modern businesses. Today’s multi-cloud world sees companies and employees continue to adopt SaaS apps that run on thin ...

DigiCert and ReversingLabs partner to advance software supply chain security

DigiCert has partnered with ReversingLabs to enhance software security by combining advanced binary analysis and threat detection from ReversingLabs with DigiCert’s enterprise-grade secure code signing solution. DigiCert customers will ...

Kasada a 2023 Fortress Cyber Security Winner for AppSec

Platform’s superior defense against automated threats with invisible and enduring protection recognized in annual awards competition. The post Kasada a 2023 Fortress Cyber Security Winner for AppSec appeared first on Security Boulevard.

NinjaOne Patch Management enhancements mitigate security vulnerabilities

NinjaOne announced enhancements to NinjaOne Patch Management, delivering the latest automated patching solutions to maintain business operations and keep organizations secure. Patching is a tedious, time-consuming task but also a critical step to ...

ChatGPT Is Here, and So Are Its Risk Management Challenges

ChatGPT promises to transform all sorts of corporate business functions, and perhaps in the fullness of time those ... Read More The post ChatGPT Is Here, and So Are Its Risk Management Challenges appeared first on Hyperproof. The post ChatGPT ...

CVE-2023-34362 – MOVEit Transfer – An attack chain that retrieves sensitive information

MOVEit Transfer is a popular secure file transfer solution developed by Progress, a subsidiary of Ipswitch. At the moment, there are more than 2,500 MOVEit Transfer servers that are accessible from the internet, according to Shodan. On May 31, ...

Google Addresses Latest Zero-Day Affecting Chrome

Yesterday, Google addressed another 0-day vulnerability affecting Google Chrome. The post Google Addresses Latest Zero-Day Affecting Chrome appeared first on Flashpoint. The post Google Addresses Latest Zero-Day Affecting Chrome appeared first ...

Trulioo announces platform enhancements to automate KYB and KYC verification

Trulioo released new capabilities for automated business and person verification workflows. The latest update bolsters Trulioo global leadership by expanding geographic coverage and localization for person verification and further automating ...

Introducing Sift’s expanded partner program: Delivering Digital Trust & Safety to more businesses across the globe

Learn about Sift’s streamlined partner program, which extends Sift’s powerful fraud prevention technology to new customers. The post Introducing Sift’s expanded partner program: Delivering Digital Trust & Safety to more businesses ...

Telegram Hacking Channels: An Emerging Risk

Telegram, a popular encrypted messaging app known for its commitment to privacy and security, has ironically become a hub for cybercriminal activities. The platform is increasingly hosting channels that facilitate hacking, distribute stolen data, ...

Lacework simplifies cloud security with risk calculation on users’ permissions

Lacework announced new CIEM functionality to address the complex and growing challenges in managing identity threats and unnecessary risk within public cloud environments. With over 35,000 granular permissions across hyperscale cloud providers, ...

Exploit Forum, Initial Access Brokers, and Cybercrime on the Dark Web

The notorious Exploit.in dark web forum is a hotspot for cybercriminals and hosts an auction system. On this forum, malicious actors can share various hacking techniques, malware samples, and proof of concept for exploits.  Some threat actors on ...

Enveedo Strategy Execution Platform for Security strengthens cyber resiliency for businesses

Enveedo has launched its Strategy Execution Platform for Security that enables organizations to build and maintain cyber resiliency. The platform includes a risk management engine, on-demand access to vCISO guidance, and a real-time centralized ...

Malware as a Service: An Emerging Threat in 2023

Capitalizing on the convenience of the Software as a Service (SaaS) model, malicious actors are offering Malware as a Service (MaaS): ready-made malware packages on the dark web, presenting less technical individuals with the opportunity to ...

Appdome collaborates with GitHub to automate delivery of secure mobile apps

Appdome has integrated its platform with GitHub to accelerate the delivery of secure mobile apps globally. GitHub Actions is now part of the Appdome Dev2Cyber Agility Partner Initiative to accelerate the delivery of secure mobile apps globally. ...

Babuk Ransomware Group: What You Need to Know

The Babuk ransomware group emerged into the world of illicit activities relatively recently in 2021. Since then, they have conducted a series of high-profile ransomware attacks across various industries. The group targeted organizations across a ...

Grief Ransomware Group: What You Need to Know

Among the multitude of threat actors dominating the cybersecurity landscape, Grief ransomware group has risen to prominence. Known for their ruthless attacks and uncompromising tactics, Grief has quickly carved a niche for itself in the dark ...

Fingerprint unveils Smart Signals to fight and prevent fraud

Fingerprint launched Fingerprint Pro Plus, featuring the company’s latest innovation, Smart Signals. These new capabilities provide real-time, actionable intelligence that builds on Fingerprint’s browser and device identification ...

AI Offers Potential to Enhance The U.S. Department of Homeland Security

The establishment of the AI Task Force by the DHS demonstrates a commitment to harnessing the potential of AI in addressing emerging threats and safeguarding national security. By leveraging AI technology in various areas, such as supply chain ...