Application Security
Many developers and security people admit to having experienced a breach effected through compromised API credentials.
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
Many developers and security people admit to having experienced a breach effected through compromised API credentials.
Vendors and agencies are bypassing a security patch that Adobe released in February 2022 to address CVE-2022-24086.
Canadian liquor distributor Liquor Control Board of Ontario said a web skimmer injected into its online store was used to steal data.
Electric car maker Tesla is using the annual Pwn2Own hacker contest to incentivize security researchers to showcase complex exploit chains that can lead to...
Hack The Box Raises $55 Million in Funding Round Led by Carlyle
Microsoft’s security patching machine hummed into overdrive Tuesday with the release of fixes for at least 97 documented software vulnerabilities, including a zero-day that’s...
Software maker Adobe has rolled out its first batch of security patches for 2023 with fixes for at least 29 security vulnerabilities in a...
Microsoft-owned code hosting platform GitHub is now providing developers with the option to have their code repositories automatically scanned for vulnerabilities.Available as a ‘default...
Security researchers at Microsoft are flagging ransomware attacks on Apple’s flagship macOS operating system, warning that financially motivated cybercriminals are abusing legitimate macOS functionalities...
Enterprise communication and collaboration platform Slack has informed customers that hackers have stolen some of its private source code repositories, but claims impact is...
Last week’s nightly builds of the open source machine learning framework PyTorch were injected with malware following a supply chain attack.Now part of the...
Microsoft has silently fixed an important-severity security flaw in its Azure Cognitive Search (ACS) after an external researcher warned that a buggy feature allowed cross-tenant network...
Password management firm LastPass says the hackers behind an August data breach stole a massive stash of customer data, including password vault data that...
Identity and access management solutions provider Okta this week informed customers that some of the company’s source code was stolen recently from its GitHub...
Foxit Software has rolled out a critical-severity patch to cover a dangerous remote code execution flaw in its flagship PDF Reader and PDF Editor...
The Federal Bureau of Investigation (FBI), the Food and Drug Administration Office of Criminal Investigations (FDA OCI), and the US Department of Agriculture (USDA)...
Microsoft-owned code hosting platform GitHub this week announced multiple security improvements, including free secret scanning for public repositories and mandatory two-factor authentication (2FA) for...
API security startup FireTail this week announced that it has raised $5 million in an early-stage financing round led by Paladin Capital Group, with...
Google introduces OSV-Scanner, a free vulnerability scanner for open source developers building on its open source vulnerability database.
Bug bounty platform HackerOne says ethical hackers have identified and reported more than 65,000 software vulnerabilities in 2022.The popular hacker-powered platform, which hosts bug...