Application Security News and Articles


SailPoint Atlas helps enterprises manage and secure their identities

SailPoint unveiled the SailPoint Atlas platform. SailPoint Atlas is the next-generation multi-tenant SaaS platform that delivers the critical elements needed to build, maintain, and scale a strong, enterprise-class identity security program. ...

What API hackers need to know about the Exploit Prediction Scoring System

Learn how to leverage the Exploit Prediction Scoring System (EPSS) to identify the vulnerabilities in your APIs that are most exploitable. The post What API hackers need to know about the Exploit Prediction Scoring System appeared first on Dana ...

Understanding the Value of Threat Intelligence

Companies today need to keep tabs on many evolving cyber threats, from sophisticated malware to stealthy phishing attacks. Complicating matters is that different threat actors with varying motivations target sectors with specific attacks and ...

Cyber Risk in CFO Lingo: CISOs Need a Financial Vocabulary

From Disregard to Nightmares: The Evolving CFO’s Perspective on Cybersecurity A few years ago, CFOs commonly delegated cybersecurity responsibilities to the IT department, viewing it as a minor operational detail. However, a recent episode ...

How and Why FireMon Pioneered Real-Time CSPM

Two years ago, FireMon elevated its game by introducing real-time features in our Cloud Defense platform. This was a significant development because it transformed our tool from a basic safety checker into a full-fledged cloud security guardian. ...

How Cloud Defense Free is Cheaper than Open Source/DIY CSPM

We are big supporters of open-source security tools and even employ some of them ourselves. However, it’s not always the right answer. Deploying and managing the infrastructure and software updates becomes your responsibility. These tools ...

Vanta AI reduces the manual, repetitive tasks hampering security teams

Vanta launched Vanta AI, a new suite of tools leveraging the latest in AI and LLMs to accelerate compliance, efficiently assess vendor risk and automate security questionnaire workflows. Featuring AI-powered vendor security reviews, generative ...

Mirai Variant IZ1H9 Adds 13 Exploits to Arsenal

A Mirai botnet variant tracked as IZ1H9 has updated its arsenal with 13 exploits targeting various routers, IP cameras, and other IoT devices. The post Mirai Variant IZ1H9 Adds 13 Exploits to Arsenal appeared first on SecurityWeek.

Open-Source Software: No Free Lunch

By Jason Turim, CTO and Co-Founder of OpsCanvas Open-source software offerings and the communities that have evolved in support of them ... The post Open-Source Software: No Free Lunch appeared first on OpsCanvas. The post Open-Source Software: ...

Riskonnect and Control Risks strengthen business resilience for companies

Riskonnect announces a new partnership with Control Risks, a global specialist risk consultancy. Control Risks is joining Riskonnect’s PartnerKonnect program to help clients build organizational resilience with technology that brings all ...

DEF CON 31 – Omer Attias’ ‘How Vulns In Global Transportation Payment Systems Cost You’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Cloudflare, Google, AWS Battle Record-Setting ‘Rapid Reset’ DDoS Attacks

Cloud giants Amazon Web Services, Google, and Cloudflare are warning about a novel zero-day vulnerability in the HTTP/2 protocol that allows threat groups to launch massive distributed denial-of-service (DDoS) attacks that dwarf previous ...

SpyHunter Web Security blocks dangerous sites and web-based threats

EnigmaSoft Limited has released SpyHunter Web Security – a browser extension that helps users block dangerous sites and web-based threats. SpyHunter Web Security offers enhanced protection against online security risks. SpyHunter Web Security ...

Utilizing Artificial Intelligence Effectively in Cybersecurity

Several AI approaches are used in cybersecurity, but it’s hard to make sense of the noise, especially when vendors say the same thing. In our newest eBook, we’ll explore what they are and the pros and cons of each one. The post Utilizing ...

N-able and SentinelOne help MSPs boost endpoint security services

N-able is deepening its ties with SentinelOne by announcing new and enhanced joint endpoint security solutions that will help MSPs capitalize on opportunities to grow their business through enterprise-grade security services delivery. Through ...

Ekran System to Speak and Exhibit at SIM Boston Technology Leadership Summit

Ekran System announces its participation in the SIM Boston Technology Leadership Summit, the premier single-day event for IT executives and solution providers. The summit takes place on October 25, 2023, at Gillette Stadium, 1 Patriot Pl, ...

SAP Releases 7 New Notes on October 2023 Patch Day

SAP has released seven new notes as part of its October 2023 Security Patch Day, all rated ‘medium severity’. The post SAP Releases 7 New Notes on October 2023 Patch Day appeared first on SecurityWeek.

Verato and CLEAR join forces to accelerate the adoption of digital identity in healthcare

Verato announced a partnership with CLEAR to accelerate the adoption of digital identity in healthcare. By joining forces, Verato’s proven, purpose-built-for-healthcare hMDM approach to enterprise identity data management and CLEAR’s ...

Heads Up: Patch for ‘Worst Curl Security Flaw’ Coming This Week

Developers who use the popular curl open-source data transfer tool will be able to patch two vulnerabilities in the software on October 11, one of which the lead developer called the “worst curl security flaw in a long time.” Daniel Stenberg, ...

SecurityWeek to Host 2023 ICS Cybersecurity Conference October 23-26 in Atlanta

SecurityWeek will host its 2023 Industrial Control Systems (ICS) Cybersecurity Conference from October 23 – 26, 2023 at the InterContinental Atlanta Buckhead. The post SecurityWeek to Host 2023 ICS Cybersecurity Conference October 23-26 in ...