Application Security News and Articles


Dell Hell Redux — More Personal Info Stolen by ‘Menelik’

Phish Ahoy! Hacker took advantage of Dell’s lack of anti-scraping defense. The post Dell Hell Redux — More Personal Info Stolen by ‘Menelik’ appeared first on Security Boulevard.

Microsoft’s May 2024 Patch Tuesday Addresses 3 Zero-Days, 61 Vulnerabilities

In Microsoft’s May 2024 Patch Tuesday, the company reported significant updates aimed at enhancing the security of various systems by addressing a total of 61 vulnerabilities. This update is crucial, as it includes patches for one critical ...

Find Deeply Hidden Security Vulnerabilities with Deeper SAST by Sonar

This post delves into an actual Jenkins vulnerability to understand the intricacies of deeper SAST for detecting deeply hidden code vulnerabilities. It illustrates how deeper SAST works and explains its impact on keeping your code clean and free ...

Daniel Stori’s ‘Kernel Economics’

via the inimitable Daniel Stori at Turnoff.US! Permalink The post Daniel Stori’s ‘Kernel Economics’ appeared first on Security Boulevard.

Investing Wisely: The Financial Benefits of Strong Cyber Resilience

What are the financial performance benefits of strong cyber governance? In a blog series dedicated to the SEC’s new rules, we haven’t talked much about the connection between cybersecurity and Read More The post Investing Wisely: The ...

Phish Sticks; Hate the Smell, Love the Taste

Phishing School I’ll Make You Great at Phishing or Your Money Back I am already making you better at phishing. Right now. How could that be possible? Please, don’t worry about specifics right now. Just trust that I am making you better at ...

Plenty of Phish in the Sea

Phishing School How to Find the Right Phishing Targets A weapon is useless unless you have something to aim it at. When we weaponize social engineering, our targets are the humans who have the ability to give us access to the systems and data we ...

Mental Health Apps are Likely Collecting and Sharing Your Data

May is mental health awareness month! In pursuing help or advice for mental health struggles (beyond just this month, of course), users may download and use mental health apps. Mental health apps are convenient and may be cost effective for many ...

Learn about the risks, costs, and benefits of shadow AI

Detect, evaluate, and mitigate shadow AI in SaaS. Identify existing apps adding AI features, and automatically survey users on business justification. The post Learn about the risks, costs, and benefits of shadow AI appeared first on Security ...

LogRhythm and Exabeam Announce Intent to Merge, Harnessing Collective Innovation Strengths to Lead the Future of AI-Driven Security Operations

The combined company will bring together two cybersecurity SIEM and UEBA innovation leaders with renowned and demonstrated track records in serving customers with effective threat detection, investigation, and response (TDIR) LogRhythm, the ...

Navigating the New Frontier of AI-Driven Cybersecurity Threats

A few weeks ago, Best Buy revealed its plans to deploy generative AI to transform its customer service function. It’s betting on the technology to create “new and more convenient ways for customers to get the solutions they need” and to ...

ManageEngine SaaS Manager Plus simplifies access management

ManageEngine launched SaaS Manager Plus, a SaaS management solution for enterprises. SaaS Manager Plus seamlessly integrates with Zoho apps and other widely utilized applications, empowering IT admins and finance managers to streamline their SaaS ...

How attackers deliver malware to Foxit PDF Reader users

Threat actors are taking advantage of the flawed design of Foxit PDF Reader’s alerts to deliver malware via booby-trapped PDF documents, Check Point researchers have warned. Exploiting the issue The researchers have analyzed several ...

The Fusion of Fraud and IAM: An Event with Transmit Security

Next week our founder Simon Moffatt will be speaking at event in London with leading customer identity and access management platform provider Transmit Security. The event is entitled "The Fusion of Identity Management and Fraud Prevention" and ...

FireMon Asset Manager 5.0 improves situational awareness

FireMon released FireMon Asset Manager 5.0. This new version of its solution provides real-time cyber situational awareness of an organization’s infrastructure, brings with it improved manageability, extends integration with other platforms, ...

Cloud Pentesting 101: What to Expect from a Cloud Penetration Test?

Hold on, let’s guess.  You’ve moved a ton of your business to the cloud – storage, applications, the whole nine yards. Cloud computing offers flexibility, scalability, and a bunch of other benefits.  But here’s the not-so-rosy side:  ...

Managing Cyber Risk in Exit Strategy Planning

Exit Planning is the strategic process of preparing for the eventual transfer or sale of a business. It takes into account the business owner’s personal and financial goals and involves decisions and actions that enable a smooth and organized ...

Systematically Bring to Light the Keys in Your Clouds

Systematically Bring to Light the Keys in Your Clouds madhav Wed, 05/15/2024 - 10:23 The cloud has enabled organizations to create data stores across the globe at breakneck speeds. Organizations can now leverage the cloud to reach a broader ...

Thunderbird Vulnerabilities Fixed in Ubuntu and Debian

In recent Ubuntu and Debian security updates, several vulnerabilities have been addressed in Thunderbird, the popular open-source mail and newsgroup client. Attackers could use these vulnerabilities to cause a denial of service, execute arbitrary ...

5 Must-Haves to Get (and Stay) Compliant With Privacy and Security Frameworks

This blog will provide you with a clear roadmap of must-haves for compliance so you can make informed decisions when evaluating solutions. The post 5 Must-Haves to Get (and Stay) Compliant With Privacy and Security Frameworks appeared first on ...