Application Security News and Articles


The Surge in Cyberattacks on UK Retailers: Understanding the Threat and Navigating the Future

In recent weeks, the UK retail sector has been rocked by a series of high-profile cyberattacks, targeting major players such as Marks & Spencer (M&S), Harrods, and the Co-operative Group. Read More The post The Surge in Cyberattacks on UK ...

Q1 2025 Recap: GitGuardian Doubles Down on Secrets Security and Machine Identity Control

GitGuardian launches new NHI Governance, enhanced synergies with Secret Manager integrations, smarter context analysis, container registry scanning, historical scanning for Jira & Confluence, and more. Take control of your secrets security, ...

White House Proposal Slashes Half-Billion from CISA Budget

The proposed $491 million cut is being positioned as a “refocusing”of CISA on its core mission “while eliminating weaponization and waste.” The post White House Proposal Slashes Half-Billion from CISA Budget appeared first on SecurityWeek.

BSidesLV24 – Proving Ground – An Adversarial Approach To Airline Revenue Management

Author/Presenter: Craig Lester Our sincere appreciation to BSidesLV, and the Presenters/Authors for publishing their erudite Security BSidesLV24 content. Originating from the conference’s events located at the Tuscany Suites & Casino; and ...

Seceon Wins Three Global Infosec Awards at RSAC 2025

At Seceon, we’ve always believed that solving cybersecurity isn’t about adding more tools but building smarter ones. That belief was validated in a big way this year at RSAC 2025, where we proudly took home three Global Infosec Awards.

Doppel Banks $35M for AI-Based Digital Risk Protection

The new investment values Doppel at $205 million and provides runway to meet enterprise demand for AI-powered threat detection tools. The post Doppel Banks $35M for AI-Based Digital Risk Protection appeared first on SecurityWeek.

Kelly Benefits Data Breach Impact Grows to 400,000 Individuals

Kelly Benefits has determined that the impact of the recently disclosed data breach is much bigger than initially believed. The post Kelly Benefits Data Breach Impact Grows to 400,000 Individuals appeared first on SecurityWeek.

California Man Will Plead Guilty to Last Year’s Disney Hack

A 25-year-old California man will plead guilty to hacking into a Disney's personal computer and using stolen credentials to break into thousands of Disney Slack channels. Ryan Mitchell Kramer, who claimed to be a member of the Russian group ...

Critical Commvault Vulnerability in Attacker Crosshairs

CISA has flagged a critical-severity Commvault vulnerability as exploited one week after technical details were released. The post Critical Commvault Vulnerability in Attacker Crosshairs appeared first on SecurityWeek.

UK retailers under cyber attack: Co-op member data compromised

UK-based retailers Marks & Spencer, Co-op, and Harrods have been targeted by cyber attackers in the last few weeks. Whether the attacks have been mounted by the same group is difficult to say for sure: the victimized businesses are sharing ...

Man Admits Hacking Disney and Leaking Data Disguised as Hacktivist 

A 25-year-old has admitted hacking Disney systems and leaking data under the guise of a hacktivist collective named NullBulge. The post Man Admits Hacking Disney and Leaking Data Disguised as Hacktivist  appeared first on SecurityWeek.

Ransomware Group Claims Attacks on UK Retailers

The DragonForce ransomware group has claimed responsibility for the recent cyberattacks on UK retailers Co-op, Harrods, and M&S. The post Ransomware Group Claims Attacks on UK Retailers appeared first on SecurityWeek.

The Ultimate ISO 27001 Checklist: Step-by-Step Guide to Simplify Your Compliance Journey

Navigating the path to ISO 27001 certification resembles assembling IKEA flat-pack furniture. Each piece is essential, but the sparse instructions can leave you scratching your head. Sure, both ISO and IKEA have Scandinavian roots, but when it ...

PoC Published for Exploited SonicWall Vulnerabilities

PoC code targeting two exploited SonicWall flaws was published just CISA added them to the KEV catalog. The post PoC Published for Exploited SonicWall Vulnerabilities appeared first on SecurityWeek.

DevSecOps Phase 3: Build Stage — CI/CD Security Gate with SAST + SCA

Here’s a comprehensive deep-dive guide into Step 3 of DevSecOps — “Build Stage → CI/CD Security Gate with SAST + SCA”, covering:Continue reading on InfoSec Write-ups »

Nuances about configuring Semgrep automated scans

I was recently struggling to use Semgrep in its official Docker container to scan some images, due to some little nuances, although not…Continue reading on System Weakness »

AirSwap $sAST: A Smart Way to Maximize Earnings

Efficient Techniques to Earn More with AirSwap $sASTContinue reading on Medium »

Cybersecurity M&A Roundup: 31 Deals Announced in April 2025

Thirty-one cybersecurity merger and acquisition (M&A) deals were announced in April 2025. The post Cybersecurity M&A Roundup: 31 Deals Announced in April 2025 appeared first on SecurityWeek.

MY TAKE: RSAC 2025’s big takeaway — GenAI is growing up fast, but still needs human direction

SAN FRANCISCO — The cybersecurity industry showed up here in force last week: 44,000 attendees, 730 speakers, 650 exhibitors and 400 members of the media flooding Moscone Convention Center in the City by the Bay. Related: RSAC 2025 by the … ...

Why EASM Projects Fail: Three Pitfalls to Avoid 

If you avoid the pitfalls detailed in this article, then EASM can provide a great defense against two-thirds of your breach problem.  The post Why EASM Projects Fail: Three Pitfalls to Avoid  appeared first on Security Boulevard.