Application Security News and Articles


Skytrack: Open-source aircraft reconnaissance tool

Skytrack is an open-source command-line tool for plane spotting and aircraft OSINT reconnaissance. The tool utilizes multiple data sources to collect information on aircraft, can produce a PDF report for a specific aircraft, and offers conversion ...

Ransomware negotiation: When cybersecurity meets crisis management

In this Help Net Security interview, Tim Morris, Chief Security Advisor at Tanium, discusses ransomware negotiation, how it typically unfolds, and how organizations should have a playbook that clearly outlines what to do, when to do it, who is ...

The power of AI in cybersecurity

The widespread adoption of artificial intelligence (AI), particularly generative AI (GenAI), has revolutionized organizational landscapes and transformed both the cyber threat landscape and cybersecurity. AI as a powerful cybersecurity tool As ...

Adversaries exploit trends, target popular GenAI apps

More than 10% of enterprise employees access at least one generative AI application every month, compared to just 2% a year ago, according to Netskope. In 2023, ChatGPT was the most popular generative AI application, accounting for 7% of ...

Confessions on MFA and Security Best Practices

The last couple weeks have brought a few discussions on the topic of multifactor authentication or MFA (sometimes also referred to as 2FA or two factor authentication).  These discussions have been driven by the SEC’s X (formerly known as ...

A fortified approach to preventing promo, bonus, and other multi-account abuse

Discover three innovative ways to prevent multi-account fraud and bonus abuse to accelerate player acquisitions and maximize market share. The post A fortified approach to preventing promo, bonus, and other multi-account abuse appeared first on ...

The Perils of Platformization

#TLDR CISOs continually have to choose between best of breed security vs Platformization and further consolidation of vendors. The emergence of ERP tools presented a similar choice and most ERP projects have ended up as expensive failures. Open ...

Calling Home, Get Your Callbacks Through RBI

Authored By: Lance B. Cain and Alexander DeMine Overview Remote Browser Isolation (RBI) is a security technology which has been gaining popularity for large businesses securing their enterprise networks in recent years. This blog post describes ...

Androxgh0st Malware: SafeBreach Coverage for US-CERT Alert (AA24-016A)

Androxgh0st malware is a python-scripted malware that has been used to target the “.env” files containing sensitive data such as credentials for high-profile applications. The post Androxgh0st Malware: SafeBreach Coverage for US-CERT Alert ...

USENIX Security ’23 – FloatZone: Accelerating Memory Error Detection using the Floating Point Unit

Authors/Presenters: Floris Gorter, Enrico Barberis, Raphael Isemann, Erik van der Kouwe, Cristiano Giuffrida, Herbert Bos Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations ...

Over 178K SonicWall Firewalls Vulnerable to DoS, Potential RCE Attacks

A significant security concern has been raised for organizations using SonicWall next-generation firewalls (NGFW). Here’s what you need to know.   Tell me more about the SonicWall firewall vulnerability  Security experts have identified that ...

Good Application Security Posture Requires Good Data

Discover how GitGuardian enhances Application Security Posture Management, ASPM, with top-notch code security and secrets detection and remediation coordination. The post Good Application Security Posture Requires Good Data appeared first on ...

Taking on EvilProxy: Advancements in Phishing Protection

Thanks to various 2023 security reports, we know phishing attacks are now the most common form of cybercrime, with an estimated close to 3.5 billion spam emails sent every day. In 2022, reports indicated that the worldwide average cost of a data ...

Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnaravi – #275 — Comic Agilé Consulting

via the respected Software Engineering expertise of Mikkel Noe-Nygaard and the lauded Software Engineering / Enterprise Agile Coaching work of Luxshan Ratnaravi at Comic Agilé! Permalink The post Comic Agilé – Mikkel Noe-Nygaard, ...

News alert: Incogni study reveals overwhelming majority of spam calls originate locally

Los Angeles, Calif., Jan. 17, 2024 – Spam calls continue to be a major nuisance in the US, and advice on how to avoid them abound. Incogni’s latest research challenges prevalent assumptions about spam calls, revealing that traditional advice ...

Product Update | NEW! Cloud Monitor Consolidated View

Major UI Changes To ManagedMethods’ Cloud Monitor Platform The product team at ManagedMethods has been working hard to provide a new way of managing information in customers’ Cloud Monitor domains. Previously, many of our customers have used ...

Hackers Building AndroxGh0st Botnet to Target AWS, O365, Feds Warn

The bad actors behind the Androxgh0st malware are building a botnet they can use to identify victims and exploit vulnerable networks to steal confidential information from such high-profile cloud applications as Amazon Web Services (AWS), ...

Apple Smashes Ban Hammer on Beeper iMessage Users

Empire strikes back: It was only a matter of time. But is this what Eric wanted all along? The post Apple Smashes Ban Hammer on Beeper iMessage Users appeared first on Security Boulevard.

Badge Makes Device-Independent Authentication Platform Available

Badge Inc.'s namesake platform that enables end users to securely be authenticated on-demand using any device is now generally available. The post Badge Makes Device-Independent Authentication Platform Available appeared first on Security Boulevard.

Skyhigh Security’s AI-driven DLP Assistant prevents critical data loss

Skyhigh Security announced an AI-driven DLP Assistant as an advanced DLP capability within its Security Service Edge (SSE) portfolio. The AI-based Assistant can help simplify many complex tasks in DLP with the ability to generate complex regular ...