Application Security News and Articles


Agile2024: Making Sure Security Is Part Of Our Processes

What does Agile have to do with improving security? A lot! Explore highlights from Agile2024, including technical health, productive meetings, and addressing shadow IT. The post Agile2024: Making Sure Security Is Part Of Our Processes appeared ...

Fortanix Extends Encyption Key Discovery to On-Premises IT Platforms

Fortanix today extended the reach of its ability to discover encryption keys to on-premises IT environments to enable organizations to more comprehensively manage risks. The post Fortanix Extends Encyption Key Discovery to On-Premises IT ...

Uncover Your Attack Surface with Discover from DataDome

Discover, a new feature available to all DataDome customers, enables organizations to identify blind spots and shrink attack surfaces against malicious bots and fraudsters. The post Uncover Your Attack Surface with Discover from DataDome appeared ...

Enzoic Dark Web Data Integration with IDTR Solutions

For IDTR solutions, addressing compromised credentials head-on is crucial to protecting end users' environments. The post Enzoic Dark Web Data Integration with IDTR Solutions appeared first on Security Boulevard.

Traveling Abroad? Here’s How to Keep Your Digital Identity Safe

Traveling abroad is not just about packing your bags and booking your flights. It’s also about securing your digital identity while away from home. As we increasingly rely on digital tools for everything from navigation to communication, it’s ...

Centraleyes Privacy Framework (CPF)

What is the CPF? The Centraleyes Privacy Framework (CPF) is a comprehensive compliance tool designed to help organizations adhere to the diverse privacy regulations that are individual to each state in the United States. As of now, these states ...

Average data breach cost jumps to $4.88 million, collateral damage increased

IBM released its annual Cost of a Data Breach Report revealing the global average cost of a data breach reached $4.88 million in 2024, as breaches grow more disruptive and further expand demands on cyber teams. Breach costs increased 10% from the ...

Adaptive Shield unveils ITDR platform for SaaS

Adaptive Shield has unveiled its Identity Threat Detection & Response (ITDR) platform for SaaS environments. The recent Snowflake breach served as a wake-up call for the SaaS industry. On May 27, a threat group announced the sale of 560 ...

Providing Security Updates to Automobile Software

Auto manufacturers are just starting to realize the problems of supporting the software in older models: Today’s phones are able to receive updates six to eight years after their purchase date. Samsung and Google provide Android OS updates and ...

VMware ESXi auth bypass zero-day exploited by ransomware operators (CVE-2024-37085)

Ransomware operators have been leveraging CVE-2024-37085, an authentication bypass vulnerability affecting Active Directory domain-joined VMware ESXi hypervisors, to gain full administrative access to them and encrypt their file system. VMware ...

OCI Customers Can Now Externally Manage Encryption Keys from a Cloud-Based Service

OCI Customers Can Now Externally Manage Encryption Keys from a Cloud-Based Service madhav Tue, 07/30/2024 - 10:20 Oracle stands apart by offering a comprehensive suite of services across all its cloud delivery models, from Oracle Alloy and ...

The Complete 2024 Crawler List You Need to Identify All Web Crawlers

The most completed and up to date crawlers list including the most common ones, the top SEO and TOOLS crawlers The post The Complete 2024 Crawler List You Need to Identify All Web Crawlers appeared first on Security Boulevard.

Too big to care? – Our disappointment with Cloudflare’s anti-abuse posture

Cloudflare, best known for its content delivery network (CDN), is marketed as a “Connectivity Cloud”. Part of its offering is protecting a vast number of websites from DDoS attacks [1]. However, its attitude to abuse management and prevention ...

Ubuntu Fixes Two OpenVPN Vulnerabilities

Two vulnerabilities were discovered in openvpn, a virtual private network software which could keep the closing session active or result in denial of service. Canonical released security updates to address these vulnerabilities in affected Ubuntu ...

Report: An 18% Increase in Ransomware Attacks Includes $75M Payment

A report published today by Zscaler finds an 18% increase in ransomware attacks, including one that involved a record $75 million payment that appears to have been made to the Dark Angels ransomware group. The post Report: An 18% Increase in ...

Cisco Security Patches: Max Severity Security Flaw Fixed

Cisco has recently released patches pertaining to a maximum severity security flaw. As per recent reports, the Cisco security patches are for flaws within the Smart Software Manager On-Prem (Cisco SSM On-Prem). In this article, we’ll dive into ...

DataDome to Demo Discover, an Innovative Tool to Eliminate Cyberfraud Blind Spots, at Black Hat USA 2024

With Discover, a new capability in the DataDome Cyberfraud Protection Platform, enterprises can better understand and protect their attack surface. The post DataDome to Demo Discover, an Innovative Tool to Eliminate Cyberfraud Blind Spots, at ...

Are Free Distributions of OpenJDK Safe to Use?

All Java builds that pass the TCK suite of tests, even free distributions of OpenJDK, are compliant with Java SE standards and safe to use. The post Are Free Distributions of OpenJDK Safe to Use? appeared first on Azul | Better Java ...

Review: Action1 – Simple and powerful patch management

Although endpoint anti-malware and other security controls are now standard at the operating system level, keeping all endpoint software up-to-date and secure remains an open issue for many organizations. Patch management is not yet a commodity, ...

Securing remote access to mission-critical OT assets

In this Help Net Security interview, Grant Geyer, Chief Strategy Officer at Claroty, discusses the prevalent vulnerabilities in Windows-based engineering workstations (EWS) and human-machine interfaces (HMI) within OT environments. Geyer also ...