Application Security News and Articles


Avoid The Hack: 7 Best Private Search Engine Recommendations

This post was originally published on 27 APR 2021; it has since been updated and revised. Are you using Google, Bing, or Yandex? Tired of "biased" search results? Tired of seeing re-targeting ads that follow you around because you've searched for ...

MSP Vs MSSP is there a distinction anymore?

MSP v MSSP – is there a distinction anymore? Well, yes and no. Yes there’s a distinction because if you look at any established MSSP today, you will see things in their stacks The post MSP Vs MSSP is there a distinction anymore? appeared ...

Happy United States Labor Day 2023 / Feliz Día del Trabajo de Estados Unidos 2023 / Bonne Fête du Travail aux États-Unis 2023

Labor Day 2023 - Three Day Weekend Edition! The post Happy United States Labor Day 2023 / Feliz Día del Trabajo de Estados Unidos 2023 / Bonne Fête du Travail aux États-Unis 2023 appeared first on Security Boulevard.

Exploit Code Published for Critical-Severity VMware Security Defect

Exploit code and root-cause analysis released by SinSinology documents the problem as a case where VMWare “forgot to regenerate” SSH keys. The post Exploit Code Published for Critical-Severity VMware Security Defect appeared first on ...

BSides Cheltenham 2023 – Sadi Zane – Attacking And Defending On-Premises And Cloud-Based Kubernetes Services

Many thanks to BSides Cheltenham for publishing their presenter’s outstanding BSides Cheltenham 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Cheltenham 2023 – Sadi Zane – Attacking And ...

Harnessing Generative AI for Building the Human Firewall Against AI-Driven Identity Scams

In response to the growing concerns surrounding AI-driven threats, Constella is not only taking steps to understand and reproduce these harmful tools but is also leveraging the potential of our trained Language Models (LLMs) and Generative AI to ...

Frontine VM Receives the Texas Risk and Authorization Management Program (TXRAMP) Certification

The post Frontine VM Receives the Texas Risk and Authorization Management Program (TXRAMP) Certification appeared first on Digital Defense. The post Frontine VM Receives the Texas Risk and Authorization Management Program (TXRAMP) Certification ...

FFIEC API Security Guidance for Financial Services

In an era where technology is the cornerstone of the financial industry, safeguarding sensitive information and maintaining the integrity of data has become paramount. Financial institutions are constantly faced with the challenge of ensuring the ...

Daniel Stori’s ‘The Modern Evil’

via the webcomic talent of the inimitable Daniel Stori at Turnoff.US. Permalink The post Daniel Stori’s ‘The Modern Evil’ appeared first on Security Boulevard.

Audit Management Software: Why You Need It and How to Put it to Work

Audits are everywhere for the modern CISO or compliance officer.  Maybe you need to undergo an internal audit in preparation for a SOC 2 audit of your security controls, or maybe you need to pass an external audit as part of HIPAA or PCI DSS ...

Why is .US Being Used to Phish So Many of Us?

Domain names ending in “.US” — the top-level domain for the United States — are among the most prevalent in phishing scams, new research shows. This is noteworthy because .US is overseen by the U.S. government, which is frequently the ...

Celebrating International Women in Cyber Day: An Interview with Axiad’s Karen Larson

September 1 is International Women in Cyber Day, a special day earmarked to bring awareness... The post Celebrating International Women in Cyber Day: An Interview with Axiad’s Karen Larson appeared first on Axiad. The post Celebrating ...

BSides Cheltenham 2023 – Stephen – All Your Firmwares Are Belong To Us: A Guide To Successful Acquisition

Many thanks to BSides Cheltenham for publishing their presenter’s outstanding BSides Cheltenham 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Cheltenham 2023 – Stephen – All Your ...

Fighting Back Against Synthetic Identity Fraud

In today’s digital-first world, synthetic identity fraud is becoming more prevalent and pervasive. The post Fighting Back Against Synthetic Identity Fraud appeared first on Security Boulevard.

Upskilling the nation’s cybersecurity savvy won’t solve the skills gap | NCWES initiative issues | Contrast Security

The White House recently announced its new National Cyber Workforce and Education Strategy & Implementation (NCWES): a mouthful that translates into something along the lines of “Let’s fix this cybersecurity skills gap STAT!” The post ...

dev up 2023: Leveling up our dev skills, security posture, and careers

dev up 2023 was a gathering of industry professionals looking to Elevate their skills and security know-how. Read about the latest in tools, DevOps, security, and career growth. The post dev up 2023: Leveling up our dev skills, security posture, ...

Google Mandiant Adds Additional Cybersecurity Services Using AI

Google is adding security data to the generative artificial intelligence (AI) platform it developed to automate a wide range of IT tasks. The post Google Mandiant Adds Additional Cybersecurity Services Using AI appeared first on Security Boulevard.

Cyberinsurance Takes Longer to Obtain, Costs More

Organizations are spending more time and exerting more effort to get cyberinsurance, and costs are rising. The post Cyberinsurance Takes Longer to Obtain, Costs More appeared first on Security Boulevard.

Black Hat: Business Continuity With Commvault’s Tim Zonca

Shira Rubinoff: Hi, this is Shira Rubinoff coming at you live from Black Hat. I’m here with Tim Zonca from Commvault. Tim, such a pleasure to be speaking with you here today and welcome to Black Hat. Tim Zonca: Thank you. Shira Rubinoff: ...

In Other News: Hacking Encrypted Linux Computers, Android Fuzzing, Skype Leaking IPs

Weekly cybersecurity news roundup providing a summary of noteworthy stories that might have slipped under the radar. The post In Other News: Hacking Encrypted Linux Computers, Android Fuzzing, Skype Leaking IPs appeared first on SecurityWeek.