#applicationsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #applicationsecurity, aggregated by home.social.
-
🔐 RELIANOID is heading to Tokyo!
We'll be following the conversations at Gartner Security & Risk Management Summit Tokyo 2026, July 22–24.
Zero Trust, cloud security, AI risk, cyber resilience, and secure application delivery are shaping the future of digital infrastructure.
📍 Tokyo, Japan
#CyberSecurity #ZeroTrust #CyberResilience #CloudSecurity #ApplicationSecurity #RELIANOID
https://www.relianoid.com/about-us/events/gartner-security-risk-management-summit-tokyo-2026/
-
Thanks to Xbow, a Platinum Sponsor of AppSecVillage. XBOW focuses on continuous app/API testing and proof of exploitability, helping teams cut through noise and understand real risk.
-
Thanks to Xbow, a Platinum Sponsor of AppSecVillage. XBOW focuses on continuous app/API testing and proof of exploitability, helping teams cut through noise and understand real risk.
-
Enhancing X11 Application Security with LXC
https://dobrowolski.dev/article/enhancing-x11-application-security-with-lxc/
#HackerNews #X11Security #LXC #Containers #ApplicationSecurity #CyberSecurity #TechNews
-
Enhancing X11 Application Security with LXC
https://dobrowolski.dev/article/enhancing-x11-application-security-with-lxc/
#HackerNews #X11Security #LXC #Containers #ApplicationSecurity #CyberSecurity #TechNews
-
Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026
Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […] -
Come un semplice account FIFA avrebbe potuto compromettere i Mondiali 2026
Quando si parla di grandi eventi sportivi globali, l’immaginario collettivo corre subito agli stadi, alle telecamere, alle regie televisive e alle centinaia di milioni di spettatori collegati da ogni parte del mondo. Molto meno visibile è invece l’enorme infrastruttura digitale che permette a tutto questo di funzionare. Eppure, secondo quanto raccontato dalla ricercatrice nota come BobDaHacker, sarebbe bastata una semplice registrazione come agente FIFA per ottenere accesso a sistemi […] -
🚨 New Vulnerability Analysis: CVE-2026-47670 🚨
In my latest technical deep dive, I break down a critical authenticated Remote Code Execution (RCE) vulnerability in DbGate (v7.1.8). Discover why relying on pseudo-sandboxing like require = null fails inherently inside Node.js environments when confronted with native, unblockable dynamic import() constructs.
👉 https://denizhalil.com/2026/06/15/cve-2026-47670-dbgate-rce-bypass/
#Cybersecurity #Infosec #NodeJS #VulnerabilityResearch #ApplicationSecurity #RCE
-
CISOs Face Pressure to Deploy Vulnerable Code
The harsh reality is that 95% of CISOs face pressure to downplay or delay reporting security issues, leading to a staggering 75% of organizations deploying vulnerable code into production environments. It's a precarious situation that demands a new approach to prioritize security without sacrificing business goals.
#ApplicationSecurity #VulnerableCode #Cisos #BusinessPressure #SecureDeployment
-
AI Coding Tools Require Embedded Security to Counter Emerging Risks
Security can't keep pace with AI coding tools unless it's embedded from the start - after all, with hundreds of daily code changes, it can't be a bolt-on activity that happens after the fact. It needs to be a fundamental part of the creation process itself.
#AiCodingTools #ApplicationSecurity #EmergingThreats #Devsecops #ArtificialIntelligence
-
Fake Claude Code installer campaigns are abusing trusted developer workflows instead of exploiting software vulnerabilities.
Rhys Downing of Ontinue explains how attackers used fake documentation pages, modified install commands, PowerShell loaders, and browser compromise techniques to steal credentials and establish persistence.“Developers are becoming a preferred target because they sit at the intersection of trust and access.”
Read more:
https://www.technadu.com/copy-paste-compromise-why-developer-workflows-need-new-guardrails/628593/#Cybersecurity #ThreatResearch #Developers #ApplicationSecurity #Ontinue #SecureCoding
-
🔐 𝗥𝗘𝗟𝗜𝗔𝗡𝗢𝗜𝗗 will be attending 𝗜𝗻𝗳𝗼𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗘𝘂𝗿𝗼𝗽𝗲 𝟮𝟬𝟮𝟲 in London from June 2–4!
