Application Security News and Articles


AWS, White House Work to Bolster K-12 School Cybersecurity

Key officials from the Biden administration convened with school administrators and technology providers to tackle the growing threat to educational institutions. The post AWS, White House Work to Bolster K-12 School Cybersecurity appeared first ...

Israel, US to Invest $4 Million in Critical Infrastructure Security Projects

Israel and US government agencies have announced plans to invest close to $4 million in projects to improve the security of critical infrastructure systems. The post Israel, US to Invest $4 Million in Critical Infrastructure Security Projects ...

Federally Insured Credit Unions Required to Report Cyber Incidents Within 3 Days

The National Credit Union Administration is requiring all federally insured credit unions to report cyber incidents within 72 hours of discovery. The post Federally Insured Credit Unions Required to Report Cyber Incidents Within 3 Days appeared ...

Your Own Devices Can Be Used Against You! – How to Prevent Living Off the Land (LOTL) Attacks

When you think about any crime, generally, criminals choose the path of least resistance. The path that gets them inRead More The post Your Own Devices Can Be Used Against You! – How to Prevent Living Off the Land (LOTL) Attacks appeared first ...

SEC Adopts Groundbreaking Cybersecurity Rules for Public Companies

Big cybersecurity news came out of the Securities and Exchange Commission (SEC) this month, and it directly affects board members and executives. The SEC adopted a set of rules that will change the way companies handle material cybersecurity ...

AWS Vs Azure Vs Google Cloud: Choosing the Right Cloud Provider for Your Business

Cloud Computing has emerged as the backbone of innovation and growth for businesses of all sizes. Cloud platforms provide a scalable, flexible, and cost-effective solution to store, manage, and process data, enabling companies to focus on their ...

4 ways simulation training alleviates team burnout

Burnout is endemic in the cybersecurity industry, damaging the mental and physical health of cyber professionals and leaving organizations underskilled, understaffed, and overexposed to cyber risk as security leaders and team members leave for ...

Zimbra users in Europe, Latin America face phishing threat

ESET researchers have uncovered a mass-spreading phishing campaign aimed at collecting Zimbra account users’ credentials. Zimbra Collaboration is an open-core collaborative software platform, a popular alternative to enterprise email solutions. ...

Types of Domain Vulnerabilities You Should be Aware of

Uncover domain vulnerabilities: Learn about domain-based attacks, and hijacking to fortify your online security. The post Types of Domain Vulnerabilities You Should be Aware of appeared first on Security Boulevard.

Reinventing OT security for dynamic landscapes

From understanding the challenges of disparate OT protocols and the increasing convergence with IT to grappling with the monumental role of human error, our latest interview with Rohit Bohara, CTO at asvin, delves deep into the landscape of OT ...

New infosec products of the week: August 18, 2023

Here’s a look at the most interesting products from the past week, featuring releases from Action1, MongoDB, Bitdefender, SentinelOne and Netskope. Action1 platform update bridges the gap between vulnerability discovery and remediation Action1 ...

A closer look at the new TSA oil and gas pipeline regulations

The TSA has announced updates to its Security Directive (SD) to strengthen the operational resilience of oil and natural gas pipeline owners and operators against cyber-attacks. In this Help Net Security video, Chris Warner, OT Senior Security ...

30% of phishing threats involve newly registered domains

Phishing remains the most dominant and fastest growing internet crime, largely due to the ubiquity of email and the ceaseless issue of human error that is preyed upon by today’s threat actors, according to Cloudflare. While business email ...

Federal agencies gear up for zero trust executive order deadline

Federal agencies are prepared to meet the zero trust executive order requirements from the Biden Administration with just over a year until the deadline, according to Swimlane. The research investigated the confidence level of these agencies in ...

ProjectDiscovery Lands $25M Investment for Cloud Security Tech

San Francisco startup ProjectDiscovery has banked $25 million in early-stage financing as investors continue bet on cloud security vendors. The post ProjectDiscovery Lands $25M Investment for Cloud Security Tech appeared first on SecurityWeek.

How to combat the emergence of automated and AI-generated fraud

Discover the top insights discussed during this recent webinar with Sift customers Mindbody and Zipcar on the impact of automated and AI-generated fraud. The post How to combat the emergence of automated and AI-generated fraud appeared first on ...

A Look Inside the Attacker’s Toolkit: DNS DDoS Attacks

DNS is a critical infrastructure for your online services, a DNS DDoS attack risks the availability of your services. Attackers are experts in DNS and know all the weak points to target. Understanding how a DNS DDoS looks like, and the risks it ...

Revving Up for Rev5, Part 3: Recommendations and Timelines

The post Revving Up for Rev5, Part 3: Recommendations and Timelines appeared first on Anitian. The post Revving Up for Rev5, Part 3: Recommendations and Timelines appeared first on Security Boulevard.

Tackling Supply Chain Security with NIST CSF 2.0

Many organizations look to the NIST for direction when setting their cybersecurity strategy. The new version of the Cybersecurity Framework (CSF 2.0) is due out early 2024, and NIST is currently soliciting feedback. This webinar will discuss the ...

Karma Catches Up to Global Phishing Service 16Shop

You've probably never heard of "16Shop," but there's a good chance someone using it has tried to phish you. Last week, the international police organization INTERPOL said it had shuttered the notorious 16Shop, a popular phishing-as-a-service ...