Application Security News and Articles


Coro Grabs Spot on Fortune Cyber 60 List

Guess who made it onto the Fortune Cyber 60?! Given the increasing sophistication and frequency... The post Coro Grabs Spot on Fortune Cyber 60 List appeared first on Security Boulevard.

Validate customers have a problem they’re willing to pay to solve before building the software product !

I speak with ambitious startup founders and tech executives in mid-market and enterprises every day. During my conversation with one business owner yesterday, he articulated...Read More The post Validate customers have a problem they’re willing ...

Top 3 API Leaks Identified by Cybersecurity & InfoSec Experts

APIs (Application Programming Interfaces) have proliferated widely, which increases their susceptibility to various vulnerabilities. In the realm of web applications, prime examples that stand out are SOAP (Simple Object Access Protocol) and ...

Patches for CVE-2024-1086 for CloudLinux 6h, 7 Users on KernelCare Live

Update April 8th, 2024: Updated ETA for CloudLinux 6h and CloudLinux 7. The KernelCare team is working on deploying a live patch for CVE-2024-1086 for CloudLinux users. A patch has already been released for CloudLinux 6h and CloudLinux 7, and ...

USENIX Security ’23 – Hoedur: Embedded Firmware Fuzzing using Multi-Stream Inputs

Authors/Presenters: Tobias Scharnowski, Simon Wörner, Felix Buchmann, Nils Bars, Moritz Schloegel, Thorsten Holz Permalink The post USENIX Security ’23 – Hoedur: Embedded Firmware Fuzzing using Multi-Stream Inputs appeared first on ...

AlphaLock, Threat Actor Branding, and the World of Cybercrime Marketing

Threat actors are not a monolith in their approach to cybercrime. The popular perception is that threat actors steal information for the sake of it, while knowing and accepting that they are doing something wrong. However, some threat actors also ...

Bitdefender Digital Identity Protection guards against web data leaks

Bitdefender has enhanced Bitdefender Digital Identity Protection, a service that monitors personal data in real-time by proactively scanning the internet including public sites, dark web, and underground forums for unauthorized leaks and data ...

Veriato introduces AI-driven predictive behavior analytics platform

Veriato released their next generation Insider Risk Management (IRM) solution. With organizations of all sizes facing a more complex cybersecurity environment, Veriato IRM delivers flexibility and scalability using the power of GenAI. Veriato’s ...

What is Attack Surface Management (ASM) and How Has it Changed?

The threat landscape to a business changes every day. Here’s how you can protect your company’s data through a robust attack surface management strategy. The post What is Attack Surface Management (ASM) and How Has it Changed? appeared first ...

Protect Your Attack Surface from Evolving Attack Vectors

Cyber risk is growing at an exponential rate. In this blog, we look at attack vectors and attack surfaces, and what they mean for your cybersecurity. The post Protect Your Attack Surface from Evolving Attack Vectors appeared first on Security ...

XZ Utils backdoor: Detection tools, scripts, rules

As the analysis of the backdoor in XZ Utils continues, several security companies have provided tools and advice on how to detect its presence on Linux systems. What happened? The open-source XZ Utils compression utility has been backdoored by a ...

Join Cequence Security at RSA Conference 2024: Protect What Connects You with Advanced API Security Solutions

Cequence Security is thrilled to announce our participation at this year’s RSA Conference, Booth 2033, where we’ll showcase our innovative bot management and API security solutions. The RSA Conference, a global summit for security innovators, ...

Meet Ekran System at the Leading Cybersecurity Event of 2024

Join Ekran System at the RSA Conference, one of the world’s leading cybersecurity events. It’s where top professionals share their expertise to equip cybersecurity teams with the tools, intelligence, and connections needed to protect their ...

Secrets Management in the Age of AI Cybercrime: Safeguarding Enterprises from Emerging Threats

Secrets Management in the Age of AI Cybercrime. Learn why Secrets Management is crucial to keeping your enterprise safe. The post Secrets Management in the Age of AI Cybercrime: Safeguarding Enterprises from Emerging Threats appeared first on ...

SymphonyAI unveils SensaAI for Sanctions to detect hidden risk in unstructured data

SymphonyAI announced SensaAI for Sanctions, a platform-agnostic “AI upgrade” for any sanctions solution. It impacts sanctions evasion efforts by optimizing match accuracy with deep, context-aware AI-based matching algorithms. SensaAI for ...

Cyber-Physical Systems Security Analysis Challenges and Solutions 2024

Securing our data’s authenticity has become quite the challenge in today’s era of smart living. Living in smart homes and cities has made life convenient. Still, the complex web of the Internet of Things (IoT) and the Internet of Everything ...

Exploiting limited markup features on web applications

Limited features. Big vulnerabilities? Web applications might seem straightforward, but stripped-down code can create hidden weaknesses. Web applications that support limited markup in fields, such as comments, utilize a simplified... The post ...

Best 5 Privacy Management Tools for 2024

High-profile data breaches have made data protection and privacy a hot subject. Hackers use more sophisticated methods to break network defenses and steal sensitive data on a large scale. Malicious actors target personal data because of its ...

CISA Warns of Volt Typhoon Risks to Critical Infrastructure

The recent joint warning issued by CISA, NSA, FBI, and other U.S. government and international partners highlights a critical cybersecurity threat: Volt Typhoon, a Chinese hacking group. This group has targeted critical infrastructure in the ...

92,000+ internet-facing D-Link NAS devices accessible via “backdoor” account (CVE-2024-3273)

A vulnerability (CVE-2024-3273) in four old D-Link NAS models could be exploited to compromise internet-facing devices, a threat researcher has found. The existence of the flaw was confirmed by D-Link last week, and an exploit for opening an ...