Application Security News and Articles


DEF CON 31 – Ceri Coburn’s ‘A Broken Marriage Abusing Mixed Vendor Kerberos Stacks’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Utilizing CRQ to empower a shared cybersecurity accountability approach | Kovrr Blog

Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post Utilizing CRQ to empower a shared cybersecurity accountability approach | Kovrr Blog appeared first on Security Boulevard.

Developing Industry Loss Curves for Cyber Insurance Using the Crimzon™ Framework | Kovrr Blog

Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post Developing Industry Loss Curves for Cyber Insurance Using the Crimzon™ Framework | Kovrr Blog appeared first on Security Boulevard.

PCI Audit – Checklist & Requirements

What is a PCI Audit? The Payment Card Industry Data Security Standard, known widely as PCI DSS, is a set of security standards intended to ensure that ALL businesses who accept, process, store, or transmit credit card data do so in a safe manner. ...

The Top 24 Security Predictions for 2024 (Part 1)

Where next for cyber in 2024? Here’s your annual roundup of cybersecurity forecasts, top cyber trends and cybersecurity industry prediction reports as we head into calendar year 2024. The post The Top 24 Security Predictions for 2024 (Part 1) ...

Week in review: Apache Struts vulnerability exploit attempt, EOL Sophos firewalls get hotfix

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: SCS 9001 2.0 reveals enhanced controls for global supply chains In this Help Net Security interview, Mike Regan, VP of Business Performance at ...

The Ultimate Guide to Network Segmentation Compliance: Ensuring Cybersecurity Standards

Network Security Policy Compliance Having a well-defined network security policy is crucial for organizations to maintain compliance with cybersecurity standards. A network security policy outlines the rules and guidelines within a network. These ...

DEF CON 31 – Ting-Yu [NiNi] Chen’s ‘Review On The Less Traveled Road – 9 Yrs of Overlooked MikroTik PreAuth RCE’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

The Murky Waters of API Visibility and What That Means for Your Company

Caves and Muddy Waters The Tham Luang cave rescue, which took place in 2018, was a high-stakes operation in northern Thailand to save a youth soccer team and their coach who were trapped inside a flooded cave. The monsoon rains … The Murky ...

Leveraging OpenAI for Static Application Security Testing

In an age where digital interconnectedness prevails, ensuring the security of applications has become paramount. Static Application…Continue reading on Medium »

DEF CON 31 – Joe Sullivan’s ‘A Different Uber Post Mortem’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Christmas scams: Attacks to be aware of this holiday season

The post Christmas scams: Attacks to be aware of this holiday season appeared first on Click Armor. The post Christmas scams: Attacks to be aware of this holiday season appeared first on Security Boulevard.

NKAbuse Threat Uses NKN Blockchain Network for DDoS Attacks

A new multiplatform threat that uses the peer-to-peer (P2P) NKN network connectivity protocol as a communication channel for launching a range of threats, from distributed denial-of-service (DDoS) attacks to a remote access trojan (RAT). The ...

Okta’s Cinderella Story

Okta can still be a Cinderella story. If they can get their own security right, history will look back on this as the low point before a happy ending. The post Okta’s Cinderella Story appeared first on Security Boulevard.

Radical Compliance – ‘404 Controls’

via Matt Kelly’s superbly hilarious Radical Compliance Permalink The post Radical Compliance – ‘404 Controls’ appeared first on Security Boulevard.

Happy New Year: Google Cookie Block Starts Soon, but Fear Remains

2024 almost here: Rollout begins Jan 4, but few trust Google’s motives. The post Happy New Year: Google Cookie Block Starts Soon, but Fear Remains appeared first on Security Boulevard.

What’s new – Escape Product Updates

Discover our latest product updates: support for Insomnia collections, WP-JSON schema, and additional business logic security tests. Plus you can now fully benefit from Escape's public API. The post What’s new – Escape Product Updates ...

AppOmni Receives Analyst Recognition for Market-Leading SSPM Solution

Read why Frost & Sullivan and Forrester recognize AppOmni as 2023 Company of the Year and Strong Performer in the Forrester Wave: SSPM, Q4 2023. The post AppOmni Receives Analyst Recognition for Market-Leading SSPM Solution appeared first on ...

2023 Regulatory Roundup: All the Major Compliance Changes that Happened

Life comes at you fast, and that’s especially true for CISOs grappling with the many compliance risks in cybersecurity. From greater regulatory pressures and heightened privacy standards to increased personal liability, topped off with new ...