Application Security
VMware confirmed that exploit code for CVE-2023-20864 has been published, underscoring the urgency for enterprise network admins to apply available patches.
Hi, what are you looking for?
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
VMware confirmed that exploit code for CVE-2023-20864 has been published, underscoring the urgency for enterprise network admins to apply available patches.
SwSec 5D framework aims to provide a roadmap for secure software development, and its use would help improve security in the software supply chain.
Hackers linked to the Truebot malware are exploiting a year-old Netwrix Auditor flaw to break into organizations in the U.S. and Canada.
Use-after-free and OS command injection vulnerabilities reach the top five most dangerous software weaknesses in the 2023 CWE Top 25 list.
Tel Aviv startup scores investment to build technology to secure in-house low-code/no-code custom applications.
New guidance from CISA and the NSA provides recommendations on securing CI/CD pipelines against malicious attacks.
Two critical-severity authentication bypass vulnerabilities in WordPress plugins with tens of thousands of installations.
Fake security researcher accounts seen distributing malware disguised as Chrome, Signal, WhatsApp, Discord and Exchange zero-day exploits.
Adobe ships urgent fixes for at least a dozen flaws that expose Adobe Commerce users to code execution attacks.
OMB has published new guidance on federal agencies obtaining security guarantees from software vendors.
Cybersecurity news that you may have missed this week: AI regulation, layoffs, US aerospace malware attacks, and post-quantum encryption.
VMware ships urgent patches to cover security defects that expose businesses to remote code execution attacks.
OWASP’s ranking for the major API security risks in 2023 has been published. The list includes many parallels with the 2019 list, some reorganizations/redefinitions,...
NCC Group announces new open source tools for finding hardcoded credentials and for distributing cloud workloads.
Google introduces Mobile VRP bug bounty program for vulnerabilities in its mobile applications.
Red Hat rolls out a new suite of tools and services to help mitigate vulnerabilities across every stage of the modern software supply chain.
Cloudflare introduces Secrets Store, a new solution to help developers and organizations securely store and manage secrets.
Lineaje introduces SBOM360 Hub, an exchange allowing software producers, sellers, and consumers to publish, share and use SBOMs and related compliance artifacts.
Former ByteDance executive said China government officials maintained access to all TikTok data, including information stored in the United States.
OpenSSF has added four new members and is receiving $5 million in funding for its Alpha-Omega open source software security project.