Application Security News and Articles


CISOs’ crucial role in aligning security goals with enterprise expectations

In this Help Net Security interview, Chris Mixter, Vice President, Analyst at Gartner, discusses the dynamic world of CISOs and how their roles have evolved significantly over the years. He outlines the critical skills for CISOs in 2024, ...

Top Insider Risk Management Predictions for 2024

The global demand for enhanced insider risk management capabilities will continue to skyrocket across industries throughout 2024. As security leaders grapple with the rise of generative AI, calls for greater collaboration between public and ...

Best practices to mitigate alert fatigue

In this Help Net Security video, Peter Manev, Chief Strategy Officer at Stamus Networks, discusses a pervasive problem plaguing security analysts called “alert fatigue,” – which occurs when security teams become desensitized to an ...

IT teams unable to deliver data fast enough to match the speed of business

Increasing data requests overwhelm IT teams, but security concerns hinder their ability to provide employees with access to timely data, according to CData Software. The majority of Ops professionals feel that they are prohibited from accessing ...

Key Considerations for Successful Cybersecurity Supply Chain Risk Management (C-SCRM)

What is C-SCRM Cybersecurity Supply Chain Risk Management (C-SCRM) is the strategic process of identifying, assessing, and mitigating risks associated with the information and communication technology (ICT) supply chain. Virtually every technical ...

Netcraft Report Surfaces Spike in Online Healthcare Product Scams

The volume of online scams relating to healthcare emanating from inexpensive TLDs is spiking—accounting for as much as 60% of daily domain registrations. The post Netcraft Report Surfaces Spike in Online Healthcare Product Scams appeared first ...

Our Journey in Building AI-First Security Features | Impart Security

In this post, I’ll share the innovation pipeline process we take when we develop new AI first features, and walk you through the actual steps we took in the journey—from experimentation with LLMs, to creating the desired security workflow, to ...

Why the US Needs Comprehensive Cybersecurity Legislation

Taking a hands-off approach to cybersecurity is no longer good enough for any organization. In... The post Why the US Needs Comprehensive Cybersecurity Legislation appeared first on Security Boulevard.

USENIX Security ’23 – Christof Ferreira Torres, Fiona Willi, Shweta Shinde – Is Your Wallet Snitching On You? An Analysis on the Privacy Implications of Web3

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

What is content abuse?

Content abuse occurs when scammers create fake user-generated content to defraud a business or another user. Discover the different types of content abuse and how you can prevent it. The post What is content abuse? appeared first on Sift ...

A New Breed Of Security Leadership: How the Digital Age Is Transforming the Security Professional

This article was originally featured in Security Informed The importance of data is ever-growing. For every profession, we’re witnessing the increasing reliance on data and its ability to promote efficiency for corporate decision-makers. The ...

Randall Munroe’s XKCD ‘Sheet Bend’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Sheet Bend’ appeared first on Security Boulevard.

Atlassian reveals critical Confluence RCE flaw, urges “immediate action” (CVE-2023-22527)

Atlassian has patched a critical vulnerability (CVE-2023-22527) in Confluence Data Center and Confluence Server that could lead to remote code execution. The good news is that the flaw was fixed in early December 2023 with the release of versions ...

OpenAI: We’ll Stop GPT Misuse for Election Misinfo

Guardrails Prevent Trouble? Sam says avoid AI abuse—protect the democratic process. The post OpenAI: We’ll Stop GPT Misuse for Election Misinfo appeared first on Security Boulevard.

The No-Nonsense Guide to Bypassing API Auth Using NoSQL Injection

Introduction Sometimes, the way to bypass API auth is easier than you think. That’s all thanks to modern software development and the exponential growth of web services and cloud-based applications. Let me explain. APIs (Application Programming ...

SBOM Examples

The post SBOM Examples appeared first on CodeSecure. The post SBOM Examples appeared first on Security Boulevard.

Fortinet unveils networking solution integrated with Wi-Fi 7

Fortinet announced a comprehensive secure networking solution integrated with Wi-Fi 7. Fortinet’s first Wi-Fi 7 access point, FortiAP 441K, delivers increased speed and capacity, and the new FortiSwitch T1024 is purpose-built with 10 Gigabit ...

Getting Started: A Beginner’s Guide for Improving Privacy

Welcome to the world of online/digital privacy! Like its sister guide for cybersecurity, this privacy guide was written for complete privacy novices in mind. It is designed to be a starting point for anyone new to the world of online privacy. It ...

USENIX Security ’23 – Fieke Miedema, Kelvin Lubbertsen, Verena Schrama, Rolf van Wegberg – Mixed Signals: Analyzing Ground-Truth Data on the Users and Economics of a Bitcoin Mixing Service

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

The State of Software Supply Chain Security 2024: Key takeaways

Software supply chain attacks are now mainstream events — a change in tactics by cyber-attackers that you can measure in headlines, which in recent years have delivered news about attacks on popular software tools including MOVEIt, 3CX, and ...