Application Security News and Articles


Olympic Gold at Risk: AI Cybercriminals Target 2024 Games.

The Summer Olympic Games will be held in Paris this year, and while the athletes will be focused on breaking world records, there are plenty of opportunistic cyberthreat actors who will be focused on breaking into the event’s complex, ...

Best Strategies to Reduce Generative AI Risk

Generative AI stands as one of the most transformative technologies of our era. However, with its vast potential comes significant responsibility. The rise of generative AI brings forth notable risks that need careful management to ensure the ...

Critical Exim vulnerability facilitates malware delivery (CVE-2024-39929)

The maintainers of the Exim mail transfer agent (MTA) have fixed a critical vulnerability (CVE-2024-39929) that currently affects around 1.5 million public-facing servers and can help attackers deliver malware to users. About CVE-2024-39929 The ...

BlueVoyant Cyber Defense Platform helps organizations reduce cyber risk

BlueVoyant unveiled its innovative Cyber Defense Platform. The platform integrates internal, external, and supply chain defense solutions into a single, cloud-native platform designed to measure and strengthen cyber defense posture in a ...

How to Setup SendGrid DMARC, SPF, and DKIM Records? Easy Step-by-Step Guide

Reading Time: 3 min Learn how to set up SendGrid DMARC, SPF, and DKIM records with our easy step-by-step guide. Protect your domain from phishing and spoofing attacks. The post How to Setup SendGrid DMARC, SPF, and DKIM Records? Easy ...

Scytale Named Leader in G2’s Summer Reports

Scytale named G2's summer 2024 Leader in governance, risk, & compliance, Momentum Leader, & High Performer in cloud and security compliance! The post Scytale Named Leader in G2’s Summer Reports appeared first on Scytale. The post ...

Debian 12.6 Released with 84 Security Updates and 162 Bug Fixes

The Debian Project announced the release of Debian 12.6 on June 29, 2024, marking the fifth ISO update to its stable Debian 12 “Bookworm” series. Released four and a half months after Debian 12.5, it continues to leverage the Linux kernel 6.1 ...

600 Cybercrime Servers Linked To Cobalt Strike Shutdown

Recent news reports have brought to light a law enforcement operation codenamed MORPHEUS. The operation was conducted against the threat actors using the Cobalt strike  tool as part of their attack infrastructure and has led to the shutdown of ...

API Access Control: Optimizing your API Security

In the digital transformation era, APIs have become the glue that holds modern tech stacks together. APIs are critical for enabling seamless communication and data exchange between systems. However; the rise of API usage also presents significant ...

Security Automation for External Surface Scanning and SAST Integration

I believe good engineering has to be effective efficient and easy. So having these parameters in mind, How easily we can automate this and…Continue reading on Medium »

Risk related to non-human identities: Believe the hype, reject the FUD

The hype surrounding unmanaged and exposed non-human identities (NHIs), or machine-to-machine credentials – such as service accounts, system accounts, certificates and API keys – has recently skyrocketed. A steady stream of ...

Realm: Open-source adversary emulation framework

Realm is an open-source adversary emulation framework emphasizing scalability, reliability, and automation. It’s designed to handle engagements of any size. “Realm is unique in its custom interpreter written in Rust. This allows us to ...

Discover the growing threats to data security

In this Help Net Security interview, Pranava Adduri, CEO at Bedrock Security, discusses how businesses can identify and prioritize their data security risks. Adduri emphasizes the necessity of ongoing monitoring and automation to keep up with ...

Authy Breach: What It Means for You, RockYou 2024 Password Leak

In episode 338, we discuss the recent breach of the two-factor authentication provider Authy and its implications for users. We also explore a massive password list leak titled ‘Rock You 2024’ that has surfaced online. Find out why this file ...

Encrypted traffic: A double-edged sword for network defenders

Organizations are ramping up their use of encrypted traffic to lock down data. Could they be making it easier to hide threats in the process? On one hand, encryption means enhanced privacy, but it can also make the job of security analysts much ...

Pressure mounts for C-Suite executives to implement GenAI solutions

87% of C-Suite executives feel under pressure to implement GenAI solutions at speed and scale, according to RWS. Despite these pressures, 76% expressed an overwhelming excitement across their organization for the potential benefits of GenAI. ...

AT&T Data Breach: What Happened and How to Prevent It from Happening to Your Enterprise

AT&T Data Breach: What Happened and How to Prevent These Disasters. Discover the methods used by the hackers in the AT&T breach. The post AT&T Data Breach: What Happened and How to Prevent It from Happening to Your Enterprise appeared ...

AI and the Changing Face of Enterprise Security Threats

Explore how AI is revolutionizing enterprise security by improving threat detection, prevention, and response. Learn about the new challenges and opportunities that AI brings to the cybersecurity landscape. The post AI and the Changing Face of ...

Strengthening Digital Customer Onboarding to Combat Deep Fakes

As deepfake technology advances, the risk of fraudulent activities in digital customer onboarding increases. This article explores how to safeguard your onboarding processes against deepfakes, ensuring a secure and trustworthy experience for your ...

Google Nears $23 Billion Purchase Of Wiz: Reports

Alphabet Inc.’s Google is closing in on a $23 billion acquisition of cybersecurity firm Wiz – its largest purchase ever, according to published reports. The mega-deal, first reported by the Wall Street Journal on Sunday, is in advanced talks ...