Application Security News and Articles


Cyber Threat Assessment

In the digital landscape, what you don’t know can hurt you. The unseen threats lurking in the shadows of your network, often called ‘blind spots’, can lead to significant business disruptions, regulatory violations, and other profound ...

ALPHV Blackcat, GCP-Native Attacks, Bandook RAT, NoaBot Miner, Ivanti Secure Vulnerabilities, and More: Hacker’s Playbook Threat Coverage Round-up: February 2024

New and updated coverage for ransomware and malware variants, including ALPHV Blackcat, NoaBot Miner, and others. The post ALPHV Blackcat, GCP-Native Attacks, Bandook RAT, NoaBot Miner, Ivanti Secure Vulnerabilities, and More: Hacker’s Playbook ...

USENIX Security ’23 – Suood Al Roomi, Frank Li – A Large-Scale Measurement of Website Login Policies

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Benefits of Schools Adopting AI for Cybersecurity

In the US, K-12 school systems are struggling to keep their IT environments safe as... The post Benefits of Schools Adopting AI for Cybersecurity appeared first on Security Boulevard.

ONCDs’ call for memory safety brings considerable challenges, changes, and costs

The recent publication Back to the Building Blocks: A Path Toward Secure and Measurable Software by the White House Office of the National Cyber Director (ONCD) provides additional detail and strategic direction supporting the National ...

Daniel Stori’s ‘Security Engineer Interview’

via the inimitable Daniel Stori at Turnoff.US. Permalink The post Daniel Stori’s ‘Security Engineer Interview’ appeared first on Security Boulevard.

Security Vulnerabilities Popping Up on Hugging Face’s AI Platform

Hugging Face is emerging as a significant player in the rapidly expanding generative AI space, with its highly popular open collaboration platform being used by software developers to host machine learning models, datasets, and applications. That ...

What is the difference between an SCA scan and a container scan?

Can you scan your containers with any old SCA and still get good results? The post What is the difference between an SCA scan and a container scan? appeared first on Mend. The post What is the difference between an SCA scan and a container scan? ...

How DSPM Can Help You to Safely Use Microsoft Copilot?

In the rapidly evolving landscape of workplace technology, Microsoft CoPilot has emerged as a groundbreaking tool, transforming how we generate reports, presentations, emails, and even song lyrics. It leverages the vast repositories of documents ...

What are the elements of an SBOM?

A software bill of materials (SBOM) is not just a list, but a detailed inventory that captures the components and dependencies contained within a piece of software. The post What are the elements of an SBOM? appeared first on Security Boulevard.

Ex-Cybercrime Forum Community Member Runs a Profitable Penetration Testing Business – An Analysis

Since 2021 as a part of an in-house research and capability building project I’ve been collecting tons of publicly accessible only cybercrime forum information data where I aimed at building the actual volume for this project which currently ...

GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL

Forking hell: Scrotebots clone thousands of projects, injecting malware millions of times. The post GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL appeared first on Security Boulevard.

IBM X-Force Threat Intelligence Index 2024

The latest IBM® X-Force® Threat Intelligence Index 2024 focuses on a growing area of risk for organizations: the increasing preference of valid credentials as an initial access vector for cyber threat actors. Today, the exploitation of ...

USENIX Security ’23 – Anthony Gavazzi, Ryan Williams, Engin Kirda, Long Lu, Andre King, Andy Davis, Tim Leek – A Study of Multi-Factor and Risk-Based Authentication Availability

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Case Study: Why Data-Centric Security Is a Must-Have for the Insurance Sector

Insurance is fundamentally a data-driven business. The insights that carriers can extract from the vast volumes of customer data they process can add huge competitive advantage–enabling them to detect fraud and optimize premium pricing more ...

Fraud Detection: Time is Not on Our Side

Fraud often takes place through social engineering against customers logging in from where they always log in, from a device they have always used. The post Fraud Detection: Time is Not on Our Side appeared first on Security Boulevard.

CNCF Graduates Falco Project to Improve Linux Security

The Cloud Native Computing Foundation (CNCF) announced today that Falco, an open source tool for defining security rules in Linux environments, has officially graduated. The post CNCF Graduates Falco Project to Improve Linux Security appeared ...

5 Facts About File Integrity Monitoring and HIPAA Integrity Controls

The risks of being found non-compliant with HIPAA guidelines are among the most pressing issues for healthcare IT professionals. In the event of a data breach, HIPAA fines can exceed $1.5 million. The Department of Health and Human Services ...

Airbnb scammers pose as hosts, redirect users to fake Tripadvisor site

Scammers on Airbnb are faking technical issues and citing higher fees to get users to a spoofed Tripadvisor website and steal their money. The Airbnb scam Malwarebytes researchers came across the Airbnb scam when trying to book an apartment ...

A CISO’s Guide to SaaS Security Posture Management

As today’s security threat environment evolves, SaaS security posture management (SSPM) has become a key part of a CISO's security defense plan. The post A CISO’s Guide to SaaS Security Posture Management appeared first on Security Boulevard.