Application Security News and Articles


Devo Achieves ATO, and Federal CISOs Gain Another Key Resource

Of all the SaaS tools used by federal IT teams, cutting-edge cybersecurity tools may be the ones in highest demand. In July 2023 a number of US agencies – including the Department of Energy and the US Office of Personnel Management – were ...

Response to CISA Advisory (AA24-016A): Known Indicators of Compromise Associated with Androxgh0st Malware

AttackIQ has released a new assessment template in response to the recently published CISA Advisory (AA24-016A) which disseminates known Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs) associated with threat actors ...

USENIX Security ’23 – Hidden Reality: Caution, Your Hand Gesture Inputs in the Immersive Virtual World are Visible to All!

Authors/Presenters: Sindhu Reddy Kalathur Gopal, Diksha Shukla, James David Wheelock, Nitesh Saxena Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to ...

Considerations for outsourcing your penetration testing

Penetration testing has become a cornerstone of robust cybersecurity strategy. It’s a critical process where experts simulate cyber attacks on your systems, networks, or applications to identify vulnerabilities before real... The post ...

SBOM Use Cases and Why Binary Composition Analysis Matters

The post SBOM Use Cases and Why Binary Composition Analysis Matters appeared first on CodeSecure. The post SBOM Use Cases and Why Binary Composition Analysis Matters appeared first on Security Boulevard.

How to Shine in Your Next Cybersecurity Audit

Organizations facing cybersecurity audits need to be doubly prepared for cyberattacks and cybercrime and an audit team. The post How to Shine in Your Next Cybersecurity Audit appeared first on Security Boulevard.

Ransomware Activity Surged in 2023, Likely to Evolve in 2024

A Rapid7 report found that last year was marked by an onslaught of ransomware attacks, and expects the same in 2024. The post Ransomware Activity Surged in 2023, Likely to Evolve in 2024 appeared first on Security Boulevard.

The Difference Between Pivoting vs. Lateral Movement

The distinction between pivoting vs lateral movement can be central to applicable protection  Understanding the nuances of different attack methodologies is crucial for effective defense. Two such concepts often discussed are ‘pivoting’ and ...

PolyCrypt Runtime Crypter Being Sold On Cybercrime Forums

We discuss the use of crypters and more specifically Polycrypt and how it can be used to evade detection and infect victims. The post PolyCrypt Runtime Crypter Being Sold On Cybercrime Forums appeared first on Security Boulevard.

How SoundCloud Beats Fraudulent Traffic with DataDome and AWS

By eliminating online fraud and malicious bot activity, the DataDome solution—paired with AWS—helps SoundCloud focus on supporting their users. The post How SoundCloud Beats Fraudulent Traffic with DataDome and AWS appeared first on Security ...

GAO Report Details FedRAMP ATO Challenges and Costs

The US Government Accountability Office (GAO) released a report on The Federal Risk and Authorization Management Program (FedRAMP®). The 37 page report provides highly relevant insights to both agencies and commercial organizations pursuing ...

Orange Spain Outage: BGP Traffic Hijacked by Threat Actor

In a recent cybersecurity incident, Orange Spain faced a significant internet outage on January 3, 2024. A threat actor, going by the name ‘Snow,’ exploited vulnerabilities in the company’s RIPE account. The Orange Spain outage resulted in ...

Out with the old and in with the improved: MFA needs a revamp

From AI to ZTA (zero-trust architecture), the technology responsible for protecting your company’s data has evolved immensely. Despite the advances, cybercriminals repeatedly find new and creative ways to gain access to sensitive information. ...

What is Mobile Application Testing? How to Conduct It

A survey indicates that more than 98% of mobile applications lack security. This is primarily attributed to a common misconception in app development practices, where mobile application testing is often deferred to the final stages of the ...

New infosec products of the week: January 19, 2024

Here’s a look at the most interesting products from the past week, featuring releases from Living Security, Skopenow, Skyhigh Security, and Wing Security. Skyhigh Security’s AI-driven DLP Assistant prevents critical data loss Skyhigh ...

Digital nomads amplify identity fraud risks

The number of foreign document verification cases in all parts of the world has grown by an average of 21% since the summer of 2021, according to Regula. It’s even higher in the US and UAE: these countries are experiencing a 25% increase. As ...

Unlocking GenAI’s full potential through work reinvention

To achieve the full potential of AI, organizations must reinvent work, reshape the workforce and prepare workers, according to Accenture. A new report from Accenture reveals an urgent need for business leaders to look beyond how generative AI ...

The Unseen Threats: Anticipating Cybersecurity Risks in 2024

Cybersecurity risks increase every year and bludgeon victims who fail to prepare properly.  It can feel like crossing a major highway while blindfolded.  Many never see the catastrophe about to happen, until it occurs.  Cybersecurity ...

The Benefits of Using DCIM Software for Data Center Cable Management

In the ever-evolving landscape of information technology, the management of data centers has become increasingly complex. The backbone of these centers is their intricate network of cables, which are essential for the seamless operation of ...

New Paper: “Future of the SOC: Evolution or Optimization — Choose Your Path” (Paper 4 of 4.5)

New Paper: “Future of the SOC: Evolution or Optimization — Choose Your Path” (Paper 4 of 4.5) After a long, long, long writing effort break, we are ready with our 4th Deloitte / Google Future of the SOC paper “Future of the SOC: ...