Application Security News and Articles


Reducing Risks and Threats with Continuous SaaS Compliance

CISOs and GRC officers are quickly recognizing the growing threats posed by misconfigured SaaS applications and integrations between SaaS apps. On average, 30% percent of corporate sensitive data now is processed or resides in SaaS applications ...

SAST Tools Must Support Your Embedded Operating Systems, Toolchains & Compilers – Chose Wisely

Embedded software development is very close to the development platform used. Whether it’s bare metal development, commercial RTOS or embedded Linux, the tool chain is an important component in software development. It’s imperative that tools ...

Securing Software for Healthy, Energy-Efficient Smart Buildings

Jason Christman, Vice President and CPSO of Johnson Controls, Inc., talks about the value of shifting left in design and development while continuously innovating smart building technologies.  The post Securing Software for Healthy, ...

Camelot Launches Cybersecurity Service Augmented by ML

Camelot this week launched a Secure360 cybersecurity platform that enables its cybersecurity team to leverage machine learning algorithms to perform vulnerability and assessments, cyberthreat hunting and cyberthreat intelligence analysis. Camelot ...

Sick of that Security Questionnaire? Automation is the Answer

Security questionnaires (SQs) are not fun. They’re time-consuming, tedious work and sometimes, they’re the one thing standing between you and a closed deal. Fortunately, the emergence of AI in the security space has resulted in many ...

Digital Trust Digest: This Week’s Must-Know News

The Digital Trust Digest is a curated overview of the week’s top cybersecurity news. Here's what happened the week of March 6 2023. The post Digital Trust Digest: This Week’s Must-Know News appeared first on Keyfactor. The post Digital Trust ...

USENIX Security ’22 – Mohammadkazem Taram, Xida Ren, Ashish Venkat, Dean Tullsen – ‘SecSMT: Securing SMT Processors against Contention-Based Covert Channels’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Mohammadkazem Taram, Xida Ren, Ashish ...

Vendor Tips for the SIG Questionnaire

Many companies understand the pain of constantly filling out extremely arduous customer- requested security questionnaires. Most of the time, the same common questions get asked over and over again. For some companies, the effort to go through a ...

‘Extraordinary, Egregious’ Data Breach at House and Senate

Capitol Trouble: Senators, representatives and staffers suffer PII leak. Could it finally kickstart some action? The post ‘Extraordinary, Egregious’ Data Breach at House and Senate appeared first on Security Boulevard.

Silicon Valley Bank Seized by FDIC as Depositors Pull Cash

The FDIC seized the assets of Silicon Valley Bank on Friday, which could impact cybersecurity firms that use the bank's services. The post Silicon Valley Bank Seized by FDIC as Depositors Pull Cash appeared first on SecurityWeek.

CommitStrip ‘Whatever You Want’

via the textual amusements of Thomas Gx, along with the Illustration talents of Etienne Issartia and superb translation skillset of Mark Nightingale - the creators of CommitStrip! Permalink The post CommitStrip ‘Whatever You Want’ ...

GrammaTech Makes Finding Vulnerabilities in Binaries Simpler

GrammaTech this week updated its CodeSentry software composition analysis (SCA) tool to make it simpler to identify specific types of vulnerabilities within application binaries. In addition, the company is also now making CodeSentry 4.2 ...

SAST, DAST, IAST, RASP And HAST

What Is SAST?Continue reading on Medium »

SAST, DAST, IAST, RASP And HAST

What Is SAST?Continue reading on Medium »

A Step-by-Step Guide to Navigating High-Stakes Audits

This article was authored by Art Provost, Vice President of Security Services and Senior Information Security Officer, at Filament Essential Services, an Apptega trusted partner. To learn more about how to navigate audits affordably and with ...

Blackbaud Fined $3M For ‘Misleading Disclosures’ About 2020 Ransomware Attack

Blackbaud has been slapped with a $3 million civil penalty by the SEC for "making misleading disclosures" about a 2020 ransomware attack that impacted more than 13,000 customers. The post Blackbaud Fined $3M For ‘Misleading Disclosures’ About ...

Orca Security Adds Attack Path Analysis to Cloud Security Platform

Orca Security this week added attack path analysis capabilities to its cloud security platform as part of an effort to make it easier to identify weaknesses that cybercriminals might exploit, including threats spanning multiple accounts and cloud ...

Domain Hijacking: The Definitive Guide to Detection & Remediation

Today, your company website is a critical part of your business. From marketing to sales, you use your website to support your business objectives. In many cases, companies incorporate portals that deliver digital customer experiences, including ...

Combo Lists & the Dark Web: Understanding Leaked Credentials

In today’s interconnected, cloud-based world, user credentials are the keys that grant entry to the house that stores an organization’s digital treasure. Just as burglars pick the lock on a physical house, cybercriminals use stolen ...

Unpatched Akuvox Smart Intercom Vulnerabilities Can Be Exploited for Spying

Researchers discover a dozen serious vulnerabilities in Akuvox smart intercom, but the vendor has not released any patches. The post Unpatched Akuvox Smart Intercom Vulnerabilities Can Be Exploited for Spying appeared first on SecurityWeek.