Application Security News and Articles


NIST + Govern = A Welcome Addition

Governance is one of the key use cases that our customers demand from Netography Fusion, which puts us well in step with NIST’s recent announcement to add Govern as a core function of its Cybersecurity Framework. The post NIST + Govern = A ...

How Attackers are Circumventing MFA (and How to Stop Them)

New capabilities fix security issues with MFA push notifications Zero Trust security models call for the use of multi-factor authentication (MFA) to ensure that only authorized users may access protected IT resources. Many organizations are ...

Passwords are Evolving as a Passwordless Future Draws Nearer

Enterprises are developing strategies now to protect identities from being stolen and abused even as a true passwordless future is slowly coming into view, according to Joseph Carson, chief security scientist and advisory CISO at privileged ...

BSidesTLV 2023 – Keren Elazari – Opening Words

Many thanks to BSidesTLV for publishing their presenter’s erudite BSidesTLV 2023 security content on the organizations’ YouTube channel. Permalink The post BSidesTLV 2023 – Keren Elazari – Opening Words appeared first on ...

Unmasking Casbaneiro: A Sneaky Cyber Threat and How Votiro Can Stop It

In an age where technology is an inextricable part of our daily lives, cybersecurity threats are a growing concern. One particular malware, known as Casbaneiro, or Metamorfo, has caused considerable alarm within cybersecurity circles due to its ...

The Time for Netography Fusion Is Now

The time is now for Netography Fusion to break through the barriers and provide real-time, end-to-end visibility to help reduce atomization – of networks and organizations. The post The Time for Netography Fusion Is Now appeared first on ...

3x’s the Reason to Celebrate: Onapsis Named to Inc. 5000 List for Third Year in a Row

3x’s the Reason to Celebrate: Onapsis Named to Inc. 5000 List for Third Year in a Row ltabo Tue, 08/15/2023 - 17:31 The news has arrived, and we are excited to announce that Onapsis has made the Inc. 5000 list for the third year in a row. ...

Randall Munroe’s XKCD ‘Car Wash’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD! Permalink The post Randall Munroe’s XKCD ‘Car Wash’ appeared first on Security Boulevard.

6 things you may have missed at Hacker Summer Camp

Tens of thousands of the world’s top cybersecurity pros descended on Las Vegas last week for the annual Hacker Summer Camp, with hundreds of sessions spread over three events. Taking it all in is an impossible task. The post 6 things you may ...

MongoDB Queryable Encryption enables organizations to meet data-privacy requirements

MongoDB Queryable Encryption helps organizations protect sensitive data when it is queried and in-use on MongoDB. It reduces the risk of data exposure for organizations and improves developer productivity by providing built-in encryption ...

AI coding helpers get FAILing grade

An academic study says ChatGPT is wrong more than half the time, when asked the sort of programming questions you’d find on Stack Overflow. The “comprehensive analysis” concludes that GitHub Copilot’s LLM engine will make many conceptual ...

Why API hackers should embrace failure

Embrace failure. Explore how mistakes and setbacks can fuel innovation, refine skills, and deepen understanding in the world of API hacking. The post Why API hackers should embrace failure appeared first on Dana Epp's Blog. The post Why API ...

2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability

A threat actor has exploited a recent Citrix vulnerability (CVE-2023-3519) to infect roughly 2,000 NetScaler instances with a backdoor. The post 2,000 Citrix NetScaler Instances Backdoored via Recent Vulnerability appeared first on SecurityWeek.

Employee Spotlight – Simon Edwards

We spoke to the Founder and CEO of SE Labs, Simon Edwards For this month’s employee spotlight, we spoke to Simon Edwards. Here at SE Labs, Simon is the Founder and Chief Executive Officer. What inspired you to set up SE Labs? I’ve always been ...

Materiality: Crux of the new SEC cyber regs?

On July 26, 2023, only a few weeks ago, 29,980 senior business leaders of the 5,996 public companies in the US got a new headache. If you are a CEO, CFO, CISO, CIO or General Counsel of a US public company, the SEC’s final rule S7-09-22 titled ...

Web-based adware’s crafty games and how to sidestep them

If you've ever been online (and, well, you're here, so obviously you have), you've probably crossed paths with something called web-based adware. Let's take a moment to unpack that.  The post Web-based adware’s crafty games and how to ...

BSides Leeds 2023 – BSides Leeds Orga – Closing Remarks

Thanks are in order to BSides Leeds for publishing their presenter’s outstanding BSides Leeds 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Leeds 2023 – BSides Leeds Orga – Closing ...

Phishing Scammers Use WordPress, Abandoned Sites to Host Malicious Pages

Hackers are using abandoned websites, smaller ones with little traffic and few security features, and those built atop the WordPress platform to house the malicious pages that are part of their phishing attacks. Hosting fake pages on such sites ...

How Organizations Can Align with HITRUST Requirements

In a recent podcast interview Robert E. Johnson III, Cimcor CEO/President, along with Mark Allers, Cimcor VP of Business Development discuss HITRUST and HIPAA requirements. The podcast can be listened to in its entirety below. The post How ...

How to Mask JSON and JSONB in PostgreSQL

Introduction We’ve previously talked about our masking feature but this is focused on masking the contents of an entire column. We’ve had some recent customer … The post How to Mask JSON and JSONB in PostgreSQL appeared first on Cyral. The ...