Application Security News and Articles


Fortifying cyber defenses: A proactive approach to ransomware resilience

Ransomware has become a pervasive threat, compromising the security and functionality of vital systems across the United States. While governmental pledges and public declarations of intent to fight cybercrime are foundational, they often lack ...

Multi-cloud computing offers benefits but makes IT far more complex

Demand for public cloud-related solutions is rising as organizations seek tools to manage and optimize complex, multi-cloud environments, according to ISG. The report finds that many enterprises worldwide migrated some or all on-premises ...

CIOs shape long-term success with GenAI expertise

Today’s CIOs have evolved from managing IT infrastructure and ensuring systems’ efficiency to becoming key business strategists, according to IDC. They stand at the intersection of technology and business, leveraging innovations to ...

Automated Security Testing in DevSecOps

The sail through the DevSecOps waters brings us to the shores of Automated Security Testing. In a domain where speed is revered, and…Continue reading on Medium »

Exploring Modern Identity: Unraveling Customer Attitudes

With the digital transformation, the expectations and behavior of modern customers are changing, desiring more seamlessness and convenience when managing their identities. A robust CIAM can help you meet customer expectations while reducing ...

Takeaways from Our Roundtable at the Millennium Alliance – Dec 2023

A few days ago our team met with security leaders at an event hosted by the Millennium Alliance. Over the course of two days, we … The post Takeaways from Our Roundtable at the Millennium Alliance – Dec 2023 appeared first on Cyral. The post ...

Navigating the Trade-Offs Between Security Vendor Consolidation and Best-Of-Breed Solutions

Vendor consolidation, a strategy where organizations reduce the number of vendors they use, has become one of the key trends witnessing significant growth in recent years. According to a Gartner survey, 75% of organizations were reported to be ...

CVE-2023-50164: Another vulnerability in the widely used Apache Struts2 component

Yet another remote code execution vulnerability in Apache’s Struts2 Framework has been discovered - leaving many with strong feelings of Deja Vu. If you're a developer, it's not unreasonable to be concerned about how you may spend the final ...

How to choose an auditor for SOC 2

TrustCloud teamed up with Dan Andrea, a partner at KLR, to discuss: Preparing for a successful SOC 2 audit Evaluation criteria when choosing an auditor Factors that influence the cost of an audit  Read more of Dan’s suggestions below, or check ...

What Makes DataDome’s Multi-Layered Bot Security Responses Truly Unique

DataDome Device Check, a new invisible challenge & CAPTCHA alternative, paired with DataDome CAPTCHA, now delivers a “Better Together” multi-layered response strategy for customers. The post What Makes DataDome’s Multi-Layered Bot ...

MFA Is Broken

MFA (Multi-Factor Authentication), if implemented correctly, is a useful security tool. But this blog from Anthony Alves covers the ways in which MFA is broken. The post MFA Is Broken first appeared on Banyan Security. The post MFA Is Broken ...

JetBrains TeamCity Vulnerability Exploit: SafeBreach Coverage for US-CERT Alert (AA23-347A)

APT29 has targeted servers hosting the JetBrains TeamCity software since September 2023 in an attack similar to the SolarWinds breach. The post JetBrains TeamCity Vulnerability Exploit: SafeBreach Coverage for US-CERT Alert (AA23-347A) appeared ...

Decrypting the Ledger connect-kit compromise: A deep dive into the crypto drainer attack

Earlier today, Ledger, a maker of hardware wallets for storing crypto, announced that they had identified malicious software embedded in one of their open source packages called @ledgerhq/connect-kit. This package is widely used as a connector ...

DEF CON 31 War Stories – Ben Sadeghipour’s, Corben Leo’s ‘# A Series Of Unfortunate Events’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

NIST Cybersecurity Framework – What it is and How it Compares to MITRE ATT&CK

The final publication date of the most significant update yet to NIST’s Cybersecurity Framework (NIST CSF 2.0) is on the horizon. Whether you are only hearing about the NIST CSF in light of the upcoming changes or you’re seeking more clarity ...

Esteemed Singapore Law Firm Neutralizes File-Borne Threats with Votiro

Established in the heart of Singapore, this Law Firm is among the country’s most respected legal institutions. With a rich history, it caters to clients across both civil and criminal spectrums, providing expert advice, representation, and ...

Unified Endpoint Management (UEM): What is it and What’s New?

What is Unified Endpoint Management? The digital landscape is evolving at an unprecedented pace, and with it, the significance of Unified Endpoint Management (UEM) has never been more paramount. What is Unified Endpoint Management? UEM offers a ...

Randall Munroe’s XKCD ‘DateTime’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘DateTime’ appeared first on Security Boulevard.

Below the Surface Winter 2023

East vs. West – The Chip Wars are in Full Effect Welcome to the Winter 2023 edition of the Below the Surface Threat Report. Every nation state has long realized that whichever nations win the race to quantum computing and AI superiority will ...

Understanding and protecting against DNS threats with Avast

Welcome to the digital age, where the internet is as essential as the air we breathe. But did you know that every time you visit a website, there's a hidden hero working behind the scenes? It's called the Domain Name System (DNS), akin to a ...