Application Security
Malicious actors can abuse GitHub and other services that host Git repositories for stealthy attacks aimed at software developers, experts showed recently at the...
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
Malicious actors can abuse GitHub and other services that host Git repositories for stealthy attacks aimed at software developers, experts showed recently at the...
“Why cover the same ground again? It goes against my grain to repeat a tale told once, and told so clearly.” ― Homer, The Odyssey
Netflix has published tools and information to help defenders identify systems that could be leveraged by malicious actors for damaging application layer distributed denial-of-service...
Mitigations put in place by Google in May 2017 to help block phishing attacks such as the recent OAuth worm weren’t enough to completely...
Google is taking another step to better protect users from malicious third-party web applications: it is now warning users of newly created web apps...
Cisco has updated the WebEx extensions for Chrome and Firefox to address critical remote code execution vulnerabilities identified by researchers working for Google and...
A new type of attack against WordPress is targeting fresh installations to get admin access and execute PHP code in the victim’s web hosting...
Organizations made some improvements to their security posture last year, but only marginally, as the average time-to-fix is still too high and remediation rates...
Hewlett Packard Enterprise (HPE) has informed customers of security bypass, information disclosure, remote code execution, cross-site scripting (XSS) and URL redirection vulnerabilities in several...
The Automobile Association (AA) -- the UK's largest motoring organization with over 15 million members -- is being heavily criticized over its public handling of...
Cloudflare Launches New Website App Store and Partners With Venture Firms to Launch $100 Million Development Fund
Redwood City, Calif.-based Elastic Beam emerged from stealth mode on Wednesday with the launch of a security solution designed to detect and block cyberattacks...
As organizations move to the cloud, one of the biggest changes we’ve seen is in the nature of the application landscape. This is the...
Popular chat platforms such as Slack, Discord and Telegram can be abused by malicious actors and turned into command and control (C&C) infrastructure, according...
Researchers announced this week the launch of a crowdfunding initiative whose goal was to raise money to subscribe to the Shadow Brokers’ monthly exploit...
A new research report takes an unusual angle. Rather than analyzing a threat or an attacker, it looks at the psychology of the user...
Google Project Zero researcher Tavis Ormandy has released a tool designed for porting Windows dynamic link library (DLL) files to Linux in an effort...
Malicious actors could hijack millions of systems using specially crafted subtitle files that exploit vulnerabilities in some of the most popular media players, security...
In the light of a recent phishing attack targeting Gmail users, Google is updating its app identity guidelines and is implementing a more thorough...
A vulnerability in Guidance Software’s EnCase Forensic Imager forensics tool can be exploited by hackers to take over an investigator’s computer and manipulate evidence,...