Application Security News and Articles


Shifting left and right, innovating product security

In this Help Net Security interview, Slava Bronfman, CEO at Cybellum, discusses approaches for achieving product security throughout a device’s entire lifecycle, fostering collaboration across business units and product lines, ensuring ...

Cybersecurity pros battle discontent amid skills shortage

The cybersecurity skills crisis continues in a multi-year freefall that has impacted 71% of organizations and left two-thirds of cybersecurity professionals stating that the job has become more difficult over the past two years—while 60% of ...

Baseline standards for BYOD access requirements

49% of enterprises across Europe currently have no formal Bring-Your-Own-Device (BYOD) policy in place, meaning they have no visibility into or control over if and how employees are connecting personal devices to corporate resources, according to ...

What is payment fraud?

Fraudulent activity comes in various forms, many of which are commonplace in today’s digital landscape. One of the most prevalent acts of online fraud includes payment fraud and its subtypes. Payment fraud occurs when a malicious party obtains ...

Axiad Wins a PeerSpot Rising Star Award – The Latest Recognition in a Milestone Year

Benjamin Franklin once said: “Never confuse motion with action.” In the cybersecurity market, which has... The post Axiad Wins a PeerSpot Rising Star Award – The Latest Recognition in a Milestone Year appeared first on Axiad. The post Axiad ...

W3LL Targets Microsoft 365 Accounts with Sophisticated Phishing Kit

A relatively unknown threat group that six years ago started with a custom tool used for bulk email spam is now running a massive operation selling a custom phishing kit that target corporate Microsoft 365 business email accounts. According to ...

Crash Dump Error: How a Chinese Espionage Group Exploited Microsoft’s Errors

Microsoft reveals how a crash dump from 2021 inadvertently exposed a key that Chinese cyberspies later leveraged to hack US government emails. The post Crash Dump Error: How a Chinese Espionage Group Exploited Microsoft’s Errors appeared ...

How to navigate DevOps principles: Analyzing Shift Left and Secure Right

In the ever-evolving world of DevOps, two concepts, Shift Left and Secure Right, surfaced as catch-phrases that signal a shared desire to develop more secure and reliable software. The post How to navigate DevOps principles: Analyzing Shift Left ...

How DSPM Reduces Cloud Costs | Eureka Security

A DSPM's core aim is fortifying data security, learn how it can also reduce cloud costs by promoting efficient resource usage, preventing security incidents, and streamlining operational practices. | Eureka Security The post How DSPM Reduces ...

BSides Cheltenham 2023 – BSides Cheltenham Organizers – Closing Remarks

Many thanks to BSides Cheltenham for publishing their presenter’s outstanding BSides Cheltenham 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Cheltenham 2023 – BSides Cheltenham Organizers ...

Demystifying Smishing vs Phishing Attacks for a Safer Online Experience

Staying safe online is more important than ever. Cybercriminals are becoming more sophisticated in their methods, making it key for internet users to be well-informed about threats. One common type of attack that can catch anyone off guard is ...

SEC Risk Updates: GRC Newsflash

Today’s edition of GRC Newsflash features our Compliance Specialist Frank Kyazze, and covers Risk Updates from the SEC announced on July 26, 2023. Listen to our update here, or read a transcript below:  What You Need to Know About the ...

Cash-Strapped IronNet Faces Bankruptcy Options

It appears to be the end of the road for IronNet, the once-promising network security play founded by former NSA director General Keith Alexander. The post Cash-Strapped IronNet Faces Bankruptcy Options appeared first on SecurityWeek.

Threat Intelligence Analytics: Making the Most of Your CTI Program

The threat landscape has never been more challenging for CISOs and security teams than in 2023. Our research has found ransomware attacks have increased by more than 100% since 2022, hundreds of thousands of corporate credentials are being ...

Dark Web Analytics: Detecting Threats Across the Dark Web

The nebulous part of the internet: the dark web, which traditional search engines don’t index, serves as a hub for cybercriminal activity, ranging from illicit trade in stolen data to planning sophisticated cyberattacks. Dark web analytics can ...

Contextual Awareness in Network Detections

In his new blog, Mal Fitzgerald talks about how Netography applies contextual awareness to address custom network challenges and security concerns. The post Contextual Awareness in Network Detections appeared first on Netography. The post ...

Randall Munroe’s XKCD ‘*Abstract Pickup’

via the comic artistry and dry wit of Randall Munroe, maker of XKCD! Permalink The post Randall Munroe’s XKCD ‘*Abstract Pickup’ appeared first on Security Boulevard.

Investors Betting Big on Upwind for CNAPP Tech

Upwind raises a total of $80 million in just 10 months as investors pour cash into startups in the cloud and data security categories. The post Investors Betting Big on Upwind for CNAPP Tech appeared first on SecurityWeek.

SaaS Super Admins Targeted in Social Engineering Campaign

Discover how threat actors hijack highly privileged roles in Okta tenants, and learn mitigation steps against social engineering campaigns. The post SaaS Super Admins Targeted in Social Engineering Campaign appeared first on AppOmni. The post ...

Proofpoint Previews Generative AI Tools to Thwart Social Engineering

Proofpoint is leveraging a BERT LLM originally created by Google to thwart social engineering attacks using generative AI. The post Proofpoint Previews Generative AI Tools to Thwart Social Engineering appeared first on Security Boulevard.