Application Security News and Articles


Survey Surfaces Lack of Confidence in Existing Cybersecurity Tools

More than half of cybersecurity leaders would replace their entire current stack of platforms if there were no budget constraints. The post Survey Surfaces Lack of Confidence in Existing Cybersecurity Tools appeared first on Security Boulevard.

SentinelOne Acquires PingSafe to Advance CNAPP Ambitions

SentinelOne is acquiring PingSafe to add a CNAPP to extend its cybersecurity portfolio of offerings that are infused with AI. The post SentinelOne Acquires PingSafe to Advance CNAPP Ambitions appeared first on Security Boulevard.

USENIX Security ’23 – Sathvik Prasad, Trevor Dunlap, Alexander Ross, Bradley Reaves – ‘Diving into Robocall Content With SnorCall’

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Software Supply Chain Security Deconstructed

In the last several years, software supply chain security has become a critical focus for organizations worldwide.  While the SolarWinds software supply chain attack in 2020 and the Kaseya ransomware attacks in mid-2021 weren’t the first ...

Netography Fusion Expands Microsoft Integrations for Greater Context Enrichment and Faster Compromise Detection

Netography Fusion adds Microsoft Defender for Endpoint and Microsoft Defender XDR integrations, enabling customers with faster detection of and response to compromises with context from Microsoft-managed identities, email, endpoints, and cloud ...

Your Guide to Building a Successful Attack Surface Management Strategy

This blog offers practical tips to assess the efficacy of an organization’s attack surface management strategy and how leaders can enhance it. The post Your Guide to Building a Successful Attack Surface Management Strategy appeared first on ...

Randall Munroe’s XKCD ‘2024’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘2024’ appeared first on Security Boulevard.

From Log4j to Long4j

Veracode reports that more than a third of Java application still use vulnerable versions of Log4j despite efforts to eradicate it. The post From Log4j to Long4j appeared first on Azul | Better Java Performance, Superior Java Support. The ...

Structuring the Unstructured: Consolidating Reports into One Cohesive Record 

Discover how combining your investigative research into a configurable, cohesive report can help surface more from your findings. Over the past few articles, I’ve shared my perspective on why building the right data structure matters. I’ve ...

EDR – More Than An Acronym

Cyber threat actors continue to focus much of their sights and tactics on compromising endpoint devices like workstations, laptops and mobile devices. In line with increased attacks against and compromises of endpoint devices, solutions like EDR ...

Embattled LastPass Enforcing 12-Character Passwords for All

Password manager vendor LastPass, beset by high-profile data breaches from 2022 that affected millions of users, is strengthening the security requirements for its customers, including requiring all of them to use a minimum of 12 characters for ...

USENIX Security ’23 – Changlai Du, Hexuan Yu, Yang Xiao, Y. Thomas Hou, Angelos D. Keromytis, Wenjing Lou – ‘UCBlocker: Unwanted Call Blocking Using Anonymous Authentication’

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Enhancing Web Security: NSFOCUS WAF Integration Solutions

According to an industry report, over 75% of cybersecurity attacks target the web application layer. Additionally, statistics indicate that more than two-thirds of websites lack adequate security measures. With digital transformation, ...

‘everything’ matters — why the npm package sparked controversy

The npm package 'everything' sparked some controversy slowly after its publication over the holidays this year. The post ‘everything’ matters — why the npm package sparked controversy appeared first on Security Boulevard.

23andMe: It’s YOUR Fault We Lost Your Data

Am I my brother's keeper? DNA testing firm doubles down on blaming victims and sics lawyer on them. The post 23andMe: It’s YOUR Fault We Lost Your Data appeared first on Security Boulevard.

Intellicheck announces Identity Platform advancements

Intellicheck announced advancements for digital users of the Intellicheck Identity Platform. Clients integrating the new Capture process can be up and running with no more than two simple web hooks. The new digital authentication experience does ...

Quantum Quandary: Navigating the Path to Unbreakable Encryption

The rise of quantum computing presents a profound challenge to data security. Termed ‘Q-Day,’ the point at which quantum computers could break existing encryption algorithms looms on the horizon. This quantum threat, now considered imminent ...

What is a Botnet and How to Detect if I’m Affected

In today’s interconnected digital landscape, the term “botnet” has become increasingly prevalent, sparking concerns about cybersecurity and individual online safety. This blog post aims to demystify the concept of botnets, shedding light on ...

Insights into SOC metrics, recent SOC Engineering Exercises, and more

Every month, the Pondurance team hosts a webinar to keep clients current on the state of cybersecurity. In November, the team discussed notable vulnerabilities and trends, gave a crash course on security operations center (SOC) metrics, and ...