Application Security News and Articles


How local governments can combat cybercrime

Amid a recent uptick in cybercrime on local governments, cities have been left to recover for months after the initial attack. For example, leaders in Dallas, Texas are ready to spend months recovering from an attack that hindered the city’s ...

SCARF cipher sets new standards in protecting sensitive data

A group of international researchers has achieved a breakthrough in computer security by developing a new and highly efficient cipher for cache randomization. The innovative cipher, designed by Assistant Professor Rei Ueno from the Research ...

Organizations want stronger AI regulation amid growing concerns

AI professionals are still facing some very real challenges in democratizing data, much less AI (much less Generative AI), across their organizations, according to Dataiku. While the global survey of 400 respondents revealed broad enthusiasm and ...

Microsoft Catches Russian Government Hackers Phishing with Teams Chat App

Microsoft says a Russian government-linked hacking group is using its Microsoft Teams chat app to phish for credentials at targeted organizations. The post Microsoft Catches Russian Government Hackers Phishing with Teams Chat App appeared first ...

Cado Security Report Surfaces Most Common Cyberattack Vectors

A Cado Security analysis of cyberattack patterns found nearly every instance of an opportunistic attack started with a scan for vulnerabilities within SSH. The post Cado Security Report Surfaces Most Common Cyberattack Vectors appeared first on ...

SafeBreach and Recorded Future: Operationalizing Threat Intelligence with Breach and Attack Simulation

Combining threat intelligence with breach and attack simulation provides the context needed to identify and remediate threats quickly. The post SafeBreach and Recorded Future: Operationalizing Threat Intelligence with Breach and Attack Simulation ...

BSides Leeds 2023 – Sarah Young – Fantastic Cloud Security Mistakes

Thanks are in order to BSides Leeds for publishing their presenter’s outstanding BSides Leeds 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Leeds 2023 – Sarah Young – Fantastic Cloud ...

Black Hat Supply Chain Security Workshop

Which is more difficult – getting coffee and breakfast during Black Hat or securing hardware,firmware, and software below the OS from supply chain attacks? Answer: Neither is difficult if you attend the Eclypsium Supply Chain Security Workshop ...

Building a Robust Cybersecurity Framework: Key Elements and Implementation Strategies

In a world where we’re all connected, we reap the benefits of high-speed communication, nearly 24/7 resource access, and the ability to serve customers far and wide. We also accept the drawbacks, which include the ability of cybercriminals to ...

Torq Taps Generative AI to Automate SecOps Workflows

Torq today announced it is injecting additional generative artificial intelligence (AI) capabilities into its platform for automating security operations (SecOps) workflows. The post Torq Taps Generative AI to Automate SecOps Workflows appeared ...

Shield and Visibility Solutions Target Phishing From Inside the Browser

Menlo Security introduced anti-phishing solutions that analyze what users see on a landing page rather than just analyzing the content of an email. The post Shield and Visibility Solutions Target Phishing From Inside the Browser appeared first on ...

The Business Value of Trustworthy Data: Beyond Compliance

Every decision and action that affects your business is only as good as the data that supports it. This means the ability to achieve and sustain trustworthy data delivers value far beyond regulatory compliance.  Compliance: Just a Beginning You ...

Challenges In Post-Exploitation Workflows

In our previous post, we talked about the problem of structured data in the post-exploitation community. We touched on the existing relationship between our tools and data and covered some of the domain-specific challenges that come with ...

FraudGPT/WormGPT: Scammy for now — but a worrying signpost for software security

The post FraudGPT/WormGPT: Scammy for now — but a worrying signpost for software security appeared first on Security Boulevard.

TrustCloud & VanRein Compliance Partner to Make Compliance Accessible and Affordable

TrustCloud is thrilled to announce a partnership with VanRein Compliance, a leading managed compliance provider that builds and manages clients’ compliance programs via audits, custom policies and procedures, online training, and more.  ...

Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnarav – #253 – Team Cognitive Overload

via the respected Software Engineering expertise of Mikkel Noe-Nygaard as well as the lauded Software Engineering and Enterprise Agile Coaching talent of Luxshan Ratnarav at Comic Agilé! Permalink The post Comic Agilé – Mikkel ...

Cloud Providers Becoming Key Players in Ransomware, Halcyon Warns

There are a number of components that make up a ransomware campaign, from the initial access brokers (IABs) to ransomware-as-a-service (RaaS) affiliates to organizations that launder the cryptocurrency from the ransom payments. A report this week ...

Rezilion Showcasing Next Generation of Software Supply Chain Security at Black Hat USA, BSides Las Vegas 2023, and DEF CON 31

Rezilion, an automated software supply chain security platform, today announced its experts will present the new generation of vulnerability management and evolution of software composition analysis (SCA) and open-source tools looking towards the ...

How the global fraud-fighting community makes the internet safer for everyone

Discover why a platform approach, combined with global data and community, is the foundation of best-in-class Digital Trust & Safety.  The post How the global fraud-fighting community makes the internet safer for everyone appeared first on ...

Safeguarding Sensitive Data: Understanding Data Exchange Risks and the Importance of Data Passports | Eureka Security

In this blog post, we explore the concept of "data exchange," and then delve into the importance of “data passports” and how security leaders can implement them to bolster data protection strategy. | Eureka Security The post Safeguarding ...