Application Security News and Articles


How cyber fusion is helping enterprises modernize security operations

In this Help Net Security video, Anuj Goel, CEO at Cyware, explains how cyber fusion is helping enterprises modernize their security operations and turn their SOC from reactive to proactive. The post How cyber fusion is helping enterprises ...

Endpoint malware attacks decline as campaigns spread wider

In Q2 2023, 95% of malware now arrives over encrypted connections, endpoint malware volumes are decreasing despite campaigns growing more widespread, ransomware detections are declining amid a rise in double-extortion attacks, and older software ...

Cloud security and functionality: Don’t settle for just one

Cloud security is important to you, but that doesn’t mean you’re willing to trade security for functionality. You need security to work for you. Whatever cloud security resources you’re using must be compatible with the services you use to ...

Why Smart SOAR is the Best SOAR for Darktrace

The need for integrated cybersecurity solutions has never been more pressing. With the growing complexity of cyber threats, having siloed security tools is no longer an option. This is where the synergy between Smart SOAR and Darktrace comes into ...

Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks

Microsoft says an APT group tracked as Storm-0062 has been hacking Confluence installations since mid-September, three weeks before Atlassian’s disclosure. The post Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks ...

Patch Tuesday, October 2023 Edition

Microsoft today issued security updates for more than 100 newly-discovered vulnerabilities in its Windows operating system and related software, including four flaws that are already being exploited. In addition, Apple recently released emergency ...

Unlock SOAR’s Potential This Cybersecurity Awareness Month

As we celebrate Cybersecurity Awareness Month in 2023, the importance of fortifying our digital defenses against ever-evolving threats cannot be overstated. This year, the focus revolves around three critical pillars: improving authentication, ...

How California’s New Emissions Disclosure Law Will Affect Data Centers

California has recently passed a new law that requires large businesses to disclose their direct and indirect greenhouse gas (GHG) emissions. This law, which is the most comprehensive of its kind in the nation, will affect more than 5,300 ...

Data sprawl: why application access controls as a security strategy doesn’t work

As enterprises maintain more and more data, there is a greater need to ensure that sensitive data is protected. Privacy regulations are increasing which is fantastic for individuals who want to keep their data secure, but this places a burden on ...

Patch Tuesday Update – October 2023

The post Patch Tuesday Update - October 2023 appeared first on Digital Defense. The post Patch Tuesday Update – October 2023 appeared first on Security Boulevard.

Safeguarding the Travel and Hospitality Industry from SMS Toll Fraud

Attackers are using bots to scale up SMS toll fraud, resulting in massive overall telecom bills for travel and hospitality companies. To protect their businesses, these companies must deploy smart bot management solutions before bots can reach ...

DEF CON 31 – Perri Adams’s & Panel: Michael Sellitto’s, Heather Adkins’, Vijay Bolina’s, Dave Weston’s, Matt Knight’s, Omkhar Arasara’s ‘DARPA AI Cyber Challenge Announcement’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Microsoft fixes exploited WordPad, Skype for Business zero-days (CVE-2023-36563, CVE-2023-41763)

On this October 2023 Patch Tuesday, Microsoft has released 103 patches and has fixed three actively exploited vulnerabilities (CVE-2023-36563, CVE-2023-41763, CVE-2023-44487). The exploited zero-days (CVE-2023-36563, CVE-2023-41763, ...

Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business

Microsoft patches more than 100 vulnerabilities across the Windows ecosystem and warned that three are already being exploited in the wild. The post Microsoft Fixes Exploited Zero-Days in WordPad, Skype for Business appeared first on SecurityWeek.

Beyond the Front Lines: How the Israel-Hamas War Impacts the Cybersecurity Industry

The war with Hamas will inevitably absorb manpower and focus from the cybersecurity sector. The post Beyond the Front Lines: How the Israel-Hamas War Impacts the Cybersecurity Industry appeared first on SecurityWeek.

Dictionary Attacks: How They Decode Passwords

The post Dictionary Attacks: How They Decode Passwords appeared first on AI Enabled Security Automation. The post Dictionary Attacks: How They Decode Passwords appeared first on Security Boulevard.

Randall Munroe’s XKCD ‘Dubious Islands’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD! Permalink The post Randall Munroe’s XKCD ‘Dubious Islands’ appeared first on Security Boulevard.

Google Pushes ‘Passkeys’ Plan — but it’s Too Soon for Mass Rollout

FIDO FAIL: “Killing passwords” is a worthy goal—but is coercion the best way? The post Google Pushes ‘Passkeys’ Plan — but it’s Too Soon for Mass Rollout appeared first on Security Boulevard.

Top 6 Things to Know about Kubernetes Spending (and How to Manage It)

Kubernetes makes it easy to deploy and scale containerized applications quickly and efficiently, and when built in alignment with best practices, it can increase the reliability, cost-efficiency, and security of deployments. As deployment to ...

Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop

Adobe Commerce customers exposed to code execution, privilege escalation, arbitrary file system read, and security feature bypass attacks. The post Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop appeared first on SecurityWeek.