Application Security News and Articles


Embassy of China in Canada Issues a Statement on U.S Cyber Espionage Campaigns Against Japan

I just came across to a statement issued by the Embassy of China in Canada on the U.S cyber espionage campaigns launched against Japan. What's so special about this statement? First it does quite Wikileaks which is a bit of an outdated approach ...

BSides Leeds 2023 – Anya Bridges – Facilitating Regional Growth Through Careers In Cyber

Thanks are in order to BSides Leeds for publishing their presenter’s outstanding BSides Leeds 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Leeds 2023 – Anya Bridges – Facilitating ...

Unpacking the CSRB Report: Lessons from the Lapsus$ Threat Group

The global digital ecosystem finds itself facing a new breed of cyber threat actors: loosely organized groups with a penchant for extortion, chaos, and the desire to gain notoriety. The US Department of Homeland Security's Cyber Safety Review ...

Daniel Stori’s – ‘When You tail -f But Forget To grep’

via the webcomic talent of the inimitable Daniel Stori and Michael Tharrington at Turnoff.US. Permalink The post Daniel Stori’s – ‘When You tail -f But Forget To grep’ appeared first on Security Boulevard.

Conducting a Cyber Risk Assessment: A Step-by-Step Guide

Cyber risk has become increasingly pervasive in almost every industry. From the new SEC cyber regulations to industry standards like the NIST CSF and HIPAA, regulatory bodies are rolling out rules for companies in all verticals to bolster ...

Shared Responsibility Model: Breakdown & Best Practices

This is a guest post from Michael Marrano, MS, CISSP, CISM, CISA, at Riskigy.  There is a widespread misunderstanding regarding cloud services, particularly in relation to Software as a Service (SaaS). Many organizations mistakenly believe that ...

Cloud Misconfigurations: Unseen Threats and How Solvo Ensures Your Cloud Security

Organizations are increasingly turning to the cloud to reap the benefits of scalability, efficiency, and cost savings. While the cloud offers numerous advantages, it also introduces unique security challenges, especially when it comes to ...

Teenage Hackers Must be Stopped: US DHS’s CSRB Report

2FA SMS FAIL: Lapsus$ social engineers exploited weak two-factor authentication. Something must be done! (Well, this is something.) The post Teenage Hackers Must be Stopped: US DHS’s CSRB Report appeared first on Security Boulevard.

CISA is Asking the IT Industry for Input in Securing Open Source Software

The US government is looking for suggestions from developers and others in the tech world for how best to ensure the security of open source software as the number of organizations affected by supply-chain attacks continues to pile up. The ...

BSides Leeds 2023 – Darren Conway – So You Want Money To Fund Your Cool Tools, Not So Fast

Thanks are in order to BSides Leeds for publishing their presenter’s outstanding BSides Leeds 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Leeds 2023 – Darren Conway – So You Want Money ...

EDR = Erase Data Remotely by Cooking Unforgettable (Byte) Signature Dish

See how SafeBreach Labs Researchers uncovered multiple attack vectors that exploit the Windows Defender update process to gain control. The post EDR = Erase Data Remotely by Cooking Unforgettable (Byte) Signature Dish appeared first on ...

The Five Stages of Grief: Coping With a Data Breach

Have you been a victim of a data breach? You’re not alone. As an incident response (IR) professional, I have met many different types of corporate staff, from the IT staff to the C-suite. Unfortunately, it was probably on their worst day ever, ...

In Other News: macOS Security Reports, Keyboard Spying, VPN Vulnerabilities

Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of August 7, 2023. The post In Other News: macOS Security Reports, Keyboard Spying, VPN Vulnerabilities appeared ...

The rise of AI in software development

Generative artificial intelligence tools are changing the world and the software development landscape significantly. Our webinar series will help you understand how. The post The rise of AI in software development appeared first on Security ...

Black Hat USA 2023 video walkthrough

Help Net Security is in Las Vegas this week for Black Hat USA 2023, and this video provides a closer look at the event. The exhibitors featured in this video are: 1Password, Aqua Security, CISA, Cisco, CyberFOX, Darktrace, Dasera, Fortanix, ...

DARPA AI Cyber Challenge Part of White House Plan to Harness, Secure AI

DARPA's AI Cyber Challenge encourages cybersecurity and AI pros to find ways to automatically detect and fix software flaws and protect critical infrastructure. The post DARPA AI Cyber Challenge Part of White House Plan to Harness, Secure AI ...

Microsoft Discloses Codesys Flaws Allowing Shutdown of Industrial Operations, Spying

Over a dozen Codesys vulnerabilities discovered by Microsoft researchers can be exploited to shut down industrial processes or deploy backdoors. The post Microsoft Discloses Codesys Flaws Allowing Shutdown of Industrial Operations, Spying ...

Northern Ireland’s Top Police Officer Apologizes for ‘Industrial Scale’ Data Breach

Northern Ireland’s top police officer apologized for what he described as an “industrial scale” data breach in which the personal information of more than 10,000 officers and staff was released to the public. The post Northern ...

BigID Access Intelligence Remediation defends users against unauthorized exposure

BigID launched Access Intelligence Remediation, empowering organizations to find and fix access rights violations at scale within their Data Security Posture Management (DSPM) workflows. With this latest innovation, BigID continues to enhance its ...

Black Hat USA 2023 – Announcements Summary

Hundreds of companies and organizations showcased their products and services this week at the 2023 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2023 – Announcements Summary appeared first on SecurityWeek.