Application Security News and Articles


Declining Ransomware Payments: Shift in Hacker Tactics?

Several cybersecurity advisories and agencies recommend not caving into ransomware gangs’ demands and paying their ransoms. For a while, though, this advice didn’t stick —organizations tended to panic and quickly pay to get important ...

Improving Software Quality with the OWASP BOM Maturity Model

By Deb Radcliff, industry analyst and editor of CodeSecure’s TalkSecure educational blogs and podcasts (syndicated at Security Boulevard, YouTube, and Bright Talk). In the software product industry, bills of materials for software (SBOMs) are ...

Qmulos Launches Q-Compliance Core for Businesses in Need of a Modern Compliance Approach

Qmulos announced the new versions and general availability of its two flagship products, Q-Compliance V4.2.0 – an all-in-one solution for any enterprise, environment, framework, control, and datasource, and Q-Audit V3.4.0 – Qmulos' ...

USENIX Security ’23 – Chenghong Wang, David Pujol, Kartik Nayak, Ashwin Machanavajjhal – Private Proof-of-Stake Blockchains using Differentially-Private Stake Distortion

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Microsoft patches two zero-days exploited by attackers (CVE-2024-21412, CVE-2024-21351)

On February 2024 Patch Tuesday, Microsoft has delivered fixes for 72 CVE-numbered vulnerabilities, including two zero-days (CVE-2024-21412, CVE-2024-21351) that are being leveraged by attackers in the wild. About CVE-2024-21412 and CVE-2024-21351 ...

Exploiting Kubernetes through Operator Injection

Intro The Kubernetes documentation describes operators as “software extensions to Kubernetes that use custom resources to manage applications and their components.” These operators automate application resource deployment and management ...

News alert: Kiteworks named as a founding member of NIST’s new AI safety consortium – ‘AISIC’

San Mateo, Calif., Feb. 13, 2023 – The U.S. White House announced groundbreaking collaboration between OpenPolicy and leading innovation companies, including Kiteworks, which delivers data privacy and compliance for sensitive content ...

‘Incompetent’ FCC Fiddles With Data Breach Rules

FCC FAIL: While Rome burns, Federal Communications Commission is once again behind the curve. The post ‘Incompetent’ FCC Fiddles With Data Breach Rules appeared first on Security Boulevard.

Guide to Advanced Fraud Monitoring & Proactive Detection in 2024

Learn about advanced fraud monitoring methods, AI in fraud detection, and the features you want in online fraud protection software. The post Guide to Advanced Fraud Monitoring & Proactive Detection in 2024 appeared first on Security Boulevard.

Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnaravi – #278 – The Non-Senior Consultant

via the respected Software Engineering expertise of Mikkel Noe-Nygaard and the lauded Software Engineering / Enterprise Agile Coaching work of Luxshan Ratnaravi at Comic Agilé! Permalink The post Comic Agilé – Mikkel Noe-Nygaard, ...

Reshaping Trust and Security for the Realities of 2024

The new year is always a time for reflection, and after a year shaped by... The post Reshaping Trust and Security for the Realities of 2024 appeared first on Entrust Blog. The post Reshaping Trust and Security for the Realities of 2024 appeared ...

Use of ‘Hunter-Killer’ Malware on the Rise, Study Finds

Hackers are increasingly deploying “ultra-evasive, highly aggressive” malware with the ability to find and shut down enterprise security tools in compromised systems, allowing the bad actor to go undetected longer, according to researchers ...

USENIX Security ’23 – Detecting and Handling IoT Interaction Threats in Multi-Platform Multi-Control-Channel Smart Homes

Authors/Presenters: Haotian Chi, Qiang Zeng, Xiaojiang Du Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the ...

Omnisend DMARC, SPF, and DKIM Setup Guide

Reading Time: 6 min Don't let your emails land in spam! Learn how to set up Omnisend DMARC, SPF, and DKIM records to ensure email deliverability, and protect your domain. The post Omnisend DMARC, SPF, and DKIM Setup Guide appeared first on ...

How AI-Powered Risk Management Supports Cybersecurity

AI, in partnership with humans, offers the potential to solidify an organization's digital trust practice amid rising cybersecurity threats. The post How AI-Powered Risk Management Supports Cybersecurity appeared first on Security Boulevard.

What is Threat Detection and Incident Response?

The post What is Threat Detection and Incident Response? appeared first on AI Enabled Security Automation. The post What is Threat Detection and Incident Response? appeared first on Security Boulevard.

Sumsub Deepfake Detection combats AI-driven identity fraud

Sumsub has launched a Deepfake Detection feature integrated into its Video Identification solution. This comes as AI-powered fraud increasingly targets businesses, not just individual users. Sumsub’s 2023 Identity Fraud Report revealed a ...

Survey Surfaces Disconnect Between Cybersecurity Confidence and Reality

A survey found that despite rating their ability to detect cyberthreats highly, well over half of respondents experienced a breach in 2023. The post Survey Surfaces Disconnect Between Cybersecurity Confidence and Reality appeared first on ...

You Can’t Stop What You Can’t See: Addressing Encrypted Cloud Traffic

Forget AI. The most immediate and threatening cybersecurity challenge is visibility into an organization’s encrypted cloud traffic. The post You Can’t Stop What You Can’t See: Addressing Encrypted Cloud Traffic appeared first on Security ...

Phishing Scams: How to Spot & Avoid Phishing Scams

Learn how to protect yourself from phishing scams with this in-depth guide. Recognize phishing emails, messages & steps to prevent attacks. The post Phishing Scams: How to Spot & Avoid Phishing Scams appeared first on SternX ...