Application Security
OWASP has added two new categories to the revised version of its Top 10 list of the most critical risks to web applications.
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
OWASP has added two new categories to the revised version of its Top 10 list of the most critical risks to web applications.
Three more VS Code extensions were infected last week and the malware has emerged in GitHub repositories as well.
Arbitrary command/code execution has been demonstrated through the exploitation of CVE-2025-11953 on Windows, macOS and Linux.
Bugcrowd said the acquisition of Mayhem has nearly doubled its valuation — previously reported at over $1 billion.
Kolter leads a panel at OpenAI that has the authority to halt the ChatGPT maker’s release of new AI systems if it finds them...
Get practical guidance to protect APIs against the threats attackers are using right now.
GitHub will implement local publishing with mandatory 2FA, granular tokens that expire after seven days, and trusted publishing.
The packages were injected with malicious code to harvest secrets, dump them to a public repository, and make private repositories public.
Designed to intercept cryptocurrency transactions, the malicious code reached 10% of cloud environments.
A supply chain attack called GhostAction has enabled threat actors to steal secrets and exploit them.
SBOM adoption will drive software supply chain security, decreasing risks and costs, and improving transparency.
CISA has updated the Minimum Elements for a Software Bill of Materials (SBOM) guidance and is seeking public comment.
CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured, and maintained.
Taking place August 12-13, CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured,...
Taking place August 12-13, CodeSecCon is the premier virtual event bringing together developers and cybersecurity professionals to revolutionize the way applications are built, secured,...
Base44 owner Wix quickly patched a critical authentication bypass vulnerability discovered by researchers at Wiz.
The open source security firm will use the investment to enhance go-to-market efforts and accelerate platform expansion.
HeroDevs has received a $125 million strategic growth investment from PSG to secure enterprise security stacks.
RevEng.ai has raised $4.15 million in seed funding for an AI platform that automatically detects malicious code and vulnerabilities in software.
New research suggests more than 10,000 SaaS apps could remain vulnerable to a nOAuth variant despite the basic issue being disclosed in June 2023.