Application Security News and Articles


SEC Cybersecurity Ruling – What to Know and How to Prepare

On July 26, 2023, the Securities and Exchange Commission (SEC) voted to adopt new rules on cybersecurity disclosures for publicly traded companies. This ruling has significant implications for public companies and their cybersecurity risk ...

The Power of Post-Production SBOMs

The post The Power of Post-Production SBOMs appeared first on Grammatech. The post The Power of Post-Production SBOMs appeared first on Security Boulevard.

Privileged Credentials Often Bite Back

Active Directory Analytics Solution Enables Domain Compromise The post Privileged Credentials Often Bite Back appeared first on Horizon3.ai. The post Privileged Credentials Often Bite Back appeared first on Security Boulevard.

Leap into Hybrid Environments and Modern Enterprise Asset Analysis with JupiterOne

JupiterOne recently announced a pivotal expansion of their cyber asset analysis platform. This latest update is centered around catering to the rapidly transforming market that is embracing hybrid infrastructure and showcasing an increasing ...

North Korean Hackers Targeted Russian Missile Developer

A sanctioned Russian missile maker appears to have been targeted by two important North Korean hacking groups. The post North Korean Hackers Targeted Russian Missile Developer appeared first on SecurityWeek.

Netography to Showcase Cloud-Native Network Defense Platform at Black Hat USA

As network security shifts to the cloud, Netography delivers first platform to address the entire network – cloud, on-prem, and the apps and data that reside on both The post Netography to Showcase Cloud-Native Network Defense Platform at Black ...

BSides Leeds 2023 – Gerard Barrett – Uh Oh, How Did I Get Here?

Thanks are in order to BSides Leeds for publishing their presenter’s outstanding BSides Leeds 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Leeds 2023 – Gerard Barrett – Uh Oh, How Did I ...

The Dark Side of Microservices: How to Protect Your Data from Breach Attacks

Hello and welcome back to my blog series on the dark side of microservices. In the previous blog we discussed the challenges that microservices architecture presents for protecting applications. In this blog, I will explore one of the most ...

How to Get Unlimited Airline Miles: Researchers Find the Cheat Codes

That’s not supposed to happen: Three ethical hackers found five huge bugs in Points.com The post How to Get Unlimited Airline Miles: Researchers Find the Cheat Codes appeared first on Security Boulevard.

New PaperCut Vulnerability Allows Remote Code Execution

A new vulnerability in the PaperCut MF/NG print management software can be exploited for unauthenticated, remote code execution. The post New PaperCut Vulnerability Allows Remote Code Execution appeared first on SecurityWeek.

ThreatConnect empowers security teams to operationalize intelligence requirements

ThreatConnect announced its new Intelligence Requirement capability. This new capability strengthens ThreatConnect’s TI Ops Platform by allowing customers to define, manage, and track their intelligence requirements (IRs), priority ...

Is Cybersecurity Having an Identity Crisis?

There has never been a better time to get into cybersecurity, or a worse one. The industry is crying out for professional skills but is also foundering in its efforts to retain and develop them. Employees in the security operations center (SOC) ...

The evolution of incident response | Contrast Security

In today's world, software is the lifeblood of organizations, powering operations across sectors and industries. Contrast has introduced an evolution in the measures we take to protect software and boost the effectiveness of incident response ...

Behind the Scenes of a Tailor-Made Massive Phishing Campaign

A global phishing campaign caught our attention after one of our colleagues was targeted by, and nearly fell victim, to a social engineering attack.  The campaign involved more than 800 different scam domains and impersonated around 340 ...

What to Look for During a SOC 2 Readiness Assessment

A SOC 2 readiness assessment is a way of examining your systems to make sure it’s compliant with security controls of the SOC 2 standard. The post What to Look for During a SOC 2 Readiness Assessment appeared first on Scytale. The post What to ...

Keystroke sounds can betray passwords

Researchers from several UK universities have proven that the recorded sounds of laptop keystrokes can be used to obtain sensitive user data such as passwords with a high accuracy. Sounds of keystrokes can reveal passwords, other sensitive data ...

CISA Unveils Cybersecurity Strategic Plan for Next 3 Years

CISA has unveiled its Cybersecurity Strategic Plan for the next 3 years, focusing on addressing immediate threats, hardening the terrain, and driving security. The post CISA Unveils Cybersecurity Strategic Plan for Next 3 Years appeared first on ...

Creating a Roadmap for Your Dream Cybersecurity Career

Akamai's Steve Winterfeld explains how you can plan and build a roadmap to help you land your dream cybersecurity career. The post Creating a Roadmap for Your Dream Cybersecurity Career appeared first on Security Boulevard.

Black Hat Fireside Chat: Horizon3.ai makes a strong case for continuous, self-service pentesting

LAS VEGAS — Penetration testing, traditionally, gave businesses a nice, pretty picture of their network security posture — at a given point in time. Related: Going on the security offensive Such snapshots proved useful for building audit ...

The state of stateful applications on Kubernetes

Kubernetes has become one of the most popular platforms for running cloud-native applications. This popularity is due to The post The state of stateful applications on Kubernetes appeared first on ARMO. The post The state of stateful applications ...