Application Security
Enterprise software maker SAP documents multiple critical-severity issues and warns of risk of command injection attacks.
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
Enterprise software maker SAP documents multiple critical-severity issues and warns of risk of command injection attacks.
Concluding a two-day OSS security summit, CISA details key actions to help improve open source security.
The API attack surface is expanding and API vulnerabilities are growing. AI will help attackers find and exploit API vulnerabilities at scale.
Only 54% of major code changes go through a full security review, a new CrowdStrike State of Application Security report reveals.
Google announces $1 million investment in improving Rust’s interoperability with legacy C++ codebases.
Google has released its fuzzing framework in open source to boost the ability of developers and researchers to identify vulnerabilities.
Over a dozen vulnerabilities discovered in Tor audit, including a high-risk flaw that can be exploited to inject arbitrary bridges.
Researchers detail a CI/CD attack leading to PyTorch releases compromise via GitHub Actions self-hosted runners.
Late-stage player in the CNAPP space secures a $60 million extended Series E funding round at a valuation north of $1 billion.
SentinelOne plans to acquire PingSafe in a cash-and-stock deal that adds cloud native application protection platform (CNAPP) technologies.
NSA has published guidance to help organizations incorporate SBOM to mitigate supply chain risks.
Adobe warned users on both Windows and macOS systems about exposure to code execution, memory leaks and denial-of-service security issues.
Government agencies in the Five Eyes countries have published new guidance on creating memory safety roadmaps.
ArmorCode raises $40 million in a Series B funding round to help organizations ship secure applications.
Aikido Security has raised €5 million (~$5.4 million) in seed funding for an all-in-one application security platform.
Adobe patches 72 security bugs and calls special attention to code-execution defects in the widely deployed Acrobat and Reader software.
New report provides a detailed look into the ever-changing threats targeting APIs.
GitGuardian discovered roughly 4,000 secrets in nearly 3,000 PyPI packages, including Azure, AWS, and GitHub keys.
GitHub adds AI-powered security features to help developers identify and address code vulnerabilities faster.
Myrror Security emerges from stealth mode to disrupt supply chain attacks with binary-to-source code analysis.