Application Security News and Articles


CISOs and Senior Leadership at Odds Over Security

Only half of cybersecurity leaders feel their C-suite understands cybersecurity risks, a Trend Micro survey found. Four in five have been told to downplay a potential risk’s severity. The post CISOs and Senior Leadership at Odds Over Security ...

LOKKER Consent Verification identifies potential compliance issues

LOKKER released Consent Verification, a new tool in LOKKER’s Privacy Edge Platform that gives businesses a simple way to check whether their consent banners are properly configured and working correctly. LOKKER’s recent research found ...

Veeam Data Cloud Vault enables users to securely store backup data

Veeam Software introduced Veeam Data Cloud Vault, a cloud-based storage service that enables users to securely store backup data not only off-site, but in an always-immutable and encrypted format, providing additional layers of protection for ...

RSAC Fireside Chat: Bedrock Security introduces advanced approach to “commoditize” data discovery

Business data today gets scattered far and wide across distributed infrastructure. Just knowing where to look – or even how to look – much less enforcing security policies, has become next to impossible for many organizations. At RSAC 2024, ...

How to Use Upskilling and Reskilling to Scale Your Cybersecurity Team

The post How to Use Upskilling and Reskilling to Scale Your Cybersecurity Team appeared first on Digital Defense. The post How to Use Upskilling and Reskilling to Scale Your Cybersecurity Team appeared first on Security Boulevard.

PoC for Progress Telerik RCE chain released (CVE-2024-4358, CVE-2024-1800)

Security researchers have published a proof-of-concept (PoC) exploit that chains together two vulnerabilities (CVE-2024-4358, CVE-2024-1800) to achieve unauthenticated remote code execution on Progress Telerik Report Servers. Telerik Report ...

ManageEngine unveils passwordless, phishing-resistant FIDO2 authentication

ManageEngine launched passwordless, phishing-resistant FIDO2 authentication for enterprise applications in ADSelfService Plus, its on-premises identity security solution, and the launch of endpoint MFA for Windows machines and elevated system ...

How to Prove Security Effectiveness with a Cybersecurity Board Report 

Security information and event management (SIEM) platforms aggregate, correlate, and analyze vast amounts of data from across an organization’s environment. With so much information feeding into your system, your SIEM tool should provide ...

SailPoint Risk Connectors helps organizations identify and act on risks

SailPoint has announced a new offering on its Atlas platform, SailPoint Risk Connectors. As part of its Atlas platform, SailPoint Risk Connectors makes it easier for organizations to make informed access decisions based on an identity’s ...

The Dual Edges of AI in Cybersecurity: Insights from the 2024 Benchmark Survey Report

Artificial intelligence (AI) in cybersecurity presents a complex picture of risks and rewards. According to Hyperproof’s 5th annual benchmark report, AI technologies are at the forefront of both enabling sophisticated cyberattacks and ...

Privacy Reimagined: The Impact of the American Privacy Act on Consumer Rights

The post Privacy Reimagined: The Impact of the American Privacy Act on Consumer Rights appeared first on Votiro. The post Privacy Reimagined: The Impact of the American Privacy Act on Consumer Rights appeared first on Security Boulevard.

eBook: Breaking bad actors

There’s never been a better time to deepen your skills in cybersecurity as the demand for experienced experts continues to grow. Learn how to break today’s bad actors in the eBook. Inside the eBook: Why the need for more cybersecurity ...

Wipro Cyber X-Ray empowers CXOs to make optimized security investment decisions

Wipro Wipro has partnered with Zscaler to introduce Wipro Cyber X-Ray, an AI-assisted decision support platform. Wipro Cyber X-Ray empowers enterprise CXOs to make optimized security investment decisions and communicate cyber values to senior ...

Consolidation is Coming to Corporate Security Technology

Why removing technology silos is critical to helping security teams save time, cut costs, and reduce risks. This article was originally published in Security Magazine. Those old enough to remember the software industry in the 1980s might recall ...

The Configuration is MITRE than the Tool

Introduction: MITRE ATT&CK stands as a cornerstone for understanding adversary tactics and techniques based on real-world observations. For SOC teams, it serves as a map to navigate the landscape of cyber threats, detailing the ...

361 million account credentials leaked on Telegram: Are yours among them?

A new trove of 361 million email addresses has been added to Have I Been Pwned? (HIBP), the free online service through which users can check whether their account credentials and other data has been compromised in one or more data breaches. Have ...

The Importance of Crypto Agility in Preventing Certificate-Related Outages

Digital certificates play a vital role in driving today's powerful system of identity-based security — from securing online communications and transactions to encrypting software developer code and much more. The post The Importance of Crypto ...

Breaking a Password Manager

Interesting story of breaking the security of the RoboForm password manager in order to recover a cryptocurrency wallet password. Grand and Bruno spent months reverse engineering the version of the RoboForm program that they thought Michael had ...

Mastering the Art of Least Privilege Access Implementation: A Comprehensive Guide

The concept of least privilege access has emerged as a paramount principle, serving as a cornerstone for robust identity governance and access management strategies. By adhering to this tenet, organizations can effectively mitigate the risks ...

DTEX i3 Issues Threat Advisory for Mitigating Third-Party Zoom Risk

Video conferencing applications like Zoom have become ubiquitous with the remote workforce, but they can also introduce a new vector for insider risk. The DTEX i3 team has observed an increase in remote control sharing with unauthorized third ...