Application Security News and Articles


Microsoft Shares Guidance and Resources for AI Red Teams

Microsoft has shared guidance and resources from its AI Red Team program to help organizations and individuals with AI security. The post Microsoft Shares Guidance and Resources for AI Red Teams appeared first on SecurityWeek.

Domain Risk Management – The Build vs. Buy Dilemma in 2023

Domain risks are growing increasingly aggressive, and detrimental to businesses despite their best domain risk management efforts. Domain threats, including typosquat domains, phishing attacks, and impersonation attacks target businesses with ...

For TSA’s updated Pipeline Security Directive, consistency and collaboration are key

Late last month, the Transportation Security Administration renewed and updated its security directive aimed at enhancing the cybersecurity of oil and natural gas pipelines. The reissued guidance, known as Security Directive (SD) ...

Getting the best possible outcome in ransomware negotiation

Though typically seen as a final measure, 90% of participants from a BigID survey revealed that their company would contemplate paying a ransom if it meant they could recover data and business processes, or recover them faster. In this Help Net ...

Dark web activity targeting the financial sector

In this Help Net Security video, Jim Simpson, Director of Threat Intelligence at Searchlight Cyber, discusses threats against the financial sector. Threat actors will invariably target banks, yet by keeping an eye on the dark web, these ...

Seasoned cyber pros are more complacent in their skills than junior staff

Average response time accelerated from 29 to 19 days, from 2021 to 2022, with lessons from Log4j and other high-profile vulnerabilities having a significant impact on urgency levels, according to Immersive Labs. Faster response time to new ...

Managing human cyber risks matters now more than ever

As artificial intelligence amplifies the sophistication and reach of phishing, vishing, and smishing attacks, understanding and managing human cyber risks has become increasingly vital, according to the SANS Institute. The report underscores the ...

How to get started with ongoing configuration assessments

There’s an old adage in business: if you’re not measuring something, you can’t manage it. These days, information technology (IT) and information security professionals know this all too well, especially when it comes to ...

Building a Human-Centric Insider Risk Program | Three Experts Weight In

Building a human-centric insider risk program has become a key priority for most federal and critical infrastructure organizations. But how do you get started? How do you do it justice? There are no short cuts, but thanks to a recent DTEX-hosted ...

An In-Depth Guide to the Vulnerability Management Lifecycle

The vulnerability management lifecycle has become an essential component of an effective cybersecurity strategy within any organization. This lifecycle is a comprehensive and iterative process that involves identifying, evaluating, treating, and ...

NodeZero Pivots Through Your Network with the Attacker’s Perspective

A NodeZero autonomous attack that leveraged two weaknesses to achieve domain compromise in 33 minutes, 9 seconds. The post NodeZero Pivots Through Your Network with the Attacker’s Perspective appeared first on Horizon3.ai. The post NodeZero ...

Building Digital Trust in an Untrusting World

Digital trust is the precursor to the public and private sector’s ability to innovate and implement tomorrow’s solutions. The post Building Digital Trust in an Untrusting World appeared first on Keyfactor. The post Building Digital Trust in ...

Threat of Side-Channel Attacks Increases with Deep-Learning Model

The rapid innovations in deep learning, expanding use of laptops, and growing number of smartphones with microphones are creating an environment that makes it easier for bad actors to compromise the laptops by recording the keystrokes on their ...

Cyberinsurance Firm Resilience Raises $100 Million to Expand Its Cyber Risk Platform

Resilience Cyber Insurance Solutions has raised $100 million through a Series D funding round to support global expansion of its cyber risk platform that was launched earlier this year. The post Cyberinsurance Firm Resilience Raises $100 Million ...

BSides Leeds 2023 – Dr. Z Cliffe Schreuders – Secgen, Hacktivity, And Hackerbot Randomised Hacking Challenges

Thanks are in order to BSides Leeds for publishing their presenter’s outstanding BSides Leeds 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Leeds 2023 – Dr. Z Cliffe Schreuders – Secgen, ...

Credential Security Enhances Privacy and Equity

Credential security plays a pivotal role in advancing privacy and equity by fostering a safer and more inclusive digital landscape. The post Credential Security Enhances Privacy and Equity appeared first on VeriClouds. The post Credential ...

Cracking the Code: The Unseen Secrets of the App Sec Vulnerability Management Lifecycle!

Application Security Vulnerabilities can be introduced in many ways into your application. How do you know where they are , and how can…Continue reading on Medium »

CISA Outlines Plan to Get Ahead of Cyberthreat Groups

The nation’s top cybersecurity agency is envisioning a future where the federal government and private companies alike set the rules of the game against threat groups and bad actors rather than constantly reacting to attacks after they happen. ...

Randall Munroe’s XKCD ‘Free Fallin’’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Free Fallin’’ appeared first on Security Boulevard.