Application Security News and Articles


Adopting Zero Trust: Continuous Trust

Listen now (30 min) | Season two, episode 12: Live from Drataverse we chat with Drata's Daniel Marashlian and Matt Hillary, and Vercel's CISO and SVCI angel investor Ty Sbano. The post Adopting Zero Trust: Continuous Trust appeared first on ...

SIEM Integration on the Indusface WAS

With SIEM integration, push logs from Indusface WAS into your SIEM platform, enabling in-depth analysis of security data for deeper insights. The post SIEM Integration on the Indusface WAS appeared first on Indusface. The post SIEM Integration on ...

APT Exploit Targeting Rockwell Automation Flaws Could Threaten Critical Infrastructure

Two Rockwell Automation product vulnerabilities have been used for a new exploit by an APT group that could use it to target critical infrastructure. The post APT Exploit Targeting Rockwell Automation Flaws Could Threaten Critical Infrastructure ...

Prioritizing Actionable Insights: The Power of Effective Continuous Control Monitoring Combined with CRQ | Kovrr blog

Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post Prioritizing Actionable Insights: The Power of Effective Continuous Control Monitoring Combined with CRQ | Kovrr blog appeared first on Security ...

Resolving the Identity Protection Gaps in APRA’s Resilience Assessment’s Findings 

The Australian Prudential Regulation Authority (APRA) recently published findings from a study examining the level of cybersecurity resilience of its regulated entities, which revealed an alarming number of security gaps. In this blog we take a ...

Combatting data governance risks of public generative AI tools

When companies utilize public generative AI tools, the models are refined on input data provided by the company. Regarding data security, unauthorized use of sensitive data or the accidental exposure of proprietary information can lead to ...

Attack Surface Management: Identify and protect the unknown

In this Help Net Security video, Brianna McGovern, Product Manager, Attack Surface Management, NetSPI, discusses Attack Surface Management (ASM). Attack Surface Management detects known, unknown, and potentially vulnerable public-facing assets ...

20% of malware attacks bypass antivirus protection

Security leaders are concerned about attacks that leverage malware-exfiltrated authentication data, with 53% expressing extreme concern and less than 1% admitting they weren’t concerned at all, according to SpyCloud. However, many still lack ...

Infrastructure upgrades alone won’t guarantee strong security

While 75% of organizations have made significant strides to upgrade their infrastructure in the past year, including the adoption of public cloud hosting and containerization, and 78% have increased their security budgets, only 2% of industry ...

Only 45% of cloud data is currently encrypted

39% of businesses have experienced a data breach in their cloud environment last year, an increase on the 35% reported in 2022, according to Thales. In addition, human error was reported as the leading cause of cloud data breaches by 55% of those ...

COURT DOC: Tracy Resident Charged With Computer Attack On Discovery Bay Water Treatment Facility

A federal grand jury has indicted Rambler Gallo, charging him with intentionally causing damage to a protected computer after he allegedly accessed the computer network for the Discovery Bay Water Treatment Facility, causing a threat to public ...

Data Trustworthiness in the Energy Industry: Challenges, Risks, and Recommendations

By downloading this executive brief on “Data Trustworthiness in the Energy Industry: Challenges, Risks, and Recommendations,” you gain valuable insights into the following key areas: Understand the unique challenges faced by energy companies ...

Letter to Customers: RiskLens Joins Forces with Safe Security to Accelerate CRQ

We are excited to share that RiskLens has been acquired by Safe Security, the real-time Cyber Risk Management company. The two market leaders are coming together to build the world’s most automated, trusted, and actionable set of Cyber Risk ...

The Ultimate Security Questionnaire Guide for Vendors

New to responding to Security Questionnaires? You’ve come to the right place! Welcome to our guide on Security Questionnaires (SQs)! We’ll cover everything you need to know about SQs, including a complete breakdown of what they’re all ...

NETSCOUT Uses Machine Learning to Help Thwart DDoS Attacks

NETSCOUT Systems is is dynamically applying machine learning algorithms to combat distributed denial-of-service (DDoS) attacks. The post NETSCOUT Uses Machine Learning to Help Thwart DDoS Attacks appeared first on Security Boulevard.

Choosing The Right Certificate Lifecycle Management Solution For Your Organization

It’s no secret that in competitive situations vendors present comparison information to help influence buying decisions. This comparison information is often feature or functionality based with some FUD (fear, uncertainty and doubt) thrown in. ...

BSides Knoxville 2023 – Connor Gannon – Summoning Angels In The Modern Age: Digitizing The Methods Of Steganographia

Our thanks to BSides Knoxville for publishing their presenter’s outstanding BSides Knoxville 2023 content on the organizations’ YouTube channel. Permalink The post BSides Knoxville 2023 – Connor Gannon – Summoning Angels In The ...

Orca Sues Wiz Over Alleged Cloud Security Patent Violations

Orca Security sues its main rival, claiming patent infringements, intellectual property theft and even marketing copycat behavior. The post Orca Sues Wiz Over Alleged Cloud Security Patent Violations appeared first on SecurityWeek.

What Your Auditor Looks for in Your Risk Management Process

TrustCloud teamed up with Dansa D’Arata Soucia on our Risk Rodeo webinar, to discuss everything you need to know to wrangle up risks with confidence.  Our panelists weighed in on the four things that auditors look for in risk management ...

Patch Tuesday Update – July 2023

Welcome to this month’s edition of the Patch Tuesday release analysis. Here in the US, we’ve just finished celebrating our nation’s freedom. Wouldn’t it be nice if we could all globally celebrate freedom from security vulnerabilities? ...