Application Security News and Articles


Sue The Hackers – Google Sues Over Phishing as a Service

Google’s Lighthouse lawsuit signals a new era in cybersecurity, where companies use civil litigation—including the CFAA, Lanham Act, and RICO—to dismantle phishing networks, seize malicious infrastructure, and fight hackers when criminal ...

Largest Azure DDoS Attack Powered by Aisuru Botnet

Microsoft said the DDoS attack was aimed at an endpoint in Australia and reached 15.72 Tbps and 3.64 Bpps. The post Largest Azure DDoS Attack Powered by Aisuru Botnet appeared first on SecurityWeek.

The 2025 MSP Cyber Crisis: Breaking Free From Vendor Lock-In and Reclaiming Profitability

The global MSP ecosystem has entered its most challenging era. As businesses accelerate cloud adoption, hybrid work, and continuous digital operations, MSPs have become essential security partners. Yet despite market growth, the sector is ...

Threat group reroutes software updates through hacked network gear

Sometimes an attack hides in the most ordinary corner of a network. ESET researchers say a China aligned threat group known as PlushDaemon has been quietly using hacked routers to steer software updates toward its own servers. The discovery shows ...

When AI Turns on Its Team: Exploiting Agent-to-Agent Discovery via Prompt Injection

Aaron Costello uncovers how second-order prompt injection turns AI agents against their own systems. He explains how attackers exploit ServiceNow’s Now Assist and offers clear guidance on securing AI collaboration. The post When AI Turns on Its ...

Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week

An OS command injection flaw, the exploited zero-day allows attackers to execute arbitrary code on the underlying system. The post Fortinet Discloses Second Exploited FortiWeb Zero-Day in a Week appeared first on SecurityWeek.

Sophos adds Intelix threat intelligence to Microsoft Security and 365 Copilot

Sophos announced the general availability of new integrations that connect Sophos Intelix, its cyber threat intelligence repository, with Microsoft Security Copilot and Microsoft 365 Copilot. Organizations of all sizes now gain real-time access ...

Arctic Wolf expands MDR capabilities with Abnormal AI behavioral email intelligence

Arctic Wolf announced a new integration between the Arctic Wolf Aurora Platform and Abnormal AI, expanding detection and response capabilities across one of the most targeted attack surfaces, email. The integration brings Abnormal AI’s ...

From Exposure to Action: How Proactive Identity Monitoring Turns Breached Data into Defense

Every 39 seconds, somewhere in the world, a new cyberattack is launched — and far too often, it’s not a sophisticated hack but the reuse of legitimate credentials already exposed online. As data breaches multiply and stolen credentials ...

Tanium integrates AI-driven Triage and Identity Insights into Microsoft Security Copilot

Tanium announced the general availability of Tanium Security Triage Agent and Tanium Security Triage Agent with Identity Insights in Microsoft Security Copilot. “Agentic AI is transforming the workflows used by security operations to ...

Vanta’s Agentic Trust Platform redefines how enterprises earn, prove, and scale trust

Vanta unveiled a number of new products that redefine how enterprises earn and prove trust at scale. Powered by intelligent automation, Vanta’s Agentic Trust Platform helps teams understand their environment, anticipate what’s next, and ...

CredShields Joins Forces with Checkmarx to Bring Smart Contract Security to Enterprise AppSec Programs

Singapore, Singapore, 19th November 2025, CyberNewsWire The post CredShields Joins Forces with Checkmarx to Bring Smart Contract Security to Enterprise AppSec Programs appeared first on Security Boulevard.

Cayosoft Guardian SaaS expands identity continuity with always-on hybrid protection

Cayosoft announced an expansion in the deployment of its flagship platform, Cayosoft Guardian SaaS. This milestone marks a significant evolution in identity continuity, empowering enterprises to detect, respond, and recover instantly, even when ...

Microsoft Unveils Security Enhancements for Identity, Defense, Compliance

Microsoft announced new security capabilities for Defender, Sentinel, Copilot, Intune, Purview, and Entra.  The post Microsoft Unveils Security Enhancements for Identity, Defense, Compliance appeared first on SecurityWeek.

authID Mandate Framework establishes governance model for secure agentic AI deployment

authID unveiled the authID Mandate Framework, a comprehensive governance model for agentic AI security with support for non-human identities, including autonomous and semi-autonomous AI agents. Mandate provides enterprises with the trust ...

Nightfall’s AI File Classifier Detectors bring LLM intelligence to unstructured IP protection

Nightfall announced the launch of AI File Classifier Detectors, the first solution to use large language models (LLMs) to classify and protect business-critical documents that traditional DLP tools cannot see. Most high-value assets, including ...

CyberProof’s Agentic AI framework sets a new standard for flexible, threat-led defense

CyberProof has launched its new Agentic AI framework and SOC agents which are designed to improve threat detection, incident response, and operational efficiency for exposure and defense management. This framework is a key part of ...

F5 BIG-IP v21.0 accelerates enterprise AI initiatives

F5 introduced BIG-IP v21.0, giving customers a unified approach to app delivery, security, and scale in the AI era. This major release extends the F5 Application Delivery and Security Platform (ADSP) with a purpose-built delivery engine for ...

Bitwarden extends passkey login to Chromium-based browsers

Bitwarden announced expanded passkey login capabilities for Bitwarden browser extensions. The update enables users to access their vaults in Chromium-based browsers using a passkey instead of a master password, delivering a secure, ...

Google Email Deliverability: How to Avoid Spam Folders

Improve Google email deliverability and land in Gmail inboxes. Learn best practices and start optimizing your email performance today. The post Google Email Deliverability: How to Avoid Spam Folders appeared first on Security Boulevard.