Application Security News and Articles


May 2023 Patch Tuesday forecast: Dealing with End-of-Support (EOS)

The April Patch Tuesday releases were unusual because we saw a whopping 62 vulnerabilities addressed in the Microsoft Server 2012 KBs. Granted there was a lot of overlap with the CVEs addressed in Windows 10 and 11, but compared to the typical ...

New infosec products of the week: May 5, 2023

Here’s a look at the most interesting products from the past week, featuring releases from Dashlane, Immersive Labs, Intruder, Private AI, Vanta, and Veza. Immersive Labs Resilience Score strengthens executive decision making in cyber crises ...

Universal Data Permissions Scanner: Open-source tool to overcome data authorization blindspots

Satori released Universal Data Permissions Scanner, a free, open-source tool that enables companies to understand which employees have access to what data, reducing the risks associated with overprivileged or unauthorized users and streamlining ...

What Business Owners Can Learn From the T-Mobile Breach

Discover the lessons learned from the T-Mobile breach and how it can help business owners improve their cybersecurity measures. The post What Business Owners Can Learn From the T-Mobile Breach appeared first on GuardRails. The post What Business ...

DAST in 5 Minutes (Or Less): What You Need to Know

Our overview provides a clear and concise explanation of what DAST is and how it can benefit your organization. Whether you're new to the world of web application security testing or just need a refresher, this page is the perfect resource for ...

Organizations brace for cyber attacks despite improved preparedness

Cyber-risk levels have improved from “elevated” to “moderate” for the first time, but insiders represent a persistent threat for global organizations, according to Trend Micro. Jon Clay, VP of threat intelligence at Trend ...

Think your data has no value? Scammers disagree

In the first quarter of 2023 there was a significant increase in cyberattacks exploiting trust in established tech brands Microsoft and Adobe, according to Avast. The Avast report also found a 40% rise in the share of phishing and smishing ...

$10M Is Yours If You Can Get This Guy to Leave Russia

The U.S. government this week put a $10 million bounty on the head of a Russian man who for the past 18 years operated Try2Check, one of the cybercrime underground's most trusted services for checking the validity of stolen credit card data. U.S. ...

Former Uber CSO Joe Sullivan Avoids Prison Time Over Data Breach Cover-Up

Former Uber security chief Joe Sullivan was sentenced to probation and community service for covering up the data breach suffered by the ride-sharing giant in 2016. The post Former Uber CSO Joe Sullivan Avoids Prison Time Over Data Breach ...

Scammers get sneaky: New malware distribution tactics revealed in Avast Threat Report

The first quarter of 2023 saw a notable rise in cyberattacks targeting trust in established tech brands Microsoft and Adobe, according to the Avast Q1 2023 Threat Report. The report also revealed a 40% increase in the share of phishing and ...

Closing the trust-risk loop with file lineage

The recent Pentagon leaks have drawn a fine line between trust and risk management, and the need to strike a balance to prevent data loss while maintaining loyalty. As an IT specialist for the Air National Guard, Jack Teixeira – the US airman ...

Sonatype Sponsoring Red Hat Summit on May 23-25 in Boston

My team and I are excited to announce that we are sponsoring Red Hat Summit 2023. Our partnership with Red Hat has allowed us to combine our state-of-the-art solutions, making securing your software supply chain more convenient and affordable. ...

COURT DOC: Cybercriminal Network Fueling the Global Stolen Credit Card Trade is Dismantled

A four-count indictment was unsealed today in the United States District Court for the Eastern District of New York charging Denis Gennadievich Kulkov with access device fraud, computer intrusion and money laundering in connection with his ...

The Week in Security: SolarWinds hack set off alarms for months before discovery

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond. This week: The supply chain hack of ...

The Risk-Based, Relationship-Driven Consultant

When looking for a consultant, companies often prioritize risk analysis as the primary concern. And while risk analysis is essential, companies should also look for consultants that clearly establish their value and show how their services will ...

USENIX Enigma 2023 – Kamesh Shekar – ‘A New Process To Tackle Misinformation On Social Media: Prevalence-Based Gradation’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Enigma ’23 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Enigma 2023 – Kamesh Shekar – ‘A New Process To ...

Why I’m Joining Axio

A spotlight on Axio's new SVP, Risk Engineering & Risk Capital, Peter Armstrong, and why he's decided to join the team. Read More The post Why I’m Joining Axio appeared first on Axio. The post Why I’m Joining Axio appeared first on ...

CISA Urges Organizations to Review FCC’s List of High-Risk Communications Equipment

The Cybersecurity & Infrastructure Security Agency (CISA) has recently issued an advisory urging organizations to review the Federal Communications Commission’s (FCC) list of communications equipment and services deemed by the U.S. ...

Lessons from ChatGPT’s Data Leak: The Crucial Role of SBOM in Your Organization

Sam Altman, OpenAI CEO, recently tweeted– “We had a significant issue in ChatGPT due to a bug in an open-source library, for which a fix has now been released and we have just finished validating. A small percentage of users were able to see ...

Randall Munroe’s XKCD ‘College Knowledge’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘College Knowledge’ appeared first on Security Boulevard.