Application Security News and Articles


Welcome to Data Privacy Week: Empowering Your Cybersecurity with BlackCloak

The importance of data privacy continues to grow exponentially. We recognize this critical need and are excited to kick off Data Privacy Week, a dedicated time to focus on the ways we can protect our personal information online. This week is not ...

Cybersecurity Challenges at the World Economic Forum

The 54th Annual Meeting of The World Economic Forum took place in Davos, Switzerland, this past week, and cybersecurity and AI were again top topics. Here are some highlights. The post Cybersecurity Challenges at the World Economic Forum appeared ...

Week in review: 10 cybersecurity frameworks you need to know, exploited Chrome zero-day fixed

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Key elements for a successful cyber risk management strategy In this Help Net Security interview, Yoav Nathaniel, CEO at Silk Security, ...

Como fazer Revisão de Código — Parte 1

A revisão de código-fonte, popularmente conhecida como (code review) é um processo de análise do código-fonte de um aplicativo de software…Continue reading on Medium »

Webinar: Join us for the latest in API Threats on January 24, 2024

In today's complex digital landscape, the security of APIs has become paramount. As we move into 2024, it's essential to stay ahead of the evolving API security threats and vulnerabilities. The upcoming webinar on "API ThreatStats™ Report: 2023 ...

USENIX Security ’23 – Unique Identification of 50,000+ Virtual Reality Users from Head & Hand Motion Data

Authors/Presenters: Vivek Nair, Wenbo Guo, Justus Mattern, Rui Wang, James F. O’Brien, Louis Rosenberg, Dawn Song Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong ...

Book Review: The Crypto Launderers: Crime and CryptoCurrencies

The Crypto Launderers: Crime and Cryptocurrencies from the Dark Web to DeFi and Beyond - by David Carlisle    I wish I had a way to review this book without having first read last year’s “Tracers in the Dark.” While Tracers talked ...

Your data is under siege. Here’s how to win the war.

I consider myself pretty savvy when it comes to protecting my personal data. But last year I nearly fell for a phone scam from someone purporting to be an IRS agent. In my own defense, it was an impressively creative scam. It was also a reminder ...

Behind the Breach: Pass-The-Cookie Beyond IdPs

Pass-The-Cookie (PTC), also known as token compromise, is a common attack technique employed by threat actors in SaaS environments.  In the past, Obsidian’s Threat Research team noted a pattern where most PTC attacks focused on stealing the ...

Unlock SaaS Security Intelligence with Splunk and Obsidian

In a world of evolving SaaS security threats, organizations require advanced threat detection and response capabilities. Obsidian’s integration with Splunk provides just that–empowering security teams to effectively address SaaS security ...

Demystifying Cybersecurity’s Public Companies

It's a lot harder to come up with a list of public cybersecurity companies than you'd think. Here are the reasons why, plus an honest attempt to get the list right. The post Demystifying Cybersecurity’s Public Companies appeared first on ...

Behind the Breach: Pass-The-Cookie Beyond IdPs

Pass-The-Cookie (PTC), also known as token compromise, is a common attack technique employed by threat actors in SaaS environments.  In the past, Obsidian’s Threat Research team noted a pattern where most PTC attacks focused on stealing the ...

USENIX Security ’23 – Habiba Farrukh, Reham Mohamed, Aniket Nare, Antonio Bianchi, Z. Berkay Celik – LocIn: Inferring Semantic Location from Spatial Maps in Mixed Reality

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Introducing DataDome Companion: A Powerful New ChatGPT Application to Build Custom Rules Fast

DataDome's new ChatGPT plugin, Companion, empowers our customers to create new custom rules quickly to keep their organizations safe from malicious actors. The post Introducing DataDome Companion: A Powerful New ChatGPT Application to Build ...

Protect Yourself and Freeze Your Credit

Breaches are never ending, and if you have not already put freezes on your credit reports, make a late New Year’s resolution and do it now. There are a couple of steps you will need to take for each of the four bureaus (yes four). Before you ...

Empowering You for a Secure 2024: Your Journey with DataDome in Review & Ahead

Invisible challenges, enterprise features, and other upgrades: Learn more about how DataDome's enhancements in 2023 will protect our customers in 2024 and beyond. The post Empowering You for a Secure 2024: Your Journey with DataDome in Review ...

Randall Munroe’s XKCD ‘Net Rotations’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Net Rotations’ appeared first on Security Boulevard.

Has My Secret Leaked? [Security Zines]

A new comic strip to better grasp the simple but effective way HasMySecretLeaked checks your secrets without asking you to reveal them! The post Has My Secret Leaked? [Security Zines] appeared first on Security Boulevard.

Ivanti EPMM and MobileIron Core vulnerability is actively exploited, CISA confirms (CVE-2023-35082)

A previously patched critical vulnerability (CVE-2023-35082) affecting Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core is being actively exploited, the Cybersecurity and Infrastructure Security Agency (CISA) has confirmed by adding the ...

Latest OpenPubkey Project Initiative Makes SSH More Secure

The OpenPubkey project shared an OIDC-based mechanism for remotely logging into IT environments that makes authentication using SSH certificates more secure. The post Latest OpenPubkey Project Initiative Makes SSH More Secure appeared first on ...