As one of 𝘌𝘶𝘳𝘰𝘱𝘦’𝘴 𝘭𝘦𝘢𝘥𝘪𝘯𝘨 𝘤𝘺𝘣𝘦𝘳𝘴𝘦𝘤𝘶𝘳𝘪𝘵𝘺 𝘦𝘷𝘦𝘯𝘵𝘴, Infosecurity Europe brings together security professionals, innovators, and decision-makers to explore the future of cyber resilience, cloud security, AI-driven protection, Zero Trust, and more.
#InfosecurityEurope #CyberSecurity #CloudSecurity #ZeroTrust #ApplicationSecurity #ADC #LoadBalancing #CyberResilience #DevSecOps #AI
https://www.relianoid.com/about-us/events/infosecurity-europe-2026/
-
Vulnerable Code Proliferates as AI Exploits Rise in Supply Chains
The alarming truth is that 75% of organizations are knowingly shipping vulnerable code, despite the risks, with the window from disclosure to exploit shrinking dramatically from 840 days in 2018 to just under two days today. This trend is expected to accelerate, with exploits potentially available in as little as one minute by 2028.
#VulnerableCode #AiExploits #SupplyChain #ApplicationSecurity #ZeroDay
-
Agentic AI Turbo Boosts Mobile App Attacks
The alarming rise of mobile app attacks is no longer looming on the horizon - it's here, with a staggering 87% of monitored apps facing threats in 2026, a drastic jump from 55% in 2022, fueled by the rapid adoption of AI models. This explosive growth in attacks is a wake-up call for businesses to bolster their mobile app security.
#AgenticAi #MobileAppAttacks #EmergingThreats #ApplicationSecurity #ArtificialIntelligence
-
https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised
#CyberSecurity #InfoSec #SupplyChainSecurity #SoftwareSupplyChain #NPM #OpenSourceSecurity #AppSec #DevSecOps #ThreatIntel #Malware #JavaScript #NodeJS #CICD #GitHubActions #CloudSecurity #TypeScript #ReactJS #WebDev #OpenSource #DevTools #SoftwareEngineering #DeveloperSecurity #SecureCoding #GitHub #SupplyChainAttack #Programming #TechNews #DevOps #ApplicationSecurity #ThreatResearch #SecurityEngineering #CyberAttack #Hackers #MalwareAlert #SecurityResearch #DevCommunity -
https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised
#CyberSecurity #InfoSec #SupplyChainSecurity #SoftwareSupplyChain #NPM #OpenSourceSecurity #AppSec #DevSecOps #ThreatIntel #Malware #JavaScript #NodeJS #CICD #GitHubActions #CloudSecurity #TypeScript #ReactJS #WebDev #OpenSource #DevTools #SoftwareEngineering #DeveloperSecurity #SecureCoding #GitHub #SupplyChainAttack #Programming #TechNews #DevOps #ApplicationSecurity #ThreatResearch #SecurityEngineering #CyberAttack #Hackers #MalwareAlert #SecurityResearch #DevCommunity -
Socket Expands Supply-Chain Visibility with Secure Annex Acquisition
Socket is supercharging its supply-chain visibility with the acquisition of Secure Annex, a cutting-edge extension security startup, to give developers unprecedented control across the entire software development life cycle. This strategic move combines Socket's expertise in application dependencies with Secure Annex's…
#SupplyChain #ApplicationSecurity #SoftwareDevelopment #Acquisition #SecureAnnex
-
GlassWorm Malware Resurfaces Through 73 OpenVSX Extensions
Researchers at Socket have uncovered a sneaky new wave of GlassWorm malware, this time hiding in 73 OpenVSX extensions that behave like sleepers - seemingly harmless at first, but turning malicious after a stealthy update. Six of these extensions have already been activated, unleashing malware on unsuspecting developers.
#GlasswormMalware #Openvsx #MalwareOperations #EmergingThreats #ApplicationSecurity
-
Anthropic's Claude Desktop sparks EU consent concerns
Can a single app really reach into your other software without asking for permission? The surprising behavior of Anthropic's Claude Desktop for macOS is raising eyebrows and sparking concerns about consent under EU law.
#EuConsent #Macos #ApplicationSecurity #EmergingThreats #Gdpr
-
Together, these measures enhance your security posture by protecting against unauthorized access and potential vulnerabilities.
Read more 👉 https://lttr.ai/AqIiJ
-
🏆 Award-winning Application Security Posture Management.
