Application Security News and Articles


ChatGPT Injection: a new type of API Abuse attack may steal your OpenAI API credits

ChatGPT is spreading like wildfire all over the internet, being used in everything from casual tools to cybersecurity and even industrial applications. It’s so popular, I wouldn’t be shocked if it starts running a nuclear power plant soon (if ...

The THIRTEENTH Annual Disaster Recovery Breakfast: Changing of the Guard

Posted under: What a long, strange trip it’s been over the last 3 years. In fact, the last time I saw many of you was at the last Disaster Recovery Breakfast in 2020. Within two weeks of that event, the world shut down due to COVID. Well, a ...

Microsoft unveils AI-powered Security Copilot analysis tool

Microsoft has unveiled Security Copilot, an AI-powered analysis tool that aims to simplify, augment and accelerate security operations (SecOps) professionals’ work. Using Microsoft Security Copilot Security Copilot takes the form of a ...

I’d TAP That Pass

Summary: Given that: Temporary Access Passes (TAP) are enabled in the Azure AD tenantAND You have an authentication admin role in Azure AD You can assign users a short lived password called a Temporary Access Pass (TAP) that satisfies most ...

Noname Security Launches API Security Platform to Help Organizations Increase Cyber Resilience

Why Enterprises Need API Security Enterprises face a challenging environment: economic headwinds, efficiency, and cybersecurity resilience dominate board meeting discussions amid rapid changes in technology. APIs especially have gone from playing ...

We’ve Been Using Email Since 1971—It’s Time We Make it Secure

An estimated 333 billion emails were sent and received daily worldwide in 2022. Email is one of the most important communication tools used today. It’s also a powerful, accessible, effective and low-cost tool for cybercriminals to use. As ...

New Wi-Fi Attack Allows Traffic Interception, Security Bypass

A group of academic researchers devised an attack that can intercept Wi-Fi traffic at the MAC layer, bypassing client isolation. The post New Wi-Fi Attack Allows Traffic Interception, Security Bypass appeared first on SecurityWeek.

Tips and Tricks to Transform Your Cybersecurity Board Report

Simply being “cyber aware” is an unviable option for board members as the impact of cybersecurity expands beyond IT systems. An unnoticed security gap or dated risk assessment are minor mistakes that can lead to cyber breaches that could ...

Fix Your Kubernetes Misconfigurations Faster with Automated Fix Pull Requests

We're excited to announce the launch of our latest Fairwinds Insights feature, Automated Fix Pull Requests (PRs). You can automatically fix many Kubernetes misconfigurations faster using the new Automated Fix PRs functionality. This new feature ...

Casino Giant Crown Resorts Investigating Ransomware Group’s Data Theft Claims

Australian casino giant Crown Resorts says the Cl0p ransomware group contacted them to claim data theft in the GoAnywhere attack. The post Casino Giant Crown Resorts Investigating Ransomware Group’s Data Theft Claims appeared first on ...

DEA Using AirTags to Track Packages (and Drug Manufacturers)

It was recently reported in Forbes that the U.S. Drug Enforcement Administration (DEA) was using Apple’s AirTags to help track drug manufacturers. According to the March 23 article by Thomas Brewster, “[B]order agents intercepted two ...

Latest State of API Security report: 400% increase in attackers and more!

The latest Salt Labs State of API Security report is out, and we’re excited to share with you some of the key findings. The security industry news has frequently covered high-profile application programming interface (API) breaches over the ...

Google Links More iOS, Android Zero-Day Exploits to Spyware Vendors

Google has linked several zero-day vulnerabilities used last year to target Android and iOS devices to commercial spyware vendors. The post Google Links More iOS, Android Zero-Day Exploits to Spyware Vendors appeared first on SecurityWeek.

Most Weaponized Vulnerabilities of 2022 and 5 Key Risks: Report

A new research report discusses the five most exploited vulnerabilities of 2022, and the five key risks that security teams should consider. The post Most Weaponized Vulnerabilities of 2022 and 5 Key Risks: Report appeared first on SecurityWeek.

RiskLens Launches Executive Board Reporting Service for Cyber Risk

As cybersecurity becomes a regular topic of board-level discussion, CISOs, CROs and other risk and security executives need a better way to translate the highly technical language of cyber risk management into business terms that non-technical ...

Over 200 Organizations Targeted in Chinese Cyberespionage Campaign

Chinese cyberespionage group Mustang Panda was seen targeting maritime, shipping, border control, and immigration organizations in recent attacks. The post Over 200 Organizations Targeted in Chinese Cyberespionage Campaign appeared first on ...

QuSecure and Accenture Test Multi-Orbit Communications Link Using Post-Quantum Cryptography

Quantum cybersecurity firm QuSecure has collaborated with Accenture to develop a multi-orbit quantum-resilient satellite communications capability.  The post QuSecure and Accenture Test Multi-Orbit Communications Link Using Post-Quantum ...

What Makes an Effective Anti-Bot Solution?

While there are likely many different approaches, here are a few points that are important for enterprises to consider when evaluating bot solutions. The post What Makes an Effective Anti-Bot Solution? appeared first on SecurityWeek.

Clouds vs Edges: Which Computing Wins the Race?

One of the most pressing challenges for businesses today is finding the right balance between cutting-edge technology and practical solutions that can help them achieve their goals. Two of the most talked-about computing technologies today are ...

How cybersecurity decision-makers perceive cyber resilience

In an economic climate putting immense pressure on business leaders to prove ROI and team efficiency – a new report from Immersive Labs looks into the lack of confidence cyber leaders have in their team’s preparation and abilities to ...