Application Security News and Articles


The Future of Cyber Risk Quantification: Beyond the Traditional Tool

Cyber risk quantification is a crucial aspect of modern risk management, providing organizations with valuable insights into the potential impact of cyber threats and security gaps. It involves evaluating and measuring the likelihood and impact ...

Business Email Compromise Threats Soar Past Phishing Risks

The risk of business email compromise (BEC) is increasing annually and is estimated to be twice as severe as the overall threat of phishing, according to an Osterman Research/IronScales survey of 249 U.S.-based IT and security professionals. In ...

BEC scammers are after physical goods, the FBI warns

BEC attacks are usually aimed at stealing money or valuable information, but the FBI warns that BEC scammers are increasingly trying to get their hands on physical goods such as construction materials, agricultural supplies, computer technology ...

Menlo Security announces expansion plans in India at official opening of entre of Excellence in Bangalore, India

New investment to enhance product engineering and research and development capabilities Bangalore, 23 March, 2023– Menlo Security, a leading cloud security company, today announced expansion of its presence in India and new investment in the ...

A bug revealed ChatGPT users’ chat history, personal and billing data

A vulnerability in the redis-py open-source library was at the root of last week’s ChatGPT data leak, OpenAI has confirmed. Not only were some ChatGPT users able to see what other users have been using the AI chatbot for, but limited ...

Best Practices for Lean Teams to Improve Application Security Maturity

Lean teams aid the success of application development projects. Here are five practices that will help your lean teams improve their application security maturity status, identify vulnerabilities, and learn how to fix them. The post Best ...

GitHub Suspends Repository Containing Leaked Twitter Source Code

Twitter sent a copyright notice to code hosting service GitHub to request the removal of a repository that contained Twitter source code. The post GitHub Suspends Repository Containing Leaked Twitter Source Code appeared first on SecurityWeek.

Competitive advantage: Digital Workforce Governance

The new competitive advantage: Digital workforce governanceThe real reason you need segregation of dutiesWith up to 68% of total business costs spent on your workforce, how you govern that workforce can profoundly impact your success (or ...

A Sub-Domain Takeover Story, Two Questions for Every WAF Provider | Sunil Agrawal (CISO, Glean)

Sunil Agrawal (CISO, Glean) shared his experience on the sub-domain takeover and how it led him to build foundationally secured SaaS products. The post A Sub-Domain Takeover Story, Two Questions for Every WAF Provider | Sunil Agrawal (CISO, ...

SEBI’s Regulations on E-Wallet KYC: What You Need to Know

Banks and fintech have been ordered by SEBI to ensure that investors complete transactions for mutual funds using e-wallets that comply with KYC requirements. The start date for this is May 1, 2023. The most recent SEBI circular suggested that ...

Bank Account Verification: The Benefits of Using Bank Account Verification APIs

When a consumer opens a bank account, the bank goes through a procedure called bank account verification. It enables all required checks to be made on the account user and the source of their income, successfully stopping illegal activities like ...

Known unknowns: Refining your approach to uncategorized web traffic

Cybersecurity is such a complex field that even the best-trained, best-equipped, and most experienced security managers will sometimes struggle to decide which of several paths to take. Let’s consider uncategorized web traffic, for instance. I ...

Samsung Chipset Zero-Day Vulnerabilities, AI-Assisted Social Engineering, ATM Fraud with a Twist

In this episode we discuss Google’s discovery of 18 zero-day vulnerabilities in Samsung’s Exynos chipsets. We examine an AI-assisted social engineering campaign that combines emerging technologies with classic techniques. Finally, we look at ...

Prioritizing data security amid workforce disruptions

Businesses have faced massive disruptions in their workforce – many are requesting employees return to the office, and layoffs are rattling several industries. This disruption in the workforce can open organizations up to significant security ...

Understanding adversaries through dark web intelligence

93 percent of CISOs are concerned about dark web threats, and almost 72 percent of CISOs believe that intelligence on cybercriminals is “critical” to defend their organization and increase cybersecurity, according to Searchlight Cyber. The ...

The era of passive cybersecurity awareness training is over

Despite increased emphasis on cybersecurity from authorities and high-profile breaches, critical gaps in vulnerability management within organizations are being overlooked by executive leadership teams, according to Action1. These gaps leave ...

USENIX Security ’22 – Hongbin Liu, Jinyuan Jia, Neil Zhenqiang Gong – ‘PoisonedEncoder: Poisoning The Unlabeled Pre-Training Data In Contrastive Learning’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Hongbin Liu, Jinyuan Jia, Neil ...

Privacy Compliance In 2023

anecdotes outlines the state privacy laws of 2023. Learn which are relevant to your organization, what they require and how to comply. The post Privacy Compliance In 2023 appeared first on Security Boulevard.

Born In A Pandemic – Our Story | Blog by anecdotes

Trials and errors during a pandemic. Launching a successful start-up is always a challenge. Now you can learn about what we did right! The post Born In A Pandemic – Our Story | Blog by anecdotes appeared first on Security Boulevard.

Continuity Joins Dell Technologies ETC Program to Help Protect Customers’ Storage and Data Protection Systems

The ETC Program underscores Dell’s commitment to offer customers flexibility and choice with complimentary solutions such as StorageGuard for protecting their critical systems from cyberattacks and insider threats. The post Continuity Joins ...