Application Security News and Articles


API3:2019 Excessive Data Exposure: Understanding the Risks, Impacts, and How to Prevent It

Excessive data exposure occurs when APIs reveal more fields, data, and information than the client requires through the API response. The post API3:2019 Excessive Data Exposure: Understanding the Risks, Impacts, and How to Prevent It appeared ...

Unlocking the Four C’s of Cloud-Native Security

The four C’s of cloud-native security are a set of security measures and practices that are critical for protecting applications and data running in cloud-native environments. Cloud-native environments, which are designed to be highly scalable, ...

The warning signs for security analyst burnout and ways to prevent

Security analysts face the demanding task of investigating and resolving increasing volumes of alerts daily, while adapting to an ever-changing threat landscape and keeping up with new technology. To complicate matters further, the cybersecurity ...

Why the manufacturing sector needs stronger cyber defenses

In this Help Net Security interview, Filipe Beato, Lead, Centre for Cybersecurity, World Economic Forum, shares his expertise on the correlation between the digitization of the manufacturing sector and the rise in cyberattacks. He delves into the ...

7 Reasons to Ditch Endpoint DLP for Endpoint Visibility

Companies really don't have any business collecting or managing. The post 7 Reasons to Ditch Endpoint DLP for Endpoint Visibility appeared first on DTEX Systems Inc. The post 7 Reasons to Ditch Endpoint DLP for Endpoint Visibility appeared first ...

The costly threat that many businesses fail to address

Insider attacks such as fraud, sabotage, and data theft plague 71% of U.S. businesses, according to Capterra. These schemes can cost companies hundreds of thousands of dollars and the vast majority of businesses (79%) say they take longer to ...

Data-driven insights help prevent decisions based on fear

Organizations have strengthened security measures and become more resilient, but threat actors are still finding ways through, according to BakerHostetler. “We launched the Data Security Incident Response Report nine years ago because we ...

Zero to SIEM in Seconds Part 4: Respond in Seconds

It all winds up here at the final part of the SOC lifecycle, Respond in... The post Zero to SIEM in Seconds Part 4: Respond in Seconds appeared first on Gurucul. The post Zero to SIEM in Seconds Part 4: Respond in Seconds appeared first on ...

IronNet Monthly Global Threat

While much of the cybersecurity world’s focus has been on attacks related to the Russian-Ukraine war, there is an urgent need to raise awareness about the growing threat of a barrage of “digital strikes” by China against the United States, ...

USENIX Enigma 2023 – Emily Stark, Google – ‘The Dirty Laundry of the Web PKI’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Enigma ’23 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Enigma 2023 – Emily Stark, Google – ‘The Dirty ...

Imperva Continues to Innovate With New Features for Online Fraud Prevention

Last year, Imperva embarked on a mission to help organizations combat the growing threat of digital fraud. We introduced a new solution and a range of innovative features to help detect and prevent online fraud at its earliest stages. Imperva ...

The benefits of cyber security gamification & how to sell it to your board

The post The benefits of cyber security gamification & how to sell it to your board appeared first on Click Armor. The post The benefits of cyber security gamification & how to sell it to your board appeared first on Security Boulevard.

Software Packages, Do We Even Need Them?

  The post Software Packages, Do We Even Need Them? appeared first on Security Boulevard.

Radware Report Sees Religion Fueling More DDoS Attacks

A report published by Radware found that, in two months alone, hacktivists claimed to launch more than 1,800 distributed denial-of-service (DDoS) attacks in the hopes of advancing various political and religious causes. The analysis of claims ...

RSAC in review: Supply chain security, cyber war and AI

More than three years after the COVID pandemic threw the global economy — not to mention the technology conference business — on its ear, the RSA Security Conference was back in full force this year, with attendance and a theme, Stronger ...

Randall Munroe’s XKCD ‘Overlapping Circles’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Overlapping Circles’ appeared first on Security Boulevard.

RSA Conference 2023 Highlights: Power up your API Security

This week the Cequence Security team hit the floor at RSAC 2023. We appreciate everyone who stopped by our booth to learn how we help organizations power up their API security strategy. We always have a good time meeting you all at the event. ...

Apache Superset RCE Vulnerability CVE-2023-27524 Highlights Ongoing Issues with Flask AppBuilder, Joining List of Previously Discovered CVEs

On Apr 24, 2023 Naveen Sunkavally, Chief Architect at Horizon3.ai, announced the discovery of a new vulnerability, CVE-2023-27524, in Apache Superset and wrote comprehensively about the whole process. The vulnerability was caused by an insecure ...

G-71 Inc. Announces Updates to LeaksID Investigation Module, Reducing Time Required to Determine Source of Confidential Document Leaks

G-71 Inc., a provider of a document security solution, announced the update of their LeaksID investigation module, which significantly reduces the time required to identify the source of a confidential document leak. The post G-71 Inc. Announces ...

USENIX Enigma 2023 – Maxime Serrano, Figma, Inc. – ‘Navigating The Sandbox Buffet’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Enigma ’23 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Enigma 2023 – Maxime Serrano, Figma, Inc. – ...