Application Security News and Articles


Behind the Breach: Phishing & Token Compromise in SaaS Environments

Earlier this year, Gartner published a new research report focused on the human component of cybersecurity which explored trends around cybersecurity leadership, challenges with hiring, and attacks targeting individuals. One notable ...

5 Data Loss Prevention Statistics You Should Know About

The tide of tainted data is growing as more businesses suffer severe security breaches. According to statistics on data breaches, money is a major driving force for hackers to acquire data, and personal information is one of the most valuable ...

BSidesSF 2023 – Tanya Janca – Secret Hunting

Our thanks to BSidesSF for publishing their presenter’s superlative BSidesSF 2023 content on the organizations’ YouTube channel. Permalink The post BSidesSF 2023 – Tanya Janca – Secret Hunting appeared first on Security Boulevard.

‘Wagner Mercenary’ Hackers Destroy Russian Satellite Comms

Dozor-Teleport hack, vandalism and data breach. But is it a Ukrainian false flag op? The post ‘Wagner Mercenary’ Hackers Destroy Russian Satellite Comms appeared first on Security Boulevard.

Human Risk Management vs Security Awareness: What’s the Difference?

The post Human Risk Management vs Security Awareness: What’s the Difference? appeared first on Click Armor. The post Human Risk Management vs Security Awareness: What’s the Difference? appeared first on Security Boulevard.

Learn FAIR Quantitative Analysis for AI Risk in a Virtual Workshop

Artificial intelligence (AI) poses novel and powerful cyber threats both external and internal to your organization – but don’t fall into FUD. With the proven techniques of Factor Analysis of Information Risk (FAIR™), you can quantitatively ...

Webinar Recap: Analyzing and Reporting Risks for MSPs and MSSPs: Introducing Seceon aiSecurity Score360 and aiSecurity BI360 with Seceon and partner, Logically

Webinar Recap: Analyzing and Reporting Risks for MSPs and MSSPs: Introducing Seceon aiSecurity Score360 and aiSecurity BI360 with Seceon and partner, Logically The post Webinar Recap: Analyzing and Reporting Risks for MSPs and MSSPs: Introducing ...

Vendor Risk Assessments: 3 Common Mistakes to Avoid

Few organizations can perform their daily tasks and operations without vendors and third-party partners. And even if they could, successful businesses understand that working with others provides a better experience than doing it alone.  The ...

Randall Munroe’s XKCD ‘Real Estate Analysis’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Real Estate Analysis’ appeared first on Security Boulevard.

Applying Zero-Trust Principles: Case Studies and Lessons From the Field

The Advanced Cyber Security Center interviewed members to understand how they implemented zero-trust and what lessons they could share with others seeking to do the same.  The post Applying Zero-Trust Principles: Case Studies and Lessons From ...

Defending against malicious packages in the npm ecosystem and beyond

Learn how to shield your organization from the danger of malicious packages in the npm ecosystem and beyond.  The post Defending against malicious packages in the npm ecosystem and beyond appeared first on Security Boulevard.

Exploring the Controversy: The Pros and Cons of Environment Variables – PyCon Italia

Using environment variables to store secrets has long been considered a good practice. But in this article, we will explore different opinions as to why using env vars might be either good or bad for security The post Exploring the Controversy: ...

BSidesSF 2023 – Dean Liu – Disrupting Malicious Traffic with Egress Proxies

Our thanks to BSidesSF for publishing their presenter’s superlative BSidesSF 2023 content on the organizations’ YouTube channel. Permalink The post BSidesSF 2023 – Dean Liu – Disrupting Malicious Traffic with Egress Proxies ...

The Health Informatics Service Deploys LogRhythm Axon to Secure Healthcare Innovation in the UK

London, UK, 29 June 2023 — LogRhythm, the company helping security teams stop breaches by turning disconnected data and signals into trustworthy insights, has partnered with The Health Informatics Service (THIS), an innovative, ...

In Other News: Hospital Infected via USB Drive, EU Cybersecurity Rules, Free Security Tools

Weekly cybersecurity news roundup that provides a summary of noteworthy stories that might have slipped under the radar for the week of June 26, 2023. The post In Other News: Hospital Infected via USB Drive, EU Cybersecurity Rules, Free Security ...

Attain Insight Security 4X 4.0 strengthens data protection for enterprises

Attain Insight released Attain Insight Security 4X version 4.0, an upgrade to its flagship security software. This latest release introduces new features and enhancements designed to fortify data protection, streamline compliance processes, and ...

The Cloud Security Risks of Overprivileged Vendors

Onboarding new software and SaaS vendors in the cloud presents a new set of security challenges for a lot of organizations. The post The Cloud Security Risks of Overprivileged Vendors appeared first on Security Boulevard.

Hand out a Yellow or Red Card According to Your Rules of the Game

In Radware’s Cloud WAF solution, your application is protected from a virus violation, including other infractions like remote file inclusions, SQL injections, security misconfiguration, sensitive data exposure, broken access control, ...

200,000 WordPress Sites Exposed to Attacks Exploiting Flaw in ‘Ultimate Member’ Plugin

Attackers exploit critical vulnerability in the Ultimate Member plugin to create administrative accounts on WordPress websites. The post 200,000 WordPress Sites Exposed to Attacks Exploiting Flaw in ‘Ultimate Member’ Plugin appeared ...

The Virtual Digital Stranger: What ChatGPT Means for Network Security

Just as we exercise caution around human strangers until they have gained our trust, we should approach these new, AI-based virtual digital strangers the same way. The post The Virtual Digital Stranger: What ChatGPT Means for Network Security ...