Application Security News and Articles


Why AD Modernization Is Critical to Your Cybersecurity Program

Active Directory (AD) is the core identity store for many organizations. As such, AD has also become a major target for bad actors. If attackers gain access to AD, they gain access to any resources in the organization. In a hybrid on-prem/cloud ...

Apptega named GRC Momentum Leader in G2 Spring Reports

It’s a tradition unlike any other. Last week, Apptega swept up 21 badges in G2’s Spring Reports, improving upon its best-in-class total of 18 from the winter awards. Among several leadership and high-performer designations, Apptega notched ...

Digital Trust & Safety Roundup: Payment fraud targets fintech, fraud industry insights, and Sift’s newest product enhancements

Explore findings from Sift’s Digital Trust & Safety Index on payment fraud, read takeaways from MRC Vegas, and learn about Sift’s spring product release. The post Digital Trust & Safety Roundup: Payment fraud targets fintech, fraud ...

USENIX Security ’22 – Fei Wang, Jianliang Wu, Yuhong Nan, Yousra Aafer, Xiangyu Zhang, Dongyan Xu, Mathias Payer – ‘ ProFactory: Improving IoT Security Via Formalized Protocol Customization’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Fei Wang, Jianliang Wu, Yuhong Nan, ...

IronNet Monthly Global Threat Update

In our third monthly global threat update, we briefly underscore some of the geopolitical, kinetic, and cyber trends/activity from the last month distilled in a few high-level takeaways. On March 7, Army Gen. Paul Nakasone, commander of U.S. ...

Cisco to Acquire Cloud Security Firm Lightspin for Reported $200 Million

Cisco is set to acquire Israel-based cloud security company Lightspin for a reported $200-250 million. The post Cisco to Acquire Cloud Security Firm Lightspin for Reported $200 Million appeared first on SecurityWeek.

NTT Taps Microsoft to Provide MDR Service

NTT Ltd has launched a managed detection and response (MDR) security service based on Microsoft Sentinel, a security information event management (SIEM) platform hosted in the Azure cloud service. The NTT MDR service collects data from any user, ...

Randall Munroe’s XKCD ‘Towed Messages’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Towed Messages’ appeared first on Security Boulevard.

SaaS Security Posture, Made to Measure with Customization

Your SaaS environment is unique. Your security approach should be too. When Obsidian first debuted our SaaS security posture management platform, we felt it was important to provide preconfigured rules based on our team’s expertise, security ...

A Serial Tech Investment Scammer Takes Up Coding?

John Clifton Davies, a 60-year-old con man from the United Kingdom who fled the country in 2015 before being sentenced to 12 years in prison for fraud, has enjoyed a successful life abroad swindling technology startups by pretending to be a ...

Introducing The Next-Gen of SaaS Security Posture Management

We are thrilled to announce the release of the next iteration of Obsidian’s SaaS Security Posture Management (SSPM). This new version of the product is the result of extensive feedback from our customers, our dedicated engineering efforts, and ...

Western Digital Hacked: ‘My Cloud’ Data Dead (Even Local Storage!)

Déjà Vu: Hack of WD systems leads to My Cloud service outage. Owners unable to access files. The post Western Digital Hacked: ‘My Cloud’ Data Dead (Even Local Storage!) appeared first on Security Boulevard.

USENIX Security ’22 – Catherine Easdon, Michael Schwarz, Martin Schwarzl, Daniel Gruss – ‘Rapid Prototyping For Microarchitectural Attacks’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Catherine Easdon, Michael Schwarz, ...

ChatGPT, the AI Revolution, and the Security, Privacy and Ethical Implications

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it. The post ChatGPT, the AI Revolution, and the Security, Privacy and Ethical Implications appeared first on ...

Prepare for the Security Resilience Onslaught

As we get ready for the upcoming RSA Conference, I gave some thought to what the industry marketing machinery will be hyping, and in looking at my inbox for clues, I saw a clear trend. ‘Security resilience’ bubbled to the top as ...

Elementor Pro Plugin Vulnerability Exploited to Hack WordPress Websites

A severe vulnerability in the Elementor Pro WordPress plugin is being exploited to inject malware into vulnerable websites. The post Elementor Pro Plugin Vulnerability Exploited to Hack WordPress Websites appeared first on SecurityWeek.

Why Security Teams Need Graph-Based Security Solutions

TL; DR  Your unknown blind spots can be your biggest undoing, no matter how prepared you think you are.  Current security teams suffer from legacy security practices in place; leading to high turnover and security incidents. Graph based ...

3CX supply chain attack: What do we know?

Five days have passed since the supply chain attack targeting 3CX customers gained wider public attention, but the software’s manufacturer is yet to confirm how the Windows and macOS desktop apps (based on the Electron software framework) ...

6 Things I Learned About the Science of Quantum Computing from Entrust Engage

After some of the basics of quantum computing are explored in the introductory episode of... The post 6 Things I Learned About the Science of Quantum Computing from Entrust Engage appeared first on Entrust Blog. The post 6 Things I Learned About ...

Passkeys and Biometrics Can Thwart Bad Actors

Cybersecurity breaches are a constant threat, and it’s only getting worse. In 2021, 45% of US companies suffered data breaches related to compromised credentials, 42 million individuals suffered losses greater than $50 billion in aggregate ...