Application Security News and Articles


Why Smart SOAR is the Best SOAR for iZOOlogic

The collaboration between Smart SOAR (Security Orchestration, Automation, and Response) and iZOOlogic offers a comprehensive solution to protect your brand from imposters. This integration spotlight explains how the integration between Smart SOAR ...

Navigating the Waters of Generative AI

Part I: The Good and the Bad of AI Few would argue that 2023 was the year AI, specifically generative AI (Gen AI) like ChatGPT, was discussed everywhere. In October, Forrester published a report about how security tools will leverage AI. The ...

FBI Warns: Ubiquiti EdgeRouter is STILL Not Secure

GRU APT28 is back again: Fancy Bear still hacking ubiquitous gear, despite patch availability. The post FBI Warns: Ubiquiti EdgeRouter is STILL Not Secure appeared first on Security Boulevard.

Randall Munroe’s XKCD ‘Goodhart’s Law’

Permalink The post Randall Munroe’s XKCD ‘Goodhart’s Law’ appeared first on Security Boulevard.

10 Years of SafeBreach

Join us as we reflect on the professional milestones and personal memories from our decade-long journey as pioneers in the breach and attack simulation industry. The post 10 Years of SafeBreach appeared first on SafeBreach. The post 10 Years of ...

Building Cyber Resilience: Insights into NIST CSF 2.0

After several years of deliberation and collaboration with industry experts, NIST has released the newest version of the NIST CSF. The NIST CSF 2.0 builds on the draft version released in September 2023. NIST has made several changes to the ...

Imperva Customers are Protected Against New SQL Injection Vulnerability in WordPress Plugin

A critical security flaw, identified as CVE-2024-1071, was discovered in the Ultimate Member plugin for WordPress, affecting over 200,000 active installations. This vulnerability has a high severity CVSS score of 9.8 and allows for SQL injection ...

Account Takeover Protection: Risks, Targets and Prevention Strategies

Sophisticated cybercriminals are constantly dreaming up ways to breach that initial wall and gain access to the goods — customer data. Learn how account takeover protection can shield against fraudsters and ATO attacks. The post Account ...

USENIX Security ’23 – Yuanyuan Yuan, Zhibo Liu, Shuai Wang – CacheQL: Quantifying and Localizing Cache Side-Channel Vulnerabilities in Production Software

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

NIST CSF 2.0 Calls for Greater Strategic Focus, Transparency, Accountability

By: Igor Volovich, VP, Compliance Strategy The release of the NIST Cybersecurity Framework (CSF) 2.0 marks a significant evolution in the landscape of cybersecurity standards and practices. With the introduction of the GOVERN function, NIST CSF ...

Complete Guide to OT Security Compliance

OT security priorities are essential for a successful OT security program. How prepared are you? Before you can properly secure your OT environment, you must understand the challenges you face. In the era of relentless digital advancement, the ...

Cohesity Gaia helps businesses transform secondary data into knowledge

Cohesity announced Cohesity Gaia, an AI-powered enterprise search assistant that brings retrieval augmented generation (RAG) AI and large language models (LLMs) to high-quality backup data within Cohesity environments. Cohesity Gaia will be made ...

European retailer Pepco loses €15.5 million in phishing (possibly BEC?) attack

Pepco Group has confirmed that its Hungarian business has been hit by a “sophisticated fraudulent phishing attack.” The European company, which operates shops under the Pepco, Poundland and Dealz brands, said that the company lost ...

Biden EO Will Keep China, Russia from Buying Americans’ Sensitive Data

The Biden Administration wants to stop data brokers and other companies from selling sensitive personal data of American citizens to organizations in China, Russia, and other adversarial countries. President Biden on Wednesday signed an executive ...

The Silent Threat: Why Vishing is Causing Major Problems for Businesses

The alarming rise in vishing attacks underscores the need for businesses to prioritize cybersecurity and remain vigilant in the face of evolving threats. The post The Silent Threat: Why Vishing is Causing Major Problems for Businesses appeared ...

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

San Jose, CA, February 28th, 2024, Cyberwire Platform Delivers Total Visibility and Control Across a Global Client Footprint  Stellar Cyber, the innovator of Open XDR, today announced that RSM US – the leading provider of professional ...

State-sponsored hackers know enterprise VPN appliances inside out

Suspected Chinese state-sponsored hackers who have been leveraging Ivanti Connect Secure VPN flaws to breach a variety of organizations have demonstrated “a nuanced understanding of the appliance”, according to Mandiant incident ...

Exabeam introduces new features to improve security analyst workflows

Exabeam announced two pioneering cybersecurity features, Threat Center and Exabeam Copilot, to its AI-driven Exabeam Security Operations Platform. A first-to-market combination, Threat Center is a unified workbench for threat detection, ...

What’s on the Radar for Aviation Industry Cybersecurity?

A chart to future aviation industry cybersecurity best practices  Digital transformation propels industries forward, and the aviation sector stands at the forefront of change, embracing technologies that promise efficiency, safety, and customer ...

Compliance Scorecard​ collaborates with ConnectSecure to automate asset governance

Compliance Scorecard​ and ConnectSecure have joined forces to automate asset governance. With just a few clicks, MSPs can pull inventory data from ConnectSecure vulnerability scans into Compliance Scorecard’s Asset Scorecard, giving them the ...