Application Security News and Articles


Managing Cloud Compliance and Security Posture

Why compliance and access security in the public cloud are so challenging – and how carefully chosen CSPM tools can help The post Managing Cloud Compliance and Security Posture appeared first on Ermetic. The post Managing Cloud Compliance and ...

USENIX Security ’22 – Chaoshun Zuo, Zhiqiang Lin – ‘Playing Without Paying: Detecting Vulnerable Payment Verification in Native Binaries of Unity Mobile Games’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Chaoshun Zuo, Zhiqiang Lin – ...

Why software transparency is critical: Understanding supply chain security in a software-driven society

By now the topic of software supply chain security is clearly among the most discussed topics in the IT/Cybersecurity industry. We know from reports from groups such as Sonatype that software supply chain attacks are up 742% over the last 3 ...

Addressing TSA’s Aviation Security Emergency Mandates for Airlines and Airports

The Department of Homeland Security (DHS) and its Transportation Security Administration (TSA) have issued a handful of sector-specific cybersecurity directives over the last eighteen months. The effort began as a response to the 2021 ransomware ...

HPE Acquires Axis Security to Gain SSE Platform

Hewlett-Packard Enterprise (HPE) has announced its intent to acquire Axis Security, a provider of a secure service edge (SSE) platform. The acquisition is part of HPE’s effort to extend the integrated software-defined wide area network ...

IronNet Monthly Global Threat Update

February 24, 2023 marked the one year anniversary of Russia’s invasion of Ukraine. When the Ukraine-Russia War began, it commenced the largest military conflict in the age of cyber, leading many to prepare for the cyber domain to become as much ...

ForgeRock and the New DoD Zero Trust Strategy Part 2

As feedback has been shared on the first blog about the Department of Defense Zero Trust Strategy, the primary responses were: "OK, how does ForgeRock do what you've claimed?" "Is that all ForgeRock does to meet the user pillar of the Zero Trust ...

Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnarav – ‘#231 – The Biggest Liar’

via the respected Software Engineering expertise of Mikkel Noe-Nygaard as well as the lauded Software Engineering and Enterprise Agile Coaching talent of Luxshan Ratnarav at Comic Agilé! Permalink The post Comic Agilé – Mikkel ...

GUEST ESSAY: Five stages to attain API security — and mitigate attack surface exposures

APIs (Application Programming Interfaces) play a critical role in digital transformation by enabling communication and data exchange between different systems and applications. Related: It’s all about attack surface management APIs help digital ...

Ransomware and Supply Chain Attacks: How to Protect Your Business From the Rising Threat of Third-Party Attacks

Stay protected from the rising threat of supply chain cyber attacks and ransomware attacks. Learn how to identify and assess the risks associated with third-party vendors and suppliers, and discover practical steps for implementing security ...

Mistakes by Threat Actors Lead to Disruption, Not Just Better Blocking

Threat actors really only stop when their infrastructure is disrupted and their flow of funds disappears. The post Mistakes by Threat Actors Lead to Disruption, Not Just Better Blocking appeared first on SecurityWeek.

USENIX Security ’22 – Simon Rohlmann, Christian Mainka, Vladislav Mladenov, Jörg Schwenk – ‘Oops… Code Execution And Content Spoofing: The First Comprehensive Analysis Of OpenDocument Signatures’

Our thanks to USENIX for publishing their Presenter’s outstanding USENIX Security ’22 Conference content on the organization’s’ YouTube channel. Permalink The post USENIX Security ’22 – Simon Rohlmann, Christian Mainka, ...

Solving Cybersecurity Staff Churn

Staff churn is a huge issue for the cybersecurity industry. Frustrations are building among security teams as they face increasing cyberattacks, scrutiny from stakeholders and data overwhelm. This is made worse when paired with the cybersecurity ...

Understanding the Integration Between KMS and Secrets Manager on AWS

Key Management Service (KMS), and Secrets Manager are easy to mix, not only because of the similarity in names but also because one might get confused over the purpose of each one. At a high level, KMS is a service that allows users to manage ...

What is dark data and how should you manage it?

Increasing volumes of dark data put sensitive company data at greater risk of compromise. This blog covers tips IT teams can use to uncover, classify, track and protect dark data. The post What is dark data and how should you manage it? appeared ...

Business Email Compromise: 3 Steps to Reduce Risk

Email has been a popular delivery of malware and risk for decades.The first phishing schemes took place in the 1990s, and phishing techniques have only become more sophisticated in the decades since. It’s particularly popular among criminals ...

3 Reasons Women Should Reskill to Work in Cybersecurity

As women, from a young age, being technically savvy or being interested in math, science or business wasn’t celebrated. You were ‘cool’ and ‘popular’ if you had great hair or nice jeans, not if you wanted to code software. If the tech ...

1Password Leverages SSO Service to Better Protect Secrets

1Password announced today general availability of a single sign-on (SSO) capability that makes sure secrets are kept secure by leveraging keys that are stored on an end user’s device. The Unlock with Single Sign-On capability requires two ...

How Coding Changed My Life

  The post How Coding Changed My Life appeared first on Security Boulevard.

‘Sys01 Stealer’ Malware Targeting Government Employees

The Sys01 Stealer has been observed targeting the Facebook accounts of critical government infrastructure employees. The post ‘Sys01 Stealer’ Malware Targeting Government Employees appeared first on SecurityWeek.