Application Security News and Articles


In the News | After a Cyber Attack: Dos and Don’ts for Higher Education IT Staff

This article was originally published in Campus Technology on 5.10.23 by Charlie Sander, CEO at ManagedMethods. For most colleges and universities, it’s a question of when, not if, they will experience a cyber attack. Here are seven key ...

Do you Know how to Protect Against Ransomware in 2023?

Do you Know how to Protect Against Ransomware in 2023? Ransomware has quickly become one of the biggest cyberthreats facing any business. Over the last couple of years, this type of attack has hugely grown in profile. Yet the ransomware attacks ...

Author Q&A: Former privacy officer urges leaders to prioritize security as part of cloud migration

Cyber threats have steadily intensified each year since I began writing about privacy and cybersecurity for USA TODAY in 2004. Related: What China’s spy balloons portend A stark reminder of this relentless malaise: the global cyber security ...

The root causes of API incidents and data breaches

API calls make up the majority of our digital lives. Take, for example, the everyday use of a cloud-based food delivery app, which could involve up to 25 API calls. Between the order being placed, transmission to the restaurant, the coordination ...

Penetration tester develops AWS-based automated cracking rig

Building a custom cracking rig for research can be expensive, so penetration tester Max Ahartz built one on AWS. In this Help Net Security interview, he takes us through the process and unveils the details of his creation. What motivated you to ...

Generative AI: The new attack vector for trust and safety

Threat actors are abusing generative AI to carry out child sex abuse material (CSAM), disinformation, fraud and extremism, according to ActiveFence. “The explosion of generative AI has far-reaching implications for all corners of the ...

Organizations spend 100 hours battling post-delivery email threats

Nearly every victim of a spear-phishing attack in the last 12 months saw impacts on their organization, including malware infections, stolen data, and reputational damage, according to Barracuda Networks. Barracuda Networks research finds 24% of ...

VPN and Wi-Fi Security: Why You Need Full Protection

The concept of using a Virtual Private Network (VPN) is not new - but in 2023, there are even more reasons why you need to implement a VPN on your device. The post VPN and Wi-Fi Security: Why You Need Full Protection appeared first on Security ...

How to Secure Your SCM Repositories with GitGuardian Honeytokens

Protect your code and secure your repositories with honeytokens. Learn how to create and add these digital traps to your SCM repositories and how GitGuardian helps you stay alert to potential threats. Read on for best practices and tips to make ...

How IT/OT Cybersecurity Threats are Growing in Volume and Scope

As we reach the middle of 2023, OT cybersecurity threats are getting more prevalent The manufacturing sector is fast becoming a hotbed for cyberattacks, with threat actors focusing their efforts on Operational Technology (OT) cybersecurity teams. ...

API7:2019 Security Misconfiguration: The What, Sample Exploits, and Prevention Methods

Security misconfigurations are very common security risks, not just in web applications but also in APIs. They have been consistently part of the OWASP Top 10 Web Application Vulnerabilities. They. The post API7:2019 Security Misconfiguration: ...

From Data Chaos to Data Mastery How to Build and Scale Data Lakes with AWS Services

In today’s data-driven world, organizations are faced with an ever-increasing volume of data from various sources. To extract meaningful insights and drive informed decision-making, it is essential to have a well-structured and scalable data ...

Protecting your business: Advice to SMB CEOs from a former CIO

The acronym CIO is sometimes understood to stand for “Career Is Over,” and here’s why: Business leaders in charge of information technology are not only tasked with driving automation, productivity, business intelligence, digitization, and ...

The Top Threats to Cloud Infrastructure Security and How to Address Them

Cloud computing has become a critical technology for businesses of all sizes. It offers many benefits, including cost savings, scalability, and flexibility. However, the security of cloud infrastructure is still a concern for many organizations. ...

United States of America: Memorial Day 2023

Photograph Courtesy of the United States Marine Corps, Photographer: Caitlin Brink, CPL, USMC Permalink The post United States of America: Memorial Day 2023 appeared first on Security Boulevard.

Essential security practices in OT control systems

Operational Technology (OT) security controls include the measures, workflows and procedures put in place to protect various OT systems from cyber threats. OT systems are used to control, run and monitor critical infrastructure, such as those in ...

CISO-approved strategies for software supply chain security

Integrating proprietary and open-source code, APIs, user interfaces, application behavior, and deployment workflows creates an intricate composition in modern applications. Any vulnerabilities within this software supply chain can jeopardize your ...

Top public cloud security concerns for the media and entertainment industry

Media and entertainment (M&E) companies are rapidly turning to cloud storage in efforts to upgrade their security measures, according Wasabi. Survey findings highlighted that, while M&E organizations are still relatively new to cloud ...

Meta’s $1.3 Billion Fine, AI Hoax Hysteria, Montana’s TikTok Ban

In this episode, we discuss Meta’s record-breaking $1.3 billion fine by the EU for unlawfully transferring user data, shedding light on the increasing risks faced by tech companies in violating privacy rules. Highly realistic images of a ...

Company size doesn’t matter when it comes to cyberattacks

65% of organizations in the enterprise sector suffered a cyberattack within the last 12 months, which is similar to the results among companies of all sizes (68%), according to Netwrix. Larger organizations are a more frequent target for ...