Application Security News and Articles


Hacker Conversations: Kunal Agarwal and the DNA of a Hacker

For Agarwal, being a hacker is not what you do, but who you are; that is, someone who always questions the status quo and questions how it could be different. The post Hacker Conversations: Kunal Agarwal and the DNA of a Hacker appeared first on ...

Forescout eyeSentry platform delivers continuous, cloud-based exposure management

Forescout has announced the launch of eyeSentry, a cloud-native exposure management solution that redefines how enterprises identify and mitigate hidden risks across IT, IoT, and IoMT environments. As hybrid and cloud environments expand, ...

SesameOp Malware Abuses OpenAI API 

A component of the newly discovered SesameOp backdoor uses the API to store and relay commands from the C&C server. The post SesameOp Malware Abuses OpenAI API  appeared first on SecurityWeek.

Why Protectionism Won’t Make Europe a Cybersecurity Powerhouse

Rethinking Digital Sovereignty: Building Value, Not Walls The post Why Protectionism Won’t Make Europe a Cybersecurity Powerhouse appeared first on Security Boulevard.

Bugcrowd expands AI-powered, human-led security with Mayhem Security acquisition

Bugcrowd has announced the acquisition of Mayhem Security to advance the next generation of AI-powered, human-in-the-loop security testing. Bugcrowd aims to help organizations ship safer software faster, at lower cost, and with greater ...

Bugcrowd Acquires Application Security Firm Mayhem

Bugcrowd said the acquisition of Mayhem has nearly doubled its valuation — previously reported at over $1 billion. The post Bugcrowd Acquires Application Security Firm Mayhem appeared first on SecurityWeek.

2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks

Baltimore, USA, 4th November 2025, CyberNewsWire The post 2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks appeared first on Security Boulevard.

AI Agents Mark the End of Traditional GRC 

AI agents are transforming governance and compliance from slow, manual processes into real-time, autonomous systems. By eliminating data silos, automating risk assessments, and enabling multi-modal collaboration, enterprises can achieve ...

Former ransomware negotiators allegedly targeted US firms with ALPHV/BlackCat ransomware

A ransomware negotiator and an incident response manager have been indicted in Florida for allegedly conspiring to deploy the ALPHV/BlackCat ransomware against multiple US companies and extorting nearly $1.3 million from one of the victims. ...

Deepwatch Launches NEXA™: The MDR Industry’s First Collaborative Agentic AI Ecosystem for Unparalleled Security Outcomes

Intelligent AI agents work in collaboration with humans to redefine MDR with clear, actionable insights that accelerate threat resolution and strengthen security posture Palo Alto, CA—November 4, 2025—Deepwatch, the leader in Precision MDR ...

K-12 Google & Microsoft Security and Safety Through a “Single Pane of Glass”

Cloud Monitor Helps Tyrone Area School District’s IT Team Keep Accounts Secure, Students Safe, and Security Budget Justified Tyrone Area School District, located in Tyrone, Pennsylvania, serves a community of approximately 1,700 students and ...

European authorities dismantle €600 million crypto scam network

Nine people have been arrested in a coordinated international operation targeting a large cryptocurrency money laundering network that defrauded victims of more than €600 million. The operation was led by Eurojust, the EU’s judicial ...

Apple Patches 19 WebKit Vulnerabilities 

Apple has released iOS 26.1 and macOS Tahoe 26.1 with patches for over 100 vulnerabilities, including critical flaws. The post Apple Patches 19 WebKit Vulnerabilities  appeared first on SecurityWeek.

Closing the Application Layer Security Blind Spot with Contrast & Microsoft Sentinel | Contrast Security

Microsoft Sentinel has rapidly become a cornerstone for security operations, offering powerful, cloud-native Security Information and Event Management (SIEM) capabilities. Security Operations Center (SOC) teams rely on it to get a unified view of ...

Zscaler Acquires AI Security Company SPLX

SPLX red teaming, asset management, and threat inspection technology will enable Zscaler to expand its Zero Trust Exchange platform. The post Zscaler Acquires AI Security Company SPLX appeared first on SecurityWeek.

Oct Recap: New and Newly Deniable GCP Privileged Permissions

As October 2025 wraps up, Sonrai’s latest analysis of Google Cloud Platform permissions reveals both newly introduced privileged actions and those that have become newly enforceable through the V2 API, meaning organizations can now explicitly ...

Android Update Patches Critical Remote Code Execution Flaw

The November 2025 Android patches resolve two vulnerabilities, both in the platform’s System component. The post Android Update Patches Critical Remote Code Execution Flaw appeared first on SecurityWeek.

Oct Recap: New AWS Privileged Permissions and Services

As October 2025 closes, Sonrai’s latest analysis of new AWS permissions reveals a continued trend: incremental privilege changes with outsized impact. This month’s additions span OpenSearch Ingestion, Aurora DSQL, QuickSight, Parallel ...

Dohop Uses DataDome to Block Millions of Scrapers & Protect 75+ Airline Partners

Dohop cut bot traffic by 70% with DataDome, blocking millions of scrapers and protecting 75+ airline partners from API overload and downtime. The post Dohop Uses DataDome to Block Millions of Scrapers & Protect 75+ Airline Partners appeared ...

New Cisco solutions bring speed, security, and automation to distributed AI networks

Cisco is introducing innovations to modernize campus, branch, and industrial networks to support the growing use of AI. Its solutions simplify operations, scale with evolving business needs, and enhance security, all of which are critical to ...