Application Security News and Articles


Consumers plan to be more consistent with their security in 2024

The vast majority of consumers are concerned that cyberattacks will increase or remain consistent over the coming year (97%) and become more sophisticated (69%), outpacing the ability of cyber defenses to protect against these threats, according ...

Online stores may not be as secure as you think

Credit card skimming is on the rise for the holiday shopping season, according to Malwarebytes. Online stores are not always as secure as you might think they are, and yet you need to hand over your valuable credit card information in order to ...

NSFOCUS WAAP: A Future-Ready Solution for Web and API Security Challenges

In the digital age, Web application and API security (WAAP) has demonstrated the importance of the development of the web application and API economy, and it is becoming the new standard of the next generation of WAF. WAAP is essential in ...

Citrix Bleed Vulnerability: SafeBreach Coverage for US-CERT Alert (AA23-325A)

The Citrix Bleed vulnerability allows threat actors to bypass multifactor authentication (MFA), allowing them to get access to active user sessions. The post Citrix Bleed Vulnerability: SafeBreach Coverage for US-CERT Alert (AA23-325A) appeared ...

DEF CON 31 – Nestori Syynimaa’s ‘From Feature To Weapon Breaking Microsoft Teams And SharePoint’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Seeking SaaS: FedRAMP Launches Modernization and 10X Increase

At the end of October, the federal Office of Management and Budget (OMB) released a draft memorandum for public comment titled Modernizing the Federal Risk Authorization Management Program (FedRAMP). For the people and teams that live, breathe ...

Building Security Culture Starts with Building Relationships

Development and security teams should be friends, not adversaries. Learn how to build trust and empathy between your teams. The post Building Security Culture Starts with Building Relationships appeared first on Mend. The post Building Security ...

The Ultimate Guide to Network Segmentation Basics: What You Need to Know

Introduction to Network Segmentation Basics In the evolving landscape of modern network security, the significance of network segmentation cannot be overstated. As cyber threats grow more sophisticated, safeguarding a business’s digital ...

Game-Changer: “Solver Services” Help Fraudsters Bypass CAPTCHAs

A new paradigm is emerging with the advent of “solver services” utilizing advanced solver bots. These automated systems are reshaping the landscape of CAPTCHA dynamics, the traditional game of distinguishing between humans and bots. CAPTCHAs, ...

Measures Healthcare Providers Can Take to Mitigate Disruptions

Earlier this month, an internet outage affected public healthcare clusters in Singapore, including major hospitals and polyclinics, lasting more than seven hours from 9:20 am. Investigations identified that a distributed denial-of-service (DDoS) ...

10 Years On, Microsoft’s Bug Bounty Program Has Paid Out $60 Million

Microsoft over the past decade has doled out more than $60 million rewards to researchers who have found various security flaws in its software and is now ready to pay out some more. The IT and cloud services giant this week noted the 10-year ...

‘LitterDrifter’ Russian USB Worm Leaks from Ukraine War Zone

FSB APT USB VBS LNK DLL: WTH? Flash drive sharing malware escapes Україна. Gamaredon fingered as perps. The post ‘LitterDrifter’ Russian USB Worm Leaks from Ukraine War Zone appeared first on Security Boulevard.

Is your bot management software ready for the holiday shopping season?

Bot traffic increases up to 30x during the holiday shopping season. Here are five things to ensure your bot management software can handle to stop bad bots in their tracks. The post Is your bot management software ready for the holiday shopping ...

Researchers Discover Dangerous Exposure of Sensitive Kubernetes Secrets

Researchers at Aqua call urgent attention to the public exposure of Kubernetes configuration secrets, warning that hundreds of organizations are vulnerable to this “ticking supply chain attack bomb.” The post Researchers Discover Dangerous ...

What Is Continuous Control Monitoring – And Why You Need it For Compliance

By: Igor Volovich, VP, Compliance Strategy Organizations face mounting pressure to implement robust and effective control mechanisms to protect sensitive data and maintain regulatory adherence. The traditional, periodic, siloed approach to ...

Threat Spotlight: Data Extortion Ransomware: Key Trends in 2023

Ransomware Trends Overview As ransomware’s fundamental nature shifts from encryption to data exfiltration, organizations’ data backup and recovery practices no longer protect them from attacks. Over the course of the past few years, the ...

DEF CON 31 – Bramwell Brizendine’s, Jacob Hince’s, Austin Babcock’s, Max Kersten’s ‘Game-Changing Advances In Windows Shellcode Analysis’

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

7 Biggest Challenges for CIOs and How to Deal With Them

The role of сhief information officers (CIOs) has transformed over the years, extending beyond traditional technical responsibilities. Currently, CIOs are facing numerous issues, such as heavily distributed workforce, economic hurdles, and ...

A guide to Purdue model for ICS security

Imagine a world where power grids, water treatment plants, and manufacturing facilities operate smoothly, ensuring our daily lives run without a hitch. These critical systems are the backbone of modern society, collectively known as Industrial ...

How AI is Encouraging Targeted Phishing Attacks

While orchestrated, targeted phishing attacks are nothing new to experienced IT and cybersecurity pros, AI has added to their ferocity and sophistication. The post How AI is Encouraging Targeted Phishing Attacks appeared first on Security Boulevard.