Application Security News and Articles


Blair and Hague’s Digital ID Notion Could Trip Up Their Entire Package

City A.M. is London's most-read financial and business newspaper, and its digital version, CityAM.com, has approximately 3.2 million unique visitors per month. It covers the latest economic, political, and business news as well as comment, sport, ...

USENIX Security ’22 – ‘TheHuzz: Instruction Fuzzing Of Processors Using Golden-Reference Models For Finding Software-Exploitable Vulnerabilities’

Complete Title: USENIX Security '22 - Rahul Kande, Addison Crump, Garrett Persyn, Patrick Jauernig, Ahmad-Reza Sadeghi, Aakash Tyagi, Jeyavijayan Rajendran - ‘TheHuzz: Instruction Fuzzing Of Processors Using Golden-Reference Models For ...

Cybercrime Losses Exceeded $10 Billion in 2022: FBI

The FBI received more than 800,000 cybercrime-related complaints in 2022, with losses totaling over $10 billion. The post Cybercrime Losses Exceeded $10 Billion in 2022: FBI appeared first on SecurityWeek.

CISA Warns of Plex Vulnerability Linked to LastPass Hack

CISA has added vulnerabilities in Plex Media Server and VMware NSX-V to its Known Exploited Vulnerabilities catalog. The post CISA Warns of Plex Vulnerability Linked to LastPass Hack appeared first on SecurityWeek.

Euler Loses Nearly $200 Million to Flash Loan Attack

London, UK based De-Fi platform company Euler has lost a reported $196 million to a flash loan attack. The post Euler Loses Nearly $200 Million to Flash Loan Attack appeared first on SecurityWeek.

New ‘GoBruteforcer’ Botnet Targets Web Servers

The recently identified Golang-based GoBruteforcer botnet is targeting web servers running FTP, MySQL, phpMyAdmin, and Postgres services. The post New ‘GoBruteforcer’ Botnet Targets Web Servers appeared first on SecurityWeek.

Let’s Stop Talking About the ‘Largest’ DDoS Attack

There have been a slew of DDoS attacks recently that are serious, but to focus on the size of the latest attack is the wrong thing to do. What we need to focus on are the impacts of these attacks. Would the CFO consider the site being down for ...

Strata Identity CTO Invited to Present at APIsecure 2023

Topher Marie will discuss the importance, challenges, and how-to best practices for modernizing legacy APIs    BOULDER, Colo., March 13, 2023 – Strata Identity, the Identity Orchestration for multi-cloud company, announced today that Topher ...

How Can GRC Teams Leverage Cyber Risk Quantification?

Articles related to cyber risk quantification, cyber risk management, and cyber resilience. The post How Can GRC Teams Leverage Cyber Risk Quantification? appeared first on Security Boulevard.

DevSecOps uses policy to take the pressure off testing

Application Security Orchestration and Correlation uses processes and automation to help accelerate vulnerability testing and mitigation. The post DevSecOps uses policy to take the pressure off testing appeared first on Security Boulevard.

Why You Need to Emphasize Cloud Security

In today’s digital age, businesses of all sizes rely heavily on cloud technology to store, process and access their critical data and applications. While cloud computing offers numerous benefits, it also poses significant security ...

NMFTA Appoints Cybersecurity Director to Help Protect Trucking Industry 

NMFTA appoints Antwan Banks as director of enterprise security as the organization shifts focus to end-to-end security for the trucking industry. The post NMFTA Appoints Cybersecurity Director to Help Protect Trucking Industry  appeared first on ...

Zoll Medical Data Breach Impacts 1 Million Individuals

Zoll Medical is notifying one million individuals that their personal information was compromised in a data breach earlier this year. The post Zoll Medical Data Breach Impacts 1 Million Individuals appeared first on SecurityWeek.

GUEST ESSAY: Could CISOs be on the verge of disproving the ‘security-as-a-cost-center’ fallacy?

This year has kicked off with a string of high-profile layoffs — particularly in high tech — prompting organizations across all sectors to both consider costs and plan for yet another uncertain 12 or more months. Related: Attack surface ...

BlackFog Wins Cybersecurity Excellence and Globee Cybersecurity Awards

BlackFog wins Cybersecurity Excellence awards for Virtual CISO offering, ransomware protection, overall company innovation and a Globee Cybersecurity Award for it's State of Ransomware report. The post BlackFog Wins Cybersecurity Excellence and ...

Counting ICS Vulnerabilities: Examining Variations in Numbers Reported by Security Firms

Reports published by various industrial cybersecurity companies provide different numbers on ICS vulnerabilities — here’s why. The post Counting ICS Vulnerabilities: Examining Variations in Numbers Reported by Security Firms appeared first ...

Google Announces Intentions to Limit TLS Certificates to 90 Days: Why Automated CLM is Crucial

On March 3, Google announced in its “Moving Forward, Together” roadmap the intention to reduce the maximum possible validity for public TLS certificates from 398 days to 90 days, in a future policy update or a CA/B Forum Ballot Proposal. This ...

The SVB demise is a fraudster’s paradise, so take precautions

For those who haven’t followed the drama, Silicon Valley Bank has been shut down by the California Department of Financial Protection and Innovation, after a bank run that followed an insolvency risk and a stock crash. The Federal Deposit ...

TSA issues additional cybersecurity rules for the aviation sector

The Transportation Security Administration (TSA) issued a new cybersecurity amendment to the security programs of certain TSA-regulated (airport and aircraft) operators in the aviation sector, following similar measures announced in October 2022 ...

Fighting financial fraud through fusion centers

Keeping up with financial fraud is incredibly difficult because accurate fraud detection requires a deep, real-time analysis of all the events surrounding a transaction. Consider a typical payment transaction: A single transfer of funds to a new ...