Application Security News and Articles


How product security reached maturity

Product security has been driving major changes throughout the automotive, medical, and industrial sectors. However, just a few short years ago, it was a term few knew and even less considered its own discipline. Slava Bronfman, Co-Founder & ...

Unlocking the passwordless era

Although interest in passwordless technology, which aims to eliminate the need for passwords, is relatively low, 65% of consumers are receptive to using new technology that simplifies their lives, according to 1Password. Passkeys, the newest and ...

A third-party’s perspective on third-party InfoSec risk management

More than ever, organizations are relying on third parties to streamline operations, scale their business, expand and leverage expertise, and reduce costs. In the complex and fast-moving world of cybersecurity-meets-regulations, working with ...

How CISOs navigate security and compliance in a multi-cloud world

Due to the increasing importance of multi-cloud and the intricate nature of cloud infrastructure, obtaining a comprehensive understanding of the various cloud workloads operating within your system, and ensuring their security, can be ...

Arkansas Social Media Consent Law, Android Malware Invasion, New Method of Keyless Car Theft

Is Arkansas taking the right step to protect children online? A new law passed in the state makes it illegal for minors to use social media without their parent or guardian’s consent. Over 60 Android apps on the Google Play Store with more than ...

Over 70 billion unprotected files available on unsecured web servers

Critical exposures outside of an organization’s firewall are the greatest source of cybersecurity threats, according to CybelAngel. Across all industries, these vulnerabilities, composed of unprotected or compromised assets, data and ...

Study of past cyber attacks can improve organizations’ defense strategies

Ransomware operators have been increasingly launching frequent attacks, demanding higher ransoms, and publicly exposing victims, leading to the emergence of an ecosystem that involves access brokers, ransomware service providers, insurance ...

Patented.ai releases LLM Shield to safeguard sensitive info from chatbots

Patented.ai has released its introductory tool, LLM Shield that allows companies to safeguard their most sensitive data – proprietary source code, private customer information, unreleased financial data, legal documents, board reports and more ...

Busted: Misconceptions on Insider Risk Programs

Insider risk management is gaining momentum, as organizations increasingly accept that cybersecurity is a human challenge that requires a human solution. The data shows that humans are a common factor in cybersecurity incidents. Gartner recently ...

Expel Vulnerability Prioritization identifies critical and‌ damaging vulnerabilities

Expel has released Expel Vulnerability Prioritization, a new solution that highlights which vulnerabilities pose the greatest risk, so organizations can take immediate, informed action. The solution empowers security teams to understand their ...

Two Reasons Why CISOs Are Failing to Reduce Cyber Risk

On the eve of RSA, you are probably looking forward to a few days of presentations, meetings, lunches, dinners, connecting with friends and colleagues, old and new. At this moment, you might find it useful to take a step back – several steps ...

USENIX Security ’22 – David Koisser, Patrick Jauernig, Gene Tsudik, Ahmad-Reza Sadeghi – ‘V’CER: Efficient Certificate Validation In Constrained Networks ‘

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – David Koisser, Patrick Jauernig, Gene ...

DevOps and Compliance Teams: Working Together for Success

While DevOps and Compliance teams are a known mismatch, anecdotes explain why it doesn't need to be that way. Ace operational excellence AND risk management The post DevOps and Compliance Teams: Working Together for Success appeared first on ...

What the SEC and Other Regulators Are Saying About Where to Start Your CRQ Journey

There have been quite a few regulatory developments recently surrounding cybersecurity and its bedfellow, tech, or IT/ICT (Information and Communications Technology) risk. So, I thought I’d take a few lines to explore some of the salient points ...

Widow-Maker: A CIO Story

When Bill Vajda, the Wyoming CIO in 2022, suddenly left his role in January of this year, few knew the real reason why. Here's the rest of the story. The post Widow-Maker: A CIO Story appeared first on Security Boulevard.

Week in review: 5 free online cybersecurity resources for SMBs, AI tools might fuel BEC attacks

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Balancing cybersecurity with business priorities: Advice for Boards In this Help Net Security interview, Alicja Cade, Director, Financial ...

USENIX Security ’22 – Philipp Jeitner, Haya Shulman, Lucas Teichmann, Michael Waidner – ‘XDRI Attacks – and – How to Enhance Resilience of Residential Routers’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Philipp Jeitner, Haya Shulman, Lucas ...

Virsec automates the path to zero trust workload protection

Virsec has unveiled a suite of capabilities that automates the path to zero trust workload protection to increase the speed of protection, stopping attacks—including zero-days—in milliseconds. Its distinctive feature-set strikes the right ...

Next DLP adds ChatGPT policy to its Reveal platform

Next DLP has unveiled the addition of ChatGPT policy templates to the company’s Reveal platform, which uncovers risk, educates employees and fulfills security, compliance, and regulatory needs. The launch of these new policy templates is in ...

Onapsis updates its platform to strenghten ERP cybersecurity

Onapsis has unveiled a series of new product updates for the Onapsis Platform. Enriched with the threat intelligence, the Onapsis Platform further simplifies business application security for CISOs and CIOs alike with a new Security Advisor, new ...