Application Security News and Articles


A Brief Overview of U.S Cyber Command’s Global Cyberspace Operations Synchronization (GCOS) Concept – Or Can We Make The Difference Between Real-Time and Synchronization in Cyberspace?

It should be clearly said that the current state of the U.S Cyber Command's overall Global Cyberspace Operations Synchronization (GCOS) Concept is fairly naïve and a bit childish in the context of what I can best describe as real-time cyberspace ...

The Ransomware "Epidemic" – Or How To Strike Back?

Not only did we live to see it we're actually living and taking actions one way or another to see it and yes it's the ransomware "epidemic" that I'm referring to and which I'll try to expose in this post by not only providing the typical for me ...

Qakbot: The trojan that just won’t go away

Qakbot (aka Qbot) – banking malware-turned-malware/ransomware distribution network – has been first observed in 2007 and is active to this day. The neverending adaptability of this threat is key to its long-term survival and success. ...

The rise and fall of ransomware: Insights from Avast’s Q1/2023 Threat Report

What’s on your computer right now?  Let’s make a list. Start with every work-related document you’ve used or created in the last six months. After that, perhaps your monthly budgets, pictures from your last vacation, all your passwords (in ...

New infosec products of the week: June 2, 2023

Here’s a look at the most interesting products from the past week, featuring releases from Bitdefender, ConnectSecure, CYTRACOM, Permit.io, and PingSafe. Permit.io launches FoAz to give frontend developers the keys to security Short for ...

How defense contractors can move from cybersecurity to cyber resilience

As the world’s most powerful military and economic power, the United States also holds another, less impressive distinction: Cyber threat actors target the US more than any other country in the world. In 2022 alone, the FBI received more than ...

Introducing the book: Cybersecurity First Principles

In this Help Net Security video interview, Rick Howard, CSO of N2K, Chief Analyst, and Senior Fellow at the Cyberwire, discusses his book – Cybersecurity First Principles: A Reboot of Strategy and Tactics. In the book, Howard challenges the ...

Google Temporarily Offering $180,000 for Full Chain Chrome Exploit

Google is offering a bug bounty reward of up to $180,000 for a full chain exploit leading to a sandbox escape in the Chrome browser. The post Google Temporarily Offering $180,000 for Full Chain Chrome Exploit appeared first on SecurityWeek.

Cybercriminals use legitimate websites to obfuscate malicious payloads

According to Egress, the evolving attack methodologies currently used by cybercriminals are designed to get through traditional perimeter security. “The evolution of phishing emails continues to pose a major threat to organizations, emphasizing ...

Despite cutbacks, IT salaries expected to rise

Despite rising labor costs, economic inflation, and companies making an effort to cut back, the salary outlook for IT professionals is positive, according to InformationWeek. Work-life balance and base pay top the list as what matters most to IT ...

App owners: Benefits of externalizing authentication & authorization

With cloud modernization, one of the most significant challenges for app owners is managing identity and authentication, which can divert attention from creating an exceptional product. For app owners and developers, it means continually juggling ...

What is Data Loss Prevention (DLP)? And How Low-Code Security Automation Can Help 

The post What is Data Loss Prevention (DLP)? And How Low-Code Security Automation Can Help  appeared first on Low-Code Security Automation & SOAR Platform | Swimlane. The post What is Data Loss Prevention (DLP)? And How Low-Code ...

What is the Gartner Hype Cycle for Security Products? Demystifying the Hype Cycle for CDR

In information security, technologies change very quickly. Security has a fast cycle of innovation: product builders launch new products quickly, adapting to the needs of the market and cybersecurity defenders, with the expectation that these ...

What is interception fraud? How to detect & prevent interception fraud.

Want to know what interception fraud is? Discover what it is & how you can prevent interception fraud from affecting your business. The post What is interception fraud? How to detect & prevent interception fraud. appeared first on ...

Uncovering the Hidden Risks of Mobile Device Security

Organizations often encounter issues when trying to implement best practices in mobile device security while also ensuring a seamless user experience. This is because end users can be hesitant to install additional apps on their mobile device, ...

What is Deepfake Technology and How Are Threat Actors Using It?

Deepfake technology is a form of artificial intelligence that employs machine learning algorithms to generate realistic media content. The post What is Deepfake Technology and How Are Threat Actors Using It? appeared first on Flashpoint. The post ...

The K-12 Guide to CIPA Compliant Content Filters

At any given moment of any random school day, chances are high that your students are online. No big deal, right? Think again. Internet access is just as dangerous as it is beneficial to your digital school system. Whether in the classroom or at ...

BSidesSF 2023 – Arjun Chakraborty – NLP For Security Log Analysis: Learning To Crawl Before You Run

Our thanks to BSidesSF for publishing their presenter’s superlative BSidesSF 2023 content on the organizations’ YouTube channel. Permalink The post BSidesSF 2023 – Arjun Chakraborty – NLP For Security Log Analysis: Learning To ...

Private APIs at Risk: Q1-2023 API ThreatStats™ Report

According to a Mar-2022 API survey by Gartner, 98% of organizations use or are planning to use internal APIs – up from 88% in 2019. And 90% of organizations use or are planning to use private APIs provided by partners – up from 68% in 2019. ...

How to Improve Your Software Supply Chain with a Software Security Framework

Just like a car manufacturer must ensure every component that goes into their vehicles is safe and reliable, you should ensure all of the components in the software you produce are secure and free from defects, especially with software supply ...