Application Security News and Articles


The European Data Protection Board Opines on President Biden’s Executive Order on Enhancing Safeguards for US Signals Intelligence Activities

After a two year absence of a data privacy law framework for transferring personal data from the EU to the U.S., President Biden signed an Executive Order on Enhancing Safeguards for United States Signals Intelligence Activities (the "Order") on ...

Fairwinds Insights Release Notes 11.7-11.11: Costs Page Updates [Beta]

This month, the Fairwinds Insights release notes include helpful improvements and bug fixes in the Insights platform. We’re also very excited to share our Costs page updates, which are currently still in Beta (but going live soon). We've ...

BlackCloak Warns That InfraGard Data Leak is Still “Alive and Well” on the Dark Web – and Free For Anyone to Access

More than three months after a hacker known as “USDoD” successfully breached the FBI’s InfraGard database in December 2022, the personal information of over 87,000 InfraGard members remains in active circulation on the Dark Web – free of ...

Solving the Tower of Babel Challenge

Modern networks are challenged by being atomized and diverse, with security teams trying to make cohesive sense out of multiple different security technologies using different languages. Martin Roesch calls this the “Tower of Babel” ...

Randall Munroe’s XKCD ‘Salt Dome’

via the comic artistry and dry wit of Randall Munroe, resident at XKCD! Permalink The post Randall Munroe’s XKCD ‘Salt Dome’ appeared first on Security Boulevard.

Throwing Caution to the Wind: The Challenges of Securing Wind Power

3 min read In a recent article for Industrial Cyber, Cyolo's Kevin Kumpf examines the growing cyberthreats facing wind farms and how they can best their critical infrastructure. The post Throwing Caution to the Wind: The Challenges of Securing ...

Analysis: SEC Cybersecurity Proposals and Biden’s National Cybersecurity Strategy

On March 15, 2023, the SEC announced a proposal for new cybersecurity requirements for covered entities. The post Analysis: SEC Cybersecurity Proposals and Biden’s National Cybersecurity Strategy appeared first on SecurityWeek.

5 Ways to Use Eclypsium to Align with the National Cybersecurity Strategy

On March 1st, 2023 the White House published an official update to the National Cybersecurity Strategy. This document further defines the nation’s focus on critical cybersecurity issues, and builds on the groundwork set forth in previous ...

Intel Boasts Attack Surface Reduction With New 13th Gen Core vPro Platform 

Intel shares information on the security improvements brought by its new vPro platform powered by 13th Gen Core processors. The post Intel Boasts Attack Surface Reduction With New 13th Gen Core vPro Platform  appeared first on SecurityWeek.

Using ChatGPT to Improve API Security: Open AI & Security

The widespread news surrounding ChatGPT and its alternatives got me thinking about how it may or may not impact API security. Current top of mind headlines are those touting an impending doom as a result of ChatGPT taking over our lives. An ...

Unpacking the National Cybersecurity Strategy: Part 3

Take a closer look at the National Cybersecurity Strategy's final two pillars on cyber resilience and collaboration in this expert analysis. The post Unpacking the National Cybersecurity Strategy: Part 3 appeared first on SafeBreach. The post ...

Top Data Breaches in 2022 and 2023 Point to Increases in Phishing and Ransomware

The hits just keep on coming in the world of headline-grabbing data breaches. Threat actors kept busy in 2022 and right on into the new year, with several notable data breaches already making news in 2023. The post Top Data Breaches in 2022 and ...

HIPAA Violation Penalties: What Happens if You Break The Rules

Discover what happens if you violate HIPAA’s rules and regulations and how you could be penalized. The post HIPAA Violation Penalties: What Happens if You Break The Rules appeared first on Scytale. The post HIPAA Violation Penalties: What ...

Spring 2023 Sift Product Release: Smarter, more flexible fraud prevention

Effectively combating fraud is not a one-size-fits-all effort. It’s critical for trust and safety solutions to be both flexible and powerful so that the teams using them can stay accurate and agile.    Sift’s latest product release puts ...

Cyber-Criminals Are Innovating: It’s Time to Hit Back with Data-Centric Security

The technology industry can move at dizzying speed. But in a space where change is the only constant, one trend has persisted over the years: a cyber arms race between attackers and defenders. While one side has the combined weight of numbers, ...

USENIX Security ’22 – Tohid Shekari, Alvaro A. Cardenas, Raheem Beyah – ‘MaDIoT 2.0: Modern High-Wattage IoT Botnet Attacks And Defenses’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Tohid Shekari, Alvaro A. Cardenas, ...

The Week in Security: NuGet hit by typosquatting, fake ChatGPT plug-in hijacks Facebook accounts

Welcome to the latest edition of The Week in Security, which brings you the newest headlines from both the world and our team across the full stack of security: application security, cybersecurity, and beyond. This week: NuGet is hit with a ...

Fake ChatGPT for Google extension hijacks Facebook accounts

A new Chrome extension promising to augment users’ Google searches with ChatGPT also leads to hijacked Facebook accounts, Guardio Labs researchers have found. While this specific trick isn’t new, this time around the extension also ...

Radware Customers Share Their Personal Ransomware Story

Just the word ransom lets you know that ransomware isn’t a welcome visitor. No industry is immune to it. In fact, many attacks on healthcare systems have prevented patients from getting medical care. Yes, it can be that evil. The post Radware ...

How to Accelerate Your Kubernetes Cost Journey Through Best Practices

Organizations are moving to the cloud and building new cloud-native applications and services in Kubernetes to increase the scalability and availability of new offerings. Others are working on digital transformation projects, refactoring legacy ...