Application Security News and Articles


Modern Device Trust for Today’s Advanced Threats

Device trust has come a long way, and is evolving even faster, stimulated by integrations and vendors that are developing device-centric solutions. But it wasn’t always this way… in the early networking days, a device that didn’t have a ...

Code42 Incydr + Splunk Integration: Streamline Your Insider Risk Management Program and Automate Response Controls

According to Code42’s 2023 Data Exposure Report, having the right technology in place and having technology that can provide the right visibility are the top two issues faced when building an Insider Risk program. When it comes to Insider Risk, ...

The DevSecOps Lifecycle: How to Automate Security in Software Development

In this blog post, we will explore the DevSecOps lifecycle and how to automate DevSecOps testing in your organization. The post The DevSecOps Lifecycle: How to Automate Security in Software Development appeared first on Security Boulevard.

Magecart/eSkimming Attack Using Kritec Skimmer Creates the Perfectly Hijacked Checkout Page

The Kritec skimmer operates by intercepting the checkout process during online purchases. After a customer enters their payment details, the skimmer simulates a fake payment dialog, giving the impression that the payment has been processed. It ...

Randall Munroe’s XKCD ‘Tapetum Lucidum’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Tapetum Lucidum’ appeared first on Security Boulevard.

Threats, Vulnerabilities, and Risks

As a business owner or employee in the UK, it's important to have a comprehensive understanding of the cyber threats, vulnerabilities, and risks that can impact your organisation. This blog post will provide an insight into these concepts, their ...

Delivering Generative AI to Cybersecurity for Over 3 Years

When it comes to Cybersecurity and Generative AI, you have to look at what traditionally takes time and investment by expert practitioners. One of the major things SOC analysts have to build and maintain is an alerting framework for their ...

GUEST ESSAY: Making the case for leveraging automation to eradicate cybersecurity burnout

The rising complexity and prevalence of cybersecurity threats are making experts anxious. Related: Training employees to mitigate phishing It pressures working analysts to perform 24 hours’ worth of work in an 8-hour day. Automation could ...

API Security for Financial Services

When it comes to the global financial services industry which includes banks, credit unions, exchange houses, finance companies, payment card issuers, and insurance companies, API security is a top priority. It only takes one data breach or ...

Modern Compliance Needs a Blend of Leadership, Culture, and GRC Power

The risks around poor cybersecurity are rising; that’s not news. Corporations have struggled for years with an increasing ... Read More The post Modern Compliance Needs a Blend of Leadership, Culture, and GRC Power appeared first on ...

Anti-Bots for Crypto

The cryptocurrency industry is growing rapidly, and with that growth comes an increase in bot attacks. These bots can cause serious damage to platforms and crypto wallet holders, leading to financial losses and reputational damage. It is crucial ...

New Apple ‘Rapid’ Update is Slow, Messy FAIL

PATCH NOW! Oh, wait, you can’t: “You are no longer connected to the internet,” it sneers. The post New Apple ‘Rapid’ Update is Slow, Messy FAIL appeared first on Security Boulevard.

USENIX Enigma 2023 – Tudor Dumitras – ‘When Malware Changed Its Mind: How “Split Personalities” Affect Malware Analysis And Detection’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Enigma ’23 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Enigma 2023 – Tudor Dumitras – ‘When Malware Changed ...

Global Operation Takes Down Dark Web Drug Marketplace

Law enforcement agencies around the world seized an online marketplace and arrested nearly 300 people allegedly involved in buying and selling drugs. The post Global Operation Takes Down Dark Web Drug Marketplace appeared first on SecurityWeek.

IT Services Firm Bitmarck Takes Systems Offline Following Cyberattack

German IT services giant Bitmarck has taken customer and internal systems offline following a cyberattack. The post IT Services Firm Bitmarck Takes Systems Offline Following Cyberattack appeared first on SecurityWeek.

Easily exploitable flaw in Oracle Opera could spell trouble for hotel chains (CVE-2023-21932)

A recently patched vulnerability (CVE-2023-21932) in Oracle Opera, a property management system widely used in large hotel and resort chains, is more critical than Oracle says it is and could be easily exploited by unauthenticated remote ...

Appdome and GitLab partner to strengthen mobile app defense

Appdome has released a pre-built integration between its platform and GitLab that is part of Appdome’s Dev2Cyber Partner initiative to accelerate delivery of secure mobile apps globally. “This new integration allows mobile brands to ...

Measuring People, Process, and Technology Effectiveness with NIST CSF 2.0

The National Institute of Standards and Technology (NIST) recently released the latest draft of the Cybersecurity Framework (CSF) 2.0, incorporating numerous updates and improvements over its predecessor. Among these changes, the addition of the ...

SBOMs Can Help You With Compliance, Too

Software bills of materials (SBOMs) are increasingly hitting the news as the federal government focuses on improving the nation’s cybersecurity. President Biden has identified this as a top priority of his administration, specifically ...

The Most Critical Domain Security Risks & Five Ways to Prevent Attacks

Security professionals are concerned about the security of their domains and are searching for how to protect their business stability and reputation. We’ve summarized the top 5 ways to prevent attacks. The post The Most Critical Domain ...