Application Security News and Articles


Why it’s time to move towards a passwordless future

Adversaries don’t need to use sophisticated methods to gain access to enterprise systems or to deploy ransomware – they can just buy or steal credentials and log in. By burdening users with the near-impossible task of maintaining ...

Why Companies Are Boosting Their AppSec Budgets for 2023

The recent data breaches have highlighted the need for companies to prioritize AppSec Budgets and take proactive steps to protect their systems and customer data. The post Why Companies Are Boosting Their AppSec Budgets for 2023 appeared first on ...

Making risk-based decisions in a rapidly changing cyber climate

Nicole Darden Ford is Global VP & CISO at Rockwell Automation. As the company’s cybersecurity leader, Nicole is entrusted to protect enterprise IT assets with scalable, future-ready platforms that enable the business. In addition to ...

How to transform cybersecurity learning and make content more engaging

While applications like Slack and Teams have transformed how we collaborate and communicate, cybersecurity training has not kept pace with these advancements. Most security training is still being delivered through web-based learning management ...

Criminal businesses adopt corporate behavior as they grow

As criminal groups increase in size, they adopt corporate-like behavior, but this shift brings about its own set of challenges and costs, according to Trend Micro. “The criminal underground is rapidly professionalizing – with groups ...

Consumers take data control into their own hands amid rising privacy concerns

Data Subject Requests (DSRs), which are formal requests made by individuals to access, modify, or delete their personal data held by a company, increased by 72% from 2021 to 2022. The increase was primarily driven by deletion and access requests, ...

Australian Finance Company Refuses Hackers’ Ransom Demand

Latitude Financial said it had recently received a ransom threat from the group behind the cyberattack, which it was ignoring in line with government advice. The post Australian Finance Company Refuses Hackers’ Ransom Demand appeared first ...

Tesla Sued Over Workers’ Alleged Access to Car Video Imagery

A Tesla owner is seeking class action status for a lawsuit accusing the automaker of allowing its workers to use intimate or embarrassing imagery captured by the electric vehicles. The post Tesla Sued Over Workers’ Alleged Access to Car ...

Final Act? Killnet Rallies Attackers to DDoS NATO Targets

While much of the world anticipated hunts for colored eggs, chocolate bunnies and family dinners on Sunday, Black Kite was busy sounding the alarm about an expected swan song from Killnet that could involve “high-impact” DDoS attacks on NATO ...

Protect Your Business From eCommerce Security Threats

As the world transitions to digital commerce, including across internet of things (IoT) devices and apps, online shopping has skyrocketed in popularity. With convenience at the touch of a button, and a device in almost every consumer’s pocket, ...

Container security essentials

As the preferred method for packaging and deploying cloud-native applications, a comprehensive understanding of containers, and how to secure them, has never been so important.  The post Container security essentials appeared first on Security ...

USENIX Security ’22 – Jason Zhijingcheng Yu, Shweta Shinde, Trevor E. Carlson, Prateek Saxena – Elasticlave: An Efficient Memory Model for Enclaves

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Jason Zhijingcheng Yu, Shweta Shinde, ...

Why I Joined Balbix – David Anteliz

During the late 1970s when computers were still a novelty and not as prevalent as they are today, my cousin and I, both aged seven, visited the data center of a company where our uncle held a VP position. As two young boys, fascinated by anything ...

What went wrong with the 3CX software supply chain attack — and how it could have been prevented

Software supply chain attacks are happening all too frequently now, especially ones that occur due to the inclusion of malicious dependencies found in open source repositories. While this kind of supply chain attack is common, other forms of ...

Randall Munroe’s XKCD ‘Paleontology Museum’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Paleontology Museum’ appeared first on Security Boulevard.

Yes, You CAN Steal This Car — by Opening the Fender

CAN You Not? Toyota RAV4 and many others vulnerable to CAN bus injection attack. Cars need zero-trust too. The post Yes, You CAN Steal This Car — by Opening the Fender appeared first on Security Boulevard.

Responding To Insider Risk Is Hard. Here Are 4 Things You Need To Do.

Data doesn’t move outside your organization by itself. It’s your employees who move it. Data loss from insiders is a growing concern for organizations. In fact, there was a 32% year-over-year average increase in the number of insider events ...

MSI Confirms Cyberattack, Issues Firmware Download Guidance

Tech giant MSI confirms a cyberattack that resulted in system disruptions and possible exposure to firmware image manipulations. The post MSI Confirms Cyberattack, Issues Firmware Download Guidance appeared first on SecurityWeek.

The Future of Cloud Security: 3 Key Trends You Need to Know About | Eureka Security

Learn about the 3 key trends that are shaping the future of cloud security in this blog by Frank Kim, CISO-in-Residence at YL Ventures. | Eureka Security The post The Future of Cloud Security: 3 Key Trends You Need to Know About | Eureka ...

USENIX Security ’22 -Guoxing Chen, Yinqian Zhang – MAGE: Mutual Attestation for a Group of Enclaves without Trusted Third Parties

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 -Guoxing Chen, Yinqian Zhang – MAGE: Mutual ...