Xygeni has been recognized at the #GlobalInfosecAwards for 𝗫𝘆𝗴𝗲𝗻𝗶 𝗔𝗦𝗣𝗠.
https://xygeni.io/aspm-application-security-posture-management/
#ASPM #ApplicationSecurity #AppSec #DevSecOps -
ZAST engine has identified and verified CVE-2026-1829 in Content Visibility for Divi Builder 4.01, along with one additional verified vulnerability in the same plugin.
Project page: https://wordpress.org/plugins/content-visibility-for-divi-builder/ Project footprint: 2,000+ active installations on WordPress.org.
The critical issue is a code-execution path where user-controlled visibility expressions reach eval() through multiple application features. This is a representative example of why security teams need autonomous verification: dangerous APIs alone do not define risk. Reachability, privilege boundaries, and runtime behavior do.
ZAST.AI promotes findings into reports only after successful PoC validation, which supports a zero-false-positive operating model and helps enterprise teams prioritize remediation on verified issues.
Full report: https://blog.zast.ai/vulnerability%20research/ai%20security/Auditing-Content-Visibility-for-Divi-Builder/
@wordfence @[email protected] @[email protected]
#ApplicationSecurity #WordPressSecurity #AppSec #VulnerabilityResearch #AIForSecurity
-
ZAST engine has identified and verified CVE-2026-1829 in Content Visibility for Divi Builder 4.01, along with one additional verified vulnerability in the same plugin.
Project page: https://wordpress.org/plugins/content-visibility-for-divi-builder/ Project footprint: 2,000+ active installations on WordPress.org.
The critical issue is a code-execution path where user-controlled visibility expressions reach eval() through multiple application features. This is a representative example of why security teams need autonomous verification: dangerous APIs alone do not define risk. Reachability, privilege boundaries, and runtime behavior do.
ZAST.AI promotes findings into reports only after successful PoC validation, which supports a zero-false-positive operating model and helps enterprise teams prioritize remediation on verified issues.
Full report: https://blog.zast.ai/vulnerability%20research/ai%20security/Auditing-Content-Visibility-for-Divi-Builder/
@wordfence @[email protected] @[email protected]
#ApplicationSecurity #WordPressSecurity #AppSec #VulnerabilityResearch #AIForSecurity
-
In tomorrow's OWASP 25th Anniversary Virtual Conference, two talks include mention of the OWASP Cornucopia card game.
In "Stop Lecturing, Start Playing" at 11:00 CET Johan Sydseter will discuss how you can utilize games to scale your application security program. And in "Connecting the dots" at 14:00 Max Alejandro Gómez Sánchez Vergaray will share his experiences of creating an AppSec programme.
#appsec #threatmodelling #software #applicationsecurity #owasp @sydseter
https://owasp.glueup.com/event/owasp-25th-anniversary-virtual-conference-164290/#agenda
-
Shai-Hulud & Co.: The software supply chain as Achilles’ heel https://www.csoonline.com/article/4123250/shai-hulud-co-the-supply-chain-as-the-achilles-heel.html #ApplicationSecurity #SoftwareDevelopment #DevSecOps #Security
-
Attackers don’t need vulnerabilities when they can weaponize your protocols😳
Recent DDoSia campaigns show how HTTP/2 abuse and slow-request tactics can disrupt systems without...a single exploit.
For AppSec teams, it’s a reminder: resilience matters as much as code fixes.
Full article from Dark Reading: https://www.darkreading.com/cyberattacks-data-breaches/ddosia-powers-volunteer-driven-hacktivist-attacks
#appsec #applicationsecurity #cybersecurity #threatintel #infosec
-
How AI agents are turning security inside-out https://www.helpnetsecurity.com/2026/01/09/ai-agents-appsec-risk/ #Artificialintelligence #applicationsecurity #Expertanalysis #cybersecurity #NokodSecurity #Expertcorner #Don'tmiss #Hotstuff #opinion #News
-
n8n Users Urged to Patch CVSS 10.0 Full System Takeover Vulnerability https://hackread.com/n8n-users-patch-full-system-takeover-vulnerability/ #ApplicationSecurity #Cybersecurity #Vulnerability #Security #database #Upwind #n8n
-
We’re excited to take part in The Elephant In AppSec Conference 2026 🐘🔐
📅 January 14–15, 2026
🌐 Virtual Event
An AppSec event where strong opinions are encouraged, assumptions are challenged, and real-world experience takes center stage.
