Application Security News and Articles


Conquering modern data stack complexities

How are data teams conquering the complexity of the modern data stack? Unravel Data has asked 350+ data scientists, engineers, analysts, and others who rely upon real-time data insights for decision-making to share their practices. “For the ...

Qwiet AI releases a suite of targeted AppSec and DevSecOps services

Qwiet AI has released a suite of targeted AppSec and DevSecOps services that help companies address their security function needs without sacrificing time and budget. “We often hear of the notion of doing more with less. However, in ...

Entrust offers zero-trust solutions for authentication, HSM, and multi-cloud compliance

Entrust is supporting organizations’ zero trust journey with new foundational identity, encryption, and key management solutions. “Zero trust approaches are reshaping security in a perimeter-less world. While the conversation often starts ...

Code42 Instructor now offers risk reduction training videos to Microsoft Teams

Code42 Software has offered a complete set of response controls to allow security teams to respond to all levels of risk, ranging from unacceptable high risk that must be blocked to the most prevalent user mistakes that require correction. ...

Cerbos Cloud manages and enforces authorization policies

Cerbos has released Cerbos Cloud, a managed service offering for Cerbos. Cerbos is an open source authorization layer to easily implement roles and permissions in software applications. It separates authorization logic from the core application ...

Cymulate ASM bridges vulnerability management and ASM gaps in hybrid infrastructure

Cymulate has expanded its Attack Surface Management (ASM) solution to close gaps between traditional vulnerability management and ASM. Organizations will now have advanced capabilities to easily visualize risky exposures across hybrid ...

CircleCI adds more security and compliance capabilities to its platform

CircleCI has unveiled a new suite of platform capabilities and integrations. Today, software teams are building at greater velocity while relying on a variety of dependent software. And with the interconnectedness of modern businesses, coupled ...

Arcitecta unveils Point in Time Ransomware Rapid Recovery Solution

Arcitecta has launched its Point in Time Ransomware Rapid Recovery Solution for the media and entertainment industry. The new solution provides studios with instant recovery from a ransomware attack, works across a studio’s existing production ...

SentinelOne announces integration of firewalls and NDR capabilities with key industry players

SentinelOne has unveiled integrations with key industry players Aruba, Checkpoint, Cisco, Darktrace, Extrahop, Fortinet, Palo Alto Networks and an enhanced collaboration with Vectra AI which expand the company’s firewall and NDR capabilities, ...

DirectDefense and Claroty join forces to secure XIoT environments

DirectDefense has partnered with Claroty which empowers organizations with visibility, protection, and threat detection to secure their Extended Internet of Things (XIoT), a vast network of cyber-physical systems across industrial, healthcare, ...

AppSec Decoded: Creating a system model in threat modeling

Learn how a system model helps guide the discussion and present results in threat modeling. The post AppSec Decoded: Creating a system model in threat modeling appeared first on Security Boulevard.

Revolutionizing Data Center Infrastructure Management with Generative AI

How generative AI is transforming the way data centers are managed, optimized, and maintained. In the world of data center infrastructure management (DCIM), efficiency and optimization have always been vital. As data centers continue to evolve ...

What you need to know about the Visa Compelling Evidence 3.0 update

Read our Q&A with Kevin Lee, VP of Trust and Safety at Sift, as he explains the new Visa compelling evidence updates and what it means for merchants. The post What you need to know about the Visa Compelling Evidence 3.0 update appeared first ...

April 2023 Patch Tuesday: 114 Vulnerability Fixes Released, Including One Actively Exploited in the Wild

On April 11th, 2023, Microsoft released their April Patch Tuesday roundup, which includes 114 new vulnerability fixes and 4 updates for existing CVEs. Of these fixes, 17 were published on April 6th and 97 were published on April 11th. One of the ...

Google Proposes More Transparent Vulnerability Management Practices

New Google paper calls for increased transparency from vendors regarding their vulnerability management practices. The post Google Proposes More Transparent Vulnerability Management Practices appeared first on SecurityWeek.

March 2023 Threat Intelligence Summary

The post March 2023 Threat Intelligence Summary appeared first on Fidelis Cybersecurity. The post March 2023 Threat Intelligence Summary appeared first on Security Boulevard.

USENIX Security ’22 – Robert McLaughlin, Fabio Pagani, Noah Spahn, Christopher Kruegel, Giovanni Vigna – ‘Regulator: Dynamic Analysis To Detect ReDoS’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Robert McLaughlin, Fabio Pagani, Noah ...

Top 10 facts about CMMC 2.0

CMMC 2.0 is here! Get to know the most important changes to the model to stay ahead of the compliance curve. Read More The post Top 10 facts about CMMC 2.0 appeared first on Axio. The post Top 10 facts about CMMC 2.0 appeared first on Security ...

What pen testing can tell you about the health of your SDLC

Tailored use of pen testing can provide critical support and insights for gauging the health of your SDLC. The post What pen testing can tell you about the health of your SDLC appeared first on Security Boulevard.

Google Cybersecurity Action Team Threat Horizons Report #6 Is Out!

This is my completely informal, uncertified, unreviewed and otherwise completely unofficial blog inspired by my reading of our sixth Threat Horizons Report (full version) that we just released (the official blog for #1 report, my unofficial blogs ...