Application Security News and Articles


Salt Labs exposes a new vulnerability in popular OAuth framework, used in hundreds of online services

This post is the second in a series describing OAuth implementation issues that put companies at risk. We create these posts to share rich technical details, drawn from real-world use cases, to educate the broader industry on the nature of these ...

Turla’s Snake May be Down, But its Legacy Lives On

The Department of Justice’s recent revelation that it dismantled the Turla cybercriminal network was met with surprise—not that the authorities had taken it down and neutralized the Snake malware, but that Snake was still in use in the first ...

Axiado introduces AI-driven security processors

Axiado introduced the AX3000 and AX2000 trusted control/compute units (TCUs), a fully integrated AI-driven hardware security platform solutions designed to help detect cybersecurity and ransomware attacks on next-generation servers and ...

Red Hat Service Interconnect solves cross-platform and multi-cloud communication challenges

Red Hat announced Red Hat Service Interconnect, simplifying application connectivity and security across platforms, clusters and clouds. Based on the open source project, Skupper.io, Red Hat Service Interconnect empowers developers to more ...

Practical ChatGPT Use Cases in GRC

anecdotes reveals how ChatGPT can enhance Compliance. Read on as we disclose practical ChatGPT use cases that benefit GRC and boost its business function. The post Practical ChatGPT Use Cases in GRC appeared first on Security Boulevard.

Opti9 collaborates with Wasabi to provide clients with AI-powered ransomware detection

Opti9 has been selected by Wasabi Hot Cloud Storage as a Technical Alliance Partner to offer integrated disaster recovery and artificial intelligence (AI) powered ransomware detection services. As result of this trusted partnership, Wasabi ...

Sekoia.io raises €35 million to strengthen its positioning on the international stage

Sekoia.io raised €35 million in a new round of financing from Banque des Territoires, European investor Bright Pixel (former Sonae IM) and its historical investors Omnes Capital, Seventure and BNP Paribas Développement. The fundraising follows ...

Microsoft, GitHub announce application security testing tools for Azure DevOps

GitHub has announced that its application security testing tools are now more widely available for subscribers of Microsoft’s Azure DevOps Services. Enabling GitHub Advanced Security for Azure DevOps (Source: Microsoft) What is GitHub ...

GUEST ESSAY: A roadmap for wisely tightening cybersecurity in the modern workplace

Hackers can hurt your business or organization in many ways. First and foremost, cyberattacks can lead to data breaches in which sensitive information is stolen. If a cyber-criminal uses you as a way to get at your customers, suppliers, or … ...

US Sanctions North Korean University for Training Hackers

The US government has announced sanctions against four entities and one individual engaging in cyber activities on behalf of the North Korean government. The post US Sanctions North Korean University for Training Hackers appeared first on ...

IT employee piggybacked on cyberattack for personal gain

A 28-year-old former IT employee of an Oxford-based company has been convicted of blackmailing his employer and unauthorized access to a computer with intent to commit other offences, after pleading guilty during a hearing at Reading Crown Court, ...

SOC 2 Compliance Checklist: The ONLY one Need | anecdotes

Preparing for a SOC 2 audit does not need to be a burden. anecdotes has made it easier than ever with our FREE SOC 2 compliance checklist! The post SOC 2 Compliance Checklist: The ONLY one Need | anecdotes appeared first on Security Boulevard.

Legion AWS credential harvester and hijacker analyzed

Researchers from Cado Labs recently encountered an update to the emerging cloud-focused malware family, Legion. This sample iterates upon the credential harvesting features of its predecessor, with a continued emphasis on exploiting PHP web ...

New Honeywell OT Cybersecurity Solution Helps Identify Vulnerabilities, Threats

Honeywell announces the launch of Cyber Insights, a solution designed to help organizations identify vulnerabilities and threats in their OT environments. The post New Honeywell OT Cybersecurity Solution Helps Identify Vulnerabilities, Threats ...

White House Unveils New Efforts to Guide Federal Research of AI

White House announced new efforts to guide federally backed research on artificial intelligence (AI). The post White House Unveils New Efforts to Guide Federal Research of AI appeared first on SecurityWeek.

How Silverfort Protects Against the Risk from Shadow Admins

Shadow admins are one of the key attack surfaces that adversaries regularly take advantage of. The pattern of discovering a user who has been inadvertently assigned high access privileges is all-too-common in today’s cyber operations. This ...

The Psychology of Social Engineering Attacks: Understanding the Tactics of Cybercriminals

The Psychology of Social Engineering Attacks: Understanding the Tactics of Cybercriminals The Psychology of Social Engineering Attacks: Understanding the Tactics of Cybercriminals Introduction Introduction Cybercriminals use social engineering ...

Legitimate Android app transforms into data-snooping malware

ESET researchers have discovered a trojanized Android app named iRecorder – Screen Recorder. It was available on Google Play as a legitimate app in September 2021, with malicious functionality most likely added in August 2022. During its ...

Virtual Event Today: Threat Detection and Incident Response Summit

Join thousands of attendees as we dive into threat hunting tools and frameworks, and explore value of threat intelligence data in the defender’s security stack. (Register Now) The post Virtual Event Today: Threat Detection and Incident ...

Shopify Stores Privacy Policy: What you need to know?

Shopify has made it incredibly easy for businesses to build an online store with a sleek and streamlined dashboard that allows the sale of products via social media, digital marketplaces, blogs, emails, and other public forums. But since this ...