Application Security News and Articles


Free Decryptor Available for ‘Key Group’ Ransomware

EclecticIQ has released a free decryption tool to help victims of the Key Group ransomware recover their data without paying a ransom. The post Free Decryptor Available for ‘Key Group’ Ransomware appeared first on SecurityWeek.

Bridging the Gap Between Engineering and Security

Bridging the Gap Between Engineering and Security With the widespread adoption of cloud computing, software development has taken on new responsibilities. Driven by the need to speed up application deployment across increasingly complex and ...

Elon Musk Says X, Formerly Twitter, Will Have Voice and Video Calls, Updates Privacy Policy

Twitter has updated its privacy policies, which will allow for the collection of biometric data and employment history, among other information. The post Elon Musk Says X, Formerly Twitter, Will Have Voice and Video Calls, Updates Privacy Policy ...

How to Prepare for a PCI DSS Audit: 7 Key Steps You Should Follow

In the modern world, where financial transactions are increasingly conducted online, ensuring the security of sensitive financial information has become paramount. The Payment Card Industry Data Security Standard (PCI DSS) guides businesses ...

Industry Reactions to Qakbot Botnet Disruption: Feedback Friday

Industry professionals comment on the law enforcement operation targeting the Qakbot botnet and its implications. The post Industry Reactions to Qakbot Botnet Disruption: Feedback Friday appeared first on SecurityWeek.

Threat Actors Adopt, Modify Open Source ‘SapphireStealer’ Information Stealer

Cisco has observed multiple threat actors adopting the SapphireStealer information stealer after its source code was released on GitHub. The post Threat Actors Adopt, Modify Open Source ‘SapphireStealer’ Information Stealer appeared ...

Segregation of Duties Examples and Best Practices

Segregation of Duties Examples and Best PracticesWelcome to the third installment of our Top Ten Searched Topics on the Segregation of Duties (SoD). In this blog, we will explore real-world examples highlighting the significance of SoD and ...

The Importance of Segregation of Duties in Accounting

Importance of Segregation of Duties in AccountingIn our last Segregation of Duties (SoD) blog, we examined the importance of SoD as a critical principle in internal control systems that helps prevent and detect errors, fraud, and misuse of ...

Security, Segregation of Duties and common examples

Security, Segregation of Duties and Common ExamplesSegregation of duties (SoD) is a core internal control that prevents unilateral actions within an organization's workflows. Segregation of Duties emphasizes sharing the responsibilities of key ...

Everything you need to know about segregation of duties

Segregation of Duties: The Why, What and HowWelcome to our latest blog series, where we delve into a critical aspect of organizational integrity and security: the segregation of duties. Maintaining effective internal controls is paramount in ...

Nisos Completes SOC 2® Type 2 Report

Nisos Nisos Completes SOC 2® Type 2 Report Nisos, The Managed Intelligence Company®, is proud to announce the successful completion of its SOC 2® Type 2 report... The post Nisos Completes SOC 2® Type 2 Report appeared first on Nisos by ...

Sourcegraph Discloses Data Breach Following Access Token Leak

Sourcegraph says customer information was breached after an engineer accidentally leaked an admin access token. The post Sourcegraph Discloses Data Breach Following Access Token Leak appeared first on SecurityWeek.

How Ducktail capitalizes on compromised business, ad accounts

Quite some money can be made from selling compromised business and ad accounts on social media platforms, and the Ducktail threat actor has specialized in just that. “We observed that an account deemed ‘low-grade’ sells for ...

Over $1 Million Offered at New Pwn2Own Automotive Hacking Contest

ZDI is offering more than $1 million at the Pwn2Own Automotive hacking contest, hosted in January at the Automotive World conference in Tokyo. The post Over $1 Million Offered at New Pwn2Own Automotive Hacking Contest appeared first on SecurityWeek.

New infosec products of the week: September 1, 2023

Here’s a look at the most interesting products from the past week, featuring releases from Ciphertex Data Security, ComplyCube, Fortinet, and MixMode. Ciphertex strengthens data security with SecureNAS CX-160KSSD-X The SecureNAS CX-160KSSD-X ...

Cybercriminals use research contests to create new attack methods

Adversary-sponsored research contests on cybercriminal forums focus on new methods of attack and evasion, according to Sophos. The contests mirror legitimate security conference ‘Call For Papers’ and provide the winners considerable financial ...

Understand the fine print of your cyber insurance policies

A significant gap is emerging between insurance providers, as organizations skip the fine print and seek affordable and comprehensive coverage, potentially putting them in a tough place when they need to use this safety net, according to a ...

Exploring the traits of effective chief audit executives

Chief audit executives (CAEs) have identified risk orientation, stakeholder management, and team leadership as the top three characteristics of the most effective individuals, according to Gartner. In April 2023, Gartner surveyed 114 CAEs across ...

OSEE, an Unexpected Journey

In this post, we review the EXP-401 course and OSEE certification offered by OffSec. The post OSEE, an Unexpected Journey appeared first on Security Boulevard.

Laminar strengthens cloud data security with Microsoft OneDrive and Google Drive integration

New cloud file share integrations mark a pivotal moment for holistic data security posture management … The post Laminar strengthens cloud data security with Microsoft OneDrive and Google Drive integration appeared first on Laminar. The post ...