Application Security News and Articles


Tines’ AI features enhance workflow automation for security and IT teams

Tines announced its first native AI features: Automatic Mode and AI Action. Customers are already experiencing a significant impact from these two new AI capabilities within the Tines platform by leveraging Large Language Models (LLMs) in a ...

Netskope introduces SaaS security enhancements to Netskope One for GenAI and SaaS collaboration

Netskope has unveiled SaaS security enhancements to Netskope One, its cloud-native platform that offers converged security and networking services to enable SASE and zero trust transformation. These new enhancements advance the platform’s ...

How Poor Cryptographic Practices Endanger Banking Software Security

In today’s digital age, financial institutions rely heavily on encryption to protect sensitive data in their banking applications. However, despite the critical role of cryptography, many implementations suffer from fundamental flaws that ...

Photos: Infosecurity Europe 2024

Infosecurity Europe is taking place at ExCel London from 4-6 June 2024. Help Net Security is on-site. This gallery takes you inside the event. The featured vendors are: Plainsea, Qualys, Akamai, Microsoft, Bridewell, Adaptive Shield, Jamf. The ...

Intel 471 launches 471 Attack Surface Protection to enhance external threat visibility

Intel 471 launched the company’s 471 Attack Surface Protection solution, an attack surface management (ASM) tool that provides its customers visibility into their external threat landscape and drives a proactive response that neutralizes ...

Otterize unveils Blast Radius Analysis & Remediation tool

Otterize rolls out a major expansion of its Cloud Security Suite, featuring the new Blast Radius Analysis & Remediation tool. This feature, designed to detect exposed infrastructure across different Kubernetes clusters and cloud ...

Why Digital Threats are the New Frontier in Executive Protection

The landscape of threats facing executives has expanded far beyond the physical realm, and home is the new attack surface. Traditional security measures, while still essential, are no longer sufficient on their own to protect high-profile ...

Thales Passwordless 360° enables organizations to improve their identity management practices

Thales announced Passwordless 360°, a new concept for passwordless authentication which offers Thales customers the broadest coverage of passwordless function across multiple types of users and assurance levels. Passwordless 360° has the ...

Python downloader highlights noise problem in open source threat detection

ReversingLabs researchers recently discovered a malicious, open source package: xFileSyncerx on the Python Package Index (PyPI). The package, with close to 300 registered downloads, contained separate malicious “wiper” components. Is it an ...

Why Companies Struggle to Innovate: Overcoming the Top 5 Excuses Leaders Make

Innovation is not just a buzzword — it’s a necessity. Yet, many organizations, even technology startups find themselves caught in the inertia of the status...Read More The post Why Companies Struggle to Innovate: Overcoming the Top 5 Excuses ...

Online Privacy and Overfishing

Microsoft recently caught state-backed hackers using its generative AI tools to help with their attacks. In the security community, the immediate questions weren’t about how hackers were using the tools (that was utterly predictable), but about ...

MSPs Look to Streamline Cybersecurity Partnerships, Skills Shortage Persists

A rising volume of risks, shortage of qualified cybersecurity professionals and time management with vendors are among the challenges MSPs face. The post MSPs Look to Streamline Cybersecurity Partnerships, Skills Shortage Persists appeared first ...

TotalRecall shows how easily data collected by Windows Recall can be stolen

Ethical hacker Alexander Hagenah has created TotalRecall, a tool that demonstrates how malicious individuals could abuse Windows’ newly announced Recall feature to steal sensitive information. TotalRecall results (Source: Alexander Hagenah) ...

Verimatrix XTD Accessibility Abuse Detector identifies Android mobile app threats

Verimatrix introduced Verimatrix XTD Accessibility Abuse Detector service that builds upon its ongoing successful discoveries of notable Android security threats and provides much-needed GDPR protections. Verimatrix XTD and its suite of ...

CISA Alert: Urgent Update Needed for Apache Flink Vulnerability

Attention Apache Flink users! The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added an Apache Flink vulnerability to its Known Exploited Vulnerabilities Catalog, highlighting evidence of its active exploitation. Apache ...

Appdome SDKProtect reduces third-party mobile supply chain risk

Appdome released a new mobile SDK protection and mobile threat streaming service, called Appdome SDKProtect. Appdome SDKProtect is designed to end third-party, mobile supply chain risk and democratize mobile threat intelligence and telemetry data ...

N2WS launches cross-cloud volume restore for AWS and Azure

N2WS has introduced several new features to its cloud-native backup and disaster recovery (BDR) platform to help enterprises and managed service providers (MSPs) with combatting the increasing number of cybersecurity attacks on organizations ...

Certificate Lifecycle Management The Key to Robust Digital Security in Healthcare

The need for robust digital security has never been more critical. As cyber threats become increasingly sophisticated, managing digital certificates effectively is paramount for protecting sensitive information and ensuring seamless ...

RSAC Fireside Chat: Seclore advances ‘EDRM’ by aligning granular controls onto sensitive data

Digital rights management (DRM) has come a long way since Hollywood first recognized in the 1990s that it needed to rigorously protect digital music and movies. By the mid-2000s a branch called enterprise digital rights management (EDRM… ...

MS Exchange Server Flaw: Keylogger Deployment Revealed

In a recent revelation, an unidentified malicious actor has been exploiting vulnerabilities in Microsoft Exchange Server to infiltrate systems with a keylogger malware, targeting various entities across Africa and the Middle East. The ...