Application Security News and Articles


NSFOCUS Innovative DDoS Protection Technology Secures Your Network Perimeter

Cybersecurity is crucial for national security in the digital world, where major powers clash over their interests. However, technology also enables more sophisticated and harmful network attacks. One of the most common and dangerous types of ...

Cybersecurity’s Class Conundrum

Cybersecurity has a class conundrum, and the gap is only getting wider. The post Cybersecurity’s Class Conundrum appeared first on Security Boulevard.

USENIX Security ’23 – Junjie Wang, Zhiyi Zhang, Shuang Liu, Xiaoning Du, Junjie Chen – FuzzJIT: Oracle-Enhanced Fuzzing for JavaScript Engine JIT Compiler

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

New MaaS InfoStealer Malware Campaign Targeting Oil & Gas Sector

By Dylan Duncan Cofense Intelligence is tracking an advanced campaign that is successfully reaching intended targets in the Oil and Gas industry. The campaign delivers an uncommon, but advanced, Malware-as-a-Service information stealer, the ...

How to Address CISA Attestation

Get details on the CISA Attestation, how to address it, and how Legit can help. The post How to Address CISA Attestation appeared first on Security Boulevard.

Fingerprint API Attackers with Runtime Hash Patterns | Impart Security

Today, we’re excited to introduce Impart Security’s Runtime Hash Patterns, an innovative feature within our Runtime Rules framework that drastically simplifies how security teams can detect and respond to different types of API users.With the ...

Top Cyber Threats Automotive Dealerships Should Look Out For

Automotive dealerships are attractive targets for hackers. A combination of storing lots of sensitive customer data, handling large financial transactions, increased dependence on digital technologies and a perception of immature cybersecurity ...

PRC State Hacking: ‘Chinese Edward Snowden’ Spills I‑Soon Secrets in Huge Dump of TTPs

Underpaid, overworked and angry: Whistleblower in hacker contractor firm for Chinese government blows lid off tactics, techniques and procedures. The post PRC State Hacking: ‘Chinese Edward Snowden’ Spills I‑Soon Secrets in Huge Dump of ...

Randall Munroe’s XKCD ‘Crossword Constructors’

The post Randall Munroe’s XKCD ‘Crossword Constructors’ appeared first on Security Boulevard.

Residual Risk Defined: Expert Strategies for Management and Mitigation

You may think you’ve covered all your bases, but can modern organizations let their guard down in the face of residual risks? Today’s corporations face increasingly complex risks, including new challenges that can have far-reaching ...

Imperva successfully defends against CVE-2024-25600 in WordPress Bricks Builder

A critical vulnerability in the Bricks Builder site builder for WordPress, identified as CVE-2024-25600, is currently under active exploitation, and poses a significant threat to over 25,000 sites. This flaw, with a CVSS score of 9.8, is an ...

Buying vs. Building Bot Protection: Choose the Best Way to Protect Your Business

Weigh the pros and cons of buying or building bot protection, including learning what criteria to assess in your business to choose the right option for you. The post Buying vs. Building Bot Protection: Choose the Best Way to Protect Your ...

Data Classification Policy: Definition, Examples, & Free Template

Editor’s note: this piece was updated with fresh information in August 2021. It was originally published in November, 2020. It’s 3 AM. Do you know where your most sensitive data is? More importantly, who can access it, and how is it ...

Don’t Brush Off the Toothbrush Story

The toothbrush story serves as an important reminder that IoT devices remain a sought-after hacker target. The post Don’t Brush Off the Toothbrush Story appeared first on Enzoic. The post Don’t Brush Off the Toothbrush Story appeared first on ...

ConnectWise Says ScreenConnect Flaw Being Actively Exploited

Hackers are actively exploiting critical security flaws in ConnectWise’s remote desktop access tool just days after the software maker alerted customers of the vulnerabilities. ConnectWise learned of the bugs – tracked as CVE-2024-1709 (with ...

USENIX Security ’23 – Nils Bars, Moritz Schloegel, Tobias Scharnowski, Nico Schiller, Thorsten Holz – Fuzztruction: Using Fault Injection-based Fuzzing to Leverage Implicit Domain Knowledge

Distinguished Paper Award Winner and Runner-Up Winner of the 2023 Internet Defense Prize Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open ...

Automate Third Party Cyber Risk

The post Automate Third Party Cyber Risk appeared first on AI Enabled Security Automation. The post Automate Third Party Cyber Risk appeared first on Security Boulevard.

Cloudflare Breached by Nation-State Hackers

In a recent podcast interview with Cybercrime Magazine's Host, Charlie Osborne, Scott Schober, Cyber Expert, Author, and CEO of Berkeley Varitronics Systems, discusses the latest breach at Cloudflare, which has since been attributed to ...

State Department Puts Up $10 Million for Info on LockBit Leaders

A day after U.S. and international law enforcement agencies disrupted the operations of notorious ransomware group LockBit, the State Department is offering up to $15 million in rewards for information about the gang’s leaders or its affiliates ...

Strata Identity Named a Representative Vendor in the 2024 Gartner® Reduce IAM Technical Debt Report

Strata’s Maverics Identity Orchestration platform cited for modernizing legacy identity management systems to cloud-based Identity and Access Management (IAM) suites  BOULDER, Colo., Feb. 22, 2024 – Strata Identity, the Identity ...