Application Security News and Articles


Why Should You Invest in AppSec?

Discover the top reasons why investing in application security (AppSec) is essential for businesses of all sizes. From protecting customer data to complying with regulations, ensure your apps are secure and your organization is protected from ...

Why DevOps needs to be DevSecOps

Although DevOps remains a popular strategy for many businesses, some are souring on the concept as expectations are failing to meet what's being delivered. Security needs to be part of it (DevSecOps) The post Why DevOps needs to be DevSecOps ...

GUEST ESSAY: Scammers leverage social media, clever con games to carry out digital exploitation

One common misconception is that scammers usually possess a strong command of computer science and IT knowledge. Related: How Google, Facebook enable snooping In fact, a majority of scams occur through social engineering. The rise of social media ...

Detecting face morphing: A simple guide to countering complex identity fraud

Our reliance on face matching for identity verification is being challenged by the emergence of artificial intelligence (AI) and facial morphing technology. This technique involves digitally creating an image which is an average of two people’s ...

How to best allocate IT and cybersecurity budgets in 2023

Despite the economic uncertainty, 57% of organizations plan to increase their cybersecurity budgets in 2023, according to a survey from Arctic Wolf. This highlights a powerful trend: critical needs like security must be addressed even with IT ...

The Benefits and Risks of Using Government Databases for ID Verification in Fraud Prevention

In today’s digital world, identity theft and fraud have become increasingly common occurrences. It is no secret that fraudsters are getting more creative, making it more challenging for businesses and individuals to protect themselves. However, ...

IT security spending to reach nearly $300 billion by 2026

Worldwide spending on security solutions and services is forecast to be $219 billion in 2023, an increase of 12.1% compared to 2022, according to IDC. Investments in hardware, software, and services related to cybersecurity are expected to reach ...

Exploring the Role of Empathy in Cybersecurity with Andra Zaharia

On this episode, Tom Eston discusses empathy in cybersecurity with Andra Zaharia, host of the Cyber Empathy Podcast. We talk about finding her passion for contributing to the industry and the importance of empathy in cybersecurity. We cover how ...

Most mid-sized businesses lack cybersecurity experts, incident response plans

99% of all businesses across the United States and Canada are mid-sized businesses facing cybersecurity challenges, according to a Huntress report. Aimed to gain insights into organizational structure, resources and cybersecurity strategies, the ...

USENIX Security ’22 – Mohsen Minaei, Mainack Mondal, Aniket Kate – ‘Empirical Understanding Of Deletion Privacy: Experiences, Expectations, And Measures’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Mohsen Minaei, Mainack Mondal, Aniket ...

Week in review: Kali Linux gets Purple, Microsoft zero-days get patched

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Samsung, Vivo, Google phones open to remote compromise without user interaction Several vulnerabilities in Samsung’s Exynos chipsets may allow ...

Roseville, Calif., CIO Brings Global Background to Local Gov

Hong Sae is the CIO for the city of Roseville, Calif., and he has a tremendous track record of success in both Texas and California local government. The post Roseville, Calif., CIO Brings Global Background to Local Gov appeared first on Security ...

What’s New in Cyolo 4.0

2 min read Cyolo 4.0 has officially arrived! Discover all the details of this latest release, including (spoiler alert!) a simplified user login workflow and portal redesign. The post What’s New in Cyolo 4.0 appeared first on Cyolo. The post ...

What is Dynamic Application Security Testing (DAST)? ☟

#DevSecOps is a philosophy that emphasizes integrating security practices into every stage of the software development lifecycle ↻, from…Continue reading on Medium »

COURT DOC: US Federal Agents Arrest Alleged Administrator of Breach Forums “pompompurin”

On March 17, 2023, US federal agents arrested a New York individual for computer crimes associated with their activities as an administrator of illicit online forum Breach Forums under the online alias “pompompurin.” The individual, ...

Keysight Digital Learning Suite streamlines and simplifies lab management

Keysight Technologies introduces the Keysight Digital Learning Suite, a new unified digital learning platform that provides university engineering educators and students with lab tools, resources, and courseware through a single, secure web ...

Huawei Has Replaced Thousands of US-Banned Parts With Chinese Versions: Founder

Huawei has replaced thousands of product components banned by the US with homegrown versions, its founder has said. The post Huawei Has Replaced Thousands of US-Banned Parts With Chinese Versions: Founder appeared first on SecurityWeek.

URGENT ACTION RECOMMENDED – Microsoft Outlook Vulnerability (CVE-2023-23397)

Summary: Microsoft disclosed a Microsoft Outlook Vulnerability (an RCE – remote code execution) titled “Microsoft Outlook Elevation of Privilege Vulnerability” and designated as CVE-2023-23397 with its patch Tuesday release (March 14th ...

Who Wants to Fuel Independent and High Quality OSINT/Cybercrime and Threat Intelligence Research? Accepting BitCoin Donations

Dear blog readers, Did you already grab a copy of my 2019-2023 "Dancho Danchev's Blog - Mind Streams of Information Security Knowledge" Ebook which is 1.7GB compilation for free? Did you already grab a copy of my Twitter 2017-2023 Ebook ...

No More Missed Opportunities: Maximizing Your Threat Hunting Efforts

Threat hunting has become an essential component of modern cybersecurity defenses. With the threat landscape constantly evolving, organizations need to stay ahead of the curve by proactively searching for potential security breaches instead of ...