Application Security News and Articles


5 Reasons Why LoginRadius Leads the Way in the CIAM Landscape in 2024 & Beyond

Discover how LoginRadius’ cutting-edge CIAM solution seamlessly integrates state-of-the-art technology for robust security and unparalleled user experiences, making it the go-to choice for businesses navigating the digital terrain. The post 5 ...

NodeZero Updated With Attack Content for Critical Confluence RCE

On 16 January, Atlassian released a security advisory concerning CVE-2023-22527 that affects vulnerable out-of-date versions of Confluence Data Center and Server. The post NodeZero Updated With Attack Content for Critical Confluence RCE appeared ...

Uncovering the hidden superpowers of your smartphone

Picture this: You've just dashed out of your favorite café, already late for a meeting, when that heart-sinking realization hits you: your phone isn't in your pocket where it should be. Panic kicks in. Or maybe you're entering your card details ...

Seceon Launches Seceon aiSIEM-CGuard Enabling MSP/MSSPs With Detection and Response Automation

Leading AI and ML-powered cybersecurity platform for MSPs/MSSPs and IT Teams announces new automated signup and enablement of threat .. The post Seceon Launches Seceon aiSIEM-CGuard Enabling MSP/MSSPs With Detection and Response Automation ...

The story behind the launch of Seceon aiSIEM-CGuard – Automating – Automated Detection and Response

SaaS (Software as a Service) and IaaS (Infrastructure as a Service) are not just ubiquitous in 2024, but for many SMBs, increasingly, they are the only deployment The post The story behind the launch of Seceon aiSIEM-CGuard – Automating – ...

CVE-2024-0204: Fortra GoAnywhere MFT Authentication Bypass Deep-Dive

On January 22, 2024 Fortra posted a security advisory for their GoAnywhere MFT product. This advisory details an authentication bypass vulnerability, CVE-2024-0204, that allows an unauthenticated attacker to create an […] The post ...

USENIX Security ’23 – Ding Wang, Yunkai Zou, Yuan-An Xiao, Siqi Ma, Xiaofeng Chen – Pass2Edit: A Multi-Step Generative Model for Guessing Edited Passwords

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

The Vendor of My Cloud-Vendor is My Friend

What does a suburban roofing company have in common with a cloud supplier? The answer can be found in the passage of time. This conversation occurred with Sean Heide, research technical director at the Cloud Security Alliance, Chris Holland, VP ...

How to Perform a Successful IT Risk Assessment

With a cyber attack being attempted every 40 seconds and ransomware attacks increasing at a rate of 400% year over year, it’s no wonder your organization has to take security seriously. But do you feel confident that you’ve allocated an ...

Blazor

Sonar is helping make C# code clean as Microsoft ASP.NET Core Blazor application development grows The post Blazor appeared first on Security Boulevard.

FBI and CISA Warn of Androxgh0st Malware Attacks

The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) have issued a joint Cybersecurity Advisory warning of the escalating threat posed by Androxgh0st malware. Threat actors are using this ...

Balancing Act: Navigating the Advantages and Risks of ServiceNow’s New Security Attributes

Learn all about Security Attributes, the advantages and risks to migrating to SA’s, and how organizations can benefit from an SSPM like AppOmni. The post Balancing Act: Navigating the Advantages and Risks of ServiceNow’s New Security ...

Randall Munroe’s XKCD ‘Log Alignment’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Log Alignment’ appeared first on Security Boulevard.

Maximizing Security in K-12 IT: Best Practices for Safeguarding Data

The prevalence of malicious cyber activity is increasing globally, and K–12 schools are not exempt... The post Maximizing Security in K-12 IT: Best Practices for Safeguarding Data appeared first on Security Boulevard.

News alert: NCA’s Data Privacy Week webinars highlight data protection for consumers, businesses

Washington D.C. Jan. 22, 2024 – Today, the National Cybersecurity Alliance (NCA), announced the program for its third annual Data Privacy Week campaign, which will take place from January 22nd to January 27th. Throughout the week, NCA will ...

SEC X Account Hack is a Case of SIM Swapping

The bad actor who hacked into the X account of the Securities and Exchange Commission earlier this month gained access through a SIM swapping attack on the agency’s phone linked to the account. A SEC spokesperson in an update this week on the ...

Securing the Move: Cyber Resilience in the Transportation and Supply Chain Industry

Cyber protection is crucial for the transportation industry and the supply chain because it ensures the seamless flow of goods, prevents disruptions, and preserves the integrity of critical data essential for global commerce. The post Securing ...

From Tsunami to Twitter: How Rigorous API Testing Can Prevent Critical System Outages During Disasters

Restricting emergency alerts during a disaster due to rate limiting is in itself a disaster. Learn how to look for this during your API testing. The post From Tsunami to Twitter: How Rigorous API Testing Can Prevent Critical System Outages During ...

Russia Hacked Microsoft Execs — SolarWinds Hackers at it Again

AKA APT29: Midnight Blizzard / Cozy Bear makes it look easy (and makes Microsoft look insecure). The post Russia Hacked Microsoft Execs — SolarWinds Hackers at it Again appeared first on Security Boulevard.

Lacework and Securiti Ally to Better Secure Data

Lacework and Securiti are partnering to integrate their respective DSPM and CNAPP platforms. The post Lacework and Securiti Ally to Better Secure Data appeared first on Security Boulevard.