Application Security News and Articles


Kali Linux 2023.2 released: New tools, a pre-built Hyper-V image, a new audio stack, and more!

Offensive Security has released Kali Linux 2023.2, the latest version of its popular penetration testing and digital forensics platform. New tools in Kali Linux 2023.2 Aside from updates for existing tools, a new Kali version usually comes with ...

How to Integrate a Third-Party API into a WordPress Website

API or Application Programmable Interface connects a website or software with other applications. And it helps to send, receive and modify data on each end. Integrating a third-party API is considered a complex task in the WordPress ecosystem. ...

The strategic importance of digital trust for modern businesses

In this Help Net Security interview, Deepika Chauhan, CPO at DigiCert, talks about the importance of maintaining high trust assurance levels for businesses in today’s digital landscape. How does DigiCert define “digital trust,” ...

Managing mental health in cybersecurity

In this Help Net Security video, Jason Lewkowicz, Chief Services Officer at Optiv, discusses mental health in cybersecurity, which needs more attention. There is a confluence of factors – from the cybersecurity talent shortage and reductions in ...

Organizations are placing OT cybersecurity responsibility on CISOs

Protecting operational technology (OT) systems is now more critical than ever as more organizations connect their OT environments to the internet, according to Fortinet. Although IT/OT convergence has many benefits, it is being hampered and ...

Attackers leave organizations with no recovery option

Organizations of all sizes are increasingly falling victim to ransomware attacks and inadequately protecting against this rising cyberthreat, according to Veeam. One in seven organizations will see almost all (>80%) data affected as a result of a ...

Discord Admins Hacked by Malicious Bookmarks

A number of Discord communities focused on cryptocurrency have been hacked this past month after their administrators were tricked into running malicious Javascript code disguised as a Web browser bookmark. The post Discord Admins Hacked by ...

The Hacker Mind Podcast: Tales From A Ransomware Negotiator

Say you’re an organization that’s been hit with ransomware. At what point do you need to bring in a ransomware negotiator? Should you pay, should you not? Mark Lance, the VP of DFIR and threat intelligence for GuidePoint Security, provides ...

SEO Poisoning: How Threat Actors Are Using Search Engines to Compromise Organizations

SEO poisoning is a black-hat technique of abusing and tricking search engine algorithms to affect how they index and rank sites. Search engines utilize various factors like keywords, backlinks, and more to determine the relevance and order of ...

Listen to These Recordings: Deepfake Social Engineering Scams Are Scaring Victims

Deepfake social engineering scams have become an increasingly scary trend among cybercriminals to socially engineer victims into submission. The threat actors are using Artificial Intelligence (AI) and Machine Learning (ML) voice cloning tools to ...

BSidesSF 2023 – Mike Kiser – New Face, Who Dis? Recent Adversarial Approaches to Facial Recognition

Our thanks to BSidesSF for publishing their presenter’s superlative BSidesSF 2023 content on the organizations’ YouTube channel. Permalink The post BSidesSF 2023 – Mike Kiser – New Face, Who Dis? Recent Adversarial Approaches to ...

Apptega Launches GLBA Framework to Coincide with Impending Updates

For companies in the financial industry, or those that handle nonpublic personal information (NPI), the Gramm-Leach-Billey Act Safeguards (GLBA) should be at the forefront of their information security practices. Under the GLBA Safeguards, ...

Why Cloud Did Not Kill the Data Center

Back in the day, you know, pre-cloud, life in the data center may have not been easy, but at least it was under control. Well, sort of. We controlled the vendors (we thought). We controlled growth (well, our users did that). But the big issue was ...

How Asset Management Bolsters Cybersecurity

Asset management plays an increasingly important role in cybersecurity. More than just a mere inventory list that you track in a spreadsheet, effective cyber asset management is a strategic weapon that, when wielded correctly, can fortify your ...

Salt Wins UK Trophy for Best Cybersecurity Solution!

We have smashing news to share! Salt Security has been named Cybersecurity Solution of the Year in the Prestigious National Technology Awards – our first award in the UK and a brilliant recognition! Organized by National Technology News, the ...

Attackers hacked Barracuda ESG appliances via zero-day since October 2022

Barracuda says that the recently discovered compromise of some of it clients’ ESG appliances via a zero-day vulnerability (CVE-2023-2868) resulted in the deployment of three types of malware and data exfiltration. The company did not say ...

Randall Munroe’s XKCD ‘The Six Platonic Solids’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘The Six Platonic Solids’ appeared first on Security Boulevard.

‘Predator’ — Nasty Android Spyware Revealed

Intellexa mercenary spyware chains five unpatched bugs—plus ‘Alien’ technology The post ‘Predator’ — Nasty Android Spyware Revealed appeared first on Security Boulevard.

9 Common IAM Risks & How to Mitigate Them

Reading Time: 6 minutes 9 Common IAM Risks and How To Mitigate Them If Identity and Access Management is on your mind, you’re not alone. Recognizing a weak point and seeking out stronger protections is the first step to securing your ...

The Lucrative Economics of API Hacking

Learn how you can make more money in less time on a consistent basis by focusing on API pentesting rather than bug bounty hunting. The post The Lucrative Economics of API Hacking appeared first on Dana Epp's Blog. The post The Lucrative Economics ...