Application Security News and Articles


Mastering the ‘cd’ Command: Tips and Tricks for Efficient Directory Navigation

Navigating through directories is a fundamental aspect of working in a command-line interface, and the ‘cd’ command plays a crucial role in this process. In this blog post, we’ll explore various tips and tricks to enhance your efficiency ...

Randall Munroe’s XKCD ‘Range Safety’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Range Safety’ appeared first on Security Boulevard.

Secure Your Secrets with .env

Using environment variables to store secrets instead of writing them directly into your code is one of the quickest and easiest ways to add a layer of protection to your projects. The post Secure Your Secrets with .env appeared first on Security ...

NIST: Better Defenses are Needed for AI Systems

The accelerating development and expanding deployment of AI systems is creating significant security and privacy risks that aren’t being mitigated by modern solutions, according to a research paper from the U.S. National Institute of Standards ...

NIS2 Compliance: Updated for 2024,  Complete Guide

The Network Information Systems Directive (NIS) was published in 2016 and required EU critical infrastructure sectors to meet basic cybersecurity compliance requirements. In October 2024 the second iteration of the Network Information Systems ...

USENIX Security ’23 – Zixin Wang, Danny Yuxing Huang, Yaxing Yao – ‘Exploring Tenants’ Preferences of Privacy Negotiation in Airbnb’

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Beyond Baby Steps: Fostering Diversity & Inclusion in the Parental Leave Adventure

Learn about the DataDome parenting pod fostering diversity and inclusion for all BotBusters, ensuring they can be fantastic parents while getting the job done. The post Beyond Baby Steps: Fostering Diversity & Inclusion in the Parental Leave ...

DOE Puts Up $70 Million to Secure US Energy Infrastructure

The federal government will spend as much as $70 million for technologies that will create a more resilient energy delivery infrastructure that is better protected against a range of threats, including from cybercriminals. The U.S. Department of ...

Votiro Cloud Protects Microsoft Teams from File-borne Threats

Virtual collaboration tools like Microsoft Teams are vital for business productivity – especially those with remote workforces. Yet, while these platforms offer convenience and efficiency, they also expand the attack surface and present new ...

2023 Wrapped: Most Viewed Blogs of 2023

2023 Wrapped: Most Viewed Blogs of 2023 ltabo Mon, 01/08/2024 - 13:05 It’s hard to believe that 2023 is over and we are helping our customers plan their 2024 SAP security strategies. As we continue to see an increase in threat activity ...

SEC Cyber Incident Reporting Rules Pressure IT Security Leaders

As the SEC gets tough on businesses' cybersecurity posture, IT security leaders will need to beef up incident response plans. The post SEC Cyber Incident Reporting Rules Pressure IT Security Leaders appeared first on Security Boulevard.

Second Interdisciplinary Workshop on Reimagining Democracy

Last month, I convened the Second Interdisciplinary Workshop on Reimagining Democracy (IWORD 2023) at the Harvard Kennedy School Ash Center. As with IWORD 2022, the goal was to bring together a diverse set of thinkers and practitioners to talk ...

McAfee Project Mockingbird defends users against AI-generated scams and disinformation

McAfee announced its AI-powered Deepfake Audio Detection technology, known as Project Mockingbird. This new, proprietary technology was developed to help defend consumers against the surging threat of cybercriminals utilizing fabricated, ...

Debian and Ubuntu Fixed OpenSSH Vulnerabilities

Debian and Ubuntu have released security updates for their respective OS versions, addressing five flaws discovered in the openssh package. In this article, we will delve into the intricacies of these vulnerabilities, shedding light on their ...

How to Conduct an Effective Phishing Audit?

Introduction Remember the alluring “million bucks!” email that nearly compromised your savings? Or the urgent “your bank account is compromised!” alert that nearly tricked you into surrendering your PIN? Step into the complex ecosystem of ...

Default Configurations of Software and Applications in Cybersecurity

This article is part of a series where we look at a recent NSA/CISA Joint Cybersecurity Advisory on the top cybersecurity issues identified during red/blue team exercises operated by these organizations. In this article you will find a more ...

Alert: Carbanak Malware Strikes Again With Updated Tactics

Recent reports have highlighted the return of the Carbanak Malware. As per the reports, it’s a banking malware used in ransomware attacks that leverages updated tactics for increased effectiveness. As of now, the malware is known to have been ...

Social engineer reveals effective tricks for real-world intrusions

In this Help Net Security interview, Jayson E. Street, Chief Adversarial Officer at Secure Yeti, discusses intriguing aspects of social engineering and unconventional methods for gathering target information. Street explores the overlooked threat ...

Review: Engineering-grade OT security: A manager’s guide

Andrew Ginter is a widely-read author on industrial security and a trusted advisor for industrial enterprises. He holds a BSc. in Applied Mathematics and an MSc. in Computer Science from the University of Calgary. He developed control system ...

AuthLogParser: Open-source tool for analyzing Linux authentication logs

AuthLogParser is an open-source tool tailored for digital forensics and incident response, specifically crafted to analyze Linux authentication logs (auth.log). The tool examines the auth.log file, extracting crucial details like SSH logins, user ...