Application Security News and Articles


Constella Introduces Advanced Know Your Employee (KYE) Solution, Redefining Internal Identity Risk Management

Groundbreaking Advanced KYE Solution Empowers Organizations to Uncover Synthetic and Fake Identities and Manage Internal Identity Risks with Precision and Confidence [LOS ALTOS, Calif., June 4, 2024] – In response to the urgent need for ...

Unlocking HIPAA Compliance: Navigating Access Control and MFA Guidelines

As technology continues to revolutionize healthcare operations, protecting patient data has never been more challenging. In the ongoing struggle against data breaches, last year marked a tipping point, as an unprecedented 133 million healthcare ...

What is DKIM Vulnerability? DKIM l= tag Limitation Explained

Reading Time: 6 min DKIM l= Tag is considered a critical DKIM vulnerability as it allows attackers to bypass email authentication. Learn how to fix it & secure your domain. The post What is DKIM Vulnerability? DKIM l= tag Limitation ...

Plainsea cybersecurity platform to launch at Infosecurity Europe

Plainsea is a cutting-edge platform set to shake up the cybersecurity scene with its European launch at Infosecurity Europe in 2024. As cyber threats continue to evolve at an alarming rate, the demand for efficient and intelligent cybersecurity ...

Trend Micro Inline NDR enhances threat detection and response

Trend Micro announced its latest breakthrough in network detection and response (NDR) technology: Inline NDR. The technology is available via the Trend Vision One platform, where it improves detection and response across all security functions ...

TP-Link Archer Vulnerable to Remote Code Execution

Router vulnerabilities present significant risks to both individuals and organizations. One such vulnerability has been identified in the TP-LINK Archer series, specifically affecting the Archer C5400X Tri-Band Gaming Router. Our recent analysis, ...

Data Defense: Leveraging SaaS Security Tools

Data Defense: Leveraging SaaS Security Tools madhav Tue, 06/04/2024 - 05:15 The Software-as-a-Service (SaaS) market has burgeoned in recent years, driven by its convenience, scalability, and cost-effectiveness. As per the Thales 2024 Data Threat ...

20 free cybersecurity tools you might have missed

Free, open-source cybersecurity tools have become indispensable to protecting individuals, organizations, and critical infrastructure from cyber threats. These tools are created through collaborative and transparent efforts, making them ...

Third-party vendors pose serious cybersecurity threat to national security

In this Help Net Security video, Paul Prudhomme, Principal Security Analyst at SecurityScorecard, discusses the findings of the 2024 Redefining Resilience: Concentrated Cyber Risk in a Global Economy Research report. This research details a surge ...

Security challenges mount as as companies handle thousands of APIs

Modern applications are taking over enterprise portfolios, with apps classed as modern now making up 51% of the total, up by more than a quarter in the last year, according to F5. According to the 2024 edition of F5’s State of Application ...

50 CISOs & Cybersecurity Leaders Shaping the Future

  I am honored and humbled to be listed among such influential luminaries who collectively push our industry to continually adapt to make our digital ecosystem trustworthy! An incredible list of cybersecurity CISOs and leaders cybersecurity ...

The NIST Finally Hires a Contractor to Manage CVEs

Security experts have been frustrated because no one was managing the Common Vulnerabilities and Exposures security reports. Good news: The NIST has hired a company to manage the backlog. Bad news: The company has no experience with this kind of ...

Securing SaaS Access of Unmanaged Applications | Grip

SaaS apps support business operations yet lie outside of traditional security controls, complicating user management and secure access. Explore the remedy. The post Securing SaaS Access of Unmanaged Applications | Grip appeared first on Security ...

Cybersecurity Automation in Healthcare Program Launched by HHS Agency

The UPGRADE program seeks to enhance and automate cybersecurity for healthcare facilities, focused on protecting operations and ensuring continuity of patient care. The post Cybersecurity Automation in Healthcare Program Launched by HHS Agency ...

Webinar Recap: Critical Concerns for Healthcare Providers in 2024

Baptist Health CISO James Case shared insights on transforming cybersecurity through a risk-focused lens at a recent webinar we hosted. The discussion was moderated by Axio President, David White and Read More The post Webinar Recap: Critical ...

The TIDE: Threat-Informed Defense Education (Moonstone Sleet, DarkGate, SocGholish, DiceLoader, and new product coverage)

Last week, Scott Small, our Director of Cyber Threat Intelligence, wrote a blog about what he and his team were seeing with some recent threats and what we put into our platforms. We have decided to level this up and expand from simply talking ...

USENIX Security ’23 – MINER: A Hybrid Data-Driven Approach for REST API Fuzzing

Authors/Presenters:Chenyang Lyu, Jiacheng Xu, Shouling Ji, Xuhong Zhang, Qinying Wang, Binbin Zhao, Gaoning Pan, Wei Cao, Peng Chen, Raheem Beyah Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, ...

A Step-by-Step Video Guide to Using Fortra VM- Series #3

The post A Step-by-Step Video Guide to Using Fortra VM- Series #3 appeared first on Digital Defense. The post A Step-by-Step Video Guide to Using Fortra VM- Series #3 appeared first on Security Boulevard.

Cyberattack Risks Keep Small Business Security Teams on Edge

Three-quarters of SMBs fear that a cyberattack could put them out of business. For good reason: 96% of them have already been the victims of a cyberattack. The post Cyberattack Risks Keep Small Business Security Teams on Edge appeared first on ...

Google Hates Ad Blockers: Manifest V3 Push Starts Today

We warned you. As of June 3, Google is following through on its threat to kill ad blockers. Plus, privacy-focused Chrome extensions are living on borrowed time; developers must upgrade to the less capable “Manifest V3” API. The post Google ...