Application Security News and Articles


IBM Extends Cloudflare Alliance to Combat Bots Using Machine Learning

IBM extends its alliance with Cloudflare to combat malicious bot attacks growing in volume and sophistication. The post IBM Extends Cloudflare Alliance to Combat Bots Using Machine Learning appeared first on Security Boulevard.

Play Ransomware Targets Victims Via MSPs’ RMM Software

The Play ransomware operators who took credit for the attack on the city of Oakland, California, in February is now targeting midsize enterprises through their managed service providers (MSPs). According to researchers with Adlumin, the global ...

KubeCrash Fall 2023: Multi-Cluster Deployments at Enterprise Scale

With KubeCon approaching fast (yes, November will be here before we know it), we’ve been preparing for KubeCrash, your cloud native warm-up!  The post KubeCrash Fall 2023: Multi-Cluster Deployments at Enterprise Scale appeared first on ...

Privacy Enhanced Computation Technologies Advantages and Disadvantages

Privacy enhanced computation technologies allow data teams to perform operations on encrypted data. In this blog post, we discussed various technologies. The post Privacy Enhanced Computation Technologies Advantages and Disadvantages appeared ...

Daniel Stori’s ‘The (Sometimes Hard) Cloud Journey’

via the webcomic talent of the inimitable Daniel Stori at Turnoff.US. The post Daniel Stori’s ‘The (Sometimes Hard) Cloud Journey’ appeared first on Security Boulevard.

Impact of the New SEC Cyber Incident Reporting Rules on the C-Suite and Beyond

We recently hosted a compact and very engaging panel discussion about the new SEC Cyber Incident Reporting Rules due to come into effect later this year. We were fortunate to be joined by two well-known experts: In the post, we will *not* rehash ...

Phishing Scam Uses QR Codes in Attacks on Energy, Other Sectors

A months-long phishing campaign that uses QR codes to bypass security controls is aimed at stealing Microsoft account credentials of victims at targeted companies in a range of industries, with one major energy firm getting inundated with almost ...

Looking Forward to the GovForward FedRAMP Headliner Summit

What’s the cloud hanging over cloud service providers’ heads? The rapidly evolving threat landscape. It’s challenging to keep up with the pace and scale of risk, which is especially true when you are working with clients as essential as ...

BSidesTLV 2023 – Tomer Fichman – (In)secure Boot Finding And Exploiting Vulnerabilities In Renesas’s Boot Implementation

Many thanks to BSidesTLV for publishing their presenter’s erudite BSidesTLV 2023 security content on the organizations’ YouTube channel. Permalink The post BSidesTLV 2023 – Tomer Fichman – (In)secure Boot Finding And Exploiting ...

Cybersecurity Insights with Contrast CISO David Lindner | 8/18

Insight #1 As an industry we need to move away from CVSS base score as the risk measuring stick. It doesn’t work and is extremely broken. The post Cybersecurity Insights with Contrast CISO David Lindner | 8/18 appeared first on Security ...

Governments Across the Globe Are Looking to Prepare for and Mitigate the Quantum Threat

While there’s never been doubt about the importance of digital security, over the last few... The post Governments Across the Globe Are Looking to Prepare for and Mitigate the Quantum Threat appeared first on Entrust Blog. The post Governments ...

In Other News: US Hacking China, Unfixed PowerShell Gallery Flaws, Free Train Tickets

Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of August 14, 2023. The post In Other News: US Hacking China, Unfixed PowerShell Gallery Flaws, Free Train ...

Why Whac-A-Mole is not a strategy for defending against ransomware attacks

Recently, I participated in a training exercise where a team of hackers (the red team) simulated an attack on an organization’s infrastructure, and a team of Cyber experts (the blue team) was tasked with responding to the incident and restoring ...

Jenkins Patches High-Severity Vulnerabilities in Multiple Plugins

Jenkins has announced patches for high and medium-severity vulnerabilities impacting several of the open source automation tool’s plugins. The post Jenkins Patches High-Severity Vulnerabilities in Multiple Plugins appeared first on SecurityWeek.

Episode 10

Cyborg Security is launching a podcast with a twist! Join us for the first fully interactive threat hunting podcast where you can hang out with threat hunters from all over the world! Join a rag-tag bunch of threat hunters as they come out of the ...

Stealthy ‘LabRat’ Campaign Abuses TryCloudflare to Hide Infrastructure

The ‘LabRat’ cryptomining and proxyjacking operation relies on signature-based tools and stealthy cross-platform malware, and abuses TryCloudflare to hide its C&Cs. The post Stealthy ‘LabRat’ Campaign Abuses TryCloudflare to ...

The Role of AI in Cybersecurity: Current Limitations and Future Possibilities

Artificial intelligence (AI) has captured the imagination of the cybersecurity industry, offering the potential to revolutionize how security and IT teams handle cyber crises, breaches and ransomware attacks. However, a realistic understanding of ...

Lateral Movement Techniques and Prevention

Understanding common lateral movement techniques, the risks, and the cybersecurity solutions   Cybersecurity breaches are more than just front-page news – they’re often pivotal moments that can make or break an organization’s future, ...

Companies Respond to ‘Downfall’ Intel CPU Vulnerability 

Several major companies have published advisories in response to the Downfall vulnerability affecting Intel CPUs. The post Companies Respond to ‘Downfall’ Intel CPU Vulnerability  appeared first on SecurityWeek.

How to Mitigate Cyber Risks in Your Third-Party Supply Chain

Supply chains are complex networks of organizations, people, processes, information, and resources, all collaborating to deliver goods and services to end consumers. Due to their intricate nature, supply chains are susceptible to various ...