Application Security News and Articles


ICS Patch Tuesday: Siemens, Schneider Electric Address Over 100 Vulnerabilities

Siemens and Schneider Electric have addressed more than 100 vulnerabilities with their March 2023 Patch Tuesday security advisories. The post ICS Patch Tuesday: Siemens, Schneider Electric Address Over 100 Vulnerabilities appeared first on ...

Using AI Cybersecurity Solutions to Stop Ransomware

Growing interconnectedness makes it harder to detect ransomware before it causes harm. Whether data is processed locally or in the cloud, the risk of a breach is the same. But edge computing also makes it easier for hackers to break in because ...

Stalkerware has grown by 239% worldwide over the past three years

Over the course of the past three years, Avast researchers have discovered a diverse range of mobile applications intended for non-consensual stalking.   The post Stalkerware has grown by 239% worldwide over the past three years appeared first ...

4 evasive web browser attacks targeting federal agencies

The way federal employees work has changed dramatically over the past three years. Digital transformation, cloud migration and hybrid work models have spread out infrastructure and endpoints away from the central data center out to the edge of ...

What Should Thoma Bravo Do With ForgeRock?

An opinion piece analysing the potential acquisition of ForgeRock by private equity firm Thoma Bravo. The post What Should Thoma Bravo Do With ForgeRock? appeared first on The Cyber Hut. The post What Should Thoma Bravo Do With ForgeRock? ...

Ring Denies Falling Victim to Ransomware Attack

Ring says it has no indications it has fallen victim to a ransomware attack after cybergang threatens to publish supposedly stolen data. The post Ring Denies Falling Victim to Ransomware Attack appeared first on SecurityWeek.

We need a new way to measure AI security

Tl;dr: Trail of Bits has launched a practice focused on machine learning and artificial intelligence, bringing together safety and security methodologies to create a new risk assessment and assurance program. This program evaluates potential ...

Success of National Cybersecurity Strategy Rests on Swift Action

Just a week after the White House unveiled its long-anticipated National Cybersecurity Strategy, a pair of incidents—a breach at DC Health Link that may have exposed the personal data of members of Congress and a warning that hackers were ...

CISA warns CI operators about vulnerabilities on their networks exploited by ransomware gangs

Organizations in critical infrastructure sectors whose information systems contain security vulnerabilities associated with ransomware attacks are being notified by the US Cybersecurity and Infrastructure Security Agency (CISA) and urged to ...

Fortinet Finds Zero-Day Exploit in Government Attacks After Devices Detect Integrity Breach

Fortinet says recently patched FortiOS vulnerability was exploited in sophisticated attacks targeting government entities. The post Fortinet Finds Zero-Day Exploit in Government Attacks After Devices Detect Integrity Breach appeared first on ...

How To Align Your SBOM with the US Government Executive Order

One of the requirements of Executive Order 14028, issued in May 2021 and designed to improve the nation’s cybersecurity, is that software producers who supply the federal government provide a software bill of materials (SBOM) for each product. ...

Ubuntu Core now compatible with the Arm SystemReady IR systems specification

Canonical announced its Ubuntu Core OS is now compatible with the Arm SystemReady IR system specification, enabling security best practices across connected devices. In addition, the OS has achieved the PSA Certified Level 1. Ubuntu Core is a ...

SHARED INTEL Q&A: Bi-partisan report calls a for a self-sacrificing approach to cybersecurity

A new report from the Bipartisan Policy Center (BPC) lays out — in stark terms – the prominent cybersecurity risks of the moment. Related: Pres. Biden’s impact on cybersecurity. The BPC’s Top Risks in Cybersecurity 2023 analysis … ...

Call for beta testers

Quality and dependability are two tenets on which all of our plugins are built. We work to achieve this day in day out through a rigorous development process that also involves considerable testing by our internal team. This enables us to ensure ...

We can’t wait for SBOMs to be demanded by regulation

Old ads can be startling—cigarette ads used to boast their health-giving properties, sugar-laden candy was once advertised as a dietary aid, and soft drinks were advertised as a milk alternative for babies. None of this would fly today, of ...

“Web Skimming Attacks – Digital Hacking Techniques for Payment Card”

Introduction A recent notion, Web Skimming attacks, which have been around for a while, was introduced with the rise in cyber threats. After the Magecart attack on British Attacks in 2018, they were created. In mitigation efforts, GDPR violations ...

Product showcase: Permit.io – Application-level permissions with a no-code UI

Managing user access in applications has always been a headache for any developer. Implementing policies and enforcing them can prove to be quite complex, and very time-consuming. Even if a homebrew authorization solution has been developed for ...

The rise of AI threats: Is your business prepared to face ChatGPT?

Skyhigh Security has seen firsthand how 33,000 enterprise users have accessed ChatGPT through corporate infrastructures. Almost 7 TB of data has been transacted with ChatGPT through corporate web and cloud assets between Nov 2022 – Feb 2023. In ...

Organizations need to re-examine their approach to BEC protection

BEC attacks are growing year over year and are projected to be twice as high as the threat of phishing in general, according to IRONSCALES and Osterman Research. 93% of organizations experienced one or more of the BEC attack variants in the ...

DTEX InTERCEPT Named Winner in 2023 Cybersecurity Excellence Awards

We are thrilled to share that DTEX InTERCEPT was named a winner in the 2023 Cybersecurity Excellence Awards for the third consecutive year. This prestigious industry awards program honors individuals and companies that demonstrate excellence, ...