Application Security News and Articles


What is Data Protection By Design?

Organisations are legally and ethically obligated to protect the data of their users. Negligent handling of user data opens up the organisation to fines or lawsuits from its users. In Europe and the UK, users own their data, giving them the right ...

Key Take Aways from NIST Releases 800-171 Revision 3

On November 9th 2023 National Institute of Standards and Technology, NIST, released special publication 800-171 Revision 3 Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations as a Final Public Draft. Both the ...

SolarWinds And A Controversial New Era For CISOs

The notorious SolarWinds cyber breach of 2020 is making headlines once again, and CISOs everywhere are talking about how the latest legal filings may have a lasting impact on how they do their jobs. SEC Charges SolarWinds CISO  As discussed in ...

ASPM vs. CSPM: Understanding the Key Differences

Organizations are looking for effective ways to protect both their applications and cloud-based assets. With malicious actors becoming more advanced in their methods and the number of assets targeted growing every day, cybersecurity is of massive ...

DEF CON 31 – winn0na, and Panel: Hacker Court Interactive Scenario

Many thanks to DEF CON 31 for publishing their terrific DefCon Conference 31 presenters content. Originating from the conference events at Caesars Forum, Flamingo, Harrah’s and Linq in Las Vegas, Nevada; via the organizations YouTube channel. ...

Industry Alert: How Fake Reviews and Bogus Rates Are Impacting Travel

Today, where wanderlust meets the internet, planning the perfect getaway often involves navigating a labyrinth of online reviews and hotel rates. But as the travel and hospitality industry continues to flourish in the virtual realm, so does the ...

Complying with Confidence: Navigating Cybersecurity Regulation and Legislation

Experts explain how expanded cybersecurity regulation changes the CISO’s role, cyber liability insurance, and pathways to cyber resilience. The post Complying with Confidence: Navigating Cybersecurity Regulation and Legislation appeared first ...

Cisco’s Cybersecurity Shopping Spree (Part 2)

What the Alaska Purchase and Seward's Folly can teach us about the strategy and upside for Cisco's acquisition of Splunk. The post Cisco’s Cybersecurity Shopping Spree (Part 2) appeared first on Security Boulevard.

What is a Network Management Station (NMS) ?

The Bedrock of the Network Coordination Hub (NCH) Delving into the substantial domain of digital networks, the Network Coordination Hub (NCH) is unveiled as a critical component ensuring fluid network operations. Let us unravel this concept - an ...

FBI Shuts Down IPStorm Botnet as Its Operator Pleads Guilty

The notorious IPStorm botnet proxy network, which first spun up in 2019 targeting Windows systems and two years later expanded to devices running other operating systems, is shut down and its creator in jail after pleading guilty to related ...

November 2023 Release Notes

November 2023 has been a busy month for the Banyan Security product and development teams, and we're excited to share highlights of our recent product updates. The post November 2023 Release Notes first appeared on Banyan Security. The post ...

FBI’s Warrantless Spying on US Must Continue, Says FBI

Privacy, schmivacy: FBI head Christopher Wray (pictured) doesn’t see what all the fuss is about. Just renew FISA section 702 already! The post FBI’s Warrantless Spying on US Must Continue, Says FBI appeared first on Security Boulevard.

Microsoft’s November 2023 Patch Tuesday Addresses 3 Zero-Days, 104 Vulnerabilities

Microsoft just released its November Patch Tuesday security updates. In this latest installment, a total of 58 vulnerabilities have been addressed. Among these, the update tackles five zero-day vulnerabilities, with three actively exploited in ...

How Much Does PCI Compliance Cost? 9 Factors to Consider

PCI compliance can represent a significant cost for small businesses and startups. However, it's important to keep in mind that the cost of compliance is always lower than the cost of non-compliance. No business can afford the stiff financial ...

Randall Munroe’s XKCD ‘Date Line’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD! Permalink The post Randall Munroe’s XKCD ‘Date Line’ appeared first on Security Boulevard.

Google Adds Passkey Support to New Titan Security Key 

Google launches new Titan security key with passkey support, allowing users to store up to 250 unique passkeys. The post Google Adds Passkey Support to New Titan Security Key  appeared first on SecurityWeek.

The ABCs of API Security: A New (Free!) Learning Center

APIs have been with us since before they were called APIs. Application programming interfaces as an interface between software or between users and software have been around since the 1940’s, around 20 years before such interfaces were called ...

Find True Positives, vs False Positives, with Runtime Security | Contrast Security

Alert: Somebody’s running reconnaissance on your network. Alarm: You’ve got a malware infection.  The post Find True Positives, vs False Positives, with Runtime Security | Contrast Security appeared first on Security Boulevard.

MOVEit Hack: What went wrong, and how to course correct

What the MOVEit Breach Tells Us About the Challenges of Patching On May 31, 2023, little-known software developer Progress Software published details of a critical vulnerability in MOVEit Transfer, a popular managed file transfer service. It soon ...

Biden Campaign Looking for CISO

The Biden for President campaign is looking for a cybersecurity chief to “define the organization's risk appetite” and manage its cybersecurity and IT initiatives. The post Biden Campaign Looking for CISO appeared first on SecurityWeek.