Application Security News and Articles


USENIX Security ’23 – Hengkai Ye, Song Liu, Zhechang Zhang, and Hong Hu – VIPER: Spotting Syscall-Guard Variables for Data-Only Attacks

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Lloyd’s of London Announces Investment in Axio

Funds to support further development of insurance solutions within the London insurance market. Read More The post Lloyd’s of London Announces Investment in Axio appeared first on Axio. The post Lloyd’s of London Announces Investment in Axio ...

Cybersecurity HR for Business Sustainability

Strengthening organizational defenses from within with cybersecurity HR We work in a rapidly evolving workplace, and cybersecurity is not just a technical challenge but a holistic organizational effort. The Human Resources (HR) department, ...

Using Proactive Intelligence Against Adversary Infrastructure

Organizations cannot and will never keep bad actors from breaching their perimeter: They’ll always find a way in. But that doesn’t mean that organizations can’t still make themselves resilient against cyber attacks and address their digital ...

Harnessing Artificial Intelligence for Ransomware Mitigation

Without AI, organizations will continue to suffer and struggle with recovery when faced with ransomware and other cyberattacks. The post Harnessing Artificial Intelligence for Ransomware Mitigation appeared first on Security Boulevard.

Securiti AI enables organizations to safely use AI

Securiti AI released AI Security & Governance offering, providing a solution to enable safe adoption of AI. It combines comprehensive AI discovery, AI risk ratings, Data+AI mapping and advanced Data+AI security & privacy controls, ...

IBM Shows How Generative AI Tools Can Hijack Live Calls

IBM researchers have discovered a way to use generative AI tools to hijack live audio calls and manipulate what is being said without the speakers knowing. The “audio-jacking” technique – which uses large-language models (LLMs), voice ...

Chinese hackers breached Dutch Ministry of Defense

Chinese state-sponsored hackers have breached the Dutch Ministry of Defense (MOD) last year and deployed a new remote access trojan (RAT) malware to serve as a backdoor. “The effects of the intrusion were limited because the victim network ...

Qualys TotalCloud 2.0 measures cyber risk in cloud and SaaS apps

Qualys unveiled TotalCloud 2.0. This significant upgrade to Qualys’ AI-powered cloud native application protection platform (CNAPP) delivers a single prioritized view of cloud risk and is the first to extend its protection to SaaS ...

‘Total Bollocks’ — No, Your Toothbrush isn’t DDoS’ing

PR FAIL: Were 3 million toothbrushes hacked into a botnet? Or does a Fortinet spokeschild have egg on his face? The post ‘Total Bollocks’ — No, Your Toothbrush isn’t DDoS’ing appeared first on Security Boulevard.

Binary type inference in Ghidra

By Ian Smith Trail of Bits is releasing BTIGhidra, a Ghidra extension that helps reverse engineers by inferring type information from binaries. The analysis is inter-procedural, propagating and resolving type constraints between functions while ...

The 8 Must Haves for the Next Generation of SIEM

A next-generation SIEM requires advanced security technologies, flexible deployment options, cost-effectiveness and transparent licensing. The post The 8 Must Haves for the Next Generation of SIEM appeared first on Security Boulevard.

SolarWinds offers complete hybrid visibility across on-premises and cloud networks

SolarWinds announced enhancements to its SaaS-based and self-hosted, on-premises observability solutions built to monitor and observe complex, distributed environments from anywhere. The AI-powered enhancements enable teams to manage on-prem, ...

Malicious PDFs, deepfakes, and romance scams were just some of the 10 billion cyber attacks we saw last year

If you've been hoping that cyber attacks were on the decline, brace yourself for a reality check: 2023 was an unprecedented year in cyber threats. We witnessed more than 10 billion attacks , shattering previous records. This isn't just another ...

Part 3: The anatomy of supply chain attacks: Non-human identities & TPRM failure

“Identity is the new perimeter.” This catch phrase is present in almost every website of identity security vendors, and for a good reason. Human access, more commonly referred to as user access, is an established security program in most ...

Menlo Security’s Global Channel Leader Todd Wilson Recognized as 2024 CRN® Channel Chief

Mountain View, CA, February 7, 2024 – Menlo Security, a leader in browser security, CRN® a brand of The Channel Company, has named Todd Wilson, Vice President of Global Channels, to the prestigious 2024 CRN® Channel Chiefs list, which ...

The fight against commercial spyware misuse is heating up

Though there are organizations out there investigating how commercial spyware is misused to target journalists, human rights defenders and dissidents, the growing market related to the development and sale of this type of software and the ...

DynaRisk Cyber Intelligence Data Lake enhances the accuracy of data breach predictions

DynaRisk launched Cyber Intelligence Data Lake. This major feature upgrade propels the company’s capabilities in preventing and predicting hacker activity. DynaRisk’s Cyber Intelligence Data Lake is a leap forward in the cyber risk ...

Super Bowl of Passwords: Chiefs vs. 49ers in the Battle of Cybersecurity

As we approach Super Bowl LVIII, with the Kansas City Chiefs and the San Francisco 49ers vying for championship glory, a different kind of competition is heating up in the realm of cybersecurity: the battle against compromised credential attacks. ...

OneTrust launches Data Privacy Maturity Model

OneTrust introduced Data Privacy Maturity Model. The model provides privacy, security, marketing, and data teams with the resources to transform their privacy programs from tactical compliance initiatives that mitigate risk, to strategic customer ...