Application Security News and Articles


Organizations invest in AI tools to elevate email security

To counteract new and emerging threat methods enhanced by artificial intelligence, specialized email security vendors are leveraging a synergy of AI and human insights to enhance email security, according to IRONSCALES and Osterman Research. ...

The complex world of CISO responsibilities

A Chief Information Security Officer (CISO) plays a crucial role in protecting an organization’s digital assets. They are responsible for ensuring the security of sensitive information, defending against cyber threats, and maintaining data ...

Exposing a Currently Active Personally Identifiable Cybercriminals XMPP/Jabber Account IDs Portfolio

Folks, I've been recently digging deep into the ever evolving cybercrime ecosystem doing research and trying to supply as much personally identifiable information on the bad guys in the form of personally identifiable email address accounts ...

A Compilation of Personally Identifiable Email Address Accounts Known to Belong to Ransomware Operators

Dear blog readers, The following is a set of personally identifiable email address accounts known to belong to ransomware operators or participants in ransomware-themed affiliate-based partner programs which I've decided to share with everyone ...

BSidesTLV 2023 – Paz Hameiri – Barcode Scanners Are Disguised Windows To Your Windows

Many thanks to BSidesTLV for publishing their presenter’s erudite BSidesTLV 2023 security content on the organizations’ YouTube channel. Permalink The post BSidesTLV 2023 – Paz Hameiri – Barcode Scanners Are Disguised Windows To ...

Suspected N. Korean Hackers Target S. Korea-US Drills

North Korea-linked "Kimsuky" hackers carried out "continuous malicious email attacks" on contractors working at the war simulation centre. The post Suspected N. Korean Hackers Target S. Korea-US Drills appeared first on SecurityWeek.

2023 Cybersecurity Awareness Month Appeal: Make Online Security Easier

Surveys show that most Americans think online security is too hard, confusing and frustrating. So as we prepare for Cybersecurity Awareness Month in October, the goal is to make cybersecurity easy. The post 2023 Cybersecurity Awareness Month ...

Week in review: VPNs vulnerable to TunnelCrack attacks, Cybertech Africa 2023

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Deception technology and breach anticipation strategies In this Help Net Security interview, Xavier Bellekens, CEO of Lupovis, explains how the ...

Using JupyterLab to Manage Password Cracking Sessions (A CMIYC 2023 Writeup) Part 1

“We become what we behold. We shape our tools, and thereafter our tools shape us.” -- Marshall McLuhan This year I didn't compete in the Defcon Crack Me If You Can password cracking competition. It was my wife's first Defcon, so there was ...

CISA Releases Cyber Defense Plan For Remote Monitoring And Management (RMM) Software

RMM tools are the easy targets for cyber attackers, and the related news over past year has highlighted several breaches initiated through RMM tools. The post CISA Releases Cyber Defense Plan For Remote Monitoring And Management (RMM) Software ...

BSidesTLV 2023 – Ofir Balassiano & Ofir Shaty – The Dark Side Of Cloud-Based Database Engines

Many thanks to BSidesTLV for publishing their presenter’s erudite BSidesTLV 2023 security content on the organizations’ YouTube channel. Permalink The post BSidesTLV 2023 – Ofir Balassiano & Ofir Shaty – The Dark Side Of ...

2023 OWASP Top-10 Series: API4:2023 Unrestricted Resource Consumption

Welcome to the 5th post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a particular focus on security practitioners. This post will focus on API4:2023 Unrestricted Resource Consumption. In this series we are taking an ...

Source Code Analysis using Semgrep

Hello folks, I would like to introduce to semgrep that analyzes source code locally. Semgrep registry have enormous security rules which…Continue reading on Medium »

Error Resolutions .NET Applications solutions

Building .NET application solutions is a critical step in the software development lifecycle. However, the road to a successful build can…Continue reading on Medium »

Five Things To Know About PCI DSS 4.0 Authentication Requirements

The Payment Card Industry Security Standards Council recently updated their Data Security Standard (PCI DSS) for protecting payment card data. The latest version, PCI DSS 4.0, introduces more than 60 new or updated requirements, with new ...

Introduction to SonarQube and Its Features

What is SonarQube?Continue reading on Medium »

Introduction to SonarQube and Its Features

What is SonarQube?Continue reading on Medium »

Securing the Cloud: Unveiling the Significance of Strong Identity and Access Management (IAM) Strategies

In today’s rapidly evolving digital landscape, where businesses are increasingly migrating their operations to the cloud, the importance of robust security measures cannot be overstated. One of the linchpins of a comprehensive cloud security ...

BSidesTLV 2023 – Georgios Karantzas – It’s Duck Season: Forensic Detection Of BadUsb Attacks

Many thanks to BSidesTLV for publishing their presenter’s erudite BSidesTLV 2023 security content on the organizations’ YouTube channel. Permalink The post BSidesTLV 2023 – Georgios Karantzas – It’s Duck Season: Forensic ...

Executive Threat Protection: Using Monitoring to Gain the Advantage

The risk of cyber threats has become an everyday reality for many organizations. This risk is amplified when it comes to company executives who, due to their high-profile nature and access to sensitive company data, are likely targets for ...