Application Security News and Articles


Avoidable digital certificate issues fuel data breaches

Among organizations that have suffered data breaches 58% were caused by issues related to digital certificates, according to a report by AppViewX and Forrester Consulting. As a result of service outages, 57% said their organizations have incurred ...

From unsuspecting click to data compromise

Phishing is a pervasive and ever-evolving cyber threat that has become a primary concern for individuals, organizations, and cybersecurity experts worldwide. This deceptive practice involves cybercriminals using various tactics to trick ...

United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity Issue

United Airlines flights were halted nationwide on Sept. 5, because of an “equipment outage,” according to the FAA. The post United Airlines Says the Outage That Held Up Departing Flights Was Not a Cybersecurity Issue appeared first on ...

CIS Benchmarks Communities: Where configurations meet consensus

Have you ever wondered how technology hardening guidelines are developed? Some are determined by a particular vendor or driven by a bottom-line perspective. That’s not the case with the CIS Benchmarks. They’re the only consensus-developed ...

Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach

In November 2022, the password manager service LastPass disclosed a breach in which hackers stole password vaults containing both encrypted and plaintext data for more than 25 million users. Since then, a steady trickle of six-figure ...

Unlocking Smartphone Security: How to Hackproof Your Smartphone

In today's digital age, where smartphones are integral to our daily lives, securing them is paramount. But is it possible to truly hackproof your smartphone in an ever-expanding cyber threat landscape? Let’s dive into the types of hacks and ...

Explainable AI: Empowering Advanced Bot Prevention Strategies

In an era marked by unprecedented advancements in artificial intelligence (AI), the pursuit of “Explainable AI” has emerged as a pivotal avenue of research and development—even in the realm of bot prevention. As AI systems progressively ...

GraphQL Vulnerabilities and Common Attacks: What You Need to Know

GraphQL is a powerful query language for APIs that has gained popularity in recent years for its flexibility and ability to provide a great developer experience. However, with the rise of GraphQL usage comes the potential for security ...

News Alert: Reflectiz declares war on Magecart web-skimming attacks as holidays approach

Tel Aviv, Israel, Sept. 5, 2023 — Reflectiz, a cybersecurity company specializing in continuous web threat management offers an exclusive, fully remote solution to battle Magecart web-skimming attacks, a popular type of cyberattacks involving ...

Clicked on a Phishing Email? All Is Not Lost

Phishing continues to be a bane of organizations. Phishing accounts for 36% of all data breaches, according to Verizon, and the FBI found that in 2021, almost 83% of companies experienced a phishing attack. And there are a lot of phishing emails ...

Takeaways from Our Roundtable at the Millennium Alliance

A few days ago our team met with security leaders at an event hosted by the Millennium Alliance. Over the course of two days, we … The post Takeaways from Our Roundtable at the Millennium Alliance appeared first on Cyral. The post Takeaways ...

The Product Pulse

Monthly Release Notes for August The post The Product Pulse appeared first on Security Boulevard.

BSides Cheltenham 2023 – James Stevenson – Identifying Rogue Android Devices: The World Of Android Attestation

Many thanks to BSides Cheltenham for publishing their presenter’s outstanding BSides Cheltenham 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Cheltenham 2023 – James Stevenson – ...

Item Recycling Site Freecycle is Hit with a Massive Data Breach

Millions of people who use the Freecycle online forum to swap unwanted items may now have their passwords, email addresses, and other sensitive information traded on the dark web following a data breach this summer. The operators of the Freecycle ...

Navigating the XDR Landscape: Choosing the Right Solution through Independent Test Results

In the rapidly evolving digital landscape, organizations are confronted with the mounting challenge of safeguarding their networks, data, and assets against unyielding cyber threats. As the threat landscape becomes more complex, traditional ...

Back to Basics: The Key Elements of a Strong Security Program

With children across the United States returning to school, a key part of their education is reinforcing the basics in each subject they’ve learned (and perhaps forgotten) since the last school year ended. A similar approach is valuable in ...

CISA Hires ‘Mudge’ to Work on Security-by-Design Principles

Peiter ‘Mudge’ Zatko joins the US government's cybersecurity agency to preach the gospel of security-by-design and secure-by-default development principles. The post CISA Hires ‘Mudge’ to Work on Security-by-Design Principles appeared ...

Reflectiz offers remote solution to battle Magecart attacks

Reflectiz, a cybersecurity company specializing in continuous web threat management, offers a remote solution to battle Magecart web-skimming attacks, a cyberattack involving injecting malicious code into the checkout pages. As the holiday season ...

Geopolitical Warfare in the Digital Age: The NATO Summit Cyber Incursion

Cybercrime, once chiefly associated with shadowy individuals seeking personal gains, has rapidly evolved into a formidable weapon of modern warfare. Today, nations deploy sophisticated cyber-espionage units, not just to wreak digital havoc but ...

Noname Security Aligns With OWASP on API Security Risks

Noname Security added support for reducing the top ten API security risks for 2023 as defined by OWASP. The post Noname Security Aligns With OWASP on API Security Risks appeared first on Security Boulevard.