Application Security News and Articles


USENIX Security ’23 – Jason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson, Prateek Saxena – Capstone: A Capability-Based Foundation for Trustless Secure Memory Access

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Why Behavioral Threat Hunting is the Big Thing for Cybersecurity in 2024

As we surge into 2024, the cybersecurity landscape is witnessing a paradigm shift. Gone are the days when Indicators of Compromise (IOCs) held the throne. 2023 marked the realization within cybersecurity circles that while IOCs serve a purpose, ...

Kaspersky Details Method for Detecting Spyware in iOS

Researchers with cybersecurity firm Kaspersky are detailing a lightweight method for detecting the presence of spyware, including The NSO Group’s notorious Pegasus software, in Apple iOS devices. The new method, which calls for looking for ...

Wing Security unveils automated protection against AI-SaaS risks

Wing Security unveils an automatic advanced approach to counter the evolving risks of Intellectual Property (IP) and data leakage into GenAI applications. Amidst the growing adoption of GenAI, and the many SaaS applications powered by GenAI, Wing ...

London Calling: Hey, US, Let’s Chat About Cyber AI – The Next WannaCry

Artificial intelligence (AI)-based attacks would likely possess greater adaptability and evasion capabilities than WannaCry and NotPetya. The post London Calling: Hey, US, Let’s Chat About Cyber AI – The Next WannaCry appeared first ...

Living Security Unify Power Insights identifies vulnerable members within an organization

Living Security announced Unify Power Insights, which combines intelligence across multiple identity management and security tools to pinpoint visibility into which members of the workforce are most vulnerable to phishing, account compromise, ...

Educating Athletes about Cyber Risks: A Guide for Sports Agents

In today’s hyper-connected world, where social media, online banking, and digital communications are integral to our daily routines, athletes, much like celebrities, are increasingly susceptible to cyber risks. As sports agents, it’s ...

Shipping-Themed Emails: Not Just for The Holidays

By Nathaniel Raymond The importance of fast and efficient shipping solutions has increased for households and businesses. This is especially true during the holiday season when demand for shipping services is high. Cofense Intelligence asked ...

Salt Security Adds Governance Engine to API Security Platform

Salt Security added a posture governance engine to its API security platform that defines and enforces implementation standards. The post Salt Security Adds Governance Engine to API Security Platform appeared first on Security Boulevard.

Vicarius raises $30 million to accelerate the development of new AI capabilities

Vicarius announced a $30 million Series B led by cybersecurity investment firm Bright Pixel (formerly Sonae IM). AllegisCyber Capital, AlleyCorp, and Strait all participated in the financing. The company’s total funding, including investments ...

AI’s Role in Cybersecurity for Attackers and Defenders in 2024

As AI becomes available and robust, malicious actors have already used it to develop more advanced attack methods; defenders must also leverage AI in 2024. The post AI’s Role in Cybersecurity for Attackers and Defenders in 2024 appeared ...

What is the Difference Between Cyberstalking and Cyberbullying?

Understanding distinctions between cyberbullying & cyberstalking requires looking beyond surface similarities at key differences in behaviors, motivations, impacts & societal responses to these rising forms of online harassment. The post ...

GitHub Actions hack bolsters case for complex binary analysis

The post GitHub Actions hack bolsters case for complex binary analysis appeared first on Security Boulevard.

Kaspersky releases utility to detect iOS spyware infections

Kaspersky’s researchers have developed a lightweight method to detect indicators of infection from sophisticated iOS spyware such as NSO Group’s Pegasus, QuaDream’s Reign, and Intellexa’s Predator through analyzing a log file ...

Industrial Defender collaborates with Dragos to enhance outcomes for OT operators

Industrial Defender announced a strategic technology partnership with Dragos. The collaboration between these leaders in OT cybersecurity integrates their respective platform capabilities, representing a major move towards combining their leading ...

Google fixes actively exploited Chrome zero-day (CVE-2024-0519)

In the new stable release of the Chrome browser, Google has fixed three security vulnerabilities affecting the V8 engine, including one zero-day (CVE-2024-0519) with an existing exploit. About CVE-2024-0519 V8 is an open-source JavaScript and ...

Shift Up: Leverage CRQ Insight for Cyber Resilience, Part 2 | Kovrr blog

Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post Shift Up: Leverage CRQ Insight for Cyber Resilience, Part 2 | Kovrr blog appeared first on Security Boulevard.

Lessons learned upgrading to React 18 in SonarQube

We share the biggest three issues we faced and the lessons we learned as we upgraded SonarQube to React 18. The post Lessons learned upgrading to React 18 in SonarQube appeared first on Security Boulevard.

Security considerations during layoffs: Advice from an MSSP

Navigating layoffs is complex and difficult for many reasons. Not only do human resources and direct managers bear the onus of responsibility when conducting exit conversations, but security teams should also make the necessary preparations for ...

The right strategy for effective cybersecurity awareness

Employees play a significant role in safeguarding organizational assets. With a constantly evolving threat landscape, cybersecurity awareness training is an essential component in creating a good security culture. Why cybersecurity awareness ...