Application Security News and Articles


What Existing Security Threats Do AI and LLMs Amplify? What Can We Do About Them?

Learn how AI and LLM technology amplifies existing cybersecurity threats and how to harden security against them. The post What Existing Security Threats Do AI and LLMs Amplify? What Can We Do About Them? appeared first on Mend. The post What ...

Defining Good: A Strategic Approach to API Risk Reduction

The cost of not knowing what good is. Could you imagine our interstate highway system without roadway bridges? I don’t think anyone would argue that bridges are not an essential part of an effective ground transportation network. So it ...

USENIX Security ’23 – Xingman Chen, Yinghao Shi, Zheyu Jiang, Yuan Li, Ruoyu Wang, Haixin Duan, Haoyu Wang, Chao Zhang – MTSan: A Feasible and Practical Memory Sanitizer for Fuzzing COTS Binaries

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

API security risks, testing, protection best practices

All you need to know about API security risks and what to and apply in order to keep your API secure and protected from exposure. The post API security risks, testing, protection best practices appeared first on Entro. The post API security ...

Stopping Alert Fatigue in 3 Simple Steps

We live in a world filled with constant notifications. From medical devices to severe weather warnings on your phone to your car’s lane departure warning systems, automated alerts play a critical role in safeguarding our well-being. These ...

PixieFail Bugs in UEFI Open Source Implementation Threaten Computers

A collection of security vulnerabilities found within the de facto open source implementation of the UEFI specification could expose systems to a range of threats, from remote code execution (RCE) and denial-of-service (DoS) to data leakage and ...

Randall Munroe’s XKCD ‘Bug Thread’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Bug Thread’ appeared first on Security Boulevard.

Massive ‘New’ Leaked Credentials List: Naz.API Pwns Troy

Have I been pwned? Yes, you probably have. Stop reusing passwords, already. Here’s what else you should do. The post Massive ‘New’ Leaked Credentials List: Naz.API Pwns Troy appeared first on Security Boulevard.

Meet Turbine Canvas and Embrace the Art of Powerful Simplicity 

The post Meet Turbine Canvas and Embrace the Art of Powerful Simplicity  appeared first on AI Enabled Security Automation. The post Meet Turbine Canvas and Embrace the Art of Powerful Simplicity  appeared first on Security Boulevard.

Continuous Compliance Steps Cybersecurity Departments Should Be Taking to Prepare for CMMC 2.0

By: Igor Volovich, VP, Compliance Strategy Historically, compliance has been seen as a box one could check, a milestone to achieve, an administrative task to cross off our list, and put in the rearview mirror; but alas, in today’s continuously ...

Qmulos Announces General Availability of Q-Compliance V4.4.0 and Q-Audit V3.70

Qmulos announced the new versions and general availability of its two flagship products, Q-Compliance V4.2.0 – an all-in-one solution for any enterprise, environment, framework, control, and datasource, and Q-Audit V3.4.0 – Qmulos' ...

USENIX Security ’23 – Carter Yagemann, Simon P. Chung, Brendan Saltaformaggio, Wenke Lee – PUMM: Preventing Use-After-Free Using Execution Unit Partitioning

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Protect AI Report Surfaces MLflow Security Vulnerabilities

Protect AI identified RCE vulnerabilities in the MLflow life cycle management tool that can be used to compromise AI models. The post Protect AI Report Surfaces MLflow Security Vulnerabilities appeared first on Security Boulevard.

Vercara UltraSecure offers protection from malicious attacks

Vercara is introducing UltraSecure bundles designed to meet the online security needs of mid-size companies. These flexible packages offer enterprise-grade, custom solutions that protect critical applications, secure online properties and ...

Making Secure Boot Even More Secure

Secure Boot lays the foundation for the security of the entire computer system. However, in practice, there are potential security risks in secure boot. I. Overview In the previous post “Secure Boot 101: Getting Started with Secure Boot”, we ...

VulnCheck IP Intelligence identifies vulnerable internet-connected infrastructure

VulnCheck launched IP Intelligence, a new feature set designed to provide real-time tracking of attacker infrastructure and vulnerable IP’s on the internet. VulnCheck IP Intelligence compiles data from popular Internet-Connected Device (ICD) ...

Poorly secured PostgreSQL, MySQL servers targeted by ransomware bot

Users exposing poorly secured PostgreSQL and MySQL servers online are in danger of getting their databases wiped by a ransomware bot, Border0 researchers are warning. The attackers asks for a small sum to return / not publish the data, but those ...

N-able MDR ingests data from existing security and IT tools

N-able continues to advance its security suite with the launch of N-able Managed Detection and Response (MDR). This latest addition to the N-able security suite combines a powerful security operations platform with expert services, giving MSPs a ...

GitHub, PyTorch and More Organizations Found Vulnerable to Self-Hosted Runner Attacks

Last July, we published an article exploring the dangers of vulnerable self-hosted runners and how they can lead to severe software supply chain attacks. A recent blog post by security researcher and bug bounty hunter Adnan Khan provides strong ...

Oleria raises $33 million to accelerate its product innovation

Oleria has raised $33.1 million in a Series A funding round. This latest investment, which brings the company’s total funding to over $40 million, is led by Evolution Equity Partners with participation from Salesforce Ventures, Tapestry VC, and ...