Tag: http://www.infosecurity-magazine.com/rss/news/76/application-security/

#InfosecurityEurope: Dunelm Shifts Security to the Edge

An increased focus on security allows furnishings retailer to boost its e-commerce operations This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Dunelm Shifts Security to the Edge

#InfosecurityEurope: Internet of Things Continues to Pose Security Risk

The growth of IoT and connected devices is contributing to an expanding attack surface, despite upcoming legal controls This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Internet of Things Continues to Pose Security Risk

Supply Chain and APIs Top Security Concerns, CISO Survey Shows

Findings indicate that 89% of CISOs are grappling with risks arising from the rapid deployment of digital services This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Supply Chain and APIs Top Security Concerns, CISO Survey Shows

Security Researchers Uncover New Spyware Implant TriangleDB

Kaspersky report that the implant specifically targets iOS devices via a malicious iMessage attachment This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Security Researchers Uncover New Spyware Implant TriangleDB

#InfosecurityEurope: One in Three UK&I Workers Susceptible to Phishing

KnowBe4 report revealed that 35.2% of users with no security training were prone to clicking on suspicious links This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: One in Three UK&I Workers Susceptible to Phishing

#InfosecurityEurope: Does Pentesting Need a New Service Model?

Shortlisted as one of the UK’s Most Innovative Cyber SMEs in 2023, the startup presented its vision of PTaaS during Infosecurity Europe This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Does Pentesting Need a New Service…

#InfosecurityEurope: Why API Security Could Be the Next Big Thing in Cyber

APIs have become fundamental to everyone’s digital life, yet API security continues to be overlooked, Contxt’s CEO Mayur Upadhyaya said during Infosecurity Europe This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Why API Security Could Be…

#InfosecurityEurope: Certifications Are No Guarantee of Security

Despite their importance, security certifications can work against diversity and innovation, according to a CISO panel This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Certifications Are No Guarantee of Security

#InfosecurityEurope: Certifications are no guarantee of security

Despite their importance, security certifications can work against diversity and innovation, according to a CISO panel This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Certifications are no guarantee of security

Smart Pet Feeders Expose Personal Data

Kaspersky warns of two security flaws discovered in popular smart pet feeders that could lead to data theft This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Smart Pet Feeders Expose Personal Data

#InfosecurityEurope: Ironscales Launches GPT-Powered Chat Assistant for Self-Service Threat Reporting

The email security provider launched the Beta program for Themis Co-pilot, a large language model-based chat assistant for Microsoft Outlook security This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Ironscales Launches GPT-Powered Chat Assistant for Self-Service…

#InfosecurityEurope: Netskope Sets Out to Help Enterprises Safely Use ChatGPT

Netskope’s new solution aims to enable organizations to use generative AI tools without running cybersecurity or data protection risks This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Netskope Sets Out to Help Enterprises Safely Use ChatGPT

US Offers $10m Reward For MOVEit Attackers

State department wants information on Clop ransomware actors This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: US Offers $10m Reward For MOVEit Attackers

UK Pledges Millions in Cyber-Defense Aid to Ukraine

Funds will help to protect under-siege country’s critical infrastructure This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: UK Pledges Millions in Cyber-Defense Aid to Ukraine

Russian National Arrested in Connection With LockBit Ransomware

Ruslan Magomedovich Astamirov allegedly targeted computer systems in the US, Asia, Europe and Africa This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Russian National Arrested in Connection With LockBit Ransomware

Barracuda Zero-Day Exploited by Chinese Actor

Mandiant lifts the lid on new espionage campaign This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Barracuda Zero-Day Exploited by Chinese Actor

Cyber-Criminals Are Using Mining Pools to Launder Crypto

Chainalysis claims threat actors are using these services like mixers This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Cyber-Criminals Are Using Mining Pools to Launder Crypto

Clop Starts MOVEit Extortion as New Bug is Discovered

Progress Software scrambles to release a new security update This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Clop Starts MOVEit Extortion as New Bug is Discovered

CISA and NSA Publish BMC Hardening Guidelines

Vulnerabilities in Baseboard Management Controllers (BMCs) serve as entry points for malicious actors This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: CISA and NSA Publish BMC Hardening Guidelines

Study Reveals Ransomware as Most Popular Cybercrime Service

Kaspersky also said 24% were infostealers and 18% included botnets, loaders and backdoors This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Study Reveals Ransomware as Most Popular Cybercrime Service

Microsoft Names Russian Threat Actor “Cadet Blizzard”

Microsoft believes Cadet Blizzard, formerly DEV-0586, to be associated with the Russian GRU This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Microsoft Names Russian Threat Actor “Cadet Blizzard”

#InfosecurityEurope: New Study Takes a Deep Dive Into Lookalike Attacks

The latest study from Infosecurity Europe exhibitor Infoblox reveals that cyber-attacks using lookalike domains are on the rise This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: New Study Takes a Deep Dive Into Lookalike Attacks

LockBit Makes $91m From US Victims in Two Years

Allied security agencies reveal figure in new advisory This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: LockBit Makes $91m From US Victims in Two Years

LockBit Makes $91m from US Victims in Two Years

Allied security agencies reveal figure in new advisory This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: LockBit Makes $91m from US Victims in Two Years

Malicious Actors Exploit GitHub to Distribute Fake Exploits

The perpetrators went to great lengths to make their profiles appear genuine This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Malicious Actors Exploit GitHub to Distribute Fake Exploits

EU Passes Landmark Artificial Intelligence Act

The European Parliament adopted the latest draft of the legislation with an overwhelming majority This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: EU Passes Landmark Artificial Intelligence Act

