Application Security News and Articles


The Week in Security: Lazarus attacks same South Korean entity twice, use of hard-coded secrets is up

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond. This week: North Korean-linked ...

Randall Munroe’s XKCD ‘Presents For Biologists’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Presents For Biologists’ appeared first on Security Boulevard.

Custom Chinese Malware Found on SonicWall Appliance

Malware deployed by Chinese hackers on a SonicWall SMA appliance includes credential theft, shell access, and persistence functionality. The post Custom Chinese Malware Found on SonicWall Appliance appeared first on SecurityWeek.

GitHub to introduce mandatory 2FA authentication starting March 13

Starting March 13, GitHub will gradually introduce the 2FA enrollment requirement to groups of developers and administrators, beginning with smaller groups. This measured approach allows the platform to ensure successful onboarding and make ...

PyPI repo poisoned with “Colour-Blind” RAT

Malicious actors are increasingly dropping malware packages into open-source software repositories in the hope that developers will spread that malicious code throughout their applications. The latest case in point: Kroll's recent discovery of a ...

Software Insecurity: Whose Problem is it?

CISA’S Jen Easterly makes a strong case for better software cyber product security in her CMU talk. Axio dives into what this means for producers and consumers of tech. Read More The post Software Insecurity: Whose Problem is it? appeared ...

From Past to Future: Why I Joined Netography

New Chief Product Officer David Meltzer shares his thoughts on why he is excited to join Netography The post From Past to Future: Why I Joined Netography appeared first on Netography. The post From Past to Future: Why I Joined Netography appeared ...

USENIX Security ’22 – Lukas Giner, Andreas Kogler, Claudio Canella, Michael Schwarz, Daniel Gruss – ‘Repurposing Segmentation As A Practical LVI-NULL Mitigation In SGX’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Lukas Giner, Andreas Kogler, Claudio ...

Ban TikTok, say FBI, CIA, NSA, DNI, GOP, DNC, POTUS (but not ACLU)

R.E.S.P.E.C.T. RESTRICT: The White House and both sides of the Senate agree that TikTok needs to be stopped—or at least RESTRICT’ed. A bipartisan bill seeks to make that happen. The post Ban TikTok, say FBI, CIA, NSA, DNI, GOP, DNC, POTUS ...

Introducing Avast One Platinum

Like great home security systems, great cybersecurity is largely invisible. You want it to do its thing, running in the background, silently protecting you and your family. The only time you should be aware of it is when something goes ...

The Real Story Behind PCI Scope and Segmentation

The definition and maintenance of a clear scope of applicability for any standard is always a challenge on complex networks. […] The post The Real Story Behind PCI Scope and Segmentation appeared first on Security Boulevard.

Radware Customers Provide Insightful Tips for Women Interested in a Cybersecurity Career

Radware has the unique opportunity to work with many women in technology and cybersecurity. So, to celebrate International Women’s Day 2023, we turned to our customers — in this case, women — who continually provide us with interesting, ...

What does a racecar have to do with cybersecurity?

Not long ago, Entrust created a racecar commercial showcasing how we help our customers manage identities, payments,... The post What does a racecar have to do with cybersecurity? appeared first on Entrust Blog. The post What does a racecar ...

Vulnerability Exposes Cisco Enterprise Routers to Disruptive Attacks

Cisco has released patches for a high-severity DoS vulnerability in IOS XR software for several enterprise-grade routers. The post Vulnerability Exposes Cisco Enterprise Routers to Disruptive Attacks appeared first on SecurityWeek.

Building a Vulnerability Management Program: Key Components and Tips to Get Started

If you are interested in a robust vulnerability management program, Strobes VM365 checks all the above boxes and more. Our continuous vulnerability management program combines manual processes The post Building a Vulnerability Management Program: ...

Achieving PCI DSS Compliance Through Penetration Testing

In this blog post, we will discuss the ins and outs of PCI DSS compliance and the role of penetration testing. The post Achieving PCI DSS Compliance Through Penetration Testing appeared first on Scytale. The post Achieving PCI DSS Compliance ...

Strata Identity Achieves SOC 2 Type I Certification for Multi-Cloud Identity Orchestration Platform

Auditor’s report confirms company meets the highest standards for protecting sensitive data and ensuring the integrity of its systems BOULDER, Colo., March 9, 2023 — Strata Identity, the Identity Orchestration company, today announced it has ...

Deanonymizing OpenSea NFT Owners via Cross-Site Search Vulnerability

TLDR Recently, a cross-site search vulnerability was discovered affecting the popular NFT marketplace OpenSea. When successfully exploited, this issue allows for the deanonymization of OpenSea users by linking an IP address, a browser session, or ...

The Security Risks of ChatGPT: Safeguarding Business Data

ChatGPT, developed by the artificial intelligence lab OpenAI, is a humanoid chatbot causing a global sensation. It is now the fastest-growing app in history, hitting 100 million active users in just two months—way faster than the nine months it ...

QuSecure Unveils Quantum-Resilient Communications Satellite Link

QuSecure announced an end-to-end quantum resilient encrypted communications link that protects data delivered by satellite. The post QuSecure Unveils Quantum-Resilient Communications Satellite Link appeared first on SecurityWeek.