Application Security News and Articles


Report: Chinese State-Sponsored Hacking Group Highly Active

Chinese hacking group linked previously to attacks on U.S. state government computers is still “highly active” The post Report: Chinese State-Sponsored Hacking Group Highly Active appeared first on SecurityWeek.

Asset Visibility: A Critical Component of Security Hygiene

As the world becomes increasingly digitized, cybercrime has become one of the most significant threats that organizations face. Environments are expanding at a rapid pace and cybercriminals are always looking for new ways to exploit ...

Visualize Your Open Source Governance With BOM Doctor

  The post Visualize Your Open Source Governance With BOM Doctor appeared first on Security Boulevard.

Meet The Team Behind Mayhem: Come See Us At These Upcoming April 2023 Events

We have a number of upcoming events planned for April 2023. Read on to learn more. The post Meet The Team Behind Mayhem: Come See Us At These Upcoming April 2023 Events appeared first on Security Boulevard.

Elastic Unfurls Cloud Security Platform for AWS

Elastic today launched a cloud security analytics platform that provides visibility into Amazon Web Services (AWS) environments. The Elastic Search platform is based on the open source search engine platform it developed. Mike Nichols, vice ...

APIs: Driving Innovation, Fueling Security Significance

APIs are the driving force of innovation within every organization, but not without a price. APIs enable the seamless connection between customers, vital data and services while allowing engineering teams to quickly iterate with better ...

Identity Attack Watch: AD Security News, March 2023

As cyberattacks targeting Active Directory continue to rise, AD security, identity, and IT teams face mounting pressure to monitor the evolving AD-focused threat landscape. To assist IT professionals in comprehending and preventing attacks that ...

Votiro Raises $11.5 Million to Prevent File-Borne Threats

Votiro raised $11.5 million in a Series A investment round led by Harvest Lane Asset Management. The post Votiro Raises $11.5 Million to Prevent File-Borne Threats appeared first on SecurityWeek.

Lumen Technologies Hit by Two Cyberattacks

Communications and IT company Lumen Technologies fell victim to two cyberattacks that led to data theft. The post Lumen Technologies Hit by Two Cyberattacks appeared first on SecurityWeek.

Twitter Presses GitHub to Turn Over User Who Leaked Source Code

When Twitter joined the ranks of tech companies whose source code leaked online, it was met with little surprise and a whole lot of unease over what the leak might mean for the platform’s security. “Unlike other recent source code leaks, it ...

Sophisticated 3CX Software Supply Chain Attack Affects Millions of Users

On March 29th, 2023, it was published that 3CX, the international VoIP IPBX software, was under an ongoing software supply chain attack. The attackers had trojanized the 3CX communication installer software, reportedly used by over 12 million ...

API Attacks Rise 400% in Last Six Months

Attacks on APIs continue to rise sharply. New findings from Salt Labs found a shocking 400% increase in unique API attackers in the last six months. Interestingly, the report also discovered that nearly 80% of attacks occur over authenticated ...

Leaked Documents Detail Russia’s Cyberwarfare Tools, Including for OT Attacks

Documents show that Russian IT company NTC Vulkan was requested to develop offensive tools for government-backed hacking group Sandworm. The post Leaked Documents Detail Russia’s Cyberwarfare Tools, Including for OT Attacks appeared first ...

Mandiant Investigating 3CX Hack as Evidence Shows Attackers Had Access for Months

Several cybersecurity companies have published blog posts, advisories and tools to help organizations that may have been hit by the 3CX supply chain attack. The post Mandiant Investigating 3CX Hack as Evidence Shows Attackers Had Access for ...

Vue vs Angular: Which Framework to Choose?

When you are developing an application, there are many decisions to make. You can use the same language for both server-side and client-side development or use completely different languages on both sides of the application. Regarding the ...

Understanding OCR in Banking: Definition and Applications

What is OCR full form in Banking? OCR is the process of using technology to read characters from printed or handwritten text included inside digital images of actual documents, such scanned paper documents (optical character recognition). OCR’s ...

Severe Azure Vulnerability Led to Unauthenticated Remote Code Execution

A high-severity vulnerability in Azure Service Fabric Explorer could have allowed a remote, unauthenticated attacker to execute arbitrary code. The post Severe Azure Vulnerability Led to Unauthenticated Remote Code Execution appeared first on ...

Biometric Verification in Fintech: The Future of Secure Online Transactions

Financial institutions (FIs) or Fintechs have historically been hotspots for fraudulent activity. The sector is a popular target for identity theft and online banking fraud, as well as financial crimes such as money laundering and terrorism ...

New infosec products of the week: March 31, 2023

Here’s a look at the most interesting products from the past week, featuring releases from BreachLock, HackNotice, LOKKER, Nile, and Tausight. HackNotice Actions helps people to understand the extent of their data exposure HackNotice is ...

Overcoming obstacles to introduce zero-trust security in established systems

In this Help Net Security interview, Michal Cizek, CEO at GoodAccess, discusses the crucial balance between leveraging distributed resources and maintaining top-notch security measures. With the growing remote work trend, Cizek highlights the ...