Application Security News and Articles


Is human threat hunting a fool’s errand?

We all have witnessed automated advances creep into our modern threat hunting processes – and with good reason. As the rate of cyberattacks steadily increases, automated threat hunting processes are being integrated to help stem the tide by ...

Setting up an OT-ICS Incident Response Plan 

Operational Technology (OT) and Industrial Control System (ICS) are the backbones of critical infrastructure that controls and monitor physical processes. They are used in a wide range of industries, including energy, manufacturing, and ...

SHARED INTEL: From airbags to malware: vehicle cyber safety arises in the age of connected cars

In an increasingly interconnected world, the evolution of the automotive industry presents an exciting yet daunting prospect. Related: Privacy rules for vehicles As vehicles continue to offer modern features such as app-to-car connectivity, ...

Private Tweets Exposed, Unauthorized Tracking Collaboration, AI Risks and Regulation

In this episode we discuss a recent Twitter security incident that caused private tweets sent to Twitter Circles to become visible to unintended recipients. Next, we discuss the collaboration between Apple and Google to develop a specification ...

Web entity activity reveals insights into internet security

For its recent research focusing on web entities (or content served over HTTP), Censys leveraged its internet-wide scan data to understand better the applications and services that have become core to our existence, evaluating the state of ...

Bad bots are coming for APIs

In 2022, 47.4% of all internet traffic came from bots, a 5.1% increase over the previous year, according to Imperva. The proportion of human traffic (52.6%) decreased to its lowest level in eight years. Bad bot traffic For the fourth consecutive ...

Role of threat intelligence in OT security: Best practices and use cases

In today’s interconnected world, operational technology (OT) systems play a crucial role in industries such as manufacturing, energy, and transportation. However, with increased connectivity comes the risk of cyber threats targeting these ...

USENIX Enigma 2023 – Kelly Shortridge – ‘The Very Hungry Defender: Metamorphosing Security Decision-Making By Incorporating Opportunity Cost’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Enigma ’23 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Enigma 2023 – Kelly Shortridge – ‘The Very Hungry ...

Week in review: Microsoft fixes two actively exploited bugs, MSI private code signing keys leaked

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Dragos blocks ransomware attack, brushes aside extortion attempt A ransomware group has tried and failed to extort money from Dragos, the ...

The Ultimate Guide to Multi-Factor Authentication

The Ultimate Guide to Multi-Factor Authentication The Ultimate Guide to Multi-Factor Authentication The Importance of Multi-Factor Authentication The Importance of Multi-Factor Authentication In today’s digital age, the security of sensitive ...

Scam Intercepters – some thoughts

Despite no longer being paid to provide consultancy to the IT security industry, I couldn’t resist catching up with an interesting BBC initiative called Scam Interceptors. Having been appalled in the past when Click actually bought a botnet*, ...

Abusing Communities

I may need to give up social media altogether. I can’t seem to avoid seeing scams in all directions, and I can’t seem to ignore them, even though writing about this stuff is no longer my living. Perhaps it’s a curse, or the result of a ...

USENIX Enigma 2023 – Josiah Dykstra – ‘The Slippery Slope Of Cybersecurity Analogies’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Enigma ’23 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Enigma 2023 – Josiah Dykstra – ‘The Slippery Slope Of ...

Executive Fired From TikTok’s Chinese Owner Says Beijing Had access to App Data in Termination Suit

Former TikTok executive said China government officials maintained access to all company data, including information stored in the United States. The post Executive Fired From TikTok’s Chinese Owner Says Beijing Had access to App Data in ...

Hammerspace acquires Rozo Systems to help users accelerate data analytics

Hammerspace acquires Rozo Systems to expand the performance and hyperscale capacity capabilities of its unstructured Data Orchestration System. Data-driven organizations have rapidly become more decentralized, with files being created, analyzed, ...

Congrats on your SOC 2 Report! Here’s What to Do Next

After tons of hard work, your company has successfully completed a SOC 2 audit and received a well-deserved SOC 2 report! Congratulations! Receiving your SOC 2 attestation is no easy feat, and it’s a significant milestone that demonstrates your ...

USENIX Enigma 2023 – Adrian Sanabria – ‘Myths And Lies In InfoSec’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Enigma ’23 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Enigma 2023 – Adrian Sanabria – ‘Myths And Lies In ...

How to Spot and Stop Active Directory Attacks Faster

The post How to Spot and Stop Active Directory Attacks Faster appeared first on Fidelis Cybersecurity. The post How to Spot and Stop Active Directory Attacks Faster appeared first on Security Boulevard.

Neutralize Identity Attacks, Stop SaaS Breaches

Mitigate credential risk from fragmented identity tools and systems, respond to SaaS compromise with airtight security controls for identities on-demand. The post Neutralize Identity Attacks, Stop SaaS Breaches appeared first on Security Boulevard.

SafeBreach Coverage for US-CERT Alert (AA23-131A) – Exploit CVE-2023-27350 in PaperCut MF and NG

SafeBreach coverage for US-CERT Alert (AA23-131A) - Malicious Actors Exploit CVE-2023-27350 in PaperCut MF and NG The post SafeBreach Coverage for US-CERT Alert (AA23-131A) – Exploit CVE-2023-27350 in PaperCut MF and NG appeared first on ...