Application Security News and Articles


The Hidden Dangers of Data Brokers: Protecting Your Personal Information

In today’s digital age, personal information has become an incredibly valuable commodity. Data brokers, companies that collect, analyze and sell personal information, have become a thriving industry. These companies collect vast amounts of data ...

LogRhythm and Zscaler integration streamlines website access control

LogRhythm and Zscaler work together to help organizations around the globe increase network insight and address a variety of cloud access security challenges faced by the modern SOC. LogRhythm SIEM and the Zscaler Zero Trust Exchange platform ...

Eclypsium @ RSA 2023

April 24 – 27 In Person Event Swing by Booth #226 and learn how to enter the drawing for a Flipper Zero, or take a quick survey to get a t-shirt! Sign Up for a Demo > The post Eclypsium @ RSA 2023 appeared first on Eclypsium | Supply ...

Protecting Yourself from Malicious Browser Extensions Is Easier Than You Think

Browser extension-based malware can range from annoying to catastrophic, but following these tips will help keep your home network safe. Few would argue that browser extensions aren't useful. They have the ability to add valuable functionality to ...

The Hacker Mind Podcast: EP 69 Self-Healing Operating Systems

It’s time to evolve beyond the UNIX operating system. OSes today are basically ineffective database managers, so why not build an OS that’s a database manager? The post The Hacker Mind Podcast: EP 69 Self-Healing Operating Systems appeared ...

5 Key Elements That Enhance the User Experience (UX) in Security Products

The user experience (UX) is a critical aspect of product design that often gets overlooked in the security industry. In an era when cybersecurity threats are constantly evolving and becoming more sophisticated, it is essential for security ...

New Variants of Qakbot Banking Trojan

The post New Variants of Qakbot Banking Trojan appeared first on Fidelis Cybersecurity. The post New Variants of Qakbot Banking Trojan appeared first on Security Boulevard.

USENIX Security ’22 – Ben Nassi, Yaron Pirutin, Raz Swisa, Adi Shamir, Yuval Elovici, Boris Zadov – ‘Lamphone: Passive Sound Recovery From A Desk Lamp’s Light Bulb Vibrations’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Ben Nassi, Yaron Pirutin, Raz Swisa, Adi ...

Polaris integrations: Secure development at the speed of business

Digitalization means you need to build more complex software than ever before – the Polaris Software Integrity Platform® can help.  The post Polaris integrations: Secure development at the speed of business appeared first on Security Boulevard.

Major Types of Account Takeover Fraud

What is Account Takeover fraud? This threat is a type of identity theft where criminals gain access to someone’s personal details in order to commit fraud. This can be done by compiling a list of validated credentials and selling or abusing ...

Secrets Exposed: The why, the how – and what to do about – secrets security in software

For software development teams to maintain and properly set up development environments and pipelines, they need to use software secrets such as environment variables, tokens and keys in these processes. The post Secrets Exposed: The why, the how ...

What is API Compliance? The Intersection of Compliance & API Security

API compliance is defined as how an organization ensures that their APIs support the security and governance protocols defined by industry-specific requirements or regulations including PCI-DSS, HIPAA, GDPR, and SOX. An integral element in API ...

Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnarav – ## #238 — Motivation for Quality

via the respected Software Engineering expertise of Mikkel Noe-Nygaard as well as the lauded Software Engineering and Enterprise Agile Coaching talent of Luxshan Ratnarav at Comic Agilé! Permalink The post Comic Agilé – Mikkel ...

Supply Chain Security: Secrets and Modern Security Frameworks (Part III)

In this final part, we'll discuss more software supply chain security frameworks and the critical role of secrets detection in them. We'll explore the NIST SSDF, SLSA, and OSC&R frameworks and how they cover the topic of secrets in software ...

Risk Quantification for Big Game Hunting or Double Extortion Ransomware

We recently helped a client in financial services use cyber risk quantitative analysis to plan defenses against double extortion ransomware AKA big-game hunting ransomware. These are sophisticated, high-stakes, multi-level cyber attacks, with ...

Investors Bet Big on Safe Security for Cyber Risk Management

Safe Security, a startup building technology to help organizations manage cyber risk, has secured a $50 million Series B funding round. The post Investors Bet Big on Safe Security for Cyber Risk Management appeared first on SecurityWeek.

USENIX Security ’22 – Henrique Teles Maia, Chang Xiao, Dingzeyu Li, Eitan Grinspun, Changxi Zheng – ‘Can One Hear The Shape Of A Neural Network?: Snooping The GPU Via Magnetic Side Channel’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Henrique Teles Maia, Chang Xiao, Dingzeyu ...

How to identify and stop card hopping and card testing fraud

Card testing and card hopping are two common types of payment fraud that can be difficult to detect and prevent. Discover the differences between these two types of fraud and how to prevent payment fraud. The post How to identify and stop card ...

Killnet Ostracizes Leader of Anonymous Russia, Adding New Chapter to Pro-Kremlin Hacktivist Drama

The apparent head of Anonymous Russia, an 18-year-old Belarusian citizen, was recently arrested by local authorities, prompting several Killnet-associated groups to call for his release and form their own coalitions The post ...

Russian Man Who Laundered Money for Ryuk Ransomware Gang Sentenced

Russian national Denis Dubnikov has been sentenced to time served after he pleaded guilty to charges related to laundering money for the Ryuk ransomware group. The post Russian Man Who Laundered Money for Ryuk Ransomware Gang Sentenced appeared ...