Application Security News and Articles


The Top 10, Top 10 Predictions for 2024

Don’t settle for just ten top cybersecurity predictions, when you can take a quick stroll through ten of the top lists. Catch Peter Silva’s annual post, here on the Ericom blog. The post The Top 10, Top 10 Predictions for 2024 appeared first ...

Must Ask Questions Before Choosing a Penetration Testing Vendor

Choosing the right penetration testing vendor is crucial for identifying vulnerabilities and reinforcing your cybersecurity. But before you commit, it’s crucial to have a set of questions ready to know... The post Must Ask Questions Before ...

Lazarus Cryptocurrency Hacks Estimated To Be $3 Billion

Threat actors from North Korea have been increasingly targeting the cryptocurrency sector since 2017 as a source of generating revenue.  Reports have claimed that the country’s ruling elite and computer science professionals have access to new ...

Many popular websites still cling to password creation policies from 1985

A significant number of popular websites still allow users to choose weak or even single-character passwords, researchers at Georgia Institute of Technology have found. Websites’ lax creation policies for passwords The researchers used an ...

eIDAS: EU’s internet reforms will undermine a decade of advances in online security

The European Union’s attempt to reform its electronic identification and trust services – a package of laws better known as eIDAS 2.0 – contains legislation that poses a grave threat to online privacy and security. An article buried deep in ...

Balancing AI advantages and risks in cybersecurity strategies

In this Help Net Security interview, Matt Holland, CEO of Field Effect, discusses achieving a balance for businesses between the advantages of using AI in their cybersecurity strategies and the risks posed by AI-enhanced cyber threats. Holland ...

Nemesis: Open-source offensive data enrichment and analytic pipeline

Nemesis is a centralized data processing platform that ingests, enriches, and performs analytics on offensive security assessment data (i.e., data collected during penetration tests and red team engagements).​​ Nemesis was created by Lee ...

WhatsApp, Slack, Teams, and other messaging platforms face constant security risks

42% of businesses report employees with BYOD devices in business settings that use tools like WhatsApp have led to new security incidents, according to SafeGuard Cyber. Messaging platforms like WhatsApp, Telegram, Slack, and Teams face constant ...

A Recap of Our Pragmatic Cyber Risk Management Webinar

Last week, the Axio services team hosted a webinar roundtable on pragmatic cyber risk management. The presentation focused on what security professionals can do today to be prepared for the Read More The post A Recap of Our Pragmatic Cyber Risk ...

KubeCon 2023: Not Your Father’s Tenable

This is not your father's Tenable! Alan Shimel talks with John Tonello from Tenable about the company's past, present and future. The post KubeCon 2023: Not Your Father’s Tenable appeared first on Security Boulevard.

Understanding Risk Assessment Standards for Deploying Safe & Secure AI Systems

A blog post by Matthew Venne, Sr. Solutions Director, stackArmor It’s no secret that Cloud 2.0 will be driven by Artificial Intelligence (AI). The rate at which the world is adopting AI-based solutions is nothing short of staggering; what was ...

Replace broken AppSec tools with an Application Security technology that actually works: Runtime Security

Tell us straight, Santa: Where did these old-school Application Security (AppSec) tools come from? Did you get the Security Specialist Elves to cobble them together from toadstool scrapings and cobwebs?  The post Replace broken AppSec tools with ...

DEF CON 31 – Austin Emmitt’s ‘Apple’s Predicament – NSPredicate Exploitation On macOS And iOS’

DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. Permalink The post DEF CON 31 – Austin Emmitt’s ...

The Future of Infrastructure as Code (IaC)

By treating infrastructure setup and configuration as software code, Infrastructure as Code has brought unprecedented efficiency and consistency to deployment processes. Markets and Markets ... The post The Future of Infrastructure as Code (IaC) ...

The top cyber security news stories of 2023

The post The top cyber security news stories of 2023 appeared first on Click Armor. The post The top cyber security news stories of 2023 appeared first on Security Boulevard.

Randall Munroe’s XKCD ‘The Wrong Stuff’

The post Randall Munroe’s XKCD ‘The Wrong Stuff’ appeared first on Security Boulevard.

Kubescape: the 1st open-source project to support VEX Generation

Guest post originally published on Kubescape’s blog by Oshrat Nir, Developer Advocate at ARMO and a Kubescape contributer. Introduction: Vulnerability Exploitability eXchange (VEX) is a The post Kubescape: the 1st open-source project to ...

Obsidian Security Recognized as Strong Performer by Independent Research Firm

Today, our team at Obsidian Security has been recognized as a Strong Performer by The Forrester Wave™: SaaS Security Posture Management, Q4 2023. We believe such acknowledgment is reflective of the work that has been done to build a team and a ...

FBI Details How Companies Can Delay SEC Cyber Disclosures

The FBI is outlining how its agents will handle requests from publicly traded companies that want to delay having to disclose a cybersecurity incident under the new controversial Securities and Exchange Commission (SEC) rules that take effect ...

Debunking Popular Myths About Vulnerability Management

The post Debunking Popular Myths About Vulnerability Management appeared first on Digital Defense. The post Debunking Popular Myths About Vulnerability Management appeared first on Security Boulevard.