Application Security News and Articles


Randall Munroe’s XKCD ‘1-to-1 Scale’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘1-to-1 Scale’ appeared first on Security Boulevard.

Why Kotlin is popular and how to use it | Contrast Security

Ever wonder why the financial industry is so hopped up on Kotlin?  The post Why Kotlin is popular and how to use it | Contrast Security appeared first on Security Boulevard.

LogonBox 2.4.2 Release Notes

This release includes fixes to some bugs, has several user interface improvements and introduces new cloud messaging options to help streamline the set-up of new appliances. Notable Bug FixesOne of the improvements of the 2.4 branch has been the ...

Adobe Plugs Gaping Security Holes in Reader, Acrobat

Adobe documents 56 security defects in multiple products, some serious enough to expose Windows and macOS users to code execution attacks. The post Adobe Plugs Gaping Security Holes in Reader, Acrobat appeared first on SecurityWeek.

LogonBox 2.4.2 Changelog

This release contains several improvements to help streamline the set-up of the appliances as well as some key bugs and user interface improvements.If you have any questions about the changes and how they may impact your deployment, please ...

*Updated!* Best Practices for Identity Management in 2023  

Many individuals’ first encounter with real cybersecurity concerns come in the form of some brush with an Identity Management (IdM) issue—whether their bank details have been stolen, someone has taken out an insurance policy in their name, or ...

A Refresher on the FTC Safeguards Rule

With a deadline of June 9, 2023 to comply with amendments to the FTC Safeguards Rule, now is the time to get crystal clear on what’s required. Unfortunately, though, automotive dealerships seem to lack clarity on these requirements. One recent ...

DMCA Violations and Notices: An In-Depth Guide

DMCA violation notices can be a stressful thing to receive as an organization. We’ve compiled a guide for how you can respond, counter a violation notice, and protect your brand. The post DMCA Violations and Notices: An In-Depth Guide appeared ...

USENIX Security ’22 – Yuan Chen, Jiaqi Li, Guorui Xu, Yajin Zhou, Zhi Wang, Cong Wang, Kui Ren – SGXLock: Towards Efficiently Establishing Mutual Distrust Between Host Application And Enclave For SGX

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Yuan Chen, Jiaqi Li, Guorui Xu, Yajin ...

OSINT Company Fivecast Raises $20 Million

Australian OSINT software company Fivecast has raised $20 million in a Series A funding round led by Ten Eleven. The post OSINT Company Fivecast Raises $20 Million appeared first on SecurityWeek.

Wicked Good Development Episode 31: Testcontainers With Oleg Šelajev

  The post Wicked Good Development Episode 31: Testcontainers With Oleg Šelajev appeared first on Security Boulevard.

Netography Detection Model Release – April 11, 2023

The Netography Threat Research Team has released its latest detection model updates to include port scanning internal resources for the detection of vulnerabilities, abuse, or attacks on customer networks, as well as new vulnerabilities in ...

10 Overlooked & Hidden Network Security Risks & How to Mitigate Them

The vast majority of information security incidents aren't caused by highly-sophisticated, unprecedented technological exploitation. In fact, the bulk of security incidents is caused by just ten known security vulnerabilities or humans who fall ...

Microsoft Azure Users Warned of Potential Shared Key Authorization Abuse

Microsoft Azure shared key authorization can be exploited to access business data and achieve remote code execution. The post Microsoft Azure Users Warned of Potential Shared Key Authorization Abuse appeared first on SecurityWeek.

BigID’s data minimization capabilities enable organizations to identify duplicate data

BigID launched ML-powered solution for finding duplicate and similar data content. The innovative technology uses AI to locate both similar and duplicate data on any data set, enabling organizations to identify duplicate data as well as ...

Beware of companies offering paid sextortion assistance

Sextortion victims are already in a vulnerable position, and shady companies are taking advantage of this vulnerability to offer “sextortion assistance” services for huge sums – services that they may be unable to render or that ...

ICS Patch Tuesday: Siemens, Schneider Electric Address Dozens of Vulnerabilities

Siemens and Schneider Electric’s Patch Tuesday advisories for April 2023 address a total of 38 vulnerabilities found in their products. The post ICS Patch Tuesday: Siemens, Schneider Electric Address Dozens of Vulnerabilities appeared first on ...

ThreatX Runtime API & Application Protection goes beyond basic observability

ThreatX has unveiled ThreatX Runtime API & Application Protection (RAAP). This patent-pending capability goes beyond basic observability to extend threat detection, tracking and blocking to customers’ runtime environments, without slowing ...

What you Missed in the White House National Cybersecurity Strategy

On the heels of the White House’s National Cybersecurity Strategy, there were plenty of reactions and opinions about how cybersecurity strategies and priorities must change. But most people missed one critical callout: Enterprises and major ...

Malware Monthly – March 2023

  The post Malware Monthly – March 2023 appeared first on Security Boulevard.