Application Security News and Articles


What is Domain Abuse?

Unraveling domain abuse: Exploring illicit activities and misuse of internet domains and email addresses for safer internet. The post What is Domain Abuse? appeared first on Security Boulevard.

Apache OpenMeetings Network Security Vulnerabilities

Apache OpenMeetings is an open-source application. Users employ it for web conferencing, presentations, and other collaborative work. However, researchers have identified several network security vulnerabilities that malicious actors might ...

ZTNA can be more than a VPN replacement for application access

In the wake of increased workforce mobility, today’s organizations require more innovative, more flexible, and more secure methods of granting network and application access to their workers. ZTNA adoption The encryption-based security approach ...

New infosec products of the week: July 28, 2023

Here’s a look at the most interesting products from the past week, featuring releases from BreachRx, Darktrace, Dig Security, Panorays, and SeeMetrics. Panorays unveils cybersecurity enhancements for supply chains Panorays announced two ...

Blocking access to ChatGPT is a short term solution to mitigate risk

For every 10,000 enterprise users, an enterprise organization is experiencing approximately 183 incidents of sensitive data being posted to ChatGPT per month, according to Netskope. Source code accounts for the largest share of sensitive data ...

National Cyber Strategy Implementation Plan: What you need to know

The Biden-Harris Administration’s recently released National Cybersecurity Strategy calls for two fundamental shifts in how the United States allocates roles, responsibilities, and resources in cyberspace. In this Help Net Security video, Kelly ...

CISOs consider zero trust a hot security ticket

The majority of organizations are on the road to implementing a zero trust framework to increase their overall security risk posture, according to PlainID. However, only 50% said that authorization makes up their zero trust program – ...

How scammers used SEO to disguise themselves as an electric utility

Summer is at its height, and it’s a good time to go sit by the pool with a glass of iced tea, go out and see that hugely promoted film in a nice cool theater, or maybe relax at home in your favorite chair…in front of the air ...

My Certified DevSecOps Professional (CDP) Course and Exam Experience

DevOps and DevSecOps are undoubtedly highly sought-after skills in the current job market. If you’re already involved in security in any…Continue reading on Medium »

Risks, Including the Defense, of Using Open-Source Software

Open-source software is widely used by many organizations as it helps to save costs. However, it is not without risks, and security professionals must take note of these risks to prevent cybersecurity breaches. In this blog post, we will discuss ...

Redefining Security: Going Beyond Compliance in Financial Organizations (Plus Memes!) 

Organizations often confuse the concept of being compliant with being secure. They assume that they must be appropriately protected once they have invested the necessary resources to achieve compliance. Considering that meeting compliance ...

US Senator Wyden Accuses Microsoft of ‘Cybersecurity Negligence’

Redmond is accused of “negligent cybersecurity practices” that enabled a successful Chinese hack of the United States government. The post US Senator Wyden Accuses Microsoft of ‘Cybersecurity Negligence’ appeared first on SecurityWeek.

BSides Leeds 2023 – Peter Jones – Practical Blue Teaming

Thanks are in order to BSides Leeds for publishing their presenter’s outstanding BSides Leeds 2023 security content on the organizations’ YouTube channel. Permalink The post BSides Leeds 2023 – Peter Jones – Practical Blue ...

Netography: Getting Beyond the ‘Black Box’ Approach to DDoS

Netography helps organizations understand emergent attacks across their Atomized Network, remediate them within hours, and improve DDoS resiliency. He even points to one notable example of helping a client under attack. The post Netography: ...

Growing AI-powered fraud highlights the need for advanced fraud detection

Discover how fraudsters exploit AI to conduct sophisticated scams and how businesses can stay safe with advanced fraud detection. The post Growing AI-powered fraud highlights the need for advanced fraud detection appeared first on Sift Blog. The ...

Randall Munroe’s XKCD ‘Bad Map Projection: ABS (Longitude)’

Permalink The post Randall Munroe’s XKCD ‘Bad Map Projection: ABS (Longitude)’ appeared first on Security Boulevard.

More malicious npm packages found in wake of JumpCloud supply chain hack

Two weeks after the IT management firm JumpCloud announced that it was the victim of a supply chain attack aimed at a small population of customers in the cryptocurrency industry, an investigation by ReversingLabs researchers has uncovered ...

A Fraud Risk Management Guide for Savvy Businesses

Fraud is a pervasive threat to any organization’s viability and sustainability, with fraudsters continually seeking innovative ways to deceive and steal from businesses. To protect themselves and their customers, it’s critical for businesses ...

Supply Chain and Firmware Security Take Center Stage in 2024 NDAA

Every year, Congress passes the National Defense Authorization Act (NDAA), which sets the budget and defines key policy priorities for the U.S. Department of Defense (DoD). This legislation plays a crucial role in shaping the defense priorities ...

The Week in Security: North Korean APT targets developers, this Barbie is a cybercriminal

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond. This week: a North Korean APT group ...