Application Security News and Articles


Security in the cloud with more automation

Hopefully, you’ve been working with the Center for Internet Security (CIS) on securing your cloud infrastructure for a while now. Initially, you might have used our CIS Benchmarks and other free resources to manually configure your operating ...

Adtran and Satelles offer new levels of security for synchronization network infrastructure

Adtran and Satelles collaboration will enable operators of critical infrastructure to safeguard their timing networks with Satellite Time and Location (STL) technology. By integrating Satelles’ STL into its Oscilloquartz network synchronization ...

50 Threat Hunting Hypothesis Examples

Threat hunting is a proactive and critical aspect of cybersecurity that involves searching for signs of malicious activity on your organization’s networks and systems. It’s a process of identifying and mitigating the risk of cyber attacks ...

Entrust Software Security Architect Recognized as an Excellence Award Finalist by Microsoft

It’s with great pride that we announce our colleague Mike Ounsworth has been named an... The post Entrust Software Security Architect Recognized as an Excellence Award Finalist by Microsoft appeared first on Entrust Blog. The post Entrust ...

What You Need to Know About the Latest KEV Updates

In June of last year, we published our first review of the vulnerabilities in CISA’s Known Exploited Vulnerabilities (KEV) Catalog. Of course, security never stands still, and the KEV has steadily been updated as adversaries have shifted their ...

Kali Linux 2023.1 released – and so is Kali Purple!

OffSec (formerly Offensive Security) has released Kali Linux 2023.1, the latest version of its popular penetration testing and digital forensics platform, and the release is accompanied by a big surprise: a technical preview of Kali Purple, a ...

USENIX Security ’22 – Timothy Trippel, Kang G. Shin, Alex Chernyakhovsky, Garret Kelly, Dominic Rizzo, Matthew Hicks – ‘Fuzzing Hardware Like Software’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Timothy Trippel, Kang G. Shin, Alex ...

Why Organizations Need to Care About Machine Identity Management

Machine Identity Management (MIM) is an essential component of an organization’s cybersecurity program. The post Why Organizations Need to Care About Machine Identity Management appeared first on Keyfactor. The post Why Organizations Need to ...

White House to Regulate Cloud Security: Good Luck With That

Be careful what you wish for: Biden wants new regulations for cloud providers—but we’re not sure it’ll help. The post White House to Regulate Cloud Security: Good Luck With That appeared first on Security Boulevard.

Augmented Software Engineering in an AI Era

Artificial Intelligence (AI) has been making waves in many industries, and software engineering is no exception. AI has the potential to revolutionize the way software is developed, tested, and maintained, bringing a new level of automation and ...

Recent CISA KEV Additions Include Silent Fixes and Unpatched Vulnerabilities

Flashpoint has observed two major discrepancies with CVE-2022-35914 and CVE-2022-33891. Security teams need to be aware that despite following vendor instructions, certain organizations may still be at risk due to the root causes of each ...

The Failure of Silicon Valley Bank Is a Ground-Shaking Crisis—and a Cybersecurity Red Alert

Last year, Silicon Valley Bank (SVB) enjoyed a market capitalization of $44 billion. It was a strategic partner to innumerable technology companies. In fact, it would not be hyperbole to describe SVB as an essential part of Silicon Valley’s ...

Unreleased findings from the Entrust Cybersecurity Institute’s “Future of Identity” Report

Younger consumers – especially Gen Z – value the promise of simplified experiences that digital... The post Unreleased findings from the Entrust Cybersecurity Institute’s “Future of Identity” Report appeared first on Entrust Blog. The ...

LogonBox VPN 2.3.20

Introduction LogonBox is pleased to announce the immediate availability of LogonBox VPN 2.3.20.This release includes the ability to force AD schema versions and additions to LDAP attributes. AD schema checking changesLogonBox needs to check the ...

LogonBox SSPR 2.3.20

Introduction LogonBox is pleased to announce the immediate availability of LogonBox SSPR 2.3.20.This release includes the ability to force AD schema versions and changes to email batching, amongst other features. Email batching changesSome ...

Software supply chain security and financial services: Mind the gaps in app sec testing

Financial services companies need to make software supply chain security (SSCS) an integral part of their application security (app sec) testing programs because app sec and DevOps testing practices that focus on addressing vulnerabilities in ...

Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnarav – ‘#232 – Is ADKAR Agile?’

Permalink The post Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnarav – ‘#232 – Is ADKAR Agile?’ appeared first on Security Boulevard.

A Letter to the Modern CISO: Part 3

Reading Time: 4 minutes Your Cloud Can Be Deleted At Any Moment This blog is the final piece of a three-part series. The series begins here.  As jarring as it sounds, your cloud is probably at risk of being deleted at any moment, and you ...

3 key insights from the Entrust Cybersecurity Institute’s “Future of Identity” Report

We surveyed 1,450 consumers globally to understand how they feel about emerging identity topics —... The post 3 key insights from the Entrust Cybersecurity Institute’s “Future of Identity” Report appeared first on Entrust Blog. The post 3 ...

Beyond IP Addresses: Getting to Context of Value

Beyond IP Addresses: Getting to Context of Value By Dan Ramaswami, Vice President of Field Engineering Netography is shaking up conventional ways of addressing network visibility and control because the approach the security industry has... The ...