Application Security News and Articles


CodeSecure and FOSSA Partner to Deliver Single Integrated Platform for Binary and Open Source Analysis

Consolidated capabilities enable customers to create comprehensive software bill of materials and eliminate security blindspots across the software development lifecycle BETHESDA, Md., Apr. 9, 2025 – CodeSecure, a leading global provider of ...

Bringing Rigor to CTEM with Threat-Informed Defense

While vulnerability management is an essential part of good cyber hygiene, it isn’t the only defense necessary against threat actors. Even if organizations could keep all their systems patched, exploited vulnerabilities are only responsible for ...

The Database Kill Chain

Modern attacks targeting sensitive data have become complex. An organization with many assets might be lost when trying to assess its overall risk, understand the pain points and prioritize the tasks required to secure its information systems. ...

Forescout eyeScope provides organizations with insight into their security posture

Forescout announced new Forescout eyeScope cloud visibility and monitoring solution, expanding the Forescout 4D Platform to the cloud. Forescout also announced a new, small footprint, edge data collector for enterprises that require Forescout’s ...

Gerçek Hayattan SDLC Süreci: Uçtan Uca Güvenlik Kültürü Nasıl İnşa Edilir?

Güvenlik, yalnızca geliştirme sürecinin sonunda yapılan bir test değildir; yazılım geliştirme yaşam döngüsünün (SDLC) her aşamasına…Continue reading ...

Enzoic AD Lite Password Audit Report

Enzoic for AD Lite Password Auditor is an innovative tool designed to integrate with an organization’s Active Directory environment seamlessly. Enzoic analyzed the 2024 AD Lite Password Auditor data to produce this report. New mandates and ...

AI Is the New Trust Boundary: STL TechWeek Reveals the Risk Shift

At St. Louis TechWeek 2025, AI took center stage as industry thought leaders shared sessions warning about inputs, data health, and how agents are the new attack surface. The post AI Is the New Trust Boundary: STL TechWeek Reveals the Risk Shift ...

WhatsApp vulnerability could be used to infect Windows users with malware (CVE-2025-30401)

WhatsApp users are urged to update the Windows client app to plug a serious security vulnerability (CVE-2025-30401) that may allow attackers to trick users into running malicious code. Meta classifies the vulnerability as a spoofing issue that ...

Okta extends identity security fabric to non-human identities

Okta announced new Okta Platform capabilities to help businesses secure AI agents and other non-human identities with the same level of visibility, control, governance, and automation as human ones. The Okta Platform will now bring a unified, ...

Gmail End-to-End Email Encryption Explained: A Guide for Enterprise Users

Google is rolling out end-to-end encrypted (E2EE) email for Gmail enterprise users using Client-Side Encryption (CSE). The post Gmail End-to-End Email Encryption Explained: A Guide for Enterprise Users appeared first on Security Boulevard.

Qevlar AI Raises $10 Million for Autonomous Investigation Platform

French cybersecurity startup Qevlar AI has raised $10 million in a funding round led by EQT Ventures and Forgepoint Capital International. The post Qevlar AI Raises $10 Million for Autonomous Investigation Platform appeared first on SecurityWeek.

Akamai boosts WAF protections across multiple environments

Akamai introduced App & API Protector Hybrid. Users can now expand the critical web application firewall (WAF) capabilities of Akamai’s web application and API protection (WAAP) while consistently securing applications and APIs for ...

NIST Deprioritizes Pre-2018 CVEs as Backlog Struggles Continue

NIST, which for more than a year has been struggling to address a backlog of CVEs in its database following budget cuts, is now putting pre-2018 vulnerabilities on the back burner to give itself more time to address the rapidly growing number of ...

Solving the Identity Crisis: Okta Redefines Security in a Machine-Led World 

Okta is stepping forward with its boldest platform evolution yet, aiming to unify identity across human and machine actors, and extend zero-trust all the way from cloud to on-premises. The post Solving the Identity Crisis: Okta Redefines Security ...

Post-Quantum Cryptography: Preparing for a Quantum Future

As quantum computing continues to evolve, the security of our digital infrastructure is under increasing scrutiny. While quantum computers promise groundbreaking advancements, they also pose a significant threat to the cryptographic algorithms ...

Treasury’s OCC Says Hackers Had Access to 150,000 Emails

The Office of the Comptroller of the Currency (OCC) has disclosed an email security incident in which 100 accounts were compromised for over a year.  The post Treasury’s OCC Says Hackers Had Access to 150,000 Emails appeared first on ...

CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days

CISA has added fresh CentreStack and Windows CLFS vulnerabilities to the Known Exploited Vulnerabilities catalog. The post CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days appeared first on SecurityWeek.

Gcore Super Transit Brings Advanced DDoS Protection and Acceleration for Superior Enterprise Security and Speed

Luxembourg, Luxembourg, 9th April 2025, CyberNewsWire The post Gcore Super Transit Brings Advanced DDoS Protection and Acceleration for Superior Enterprise Security and Speed appeared first on Security Boulevard.

Four Tips for Optimizing Data Backup and Recovery Costs

By taking simple steps like choosing a cost-effective backup storage strategy and minimizing recovery infrastructure costs, you can protect your business without bloating your budget.  The post Four Tips for Optimizing Data Backup and Recovery ...

Vulnerabilities Patched by Ivanti, VMware, Zoom 

Ivanti, VMware, and Zoom released fixes for dozens of vulnerabilities in their products on April 2025 Patch Tuesday. The post Vulnerabilities Patched by Ivanti, VMware, Zoom  appeared first on SecurityWeek.