Application Security News and Articles


Securing Against OAuth Exploitation: A Step-By-Step Guide

Recent findings from Microsoft Threat Intelligence reveal a concerning trend: threat actors exploiting vulnerabilities in Microsoft 365 and Azure environments to execute attacks, with a focus on OAuth application abuse. In this blog post, we ...

Are you sure that online store is real? You might be surprised

The surge in online shopping has unfortunately paved the way for numerous internet frauds. Cybercriminals are craftily establishing phony online boutiques, offering an array of products from trendy apparel to high-tech gadgets, and occasionally, ...

Explore PCI DSS 4.0: The future of cardholder data security

For those in charge of industry standards, ensuring rules are up to date and fit for purpose is a constant battle against time. And when it comes to addressing the risk of payment card data theft, the stakes couldn’t be higher. That’s why the ...

TrustCloud Product Updates: 2023 Greatest Hits

TrustCloud’s “Greatest Hits” of 2023 As we bid farewell to 2023, let’s take a stroll down memory lane and groove through the top hits of TrustCloud’s product releases. We’re breaking down your favorite chart-toppers, from the smooth ...

File Integrity Monitoring for PCI Compliance

The PCI-DSS (Payment Card Industry Data Security Standard) is a set of industry-recommended requirements for business organizations that store, process, or transmit payment card details that aim to protect payment card data from theft, misuse, ...

Randall Munroe’s XKCD ‘Puzzles’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Puzzles’ appeared first on Security Boulevard.

CMMC Enclaves: What they are. How they help compliance.

As CMMC Final Rule approaches, one of the most common concerns defense contractors have is the cost of achieving compliance. CMMC will step up enforcement of the 110 NIST 800-171 controls, making compliance a prerequisite for continued work with ...

That time I broke into an API and became a billionaire

Read an intriguing real world story about how tainted data and API abuse can lead to the perfect digital bank heist. The post That time I broke into an API and became a billionaire appeared first on Dana Epp's Blog. The post That time I broke ...

Under the hood of CVE patching

Addressing Common Vulnerabilities and Exposures, known as CVE patching, is a practice of applying updates to software (patching) The post Under the hood of CVE patching appeared first on ARMO. The post Under the hood of CVE patching appeared ...

Prioritizing Threat Actors: 3 Steps to Uncovering and Concentrating on Your Most Significant Risks

Learn how to sift through the noise and focus on the threats likely to significantly impact your organization. Contents The Growing Challenge of Accurate Prioritization Gather Information on Persons of Interest (POI) Conduct Threat Assessments ...

Law enforcement seizes ALPHV/Blackcat sites, offers decryptor to victims

The US Justice Department announced today a disruption campaign against the Blackcat/ALPHV ransomware group and let victims know that there is a decryptor they can use. FBI develops ALPHV/Blackcat decryptor Over the past 18 months, ALPHV/Blackcat ...

DEF CON 31 – Mar Williams’ ‘Making The DEF CON 31 Badge’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

10 Cybersecurity Trends That Emerged in 2023

Our digital world never stands still. How we do business and interact with each other is evolving at a breakneck pace. We saw during the pandemic that digital transformation of all kinds can happen faster than we ever thought possible. It’s a ...

Mr. Cooper Hackers Stole ~15 Million Users’ Data

Another day, another huge leak: In October, they called it an “outage;” last month, it became a “cybersecurity incident;” now it’s a full-on PII leak. The post Mr. Cooper Hackers Stole ~15 Million Users’ Data appeared first on ...

2024 Cybersecurity Outlook

As we step into 2024, the cybersecurity arena continues to morph, posing persistent challenges amid a backdrop of high-profile breaches and relentless attacks. In this dynamic landscape, staying ahead demands a heightened security posture to ...

Wiz and Apiiro partner to provide context-driven security from code to cloud

Apiiro, a leading application security posture management (ASPM) solution, today announced its partnership with Wiz, the leading cloud security company and Cloud Native Application Protection Platform (CNAPP) provider. By joining Wiz Integrations ...

Beyond DLP: Embracing a Multi-Layered Strategy for Personal Data Security

DLP plays an important role, but it's not the only necessary component in a robust data protection strategy. The post Beyond DLP: Embracing a Multi-Layered Strategy for Personal Data Security appeared first on Security Boulevard.

Phishing prevention with AI tools for zero-hour threats

New, undetectable attacks called zero-hour threats are the current danger for cybercriminals. Traditional cybersecurity solutions cannot detect these attacks, which pose a significant risk. Over the past 30 days, the Menlo Labs research team has ...

EclecticIQ Retrospective: A Look at the Themes & Events That Shaped the 2023 Cyber Landscape

As the year draws to a close, EclecticIQ’s Intelligence & Research Team looked back on the 2023 cyber landscape: from the evolving tactics of Chinese state-sponsored cyber operations, the increasing integration of AI tools by threat actors, ...

Fortinet enhances its OT security solutions and services

Fortinet announced the latest release of new, integrated operational technology (OT) security solutions and services. These additions further distance Fortinet’s industry-leading OT Security Platform from the rest of the market. “We ...