Application Security News and Articles


Choosing the Right Database for your Mobile App & 7 Emerging Mobile App Databases

In 2023, mobile app development is expected to continue its upward trend, with the global mobile app market projected to grow to $935 billion by...Read More The post Choosing the Right Database for your Mobile App & 7 Emerging Mobile App ...

CISA Ships ‘Untitled Goose Tool’ to Hunt for Microsoft Azure Cloud Infections

The U.S. government’s cybersecurity agency ships a new tool to help network defenders hunt for signs of compromise in Microsoft’s Azure and M365 cloud deployments. The post CISA Ships ‘Untitled Goose Tool’ to Hunt for Microsoft Azure ...

USENIX Security ’22 – Shawn Shan, Arjun Nitin Bhagoji, Haitao Zheng, Ben Y. Zhao – ‘Poison Forensics: Traceback of Data Poisoning Attacks in Neural Networks’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Shawn Shan, Arjun Nitin Bhagoji, ...

Simplifying DDoS Protection in Large Service Provider Networks

Distributed denial of service (DDoS) attacks pose a significant threat to service providers; they have the potential to bring down critical infrastructure and disrupt business operations. In today's digital age, protecting against DDoS attacks is ...

Making SBOMs Useful

Interview with Tom Alrich, well-known SBOM and supply chain security consultant. The post Making SBOMs Useful appeared first on Security Boulevard.

Critical WooCommerce Payments Vulnerability Leads to Site Takeover

A critical-severity flaw in the WooCommerce Payments WordPress plugin could allow attackers to take over site administrator accounts. The post Critical WooCommerce Payments Vulnerability Leads to Site Takeover appeared first on SecurityWeek.

An Interview with dope.security Founder and CEO Kunal Agarwal

A discussion about re-imagining the Secure Web Gateway (SWG) with fly direct, building an authentic brand, and the future of dope.security. The post An Interview with dope.security Founder and CEO Kunal Agarwal appeared first on Security Boulevard.

PoC Exploit Published for Just-Patched Veeam Data Backup Solution Flaw

Proof-of-concept code to exploit a just-patched security hole in the Veeam Backup & Replication product has been published online. The post PoC Exploit Published for Just-Patched Veeam Data Backup Solution Flaw appeared first on SecurityWeek.

Modern Cybersecurity Problems Need Next-Gen PAM Solutions

The digital landscape continues evolving with no signs of slowing down. As the volume and severity of cyberattacks intensify, IT and security leaders need effective, user-friendly solutions to help secure their privileged credentials, accounts ...

CISA Gets Proactive With New Pre-Ransomware Alerts

CISA has sent notifications to more than 60 organizations as part of a new initiative to alert entities of early-stage ransomware attacks. The post CISA Gets Proactive With New Pre-Ransomware Alerts appeared first on SecurityWeek.

CISA releases free tool for detecting malicious activity in Microsoft cloud environments

Network defenders searching for malicious activity in their Microsoft Azure, Azure Active Directory (AAD), and Microsoft 365 (M365) cloud environments have a new free solution at their disposal: Untitled Goose Tool. Released by the Cybersecurity ...

Watch on Demand: Supply Chain & Third-Party Risk Summit Sessions

Join us for the virtual experience as we bring together security experts to discuss the complex nature of the supply chain problem, best practices for mitigating security issues. The post Watch on Demand: Supply Chain & Third-Party Risk ...

TikTok CEO Grilled by Skeptical Lawmakers on Safety, Content

A nearly six-hour grilling of TikTok’s CEO by lawmakers brought the platform’s 150 million U.S. users no closer to an answer as to whether the app will be wiped from their devices. The post TikTok CEO Grilled by Skeptical Lawmakers on Safety, ...

Phishing, Brute Force Attacks Rise in Expanded Threat Landscape

Phishing attacks and brute force attacks are on the rise as cybercriminals evolve their attacks to mobile and personal communication channels, according to a report from SaaS Alerts. On average, there were approximately 40,000 brute attacks daily ...

Intel vPro platform unveils advanced security measures

Intel has launched the latest Intel vPro platform, which is powered by 13th Gen Intel Core processors and offers a broad range of features, including powerful security measures. The extensive commercial portfolio will offer over 170 laptops, ...

Cybersecurity Insights with Contrast CISO David Lindner | 3/24

Insight #1 " Cybersecurity is no longer just a CISO or CIO problem, it’s a business problem. It’s time for cybersecurity to be a topic of conversation at every board meeting."   Insight #2 " CISA alerts to many newly ...

Fixing the most common vulnerabilities in Ruby apps

This blog post discusses the most common Ruby security vulnerabilities and how to fix them. The post Fixing the most common vulnerabilities in Ruby apps appeared first on GuardRails. The post Fixing the most common vulnerabilities in Ruby apps ...

China and India present new Challenges and Opportunities for Mobile App Developers

Pinduoduo Malware highlights the need for App Attestation on a Global Scale The recent Pinduoduo hack may have impacted over 700 million users in China, and highlights the need for mobile app attestation to protect against mobile app malware and ...

The Ultimate Guide to SaaS User Onboarding

User onboarding, in particular for SaaS organisations, may raise the bar for your product. More sales may result straight from onboarding. So, encouraging new users to stay is essential. Additionally, the best way to build a community around your ...

MITRE’s System of Trust risk model manager improves supply chain resiliency

MITRE launched its System of Trust risk model manager and established a community engagement group of 30 members. Expanding from its free and open platform, System of Trust now delivers a collaborative community to identify and mitigate threats ...