Application Security News and Articles


USENIX Security ’23 – Bingyu Shen, Tianyi Shan, Yuanyuan Zhou – ‘Improving Logging to Reduce Permission Over-Granting Mistakes’

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Comprehensive Guide to Fraud Detection, Management, & Analysis

Fraud is everywhere, and it’s affecting you whether you realize it or not. From fraudulent credit card charges to identity theft, fraud can cause serious financial and emotional damage. That’s why fraud detection, management, and analysis are ...

Q4 2023 Security Use Cases: Insights From Success Services

As part of Success Services, this past quarter LogRhythm consultants have been hard at work helping customers improve their defenses against cyberthreats. This quarter, the team observed a shift in attack vectors back into Credential evasion via ...

The Complete Guide to Smishing (SMS Phishing)

It’s unfortunately become an all-to-common scenario: you’re waiting for a package to be delivered—but then you receive an SMS text message that seems to be from the carrier, demanding payment before delivery can be completed. If you follow ...

Abnormal Security Shares Examples of Attacks Using Generative AI

Abnormal Security published examples of how cybercriminals are beginning to leverage generative AI to launch cyberattacks. The post Abnormal Security Shares Examples of Attacks Using Generative AI appeared first on Security Boulevard.

Addressing the Rising Threat of API Leaks

In the realm of cybersecurity, the metaphor of "Leaky Buckets" has become an increasingly prevalent concern, particularly in the context of API security. This term encapsulates the hidden vulnerabilities and exposures in API infrastructures that ...

Randall Munroe’s XKCD ‘Iceland’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Iceland’ appeared first on Security Boulevard.

The Clock Is Ticking on NY-DFS MFA Requirements

On March 1, 2017, the Department of Financial Services enacted a regulation establishing cybersecurity requirements for financial services companies, 23 NYCRR Part 500 (referred to below as “Part 500” or “the Cybersecurity Regulation”). ...

The InfoSec Guide to HIPAA Compliance

The average cost of a data breach for a business in the United States was $9.05 million, and the average worldwide was $4.24 million, according to IBM’s 2021 Cost of a Data Breach Report. Even more alarmingly, the report also discovered that ...

The Ultimate Guide to Cyber Resilience

The average cost of a data breach for a business in the United States was $9.05 million, and the average worldwide was $4.24 million, according to IBM’s 2021 Cost of a Data Breach Report. Even more alarmingly, the report also discovered that ...

The Complete InfoSec Guide for Threat Intelligence

The average cost of a data breach for a business in the United States was $9.05 million, and the average worldwide was $4.24 million, according to IBM’s 2021 Cost of a Data Breach Report. Even more alarmingly, the report also discovered that ...

Flaw in Black Basta Ransomware Exploited to Create Decryptor

Researchers at cybersecurity firm Security Research Labs exploited a flaw found in the algorithm of a ransomware variant used by the high-profile threat group Black Basta to develop a decryptor that can help some victims recover their encrypted ...

What is the Digital Operations and Resilience Act (DORA)?

The average cost of a data breach for a business in the United States was $9.05 million, and the average worldwide was $4.24 million, according to IBM’s 2021 Cost of a Data Breach Report. Even more alarmingly, the report also discovered that ...

Facebook’s New Privacy Nightmare: ‘Link History’

How stupid does he think we are? You’ll want to turn off this new app setting. The post Facebook’s New Privacy Nightmare: ‘Link History’ appeared first on Security Boulevard.

USENIX Security ’23 – ‘Auditing Frameworks Need Resource Isolation: A Systematic Study On The Super Producer Threat To System Auditing And Its Mitigation’

Authors/Presenters: Peng Jiang, Ruizhe Huang, Ding Li, Yao Guo, Xiangqun Chen, Jianhai Luan, Yuxin Ren, Xinwei Hu Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong ...

CyberTalk Series: MSP Challenges: Managed Security Services with Ken Patterson

Our industry is way more complex than meets the eye. MSPs and MSSPs are not just managing their clients’ cybersecurity programs, they are also accountable to their auditors, The post CyberTalk Series: MSP Challenges: Managed Security Services ...

Cybersecurity Post-Incident Cleanup – What You’re Probably Not Doing

In the aftermath of a cyber incident, organizations often experience a sense of relief as they diligently implement remediation efforts. However, the deceptive nature of cyber threats can leave behind subtle traces that elude traditional ...

Mend’s Handy Guide to Using EPSS Scores

Find out what EPSS scores are and how to use them for better remediation prioritization. The post Mend’s Handy Guide to Using EPSS Scores appeared first on Mend. The post Mend’s Handy Guide to Using EPSS Scores appeared first on Security ...

HTTP/2 Rapid Reset Mitigation With Imperva WAF

In the modern application landscape, where businesses are constantly under the threat of cyber attacks, one of the most recent to emerge is HTTP/2 Rapid Reset (CVE-2023-44487), a type of Distributed Denial-of-Service (DDoS) attack. This attack is ...

Is your ID badge giving away too much about you?

It seemed like an innocuous thing to do. Before flying home to Australia from Japan, Tony Abbott posted a photo of his boarding pass on Instagram with a message thanking the Qantas Airlines crew. But the well-intentioned gesture triggered a minor ...