Researchers Uncover XSS Vulnerabilities in Azure Services

They could allow unauthorized access to sessions within the compromised Azure service iframe This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Researchers Uncover XSS Vulnerabilities in Azure Services

Europol Warns of Metaverse and AI Terror Threat

Emerging technologies could help propaganda and recruitment efforts This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Europol Warns of Metaverse and AI Terror Threat

Fortinet Addresses Critical FortiGate SSL-VPN Vulnerability

The release notes did not initially mention the critical SSL-VPN RCE vulnerability being addressed This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Fortinet Addresses Critical FortiGate SSL-VPN Vulnerability

Crypto Wallets Under Attack By DoubleFinger Malware

The malware discovered by Kaspersky employs a multistage attack method This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Crypto Wallets Under Attack By DoubleFinger Malware

#InfosecurityEurope: What TechUK’s New Plan Means for Cybersecurity

The British tech trade association called for more collaboration between government and industry actors to improve the security of critical sectors This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: What TechUK’s New Plan Means for Cybersecurity

#InfosecurityEurope: Top Five Things to Check Out at This Year’s Event

With Infosecurity Europe just around the corner, here are four of the must-see activities happening at this year’s event This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: #InfosecurityEurope: Top Five Things to Check Out at This Year’s…

Microsoft Pays $20m to Settle Another FTC COPPA Case

Regulator alleged Microsoft knowingly collected personal information from children This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Microsoft Pays $20m to Settle Another FTC COPPA Case

Ofcom Latest MOVEit Victim as Exploit Code Released

UK regulator admits hundreds of employees are impacted This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Ofcom Latest MOVEit Victim as Exploit Code Released

Historic Zacks Breach Impacts Nearly Nine Million

Stock research firm revealed more recent incident in January This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Historic Zacks Breach Impacts Nearly Nine Million

Data Flows Between UK and US to be Simplified Under New Agreement

The ‘data bridge’ is an extension to the Data Privacy Framework agreed between the US and EU last year This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Data Flows Between UK and US to be Simplified Under…

Swiss Government Targeted by Series of Cyber-Attacks

A DDoS attack targeting Switzerland’s administration is the third campaign targeting the country in two weeks This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Swiss Government Targeted by Series of Cyber-Attacks

Barracuda Urges Swift Replacement of Vulnerable ESG Appliances

Investigating the ESG bug, Rapid7 assumed the presence of persistent malware hindering device wipes This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Barracuda Urges Swift Replacement of Vulnerable ESG Appliances

Security Experts Highlight Exploit for Patched Windows Flaw

Numen Cyber said exploiting the vulnerability does not require novel techniques This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Security Experts Highlight Exploit for Patched Windows Flaw

Google Launches Framework to Secure Generative AI

The Secure AI Framework (SAIF) is a first step to help collaboratively secure AI technology, said Alphabet’s subsidiary This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Google Launches Framework to Secure Generative AI

Minecraft Users Warned of Malware Targeting Modpacks

Bitdefender researchers warn that mods and plugins have been rigged by the infostealer malware, dubbed Fractureiser This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Minecraft Users Warned of Malware Targeting Modpacks

Pharmaceutical Giant Eisai Hit By Ransomware Incident

Several systems, including logistics systems, have been temporarily taken offline This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Pharmaceutical Giant Eisai Hit By Ransomware Incident

Microsoft Brings OpenAI Tech to US Agencies

The capabilities will expedite content generation and enhance decision-making processes This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Microsoft Brings OpenAI Tech to US Agencies

Lazarus Group Blamed for Atomic Wallet Heist

Notorious North Korean group pegged for recent campaign This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Lazarus Group Blamed for Atomic Wallet Heist

CISA and Partners Publish Guide For Remote Access Security

Cyber-actors are utilizing these tools for easy and broad access to victim systems This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: CISA and Partners Publish Guide For Remote Access Security

Cisco Counterfeiter Pleads Guilty to $100m Scheme

Dual US/Turkish citizen ran at least 19 companies This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Cisco Counterfeiter Pleads Guilty to $100m Scheme

FBI Warns of Surge in Deepfake Sextortion Attempts

Fake imagery is being used to harass and extort victims This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: FBI Warns of Surge in Deepfake Sextortion Attempts

CVEs Surge By 25% in 2022 to Another Record High

Volume of new vulnerabilities has increased three-fold in a decade This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: CVEs Surge By 25% in 2022 to Another Record High

Three Vulnerabilities Discovered in Game Dev Tool RenderDoc

Qualys identified one instance of privilege escalation and two heap-based buffer overflows This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Three Vulnerabilities Discovered in Game Dev Tool RenderDoc

Exploitation of Vulnerabilities Have Soared, Unit 42 Report Finds

The Palo Alto Networks report also suggests Linux malware emerged as a growing concern last year This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Exploitation of Vulnerabilities Have Soared, Unit 42 Report Finds

New ChatGPT Attack Technique Spreads Malicious Packages

Vulcan Cyber’s Voyager18 research team called the technique “AI package hallucination” This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: New ChatGPT Attack Technique Spreads Malicious Packages

BEC Volumes and Ransomware Costs Double in a Year

Annual Verizon report reveals humans are still a major source of risk This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: BEC Volumes and Ransomware Costs Double in a Year

Critical Zero-Day Flaw Exploited in MOVEit Transfer

The vulnerability (CVE-2023-34362) can grant escalated privileges and unauthorized access This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Critical Zero-Day Flaw Exploited in MOVEit Transfer

Spanish Bank Globalcaja Hit By Ransomware Attack

The firm said the attack occurred last Thursday and prompted it to activate its security protocols This article has been indexed from http://www.infosecurity-magazine.com/rss/news/76/application-security/ Read the original article: Spanish Bank Globalcaja Hit By Ransomware Attack