Application Security News and Articles


Segregation of Duties in Financial Institutions

Segregation of Duties in Financial Institutions:Ensuring Accountability and SecurityFinancial institutions play a key role in our global economy, managing vast sums of capital, sensitive financial data, and critical economic transactions. These ...

The Importance of Segregation of Duties in Auditing

The Importance of Segregation of Duties in Auditing ExcellenceAuditing is an important practice for any organization, regardless of size or industry. It safeguards your business's financial integrity, ensuring that your financial reporting ...

How to Get ISO 27001:2022 Compliant?

The ISO 27001:2022 standard for information security management systems (ISMS) is widely recognized. It is made to help businesses protect sensitive data. This helps businesses to ensure their confidentiality, integrity, and availability. The ...

Cloudflare vs. Azure WAF

Cloudflare vs. Azure WAF compared: An analysis of features, advantages, and limitations of leading WAF Solutions, with a focus on what sets AppTrana apart. The post Cloudflare vs. Azure WAF appeared first on Indusface. The post Cloudflare vs. ...

How should organizations navigate the risks and opportunities of AI?

As we realize exciting new advancements in the application of generative pre-trained transformer (GPT) technology, our adversaries are finding ingenious ways to leverage these capabilities to inflict harm. There’s evidence to suggest that ...

New infosec products of the week: September 29, 2023

Here’s a look at the most interesting products from the past week, featuring releases from AlphaSOC, Baffle, Immersive Labs, OneTrust, Panzura, runZero, and SeeMetrics. Immersive Labs Workforce Exercising allows cyber leaders to identify and ...

VMware users anxious about costs and ransomware threats

VMware customers have growing concerns about the state of the virtualization software and the company behind it – ranging from rising licensing costs, ransomware vulnerabilities and a diminishing quality of support, according to VergeIO. 84% of ...

Financial crime compliance costs exceed $206 billion

The growing complexity of compliance regulations and ever-evolving criminal methodologies are a major difficulty for financial institutions, according to LexisNexis Risk Solutions. Global financial crime compliance costs for financial ...

Security Spotlight: Monitoring Users Opening Malicious Files

The ‘Security Spotlight’ series of blogs is written in accompaniment with the YouTube series of the same name, which is aimed at providing quick visibility and understanding into how you can leverage the LogRhythm platform against a variety ...

Why California’s Delete Act matters for the whole country

The California State Legislature passed Senate Bill 362, known as the Delete Act, to simplify the process for consumers to ask to remove their personal data gathered by data brokers. In this Help Net Security video, Dr. Chris Pierson, CEO of ...

Cybersecurity budgets show moderate growth

Despite the economic uncertainty and inflation, security budgets generally continued to rise but at a lower rate than prior years, according to new research from IANS and Artico Search. Security budgets increase by 6% in 2023 Respondents reported ...

US State Department Says 60,000 Emails Taken in Alleged Chinese Hack

The US State Department said that hackers took around 60,000 emails in an attack which Microsoft has blamed on China. The post US State Department Says 60,000 Emails Taken in Alleged Chinese Hack appeared first on SecurityWeek.

What You Need to Know About the libwebp Exploit

libwebp exploit timeline CVE-2023-41064; CVE-2023-4863; CVE-2023-5129 On September 7th 2023, researchers at Citizen Lab reported a zero-click exploit that was actively used by NSOs to infect iOS devices with the Pegasus malware – this was ...

Why Ordr? Why Now?

I just joined Ordr as Chief Healthcare Officer and, as is often the case in life, there’s a story, personal and professional, behind my new adventure here.  A little more than seven years ago, while I was CTO at Sutter Health, a friend from my ...

Build for Detection Engineering, and Alerting Will Improve (Part 3)

This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator. In this blog (#3 in the series), we will start to define and refine our detection engineering machinery ...

Vulnerability Assessment: A Guide

Performing a vulnerability assessment is the first step towards securing your organization. We breakdown what you need to know and where to start. The post Vulnerability Assessment: A Guide appeared first on Mend. The post Vulnerability ...

Aligning Compliance Standards with DevOps Methodologies: An Engineer’s Roadmap

DevOps and Compliance Building compliant workloads cannot be an afterthought in the rapidly evolving landscape of DevOps, where continuous integration, delivery,... Read more » The post Aligning Compliance Standards with DevOps Methodologies: An ...

Crocs enhances customer journey and safeguards revenue growth with Kasada

Bots are used to purchase and resell valuable products — sneakers, clothing, electronics, and more — along with many forms of account and checkout fraud. The post Crocs enhances customer journey and safeguards revenue growth with Kasada ...

Threat Spotlight: The Dark Web and AI

Executive Overview More than 200,000 credentials to AI language models are currently being sold on the dark web as part of stealer logs, files containing thousands of credentials derived from infostealer malware. This certainly raises the risk ...

Lawsuit Filed Against Google, Meta, H&R Block for Sharing Taxpayer Data

Meta, Google, and giant tax preparer H&R Block are being accused of conspiring to illegally use spyware from the tech giants to collect and share tax return information from hundreds of taxpayers that could be used to generate targeted online ...