Application Security News and Articles


Navigating Cybersecurity Budget Constraints for K-12 Schools

K-12 education is one of the most targeted industries for ransomware. Damage can include permanent... The post Navigating Cybersecurity Budget Constraints for K-12 Schools appeared first on Security Boulevard.

CVE-2024-21893: Another Ivanti Vulnerability Exploited in the Wild. Verify with NodeZero Today!

On 22 January, Ivanti published an advisory stating that they discovered two new, high-severity vulnerabilities (CVE-2024-21888 and CVE-2024-21893) after researching previously reported vulnerabilities affecting Ivanti Connect Secure, Ivanti ...

USENIX Security ’23 – FISHFUZZ: Catch Deeper Bugs by Throwing Larger Nets

Authors/Presenters: Han Zheng, Jiayuan Zhang, Yuhang Huang, Zezhong Ren, He Wang, Chunjie Cao, Yuqing Zhang, Flavio Toffalini, Mathias Payer Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and ...

Migrate Off That Old SIEM Already!

This is cross-posted from Google Cloud Community site, and written jointly with Dave Herrald. If you are like us, you may be surprised that, in 2024, traditional security information and event management (SIEM) systems are still the backbone of ...

CFO Deepfake Fools Staff — Fakers Steal $26M via Video

Bad hoax blood: Spearphish pivots to deepfake Zoom call, leads to swift exit of cash. The post CFO Deepfake Fools Staff — Fakers Steal $26M via Video appeared first on Security Boulevard.

Survey Surfaces Willingness to Switch Data Protection Platforms

A Veeam survey found 54% of respondents planned to change their primary backup solution compared to 27% who wouldn't switch. The post Survey Surfaces Willingness to Switch Data Protection Platforms appeared first on Security Boulevard.

Beyond the basics: advanced insights into secrets management challenges

Cybersecurity is high stakes, and secrets management is the bedrock upon which your security architecture stands.  You know the drill — keeping those API keys, connections-strings, and certificates under wraps is crucial. But let’s not beat ...

Breach analysis: Cloudflare falls victim to Okta attack

In a not-so-surprising turn of events, one of the victims in Okta’s supply chain attack reveals further exploits. Cloudflare recently reported that their entire Atlassian suite – Bitbucket, Jira and Confluence were breached back in November ...

Five Lessons from the Microsoft Identity Breach

Notable new developments from Microsoft’s identity breach and five lessons security teams can take from it. The post Five Lessons from the Microsoft Identity Breach appeared first on RevealSecurity. The post Five Lessons from the Microsoft ...

CSO’s Guide: Water-Tight Account Security For Your Company

This essential CSO guide outlines the robust account monitoring, access notifications, multi-factor authentication, deception technology, and user controls crucial for implementing unmatched account security across your organization. The post ...

Top 2024 Scams: The top predicted scams for this year

The post Top 2024 Scams: The top predicted scams for this year appeared first on Click Armor. The post Top 2024 Scams: The top predicted scams for this year appeared first on Security Boulevard.

How to Protect Against Supply-Chain Attacks | ARIA Cybersecurity

SUNBURST (SolarWinds) – How ARIA would have stopped the supply-chain cyberattack of the decade – and others like it   The post How to Protect Against Supply-Chain Attacks | ARIA Cybersecurity appeared first on Security Boulevard.

Top Trends in Cybersecurity, Ransomware and AI in 2024

As the cybersecurity landscape evolves, organizations must adapt their strategies to combat emerging threats. The post Top Trends in Cybersecurity, Ransomware and AI in 2024 appeared first on Security Boulevard.

Deepfaked video conference call makes employee send $25 million to scammers

A deepfake video conference call paired with social engineering tricks has led to the theft of over US$25 million from a multinational firm, the South China Morning Post has reported. The scheme and the deepfake video conference call The attack ...

AnyDesk Revokes Certificates, Urges Password Changes After Attack

Remote access software maker AnyDesk has revoked all security-related certificates and is urging users to change their passwords in the wake of a cyberattack that compromised some of its systems. The Germany-based company in a relatively brief ...

Varonis MDDR helps organizations prevent data breaches

Varonis introduced Varonis Managed Data Detection and Response (MDDR), a managed service dedicated to stopping threats at the data level. Unlike traditional MDR services that are endpoint- and network-centric, MDDR focuses on threats to data. The ...

Home Network Security for Corporate Executives and Board Members: A Necessity for Remote Work Cybersecurity

The importance of robust home network security for board members and corporate executives cannot be overstated. As the trend towards remote work continues to grow, the lines between home and office network security have blurred, presenting unique ...

Key Considerations for NIST 800-53 Control Family Selection

Key Considerations for NIST 800-53 Control Families, How They Work, and How to Get Started With Implementing Them. The post Key Considerations for NIST 800-53 Control Family Selection appeared first on Scytale. The post Key Considerations for ...

Improving the state of Cosmos fuzzing

By Gustavo Grieco Cosmos is a platform enabling the creation of blockchains in Go (or other languages). Its reference implementation, Cosmos SDK, leverages strong fuzz testing extensively, following two approaches: smart fuzzing for low-level ...

OPSWAT enhances its MetaDefender Kiosk product line

OPSWAT announced new advancements to its MetaDefender Kiosk product line. In response to the escalating challenges faced by organizations in managing and handling threats originating from peripheral media such as USBs and bring-your-own-devices ...