Application Security News and Articles


Gen AI’s thoughts on the Future of DevSecOps; As it is

Predicting the future is always a tricky business, but here are some educated guesses about where DevSecOps might be in the next five…Continue reading on Medium »

What should be in your first year of security awareness plan?

The post What should be in your first year of security awareness plan? appeared first on Click Armor. The post What should be in your first year of security awareness plan? appeared first on Security Boulevard.

Google Includes ARC in 2024 Email Sender Guidelines

Google recommends ARC is their 2024 sender guidelines. Authenticated Received Chain preserves email authentication data during forwarding. The post Google Includes ARC in 2024 Email Sender Guidelines appeared first on Security Boulevard.

Welltok Data Breach: 8.5M US Patients’ Information Exposed

In a recent cybersecurity incident, Welltok, a leading healthcare Software as a Service (SaaS) provider, reported unauthorized access to its MOVEit Transfer server, affecting the personal information of approximately 8.5 million patients in the ...

December 2023 Patch Tuesday forecast: ‘Tis the season for vigilance

The final Patch Tuesday of the year is almost upon us! This is the time of year when we want to relax and enjoy the holidays, but we need to be extra vigilant to detect and respond to suspicious activity. Many in the retail industry have placed ...

New infosec products of the week: December 8, 2023

Here’s a look at the most interesting products from the past week, featuring releases from Atsign, Daon, Global Integrity, Living Security, Panther Labs, Searchlight Cyber, and Varonis. Varonis enhances DSPM capabilities with Azure and AWS ...

Aim for a modern data security approach

Risk, compliance, governance, and security professionals are finally realizing the importance of subjecting sensitive workloads to robust data governance and protection the moment the data begins traversing the data pipeline. Many organizations ...

Alert fatigue puts pressure on security and development teams

Security practitioners are under a tremendous amount of pressure to secure today’s applications, according to Cycode. The research found that AppSec chaos reigns, with 78% of CISOs responding that today’s AppSec attack surfaces are ...

AI literacy gap extends beyond technical skills

Even as organizations accelerate AI adoption, the majority don’t understand the AI skills their employees possess, if any, or have an upskilling strategy to develop them, according to Pluralsight. “AI is transforming the way that business is ...

Love for sports could lead to poor password practices

33% of Americans have used a sports-related term in a password, according to Bitwarden. Those who have are twice as likely to have used one inspired by a professional sports team (46%) versus a college sports team (22%). 49% of Americans aged ...

Preventing PII Leakage through Text Generation AI Systems

Do an online search for ways to bypass text generation AI security filters, and you will find page after page of real examples and recommendations on how one can trick them into giving you information that was supposed to be blocked. This remains ...

Eclypsium Helps Florida Law Enforcement Agencies Achieve CJIS Compliance

Recent Criminal Justice Information Services (CJIS) regulations have introduced stringent new rules that define how law enforcement agencies must protect criminal justice information (CJI). These changes require agencies to manage risk, ...

How Data Ingestion Works in SOAR

SOAR tools work as consolidation platforms for security alerts and incident response. Endpoint security tools, network security tools, email systems, and other tools collect logs, run detection rules and generate alerts. SOAR then ingests those ...

The Top 5 trends every DevOps leader needs to know for 2024

As a leading provider of products and solutions to help secure software supply chains, we recently hosted our webinar "2024 Predictions: Top 5 Trends Every DevOps Manager Needs to Know," featuring Tyler Warden, Senior Vice President of ...

The Top 5 trends every CISO needs to know for 2024

From the security challenges derived from the rise of artificial intelligence (AI) to the increasing legal liabilities placed on Chief Information Security Officers (CISOs), 2023 has been a busy year for the CISO community – and 2024 shows no ...

Merry and Cyber Resilient: Are Holiday Bots Actually Helping Your Business?

By harnessing the transformative power of today’s cyber threats, businesses can leverage adversity to fortify key areas.  It’s the holidays, so let’s bypass the standard discourse on bot attacks against businesses and look for the silver ...

Navigating Public Company Cybersecurity Disclosures

Transparency in the disclosure of cybersecurity incidents for public companies is no longer good practice – it’s now a regulatory necessity. The imminent requirement for public companies to disclose current material cybersecurity incidents is ...

DEF CON 31 – Dan Petro’s, David Vargas’ ‘Badge Of Shame Breaking Into Secure Facilities With OSDP’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Using LLMs to Automate and Streamline Cyber Threat Analysis

TechSpective Podcast Episode 122   There are a number of steps involved in cyber threat analysis to review event information and determine which events are benign or innocuous and which are malicious–or at least deserve greater scrutiny. For ...

News alert: Reflectiz adds AI-powered capabilities to its Smart Alerting web threat management system

Tel Aviv, Israel, Dec. 7, 2023 — Reflectiz, a cybersecurity company specializing in continuous web threat management, proudly introduces a new AI-powered capability enhancing its Smart Alerting system. The new AI-powered insights enhances the ...