Application Security News and Articles


Deception technology and breach anticipation strategies

Cybersecurity is undergoing a paradigm shift. Previously, defenses were built on the assumption of keeping adversaries out; now, strategies are formed with the idea that they might already be within the network. This modern approach has given ...

How manufacturers can navigate cybersecurity regulations amid NIST 2.0

The National Institute of Standards and Technology (NIST) released a discussion draft for possible Cybersecurity Framework (CSF) changes earlier this year. The proposed changes aim to help increase the CSF’s clarity and bring the updated ...

Product showcase: Free email security test by ImmuniWeb Community Edition

According to an FBI report, in 2022, global losses from business email compromise (BEC) and email account compromise (EAC) attacks attained $43 billion, hitting a historic anti-record. Multiple cybersecurity vendors, including Microsoft and Trend ...

Navigating generative AI risks and regulatory challenges

The mass availability of generative AI, such as OpenAI’s ChatGPT and Google Bard, became a top concern for enterprise risk executives in the second quarter of 2023, according to Gartner. A benchmarked view of emerging risks “Generative AI was ...

Building a secure future without traditional passwords

As organizations try to fortify their defenses against an increasingly sophisticated threat landscape, traditional password-based systems reveal their limitations. This is where passwordless authentication steps in – a concept that simplifies ...

Don’t Expect Quick Fixes in ‘Red-Teaming’ of AI Models. Security Was an Afterthought

Security in current AI models was an afterthought in their training as data scientists amassed breathtakingly complex collections of images and text. The post Don’t Expect Quick Fixes in ‘Red-Teaming’ of AI Models. Security Was an ...

The Data Exfiltration Techniques You Need to be Aware of

What data exfiltration techniques are being used to target businesses with threats such as ransomware in 2023? The post The Data Exfiltration Techniques You Need to be Aware of appeared first on Security Boulevard.

Black Hat insights: Generative AI begins seeping into the security platforms that will carry us forward

LAS VEGAS – Just when we appeared to be on the verge of materially shrinking the attack surface, along comes an unpredictable, potentially explosive wild card: generative AI. Related: Can ‘CNAPP’ do it all? Unsurprisingly, generative AI was ...

BSides Leeds 2023 – Gerald Benischke – Precision Munitions For Denial Of Service

Thanks are in order to BSides Leeds for publishing their presenter’s outstanding BSides Leeds 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Leeds 2023 – Gerald Benischke – Precision ...

Highlights from the 16th Annual MS-ISAC Meeting

The 2023 MS-ISAC and EI-ISAC meeting just wrapped up in Salt Lake City. Here’s a roundup of what happened and what’s next. The post Highlights from the 16th Annual MS-ISAC Meeting appeared first on Security Boulevard.

A Compilation of Bulletproof Hosting Provider Domains

In need of a fresh and relevant bulletproof hosting provider domain list for research purposes? Check out the following list of domains which I compiled today and decided to share with everyone reading my blog. Sample bulletproof hosting provider ...

Week in review: 8 free cybersecurity docus, vulnerable Intel Core processors, Black Hat USA 2023

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zoom CISO Michael Adams discusses cybersecurity threats, solutions, and the future In this Help Net Security interview, we delve into the world ...

Guarding Against Evolving Threats: Insights from the Q2 Email Threat Trends Report

In the ever-evolving cybersecurity landscape, staying informed about the latest email threat trends is crucial to protect individuals and organizations. The Q2 Email Threat Trends Report presents a comprehensive analysis of the second quarter’s ...

Enhancing Identity Security and Permission Management with ConductorOne

In today’s digital landscape, ensuring robust identity security and effective permission management is essential for businesses of all sizes, regardless of region or industry. With the increasing complexity and diversity of IT environments, ...

BSides Leeds 2023 – Sara Anstey – Educating Your Guesses: How To Quantify Risk And Uncertainty

Thanks are in order to BSides Leeds for publishing their presenter’s outstanding BSides Leeds 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Leeds 2023 – Sara Anstey – Educating Your ...

2023 OWASP Top-10 Series: API3:2023 Broken Object Property Level Authorization

Welcome to the 4th post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a particular focus on security practitioners. This post will focus on API3:2023 Broken Object Property Level Authorization. In this series we are ...

Improve Data Understanding, Accessibility, & Control With an Automated Data Catalog

With the rapid expansion of data across multiple clouds, it is extremely difficult for companies to manually track all the data systems and data that exists within their organization. Business and technical users need to easily search and explore ...

7 Ways Enterprises are Taking Advantage of Biometrics

The global biometrics market is expected to grow to a staggering $82.9 billion by 2027 and organizations have taken notice of its many capabilities. In particular, as cyberattackers and their tools become more sophisticated, it's become ...

A Portfolio of Iran-Based Hacker Groups and Lone Iran-based Hackers Personal Web Sites

In need of a freshly collected Iran-based hacker groups and lone hacker personal Web sites? As I did some homework on the topic of finding these I actually came across to the fact that the majority of these are located on an Iran-based hosting ...

A Portfolio of Publicly Accessible Cybercrime Friendly Forum Communities

Who needs access to a recently collected portfolio of publicly accessible cybercrime friendly forum communities for Technical Collection and situational awareness? I recently spend some time doing my homework on the topic in terms of improving ...