Application Security News and Articles


The Gig Economy: 6 Attack Scenarios to Remember

While the primary goal of gig economy platforms is to facilitate connections between users and service providers, threat actors can exploit the platform’s messaging features to conduct SMS toll fraud and plenty of other attacks.  The emergence ...

Tips and Tools for Open Source Compliance

Learn more about keeping track of open source licenses and the tools that can help. The post Tips and Tools for Open Source Compliance appeared first on Mend. The post Tips and Tools for Open Source Compliance appeared first on Security Boulevard.

APT Group Earth Estries Runs Espionage Campaigns Against US, Others

A newly discovered cyber-espionage threat group for at least three years has been using advanced and novel tools to steal information from governments and tech companies in half a dozen countries, including the United States. The advanced ...

News alert: Voxel AI increases funding to $30M, aims to transform industrial workplace safety

San Francisco, Calif.,  Aug. 30, 2023 — Every year over 340m workers suffer a workplace injury: slips and falls, strains and sprains, vehicle collisions and crashes. Voxel, an AI startup using computer vision to transform safety and ...

BSides Cheltenham 2023 – Gert-Jan Bruggink – Reimagining The Intelligence Deliverables Using Structured Threat Content

Many thanks to BSides Cheltenham for publishing their presenter’s outstanding BSides Cheltenham 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Cheltenham 2023 – Gert-Jan Bruggink – ...

SANS 2023 DevSecOps Survey

New 2023 SANS DevSecOps Survey explores DevSecOps challenges and trends. The post SANS 2023 DevSecOps Survey appeared first on Security Boulevard.

Discovering Unknown Problems in the Alert Pipeline

A global FSI with more than $1 trillion in customer assets partnered with SafeBreach to regain confidence in their incident response processes. The post Discovering Unknown Problems in the Alert Pipeline appeared first on SafeBreach. The post ...

BadBazaar: Chinese Spyware Shams Signal, Telegram Apps

After sneaking into Google and Samsung app stores, “GREF” APT targets Uyghurs and other PRC minorities. The post BadBazaar: Chinese Spyware Shams Signal, Telegram Apps appeared first on Security Boulevard.

All Alarms, No Time: What My Training as a Black Hawk Pilot Taught Me About Privileged Access Management

In 2013, I began training in the Army to be a Black Hawk pilot. The requirements I had to meet […] The post All Alarms, No Time: What My Training as a Black Hawk Pilot Taught Me About Privileged Access Management appeared first on Security ...

Threat-informed Defense Is Hard, So We Are Still Not Doing It!

Guest post by Dr Anton Chuvakin, Senior Staff Security Consultant, Office of the CISO, Google Cloud. If you wake up an average security professional at 3AM and ask them “hey, what is security about?”, a large majority would say “it is ...

Air Gapped Environments Need Strong Authentication

Background Starting with the definition: An air gap network “… is physically isolated from unsecured... The post Air Gapped Environments Need Strong Authentication appeared first on Axiad. The post Air Gapped Environments Need Strong ...

Randall Munroe’s XKCD ‘*@gmail.com’

via the comic artistry and dry wit of Randall Munroe, maker of XKCD! Permalink The post Randall Munroe’s XKCD ‘*@gmail.com’ appeared first on Security Boulevard.

Black Hat: The Importance of Collaboration With Digital Hands’ Charlotte Baker

Shira Rubinoff: This is Shira Rubinoff here at Black Hat, coming at you live. I’m here with Charlotte Baker, CEO of Digital Hands. Charlotte, it’s such a pleasure to see you again. Charlotte Baker: It’s so nice to see you. ...

Black Hat: Defending Against Website Spoofing With Memcyco’s Israel Mazin

Shira Rubinoff: Hi, this is Shira Rubinoff broadcasting live here at Black Hat with Techstrong. I’m here with Israel Mazin from Memcyco. Israel, it’s a pleasure to be with you here today and I’m so happy I was able to catch you ...

Black Hat: Security Validation With Pentera’s Aviv Cohen

Shira Rubinoff: Hi, this is Shira Rubinoff. I’m here with Aviv from Pentera. Aviv, it’s such a pleasure to be with you here today. Can you please share with our audience who you are and what you do with Pentera? Aviv Cohen: Hi, Shira. ...

TrustCloud Product Updates: August 2023

See what’s new in TrustCloud Our team has been hard at work creating updates and new features just for you, see what we’ve been up to over the last month. Coming Soon: Prove your impact with TrustCloud Business Intelligence (BI) GRC is a ...

Inherent Risk vs. Residual Risk: What You Need to Know

Risk management is not new, but the way organizations look at risk has shifted. Modern businesses are moving at a breakneck speed, continuously making changes to their tech stack, product lines, services, vendor ecosystem, and org structures. ...

Paid Subscriptions to Stop Bots: Is Elon Musk Right?

Subscription-based services aren't the silver bullet to stopping bot attacks - with the right motivation, these accounts are just as likely to be botted. The post Paid Subscriptions to Stop Bots: Is Elon Musk Right? appeared first on Security ...

Get the Help You Need, Wherever You Are in Your Kubernetes Journey

Just as Kubernetes itself has grown and evolved, so has Fairwinds. For the last five years, I've been involved in delivering Kubernetes infrastructure to our customers in a lot of different ways. Originally, we were focused primarily on services. ...

BSides Cheltenham 2023 – Imran Saleem – Are Politically Motivated Cyberattacks A Threat To Democracy?

Many thanks to BSides Cheltenham for publishing their presenter’s outstanding BSides Cheltenham 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Cheltenham 2023 – Imran Saleem – Are ...