Application Security News and Articles


CVE-2023-29552: Abusing the SLP Protocol to Launch Massive DDoS Amplification Attacks

On April 25, 2023, researchers at Bitsight and Curesec jointly discovered a high-severity vulnerability — tracked as CVE-2023-29552 — in the Service Location Protocol (SLP), a legacy Internet protocol. What is SLP protocol? Service Location ...

Using Threat Intelligence to Get Smarter About Ransomware

Given the crippling effects ransomware has had and indications that these types of attacks aren’t slowing down, it makes sense to look to threat intelligence to help. The post Using Threat Intelligence to Get Smarter About Ransomware appeared ...

Meta Swiftly Neutralizes New ‘NodeStealer’ Malware

Meta says it disrupted the new NodeStealer malware, which likely has Vietnamese origins, within weeks after it emerged. The post Meta Swiftly Neutralizes New ‘NodeStealer’ Malware appeared first on SecurityWeek.

Has the Altruism Model of Open Source Security Peaked?

With an executive order, the Biden administration attempted to address concerns around open source software’s security. In Section 4 of Executive Order 14028, Improving the Nation’s Cybersecurity, open source and the software supply chain ...

AppOmni releases Salesforce Community Cloud Scanner

AppOmni announced free Salesforce Community Cloud Scanner to help organizations secure their Salesforce Community websites from data exposure risks and misconfigurations. Salesforce data leaks recently identified by Krebs on Security have ...

Orca Security Integrates CNAPP With Microsoft GPT Service

Orca Security today announced it has fully integrated its cloud security platform with the Microsoft Azure OpenAI GPT-4 generative artificial intelligence (AI) service to make its simpler to, for example, identify code that can be used to ...

Phishing Attacks Target BYOD Through Private Messaging Apps

Employees’ personal devices pose a threat to organizations as bring-your-own-device (BYOD) policies cause security headaches for IT professionals, according to a SlashNext survey of 300 tech workers and employers. The study revealed 95% of ...

Arthur Shield tackles safety and performance issues in large language models

Arthur introduced a powerful addition to its suite of AI monitoring tools: Arthur Shield, a firewall for large language models (LLMs). This patented new technology enables companies to deploy LLM applications like ChatGPT more safely within an ...

Cisco Warns of Critical Vulnerability in EoL Phone Adapters

Cisco warns of a critical-severity RCE vulnerability impacting EoL SPA112 2-Port Phone Adapters. The post Cisco Warns of Critical Vulnerability in EoL Phone Adapters appeared first on SecurityWeek.

US Announces Takedown of Card-Checking Service, Charges Against Russian Operator

The US announces charges against Denis Gennadievich Kulkov, the creator and operator of card-checking platform Try2Check since 2005 until it was taken down this week. The post US Announces Takedown of Card-Checking Service, Charges Against ...

Harris to Meet With CEOs About Artificial Intelligence Risks

The Biden administration plans to announce an investment of $140 million to establish seven new AI research institutes, administration officials said. The post Harris to Meet With CEOs About Artificial Intelligence Risks appeared first on ...

A Comprehensive Guide to K-12 Cybersecurity and Safety

Whether they take the form of a targeted attack or an accidental leak, cyber incidents are a major threat to the U.S. school system. From public school districts to higher education and everywhere in between, malicious actors are chomping at the ...

Apple Releases First-Ever Security Updates for Beats, AirPods Headphones

Apple has released firmware updates for Beats and AirPods to patch a vulnerability that can be exploited to gain access to headphones via a Bluetooth attack. The post Apple Releases First-Ever Security Updates for Beats, AirPods Headphones ...

When Good APIs Go Bad: Uncovering 3 Azure API Management Vulnerabilities

Learn how now-patched Azure API Management service vulnerabilities revealed by the Ermetic research team enabled malicious actions The post When Good APIs Go Bad: Uncovering 3 Azure API Management Vulnerabilities appeared first on Ermetic. The ...

Large Language Models and Elections

Earlier this week, the Republican National Committee released a video that it claims was “built entirely with AI imagery.” The content of the ad isn’t especially novel—a dystopian vision of America under a second term with President Joe ...

ChatGPT and other AI-themed lures used to deliver malicious software

“Since the beginning of 2023 until the end of April, out of 13,296 new domains created related to ChatGPT or OpenAI, 1 out of every 25 new domains were either malicious or potentially malicious,” Check Point researchers have shared on ...

Apricorn introduces Aegis NVX hardware-encrypted USB storage device

Employing proprietary architecture, the Aegis NVX is the first Apricorn encrypted device to feature an NVME SSD inside, to address the immediate protection of raw data delivered directly from its source at high speeds. Initial capacity offerings ...

How to Prevent Evasive File-Based Threats 

In the age of rampant security threats, the ever-evolving cybersecurity landscape demands continuous adaptation and innovation. Attacks continue to rise, the associated costs are reaching an all-time high, and cybercriminals are developing ...

Enhance Your Cybersecurity With An SBOM

With all the cybersecurity benefits an SBOM offers, it’s a wonder they weren’t used in the software development life cycle long ago. Today, the need for SBOMs has grown more urgent because open source has become a core part of modern software ...

Protecto boosts privacy protection with GPU technology from NVIDIA

Protecto announced it has been able to boost the performance of its privacy models on NVIDIA GPUs, allowing the discovery of privacy issues up to 10x faster than before. With the help of powerful NVIDIA GPU technology, Protecto has delivered ...