Application Security News and Articles


Preparing for federal supply chain security standardization

In 2021, the Biden Administration published the Executive Order on Improving the Nation’s Cybersecurity (EO 14028), setting off an agency-wide security initiative with the ultimate objective of standardizing security requirements across the ...

Run Static Application Security Testing (SAST) for Terraform AWS Code Using tfsec in GitHub Actions

Static Application Security Testing (SAST), as quoted from article from Aqua Security is a code testing tool that analyzes application…Continue reading on AWS in Plain English »

Malicious open-source components threatening digital infrastructure

A new risk emerges in the digital era, where open-source software has become a fundamental pillar in developing innovative applications. The threat? Malicious open-source components. In this Help Net Security video, Henrik Plate, Lead Security ...

Infamous cybercrime marketplace offers pre-order service for stolen credentials

Infostealer malware, which consist of code that infects devices without the user’s knowledge and steals data, remains widely available to buy through underground forums and marketplaces, with the volume of logs, or collections of stolen data, ...

The CIS Benchmarks Community consensus process

The Center for Internet Security (CIS) recently celebrated 20 years of bringing confidence to the connected world with consensus-based security guidance. The first CIS Benchmark was released in 2000. Today, there are more than 100 CIS Benchmarks ...

New: Dynamic Application Security Testing (DAST) (Beta)

Experience streamlined security analysis with our DAST product update, simplifying vulnerability detection and mitigation. The post New: Dynamic Application Security Testing (DAST) (Beta) appeared first on GuardRails. The post New: Dynamic ...

The Future of Cloud Computing is Under the Sea

The underwater data center is an innovative and sustainable solution for the growing demands of cloud computing. In this blog post, we will explain what underwater data centers are, why they are beneficial for the environment and the economy, and ...

Gmail now offers a new checkmark for emails enabled with Verified Mark Certificates and BIMI

Entrust Verified Mark Certificates (VMCs) are digital certificates that enable organizations to create a more... The post Gmail now offers a new checkmark for emails enabled with Verified Mark Certificates and BIMI appeared first on Entrust ...

Overcoming the Top Compliance Challenges (or Headaches) Faced by Leaders and Teams

Discover the most common challenges and pitfalls of compliance management and how you can avoid them. The post Overcoming the Top Compliance Challenges (or Headaches) Faced by Leaders and Teams appeared first on Scytale. The post Overcoming the ...

CactusCon 11 – Day 2 (1/28) Track 1

Arizona) for publishing their presenter’s outstanding CactusCon 11 Conference content on the organizations’ YouTube channel. Additionally, CactusCon is a Tax Exempt 501(c)3 organization accredited through the United States Internal Revenue ...

Cactus Ransomware: A Thorny New Threat on the Horizon

What is Cactus Ransomware? Unleashing a prickly assault on the cyber landscape, the recently discovered Cactus Ransomware has been actively wreaking havoc since March 2023. Its unique moniker, “Cactus”, is derived from the filename linked to ...

COURT DOC: Ransomware Charges Unsealed Against Russian National

An indictment was unsealed today in the District of Columbia charging a Russian national with participating in a global ransomware campaign which deployed ransomware variants against victims in the District of Columbia, the United States, and ...

From DA to EA with ESC5

There’s a new, practical way to escalate from Domain Admin to Enterprise Admin. ESC5 You’ve heard of ESC1 and ESC8. But what about ESC5? ESC5 is also known as “Vulnerable PKI Object Access Control”. Will Schroeder and Lee Christensen’s ...

Aqua Security launches Real-Time CSPM to help teams focus on critical threats

Aqua Security has launched Real-Time CSPM, a next-gen cloud security posture management (CSPM) solution, which provides a complete view of multi-cloud security risk, pinpoints threats that evade agentless detection, and reduces noise so security ...

Compromise Detection vs. Threat Detection: Why ‘Right of Boom’ Now

In the past, the focus has been on threat detection to prevent attacks, but in the modern Atomized Network it becomes impossible to guard against everything. Instead there should be a focus on compromise detection for the period during and after ...

ChatGPT’s Chief Testifies Before Congress, Calls for New Agency to Regulate Artificial Intelligence

The head of OpenAI, which makes ChatGPT, told Congress that government intervention “will be critical to mitigate the risks of increasingly powerful” AI systems. The post ChatGPT’s Chief Testifies Before Congress, Calls for New Agency to ...

Scality ARTESCA 2.0 strenghtens ransomware protection

Scality announced its newest release of Scality ARTESCA, its secure S3 object storage software for data deployments starting at a few terabytes. Over a dozen innovations in ARTESCA 2.0 strengthen cyber resiliency through a hardened, reduced ...

Circle Security and ForgeRock join forces to enhance clients’ digital security posture

Circle Security has unveiled a joint integration with the ForgeRock Identity Platform. The pre-built on-premises integrated node will help businesses stay ahead of evolving threats and achieve their security goals by integrating identity ...

Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnarav – #236 — The Mental Load (Mother’s Day Special)

via the respected Software Engineering expertise of Mikkel Noe-Nygaard as well as the lauded Software Engineering and Enterprise Agile Coaching talent of Luxshan Ratnarav at Comic Agilé! Permalink The post Comic Agilé – Mikkel ...

Island Self-Protection provides secure browsing in challenging environments

Island announced Self-Protection for the Enterprise Browser, delivering a fundamentally new approach and level of security to enterprise work. Island has introduced the ideal solution for organizations with extremely sensitive data and ...