Application Security News and Articles


Google Backs Creation of Cybersecurity Clinics With $20 Million Donation

Google CEO pledged $20 million in donations to support and expand the Consortium of Cybersecurity Clinics to introduce thousands of students to potential careers in cybersecurity The post Google Backs Creation of Cybersecurity Clinics With $20 ...

Four Steps to Securing Your Cloud

Reading Time: 6 minutes TAG Cyber and Sonrai Security have partnered to share a perspective on securing your cloud and your most critical business assets. The rapid adoption of cloud computing has brought about a new era of convenience and ...

Connected Devices Conspicuously Absent from 2023 Verizon Data Breach Investigations Report

The 2023 Verizon Data Breach Investigations Report is out. Like most folks in the cybersecurity industry, we downloaded it and pored over the contents to see what was new and relevant and surprising. As always, there’s a lot of data that ...

Randall Munroe’s XKCD ‘Bookshelf Sorting’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Bookshelf Sorting’ appeared first on Security Boulevard.

Understanding the Role of SCIM in SaaS, Workflow, and Identity Lifecycle Management

With the explosion of Software as a service applications, organizations are juggling a lot –... The post Understanding the Role of SCIM in SaaS, Workflow, and Identity Lifecycle Management appeared first on Entrust Blog. The post Understanding ...

Web Application Security Vulnerabilities

Web applications have become a vital part of any business, especially as many businesses continue to realize their digital transformations. As such, web application security vulnerabilities are security risks for businesses of all sizes, ...

US Military Personnel Receiving Unsolicited, Suspicious Smartwatches

The US army says soldiers says unsolicited, suspicious smartwatches are being sent to soldiers, exposing them to malware attacks. The post US Military Personnel Receiving Unsolicited, Suspicious Smartwatches appeared first on SecurityWeek.

Salesforce Misuse of Platform Cache Leads to Widespread Data Exposure 

Learn how Salesforce Platform Cache misuse is causing information disclosure in over 80% of implementations handling sensitive data. The post Salesforce Misuse of Platform Cache Leads to Widespread Data Exposure  appeared first on AppOmni. The ...

How to Delete Fake Facebook Accounts that Impersonate your Brand

Getting a Facebook post, profile, or page taken down because it impersonates your brand and could lead to the defrauding of your customers can seem like… The post How to Delete Fake Facebook Accounts that Impersonate your Brand appeared first ...

AI as Sensemaking for Public Comments

It’s become fashionable to think of artificial intelligence as an inherently dehumanizing technology, a ruthless force of automation that has unleashed legions of virtual skilled laborers in faceless form. But what if AI turns out to be the one ...

BSidesSF 2023 – Sal Olivares – How Segment Proactively Protects Customer’s API keys

Our thanks to BSidesSF for publishing their presenter’s superlative BSidesSF 2023 content on the organizations’ YouTube channel. Permalink The post BSidesSF 2023 – Sal Olivares – How Segment Proactively Protects Customer’s API ...

PyPI Attackers Still At It: Malicious Packages Drop Trojans and Info-stealers

This month, Sonatype’s automated malicious open source and malware detection systems flagged hundreds of malicious packages, 10 of which we have analyzed in this blog post. The post PyPI Attackers Still At It: Malicious Packages Drop Trojans ...

China-Linked APT15 Targets Foreign Ministries With ‘Graphican’ Backdoor

A Chinese hacking group flagged as APT15 is targeting foreign affairs ministries in the Americas with a new backdoor named Graphican. The post China-Linked APT15 Targets Foreign Ministries With ‘Graphican’ Backdoor appeared first on ...

News Alert: Cynomi launches first of its kind directory of virtual CISO providers

Tel Aviv, Israel, June 23, 2023 — The industry’s first-ever directory of virtual Chief Information Security Officer service providers has gone live today at www.thevcisodirectory.com. This extensive list of virtual CISO (vCISO) providers, ...

The Week in Security: BlackCat threatens to leak Reddit data, attackers target npm packages (again)

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond. This week: BlackCat hackers threaten ...

North Korean Hackers Caught Using Malware With Microphone Wiretapping Capabilities

A hacking group linked to the North Korean government has been caught using new malware with microphone wiretapping capabilities. The post North Korean Hackers Caught Using Malware With Microphone Wiretapping Capabilities appeared first on ...

Security Fixes Released for Node.js

New releases of the popular Node.js JavaScript framework are available to address multiple vulnerabilities. The post Security Fixes Released for Node.js appeared first on Flashpoint. The post Security Fixes Released for Node.js appeared first on ...

Exabeam appoints Adam Geller as CEO

Exabeam has unveiled that Adam Geller has been appointed as CEO. Michael DeCesare is stepping down as CEO and President, but will continue to serve as a Board advisor. Geller is a well-respected Silicon Valley leader who has built a 25-year ...

HYAS Protection for growing businesses

Securing SMB Success: The Indispensable Role of Protective DNS Cyber attacks pose as much risk to small and medium-sized businesses (SMBs) as they do to large organizations — if not more. Implementing a Domain Name Service (DNS) security ...

Resisting Identity-Based Threats With Identity Management

We all authenticate ourselves multiple times in a day, whether online shopping, logging into our bank account or booking flights. And with authentication, we confirm our digital identities so often that it doesn’t seem like a security action; ...