Application Security News and Articles


Enterprises increasingly turn to cloud and AI for database management

Across various tasks, from predictive analytics to code generation, organizations in all sectors are exploring how AI can add value and increase efficiency. In this Help Net Security video, Ryan Booz, PostgreSQL Advocate at Redgate, discusses the ...

How to Leverage Advanced Customer Identity Resolution for Better Marketing Outcomes

In the digital marketing landscape, understanding your customers is crucial for driving exceptional results. Advanced customer identity resolution unifies disparate data points to create comprehensive customer profiles. This enables personalized ...

How NinjaOne’s New MDM Capabilities Transform IT Management

IT security teams are tasked with protecting an increasingly mobile work environment—managing a myriad of devices efficiently and securely. Addressing this need, NinjaOne has launched its new Mobile Device Management (MDM) capabilities, marking ...

Chinese APT Groups Use Ransomware to Hide Spying Activities

A Chinese cyberespionage group and two more possibly from China and North Korea are using ransomware in their attacks to either add financial gains to their efforts or to cover their tracks by convincing victims and cybersecurity experts that the ...

News Alert: FireTail unveils free access to its enterprise-level API security platform — to all

McLean, Va., June 26, 2024, CyberNewsWire — FireTail today announced a free version of its enterprise-level API security tools, making them accessible to developers and organizations of all sizes. •FireTail’s unique combination of ...

USENIX Security ’23 – Assessing Anonymity Techniques Employed in German Court Decisions: A De-Anonymization Experiment

Authors/Presenters:Dominic Deuber, Michael Keuchen, Nicolas Christin Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from ...

Protecting the Soft Underbelly of the Data Center

The CIS Controls list hardware asset management as the most important security control, but how many organizations keep track of the components that make up the servers in their datacenter? Components such as baseboard management controllers, ...

A Milestone of Excellence: Praetorian Security Inc. Named to Inc.’s Best Workplaces

This recognition is more than just a badge of honor; it is a testament to what makes Praetorian an exceptional place to work. The dedication exhibited daily by each team member truly sets us apart, highlighting the organic culture shaped by our ...

FakePenny Ransomware, Qilin Ransomware, and More: Hacker’s Playbook Threat Coverage Round-up: June 2024

New and updated coverage for ransomware and malware variants, including AI Threat Scenario, GuLoader, DarkGate, MirrorBlast, & Kutaki Stealer The post FakePenny Ransomware, Qilin Ransomware, and More: Hacker’s Playbook Threat Coverage ...

Scattered Spider: Evolving & Resilient Group Proves Need for Constant Defender Vigilance

Recent reporting highlighted new techniques for a prominent group that already possessed a deep set of capabilities. As the pace of adversary TTP evolution increases, organizations must stay vigilant and regularly reassess their defenses against ...

Randall Munroe’s XKCD ‘Network Configuration’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Network Configuration’ appeared first on Security Boulevard.

Pen Testing Across the Environment: External, Internal, and Wireless Assessments

The post Pen Testing Across the Environment: External, Internal, and Wireless Assessments appeared first on Digital Defense. The post Pen Testing Across the Environment: External, Internal, and Wireless Assessments appeared first on Security ...

WordPress Plugin Supply Chain Attack Gets Worse

30,000 websites at risk: Check yours ASAP! (800 Million Ostriches Can’t Be Wrong.) The post WordPress Plugin Supply Chain Attack Gets Worse appeared first on Security Boulevard.

A WIN for Cloud Security with Adaptive Shield and Wiz

It’s easy to confuse CSPM and SSPM (Cloud Security Posture Management and SaaS Security Posture Management). They both secure assets on the cloud, automatically identify misconfigurations, and detect identity-based threats. The difference ...

Malicious npm package targets AWS users

ReversingLabs researchers have made it a priority to monitor public, open source repositories for malicious packages that may lurk on them in recent years. The number and frequency of malicious packages has increased steadily as malicious actors ...

Dependency Management vs Dependency Updates: What’s the Difference?

Keeping dependencies up to date is a big part of dependency management, but it's not everything. Learn more about the differences between the two. The post Dependency Management vs Dependency Updates: What’s the Difference? appeared first on ...

New Portal Helps Devs Spot Malicious Open Source Packages

Spotting compromises hidden deep in open source- or commercial supply chains is difficult under the best of circumstances. For developers and development teams tasked with achieving aggressive development and release goals — an environment in ...

GAO Urges Action to Address Critical Cybersecurity Challenges Facing U.S.

A report from the Government Accountability Office (GAO) highlighted an urgent need to address critical cybersecurity challenges facing the nation. The post GAO Urges Action to Address Critical Cybersecurity Challenges Facing U.S. appeared first ...

Misconfigured MFA Increasingly Targeted by Cybercriminals

In the first quarter of 2024, nearly half of all security incidents our team responded to involved multi-factor authentication (MFA) issues, according to the latest Cisco Talos report. The post Misconfigured MFA Increasingly Targeted by ...

Choosing Your Kubernetes Cloud Provider: The Pros and Cons of GKE

Kubernetes was released over ten years ago by Google as an open source project to improve container orchestration. While several cloud providers offer managed Kubernetes services, Google Kubernetes Engine (GKE) was (unsurprisingly) the first to ...