Application Security News and Articles


New SBOM Hub Designed to Help All Stakeholders in Software Distribution Chain

Lineaje introduces SBOM360 Hub, an exchange allowing software producers, sellers, and consumers to publish, share and use SBOMs and related compliance artifacts. The post New SBOM Hub Designed to Help All Stakeholders in Software Distribution ...

Kyndryl and SAP boost partnership to ease digital transformation

Kyndryl has expanded strategic partnership with SAP focused on developing new solutions to help customers solve their most complex digital business transformation challenges. Under their expanded collaboration, the companies have leveraged SAP ...

Which Cyberattack Vectors Were Most Pervasive in 2022? (Part 2)

“What has been will be again, and what has been done will be done again; there is nothing new under the sun.” The post Which Cyberattack Vectors Were Most Pervasive in 2022? (Part 2) appeared first on Security Boulevard.

Is SSPM Enough for the SaaS Security Identity Fabric?

Discover the limitations of SSPM in protecting the identity fabric of SaaS security and explore alternative solutions for a comprehensive security strategy. The post Is SSPM Enough for the SaaS Security Identity Fabric? appeared first on Security ...

5 Tips on How to Align Sales and Compliance Teams

anecdotes advises how to improve your sales and Compliance team collaboration. Get on the same team to up sales, meet Compliance and grow your business. The post 5 Tips on How to Align Sales and Compliance Teams appeared first on Security Boulevard.

Aviatrix Distributed Cloud Firewall Streamlines App Security

Aviatrix today made generally available a Distributed Cloud Firewall (DCF) that programmatically pushes and enforces cybersecurity policies for cloud computing environments via a central console. Rod Stuhlmuller, vice president of solutions ...

When ChatGPT Goes Phishing

ChatGPT has become a powerful tool for security professionals seeking to enrich their work. However, its widespread use has raised concerns about the potential for bad actors to misuse the technology. Experts are worried that ChatGPT’s ...

A Comparison of Visible Watermarks and LeaksID Anti-Leak Labels

This article compares visible watermarks with LeaksID's anti-leak labels (fingerprints) and emphasizes the advantages of LeaksID's undetectable labeling. The post A Comparison of Visible Watermarks and LeaksID Anti-Leak Labels appeared first on ...

Google Announces New Rating System for Android and Device Vulnerability Reports

Google is updating its vulnerability reports rating system to encourage researchers to provide more details on the reported bugs. The post Google Announces New Rating System for Android and Device Vulnerability Reports appeared first on SecurityWeek.

Phishing Attacks Shift to IT, Online Services-Related Campaigns 

More IT and online services-related email subjects are being used as a phishing lure, as phishing emails continue to be one of the most common methods to perpetuate malicious attacks on organizations worldwide. These were among the key findings ...

PoC Tool Exploits Unpatched KeePass Vulnerability to Retrieve Master Passwords

Researcher publishes PoC tool that exploits unpatched KeePass vulnerability to retrieve the master password from memory. The post PoC Tool Exploits Unpatched KeePass Vulnerability to Retrieve Master Passwords appeared first on SecurityWeek.

2023 State of the Threat for Financial Services and Banks

Arkose Labs’ extensive analysis in 2022 delved into current threats across various industries, revealing the frequency and types of attacks that plague today’s landscape. Explore valuable insights on emerging threats for financial services ...

Applying Service Accounts Security Best Practices with Silverfort

Managing service accounts can be a daunting task for organizations, as service accounts are scattered across different environments and are used by various business applications, and are typically forgotten about unsupervised. Meaning in most ...

Cisco Says PoC Exploits Available for Newly Patched Enterprise Switch Vulnerabilities

Cisco has released patches for critical vulnerabilities in small business switches for which public proof-of-concept (PoC) code exists. The post Cisco Says PoC Exploits Available for Newly Patched Enterprise Switch Vulnerabilities appeared first ...

Aqua Security collaborates with ServiceNow to accelerate cloud native risk remediation

Aqua Security integrates with the ServiceNow to enable joint customers to identify vulnerabilities in running containers with the broadest coverage across operating systems and programming languages, and with the highest accuracy. Security and ...

Millions of Smartphones Distributed Worldwide With Preinstalled ‘Guerrilla’ Malware

A threat actor tracked as Lemon Group has control over millions of smartphones distributed worldwide thanks to preinstalled Guerrilla malware. The post Millions of Smartphones Distributed Worldwide With Preinstalled ‘Guerrilla’ ...

Cisco fixes critical flaws in Small Business Series Switches

Nine vulnerabilities – 4 of them critical – have been found in a variety of Cisco Small Business Series Switches. PoC exploit code is available (but not public), and there is no indication that they are being exploited in the wild. ...

What is the Grey Market: 5 Ways to Protect Your Business

Business is one great balancing act: on the one hand, you strive to derive the maximum benefit from the available opportunities, and on the other hand, you must protect yourself from potential threats.  The grey market, aka the shadow market or ...

RSAC Fireside Chat: Deploying Hollywood-tested content protection to improve mobile app security

Your go-to mobile apps aren’t nearly has hackproof as you might like to believe. Related: Fallout of T-Mobile hack Hackers of modest skill routinely bypass legacy security measures, even two-factor authentication, with techniques such as ...

API Security: Authorization, Rate Limiting, and Twelve Ways to Protect APIs

41% of organizations suffered an API security incident. Here are 12 methods that you need to incorporate in order to secure and protect APIs. The post API Security: Authorization, Rate Limiting, and Twelve Ways to Protect APIs appeared first on ...