Application Security News and Articles


Red teaming a country: Lessons learned from Sakura Samurai’s Indian government hack investigation

In the midst of the COVID-19 pandemic, John Jackson was looking for ways to stay busy. Jackson is a renowned offensive security consultant and the founder of Sakura Samurai, a (now defunct) hacking crew that gained notoriety for plumbing the ...

Fusion Risk Management TPRM enhancements deliver continuous monitoring of third parties

Fusion Risk Management announced expanded functionality of its third-party risk management (TPRM) offering. The enhanced solution delivers continuous monitoring of third parties beyond its traditional instance as well as an evaluation of ...

Iranian Hackers Using New Windows Kernel Driver in Attacks

Iranian threat actors use a Windows kernel driver called ‘Wintapix’ in attacks against Middle East targets. The post Iranian Hackers Using New Windows Kernel Driver in Attacks appeared first on SecurityWeek.

IRONSCALES and Infinigate collaborate to provide customers with email security solution

IRONSCALES has partnered with the Infinigate Group to distribute IRONSCALES’ cloud email security platform in the Benelux, the Nordics, and Switzerland regions, with a view to widen the partnership across the wider EMEA territory. “Infinigate ...

Google Launches Bug Bounty Program for Mobile Applications

Google introduces Mobile VRP bug bounty program for vulnerabilities in its mobile applications. The post Google Launches Bug Bounty Program for Mobile Applications appeared first on SecurityWeek.

Rheinmetall Says Military Business Not Impacted by Ransomware Attack

Rheinmetall confirms being hit by Black Basta ransomware group, but says its military business is not affected. The post Rheinmetall Says Military Business Not Impacted by Ransomware Attack appeared first on SecurityWeek.

Red Hat Pushes New Tools to Secure Software Supply Chain

Red Hat rolls out a new suite of tools and services to help mitigate vulnerabilities across every stage of the modern software supply chain. The post Red Hat Pushes New Tools to Secure Software Supply Chain appeared first on SecurityWeek.

How Software Supply Chain Vulnerabilities Lead to Attacks

By Esther Shein Software supply chain attacks are increasingly gaining attention. Why? Software developers today have grown increasingly reliant on vendors, suppliers, and partners, so the software supply chain has become a key factor in the ...

Conceal and White Rock Cybersecurity partner to isolate browsing sessions

Conceal has announced a new strategic partnership with White Rock Cybersecurity. “White Rock Cybersecurity is committed to delivering innovative, scalable, and manageable solutions in information technology,” said James Range, CEO of ...

Three Biggest Issues Driving Cybersecurity

Cyberattacks have become one of the top concerns for technology executives and business owners. Cybercrime will cost companies $10.5 billion annually by 2025. The estimated cost of cybercrime in 2021 was $6.1 trillion, which is expected to grow ...

Discover Dangling Domains that point to your cloud assets to prevent subdomain takeover

Dangling domains are DNS records that point to a domain or subdomain that no longer exists or is not configured properly. It occurs when a domain or subdomain has been deleted, but the DNS record that resolves the domain or subdomain still exists ...

SuperMailer Abuse Explodes, Now Responsible for 14% of All Credential Phish Discovered in Inboxes

By: Brad Haas  In early 2023, an increasing number of credential phishing URLs in emails reported to the Cofense Phishing Defense Center (PDC) have included a unique string showing that they were produced by a legitimate email newsletter program ...

Why Remote Work Data Protection Matters More Than Ever

Every business now needs a remote work data protection policy. What do you need to know to make sure you're protected? The post Why Remote Work Data Protection Matters More Than Ever appeared first on Security Boulevard.

N-able partners with JCDC to reduce security risk for MSPs

N-able is collaborating with the Joint Cyber Defense Collaborative (JCDC) to help create a more secure global ecosystem and work towards helping reduce security risk for MSPs and their customers. The Cybersecurity and Infrastructure Security ...

WithSecure releases Cloud Security Posture Management to identify insecure cloud configurations

WithSecure has released Cloud Security Posture Management, a new module for its WithSecure Elements security platform, that identifies insecure cloud configurations attackers use to compromise networks. It’s now become commonplace for ...

Mastercard collaborates with HealthLock to protect medical data

Mastercard and HealthLock have partnered to offer millions of Americans help in protecting themselves against medical bill fraud, claim errors and overcharges. Consumers who link their insurance accounts to the HealthLock platform gain the ...

Summer-Time Scams: The Return of Vacation-Request Phishing Emails

Author: Andrew Remo  SEG Bypassed: Trend Micro, Microsoft  The summer season is fast approaching, and with it comes employee PTO requests. The Phishing Defence Center (PDC) recently observed a phishing campaign where the threat actor sent an ...

Credible Handwriting Machine

In case you don’t have enough to worry about, someone has built a credible handwriting machine: This is still a work in progress, but the project seeks to solve one of the biggest problems with other homework machines, such as this one that I ...

In the News | A Step-by-Step Guide to Preparing for a Cybersecurity Audit

This article was originally published in The Learning Counsel on 5.8.23 by Charlie Sander, CEO at ManagedMethods. A cybersecurity audit gives you visibility into how effective your security measures are performing K-12 school districts put ...

Cutting Through the Noise: What is Zero Trust Security?

With proactive steps to move toward Zero Trust, technology leaders can leverage an old, yet new, idea that must become the security norm. The post Cutting Through the Noise: What is Zero Trust Security? appeared first on SecurityWeek.