Application Security News and Articles


Imperva and Kong Partner to Bring API Security to the Gateway for Enhanced API Management

Imperva is delighted to announce a new partnership with Kong Inc, provider of the leading cloud-native API platform, to offer best-in-class API Security to users of the Kong platform. Through the new partnership, Kong Enterprise customers can ...

Should physical proximity be a required MFA factor?

Why it’s time to move to high assurance passwordless MFA with physical proximity. The most... The post Should physical proximity be a required MFA factor? appeared first on Entrust Blog. The post Should physical proximity be a required MFA ...

What You Need to Know about PIPEDA Compliance

PIPEDA compliance is a requirement for any organization handling the personal information of Canadian citizens. Read on for five tips to ensure compliance. The post What You Need to Know about PIPEDA Compliance appeared first on Security Boulevard.

Dasera Scores $12M Funding for Cloud Data Security

The Series A funding round was led by Storm Ventures and brings the total raised by Dasera to $20 million. The post Dasera Scores $12M Funding for Cloud Data Security appeared first on SecurityWeek.

Lacework Adds Custom Risk Scoring Capability to CNAPP

Lacework today announced it has added a risk vulnerability scoring capability to its cloud-native application protection platform (CNAPP) that can be customized to a specific cloud computing environment. Lacework also announced it has expanded ...

Rethinking the Status Quo of Mobile App Security

Most executives view mobile applications as a crucial component of their organization’s business strategy. Mobile apps help companies generate revenue, engage with customers and create new business opportunities. With mobile apps accounting for ...

Examples of SAST Tools for App Security

Looking for the best SAST tools for your software product? We’ve listed 3 SAST tools worth consideration. Check them out!Continue reading on Medium »

Enterprises Exposed to Hacker Attacks Due to Failure to Wipe Discarded Routers

Discarded enterprise routers are often not wiped and contain secrets that could be highly useful to malicious hackers. The post Enterprises Exposed to Hacker Attacks Due to Failure to Wipe Discarded Routers appeared first on SecurityWeek.

Maximizing security awareness team success through organizational structure

The post Maximizing security awareness team success through organizational structure appeared first on Click Armor. The post Maximizing security awareness team success through organizational structure appeared first on Security Boulevard.

What Uber’s Latest Data Breach Means for Third-Party Risk

Uber is in the headlines once again for losing sensitive data. However, this round of data exposure isn’t due to a breach of Uber’s facilities. Rather, New Jersey-based law firm Genova Burns was storing data about Uber’s drivers, including ...

Influence Tactics in Everyday Life: Collections

Social engineering and collections may seem like two vastly different professions. However, they share many similarities when it comes to […] The post Influence Tactics in Everyday Life: Collections appeared first on Security Boulevard.

Google Patches Second Chrome Zero-Day Vulnerability of 2023

Google warns of another zero-day vulnerability in Chrome, only days after addressing a similar issue. The post Google Patches Second Chrome Zero-Day Vulnerability of 2023 appeared first on SecurityWeek.

Oracle Releases 433 New Security Patches With April 2023 CPU

Oracle’s April 2023 critical patch update (CPU) includes 433 new security patches, including more than 70 that fix critical vulnerabilities. The post Oracle Releases 433 New Security Patches With April 2023 CPU appeared first on SecurityWeek.

Coro Raises $75 Million for Mid-Market Cybersecurity Platform

Coro, an enterprise cybersecurity platform for mid-market organizations, has raised $75 million from Energy Impact Partners. The post Coro Raises $75 Million for Mid-Market Cybersecurity Platform appeared first on SecurityWeek.

Microsoft: Iranian Hackers Moved From Recon to Targeting US Critical Infrastructure

A subgroup of Iran-linked APT Phosphorus (Mint Sandstorm) has started to quickly adopt PoC exploit code targeting vulnerabilities in internet-facing applications. The post Microsoft: Iranian Hackers Moved From Recon to Targeting US Critical ...

US, UK: Russia Exploiting Old Vulnerability to Hack Cisco Routers

US and UK government agencies have issued a joint warning for Russian group APT28 targeting Cisco routers by exploiting an old vulnerability. The post US, UK: Russia Exploiting Old Vulnerability to Hack Cisco Routers appeared first on SecurityWeek.

Researchers discover sensitive corporate data on decommissioned routers

Looking at configuration data, 56% of decommissioned routers disposed of and sold on the secondary market contained sensitive corporate data, according to ESET. Of the networks that had complete configuration data available: 22% contained ...

RSAC Fireside Chat: Demystifying cloud-stored data via ‘data security posture management’

In the age before the cloud, data security was straightforward. Related: Taming complexity as a business strategy Enterprises created or ingested data, stored it and secured it in a physical data center. Data security was placed in the hands of ...

API Penetration Testing Checklist – Your Ultimate Hack Plan

Check out the API Penetration Testing checklist, which outlines how to conduct an effective API security assessment for your organization. The post API Penetration Testing Checklist – Your Ultimate Hack Plan appeared first on Indusface. The ...

5 free online cybersecurity resources for small businesses

As cyberattacks increase in frequency and sophistication, small and medium-sized businesses (SMBs) become more vulnerable to cyber threats. Unlike larger enterprises, SMBs often lack the financial and technical resources to secure their networks ...