Application Security News and Articles


VMware patches critical vulnerability in vCenter Server (CVE-2023-34048)

VMware has fixed a critical out-of-bounds write vulnerability (CVE-2023-34048) and a moderate-severity information disclosure flaw (CVE-2023-34056) in vCenter Server, its popular server management software. About CVE-2023-34048 and CVE-2023-34056 ...

PlainID partners with BigID to enhance data protection and visibility for customers

PlainID announces their strategic partnership with BigID to deliver an enhanced data protection solution for its customers. This collaboration brings together the unique strengths and capabilities of both companies to provide enterprises complete ...

Preparing for a Cyber Catastrophe With a Data-Driven Risk Appetite | Kovrr Blog

Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post Preparing for a Cyber Catastrophe With a Data-Driven Risk Appetite | Kovrr Blog appeared first on Security Boulevard.

AWS European Sovereign Cloud allows customers to keep all metadata in the EU

AWS announced it will launch the AWS European Sovereign Cloud, a new, independent cloud for Europe designed to help public sector customers and those in highly regulated industries meet the most stringent regulatory data residency and operational ...

A Visual Journey: Exploring the Redesigned Bolster Dashboard

One of the top challenges that security practitioners often face is acting on the data that is presented in front of them. To address these challenges and expedite responses to growing threats, we at Bolster are launching a redesigned data ...

How To Prevent The Gmail Unauthenticated Question Mark?

Should you observe a question mark alongside the sender's name in Gmail, it signifies that the message lacks authentication. The post How To Prevent The Gmail Unauthenticated Question Mark? appeared first on Security Boulevard.

The Importance of Secure Email in Building Trust with Customers

Securing your email plays a vital role in protecting your clients against cyber threats and safeguarding your brand’s reputation. The post The Importance of Secure Email in Building Trust with Customers appeared first on Security Boulevard.

DMARC “t=” Tag replaces “pct” in DMARCbis

Over time, the DMARC protocol has seen several updates, and one such significant change is the replacement of the "pct" tag with the "t" tag. The post DMARC “t=” Tag replaces “pct” in DMARCbis appeared first on Security Boulevard.

CEO Phishing – Can you trust the email from your boss?

CEO Phishing involves impersonating high-ranking company executives, like the CEO or CFO tp trick employees. The post CEO Phishing – Can you trust the email from your boss? appeared first on Security Boulevard.

What is operational risk and why should you care? Assessing SEC rule readiness for OT and IoT

The newly released Security and Exchange Commission (SEC) cyber incident disclosure rules have been met with mixed reviews. Of particular concern is whether public companies who own and operate industrial control systems and connected IoT ...

Strategies to overcome cybersecurity misconceptions

Many CISOs may believe their cybersecurity defenses are robust enough to repel any attack, but there are critical misconceptions they may be harboring. In this Help Net Security video, Kevin Kirkwood, Deputy CISO at LogRhythm, stresses that one ...

Security leaders have good reasons to fear AI-generated attacks

Generative AI is likely behind the increases in both the volume and sophistication of email attacks that organizations have experienced in the past few months, and it’s still early days, according to Abnormal Security. Their leading worry ...

Consumers are taking action to protect their privacy

Younger consumers are taking deliberate action to protect their privacy, as 42% of consumers aged 18-24 exercise their Data Subject Access Rights, compared with just 6% for consumers 75 and older, according to Cisco. Consumers express willingness ...

Personal Information Stolen in City of Philadelphia Email Hack

The City of Philadelphia says personal, health, and financial information was stolen in a cyberattack on its email environment. The post Personal Information Stolen in City of Philadelphia Email Hack appeared first on SecurityWeek.

Handling SaaS Data Exposure Risks Due to Potential ServiceNow Misconfigurations

See the impact of customer-side SaaS app misconfigurations, like those recently reported on ServiceNow, and how a robust SSPM solution can mitigate possible risk. The post Handling SaaS Data Exposure Risks Due to Potential ServiceNow ...

DEF CON 31 – Craig Martell’s ‘Shall We Play A Game’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Stealth Techniques Used in ‘Operation Triangulation’ iOS Attack Dissected

Kaspersky analyzes the stealth techniques that were used in the ‘Operation Triangulation’ iOS zero-click attacks. The post Stealth Techniques Used in ‘Operation Triangulation’ iOS Attack Dissected appeared first on SecurityWeek.

IBM: ChatGPT-Generated Can Write Convincing Phishing Emails

OpenAI’s widely popular ChatGPT can write phishing emails that are almost as convincing as those created by humans and can write them exponentially faster, according to research from IBM that is sure to ramp up corporate worries about ...

Rockwell Automation Warns Customers of Cisco Zero-Day Affecting Stratix Switches

Rockwell Automation has warned customers about the impact of the actively exploited Cisco IOS XE zero-day on its Stratix industrial switches. The post Rockwell Automation Warns Customers of Cisco Zero-Day Affecting Stratix Switches appeared first ...