Looking forward to engaging in honest conversations and sharing how RELIANOID supports modern Application Security through secure application delivery and resilient architectures.
See you online!
https://www.relianoid.com/about-us/events/the-elephant-in-appsec-conference-2026/
-
Critical RCE flaw allows full takeover of n8n AI workflow platform https://www.csoonline.com/article/4113980/critical-rce-flaw-allows-full-takeover-of-n8n-ai-workflow-platform.html #ArtificialIntelligence #ApplicationSecurity #Vulnerabilities #Security
-
Check out ˗ˏˋ ⭒ https://lnkd.in/gE2wUqgc ⭒ ˎˊ˗ to see my intro whilst you listen.
I'm thus re-naming this work as "CVE Keeper - Security at x+1; rethinking vulnerability management beyond CVSS & scanners". I must also thank @andrewpollock for reviewing several of my verbose drafts. 🫡
So, Security at x+1; rethinking vulnerability management beyond CVSS & scanners -
Most vulnerability tooling today is optimized for disclosure and alert volume, not for making correct decisions on real systems. CVEs arrive faster than teams can evaluate them, scores are generic, context arrives late, and we still struggle to answer the only question that matters: does this actually put my system at risk right now?
Over the last few years working close to CVE lifecycle automation, I’ve been designing an open architecture that treats vulnerability management as a continuous, system-specific reasoning problem rather than a static scoring task. The goal is to assess impact on the same day for 0-days using minimal upstream data, refine accuracy over time as context improves, reason across dependencies and compound vulnerabilities, and couple automation with explicit human verification instead of replacing it.
This work explores:
⤇ 1• Same-day triage of newly disclosed and 0-day vulnerabilities
⤇ 2• Dependency-aware and compound vulnerability impact assessment
⤇ 3• Correlating classical CVSS with AI-specific threat vectors
⤇ 4• Reducing operational noise, unnecessary reboots, and security burnout
⤇ 5• Making high-quality vulnerability intelligence accessible beyond enterprise teamsThe core belief is simple: most security failures come from misjudged impact, not missed vulnerabilities. Accuracy, context, and accountability matter more than volume.
I’m sharing this to invite feedback from folks working in CVE, OSV, vulnerability disclosure, AI security, infra, and systems research. Disagreement and critique are welcome. This problem affects everyone, and I don’t think incremental tooling alone will solve it.
P.S.
- Super appreciate everyone that's spent time reviewing my drafts and reading all my essays lol. I owe you 🫶🏻
- ... and GoogleLM. These slides would have taken me forever to make otherwise.
Take my CVE-data User Survey to allow me to tailor your needs into my design - lnkd.in/gcyvnZeE
See more at - lnkd.in/gGWQfBW5
lnkd.in/gE2wUqgc#VulnerabilityManagement #Risk #ThreatModeling #CVE #CyberSecurity #Infosec #VulnerabilityManagement #ThreatIntelligence #ApplicationSecurity #SecurityOperations #ZeroDay #RiskManagement #DevSecOps #CVE #CVEAnalysis #VulnerabilityDisclosure #SecurityData #CVSS #VulnerabilityAssessment #PatchManagement #AI #AIML #AISecurity #MachineLearning #AIThreats #AIinSecurity #SecureAI #OSS #Rust #ZeroTrust #Security
https://www.linkedin.com/feed/update/urn:li:activity:7409399623087370240
-
🎄✨ For those starting their holiday break, take the opportunity to watch this gem from our 2024 archives!
🎥 "From code to security, Mastering the art of AppSec" by Justin Landry
Dive into the world of application security with Justin Landry as he guides us from code to security. An essential masterclass for anyone interested in AppSec! 🔐💻
👉 Watch now: https://www.youtube.com/watch?v=V4OO4fu5W2M
-
🎄✨ Pour ceux qui commencent leurs vacances du temps des fêtes, profitez-en pour revoir cette vidéo de nos archives 2024!
🎥 "From code to security, Mastering the art of AppSec" par Justin Landry
Plongez dans l'univers de la sécurité applicative avec Justin Landry qui nous guide du code à la sécurité. Une masterclass essentielle pour quiconque s'intéresse à l'AppSec! 🔐💻👉 Regardez maintenant : https://www.youtube.com/watch?v=V4OO4fu5W2M
#AppSec #Cybersecurity #ApplicationSecurity #InfoSec #Hacking