Application Security News and Articles


How to make sense of the new SEC cyber risk disclosure rules

SEC’s new cybersecurity risk management, strategy, governance, and incident disclosure rules, which require increased transparency around cybersecurity incidents, have been in effect since December 18, 2023. For businesses that already harbor ...

How decentralized identity is shaping the future of data protection

In this Help Net Security interview, Patrick Harding, Chief Architect at Ping Identity, discusses the promises and implications of decentralized identity (DCI) in cybersecurity. By redistributing identity management responsibilities among ...

Why identity fraud costs organizations millions

92% of respondents to a recent report shared that their organization had been a victim of identity fraud, costing an average of $4.3 million over the last 12 months. Even so, only 40% stated identity verification as a top identity challenge, ...

36% of code generated by GitHub CoPilot contains security flaws

Security debt, defined as flaws that remain unfixed for longer than a year, exists in 42% of applications and 71% of organizations, according to Veracode. Worryingly, 46% of organizations have persistent, high-severity flaws that constitute ...

Clean links and sophisticated scams mark new era in email attacks

Analysis of 7 billion emails shows clean links are duping users, malicious EML attachments increased 10-fold in Q4, and social engineering attacks are at all-time highs, according to VIPRE Security. The rise of the EML file attachments In 2024, ...

The Digital Services Act is Here. Nisos Can Help!

Nisos The Digital Services Act is Here. Nisos Can Help! As of February 17, 2024, the European Union’s Digital Services Act (DSA) is in full effect... The post The Digital Services Act is Here. Nisos Can Help! appeared first on Nisos by ...

Titanium and LogRhythm: Elevating Visibility into Cybersecurity Risks in Pakistan

Titanium stands as the information security division of Pakistan’s leading ISP Cybernet. Established in 1996, Cybernet is a part of the Lakson Group of Companies, specialising in connectivity solutions for enterprise and SMEs. Over the years, ...

NSO Group and Its ‘MMS Fingerprint’ Attack

Buried among the piles of legal documents that form WhatsApp’s five-year-old lawsuit against NSO Group is a line in a contract that exposes a mobile network attack dubbed “MMS Fingerprint,” a tactic for infecting mobile devices that was ...

Generative AI and Cybersecurity: The Impact on CISOs and Security Teams

Generative AI, a subset of artificial intelligence (AI), has emerged as a transformative force in the today’s digital world. This kind of advanced technology uses machine learning models to generate content, enabling it to autonomously create ...

EU Court of Human Rights Rejects Encryption Backdoors

The European Court of Human Rights has ruled that breaking end-to-end encryption by adding backdoors violates human rights: Seemingly most critically, the [Russian] government told the ECHR that any intrusion on private lives resulting from ...

Automated remediation of exposed secrets: Pros and cons

How much can you automate secrets exposure remediation and what is the compromise? The post Automated remediation of exposed secrets: Pros and cons appeared first on Entro. The post Automated remediation of exposed secrets: Pros and cons appeared ...

Google Initiative Aims to Boost AI for Cybersecurity

Google is pushing AI as the technology that will shift the balance of power from cyberattackers to security professionals and is launching a new project to make that a reality. The AI Cyber Defense initiative is the tech giant’s latest effort ...

Join our new Escape community on Slack!

If you're a security professional who enjoys asking questions, sharing your knowledge with others, and is passionate about API security, this group is for you! The post Join our new Escape community on Slack! appeared first on Security Boulevard.

3 Ways the CTO Can Fortify the Organization in the Age of Generative AI

Most enterprises testing the generative AI waters primarily lean on their CISOs and general counsel. But the CTO should be involved, too. The post 3 Ways the CTO Can Fortify the Organization in the Age of Generative AI appeared first on Security ...

Data Security: Beyond Threat Hunting to Monitoring Data Flow and User Behavior

Cybersecurity is moving from conventional threat detection to a strategy that emphasizes context and preempts user behavior to detect anomalies. The post Data Security: Beyond Threat Hunting to Monitoring Data Flow and User Behavior appeared ...

XSS Marks the Spot: Digging Up Vulnerabilities in ChatGPT

With its widespread use among businesses and individual users, ChatGPT is a prime target for attackers looking to access sensitive information. In this blog post, I’ll walk you through my discovery of two cross-site scripting (XSS) ...

Demystifying JWT, OAuth, OIDC, and SAML: A Technical Guide

Dive into a clear technical guide explaining JWT, OAuth, OIDC, and SAML. Learn their strengths and weaknesses and use cases to choose the right approach for your next project. Stay updated with 2024 best practices and unlock seamless user ...

How Data Exfiltration is Changing the Ransomware Landscape

An exponential rise in data exfiltration is changing the ransomware landscape afflicting over 91% of all attacks. The post How Data Exfiltration is Changing the Ransomware Landscape appeared first on Security Boulevard.

Arcitecta enhances Mediaflux Livewire to optimize data movement

Arcitecta announced significant enhancements to its Mediaflux Livewire offering that address the challenges of transmitting data over low-bandwidth and unreliable network connections. With the latest Mediaflux Livewire, customers can securely and ...

Streamlining certificate management: The case for eliminating Microsoft Active Directory Certificate Services

Enhance security and productivity with automated certificate management. Move beyond Microsoft AD CS for streamlined processes. The post Streamlining certificate management: The case for eliminating Microsoft Active Directory Certificate Services ...