Application Security News and Articles


Enhancing Data Center Efficiency and Sustainability with Power Capacity Effectiveness

The digital age demands the optimization of data centers, serving as critical hubs for information storage and processing. The introduction of Power Capacity Effectiveness (PCE) has emerged as a key metric in addressing the efficiency and ...

What is Identity Threat Detection and Response?

Identity Threat Detection and Response (ITDR) remains crucial for preventing unauthorized access and mitigating security breaches The security of digital identities has never been more paramount, and Identity Threat Detection and Response (ITDR) ...

The Impact of OpenAI’s GPT Store

In recent years, the world of Artificial Intelligence (AI) has been buzzing with groundbreaking advancements, and OpenAI has been at the forefront of these developments. The introduction of the GPT Store by OpenAI is set to redefine how we access ...

How to secure APIs built with Express.js

Learn how to secure your Express.js APIs effectively with our expert hands-on tutorial. Enhance security for your projects in just a few steps! The post How to secure APIs built with Express.js appeared first on Security Boulevard.

DDoS Attackers Put Environmental Services Firms in Their Crosshairs

Environmental services websites are becoming significant targets for threat groups launching distributed denial-of-services attacks, with researchers at Cloudflare noting a staggering 61,839% year-over-year increase in the fourth quarter last ...

Embedding Security Into Cloud Operations: 5 Key Considerations

Cloud operations involves more than technology; it's about a culture that values agility, flexibility and continuous improvement. The post Embedding Security Into Cloud Operations: 5 Key Considerations appeared first on Security Boulevard.

Critical Linux Security Updates for Debian 12 and Debian 11

In the dynamic realm of cybersecurity, staying ahead of potential threats is crucial for maintaining a secure computing environment. For Debian GNU/Linux users, keeping the system updated with the latest security patches is an essential step ...

Internet freedom with the Open Technology Fund

By Spencer Michaels, William Woodruff, Jeff Braswell, and Cliff Smith Trail of Bits cares about internet freedom, and one of our most valued partners in pursuit of that goal is the Open Technology Fund (OTF). Our core values involve focusing on ...

Windows SmartScreen bug exploited to deliver powerful info-stealer (CVE-2023-36025)

A vulnerability (CVE-2023-36025) that Microsoft fixed in November 2023 continues to be exploited by malware peddlers: this time around, the delivered threat is a variant of the Phemedrone Stealer. About the malware Phemedrone Stealer is a piece ...

New Jersey Privacy Act: What to Expect

The last couple of years have seen a wave of state privacy law proposals across the United States. As of 2018, only California had passed a comprehensive privacy law. By late 2022, the federal government and 29 states were playing the game, with ...

Stupid Human Tricks: Top 10 Cybercrime Cases of 2023

Mark Rasch examines 2023 cybercrime cases that appear to be the most impactful—not the most extensive or expensive—just the most “interesting.” The post Stupid Human Tricks: Top 10 Cybercrime Cases of 2023 appeared first on Security ...

US Army – lack of segregation of duties

Could a lack of Segregation of Duties allow woman to steal millions from US army?San Antonio Woman Accused of Stealing $103 Million from US ArmyIn a startling case that captured headlines, Janet Mello is currently facing charges of embezzling ...

Strategies to Overcome Vendor Risk Assessment Challenges

Your business relies on a vast network of third-party vendors, from cloud service providers to software-as-a-service (SaaS) platforms. They’re the backbone of your operations, handling your most sensitive customer data and safeguarding your ...

Trellix XDR Platform for RDR strengthens operational resilience for customers

Trellix announced Trellix XDR Platform for Ransomware Detection and Response (RDR), available immediately worldwide. Trellix XDR Platform for RDR provides visibility across an organization’s entire security ecosystem and delivers critical ...

Top 5 Access Security Challenges in SAP

Top 5 Access Security Challenges in SAPHere are five high-level challenges that SAP users commonly face when it comes to securing access:1. Complexity of Authorization Models: SAP systems often have complex authorization models with numerous ...

How to Create Roles in PostgreSQL

PostgreSQL is a powerful and feature-rich open-source relational database management system. One of its key features is the role-based access control (RBAC) system, which allows you to define and manage user access and permissions within your ...

Juniper fixes critical RCE in its SRX firewalls and EX switches (CVE-2024-21591)

Juniper Networks has fixed a critical pre-authentication remote code execution (RCE) vulnerability (CVE-2024-21591) in Junos OS on SRX firewalls and EX switches. About CVE-2024-21591 CVE-2024-21591 is an out-of-bounds write vulnerability that ...

Dr. Martin Luther King, Jr. Day 2024

Permalink The post Dr. Martin Luther King, Jr. Day 2024 appeared first on Security Boulevard.

2024: Reflecting on a Dynamic, Tumultuous Cyber Year

As we step into 2024, it's crucial to reflect on the cyber landscape of the past year, marked by significant breaches that underscore the persistent challenges in securing our digital lives. Here are some notable incidents that grabbed ...

Are DDoS Simulation Tests Legal?

DDoS simulation tests fall into a different legal category than real DDoS attacks carried out by hackers. In the United States, for example, the Computer Fraud and Abuse Act considers a DDoS attack to be a cybercrime with serious prison time and ...