Application Security News and Articles


Seceon Expands Leadership Team with William Toll as VP of Marketing to Serve MSP and MSSP Communities

Experienced marketing and IT channel leader joins the AI and ML-powered cybersecurity platform provider to accelerate growth and support partners as they expand their security services. The post Seceon Expands Leadership Team with William Toll as ...

NTT DATA case study | Contrast Security

Contrast Security, the code security platform built for developers and trusted by security, has successfully implemented Contrast Assess — Contrast’s leading Interactive Application Security Testing (IAST) solution — for NTT DATA, a trusted ...

CISA’s Ransomware Vulnerability Awareness Pilot: But Is It Enough?

In early 2023, CISA launched their Ransomware Vulnerability Awareness Pilot (RVWP). It’s designed to warn critical infrastructure (CI) entities that their systems have exposed vulnerabilities that may be exploited by ransomware threat actors. ...

‘Extinction risk’: Could code-writing AI wipe out humans via software backdoors?

Industry luminaries are warning of near-imminent doom unless AI is tamed. Given that today’s generative AI models are writing semi-decent code, shouldn’t we worry we’re preparing the ground for Skynet? The post ‘Extinction risk’: Could ...

Randall Munroe’s XKCD ‘Wikipedia Article Titles’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Wikipedia Article Titles’ appeared first on Security Boulevard.

Seceon to Participate In AGC Partners’ 2017 Boston Technology Growth Conference

Seceon will again be participating with AGC Partners in its 14th Annual Boston Technology Growth Conference to be held on Thursday, November 9th. The AGC Partner Conference is a premier showcase for fast growing, predominantly private technology ...

Identity Attack Watch: AD Security News, May 2023

As cyberattacks targeting Active Directory continue to rise, AD security, identity, and IT teams face mounting pressure to monitor the evolving AD-focused threat landscape. To assist IT professionals in comprehending... The post Identity Attack ...

Seceon to Participate In AGC Partners’ 2017 Boston Technology Growth Conference

Seceon will again be participating with AGC Partners in its 14th Annual Boston Technology Growth Conference to be held on Thursday, November 9th. The AGC Partner Conference is a premier showcase for fast growing, predominantly private technology ...

Barracuda Patches Zero-Day in Email Security Gateways (ESG)

Barracuda, a prominent enterprise security firm, recently shared details regarding a serious vulnerability that malicious actors had leveraged to compromise its Email Security Gateway (ESG) appliances since October 2022.   What does Barracuda ...

Rezilion Smart Fix improves software supply chain security

Rezilion released its new Smart Fix feature in the Rezilion platform, which offers critical guidance so users can understand the most strategic, not just the most recent, upgrade to fix vulnerable components. Patching is a complicated and noisy ...

What Are Cyber-Physical Systems?

Paradigmatic shifts are often not fully recognized until after they have occurred. Innovations are made, evolutions take place, and then someone realizes, “Hey, this is much different from when it started.” That’s when people start to ...

Bitdefender GravityZone Security for Mobile provides protection against mobile attack vectors

Bitdefender unveiled GravityZone Security for Mobile, designed to provide organizations with advanced Mobile Threat Detection (MTD) and security for Android, iOS and Chromebook devices, including Chrome extensions. The new offering helps ...

BSidesSF 2023 – Nolan Reisbeck – Certificate Transparency Logs: Roadmaps to Riches or Ruin?

Our thanks to BSidesSF for publishing their presenter’s superlative BSidesSF 2023 content on the organizations’ YouTube channel. Permalink The post BSidesSF 2023 – Nolan Reisbeck – Certificate Transparency Logs: Roadmaps to ...

RSAC Fireside Chat: Reinforcing ‘Identity and Access Management’ to expose ‘shadow access’

The world of Identity and Access Management (IAM) is rapidly evolving. Related: Stopping IAM threats IAM began 25 years ago as a method to systematically grant human users access to company IT assets. Today, a “user” most often … (more…) ...

php[tek] 2023 – A Community Of Communities Powering The Internet

The PHP community came together in Chicago for php[tek] 2023, sharing best practices and the latest updates from the language and frameworks that run over 77% of the internet The post php[tek] 2023 – A Community Of Communities Powering The ...

An Enterprise Guide: Periodic Cloud Security Risk Assessments

As cloud adoption continues to grow, periodic cloud security risk assessments should be high on your organization’s priority list.  The post An Enterprise Guide: Periodic Cloud Security Risk Assessments appeared first on Security Boulevard.

Entrust Digital Card Solution launches new In-app Provisioning extension for Apple Pay

Consumer demand for intuitive digital services has changed the way we approach everything, including banking.... The post Entrust Digital Card Solution launches new In-app Provisioning extension for Apple Pay appeared first on Entrust Blog. The ...

Permit.io launches FoAz to give frontend developers the keys to security

Permit.io has launched FoAz which enables frontend developers to take access controls into their own hands. Short for frontend-only authorization, FoAz is a technology that empowers frontend developers to use sensitive APIs directly from the ...

External Attack Surface Management: How Focusing on Basics Improves Security

External attack surface management (EASM) has become a vital strategy for improving cybersecurity, particularly amid recession fears that have stressed the business landscape across several sectors for many months. The task is now more ...

Someone is roping Apache NiFi servers into a cryptomining botnet

If you’re running an Apache NiFi instance exposed on the internet and you have not secured access to it, the underlying host may already be covertly cryptomining on someone else’s behalf. The attack Indicators of the ongoing campaign ...