Application Security News and Articles


Colorado Privacy Act (CPA) 

What is the Colorado Privacy Act? The Colorado Privacy Act (CPA), signed into law on July 7, 2021, is a comprehensive privacy legislation that aims to enhance data privacy rights for residents of Colorado. The CPA provides consumers with greater ...

No summer break for cybercrime: Why educational institutions need better cyber resilience

The education system isn’t equipped to handle today’s cyberthreats. I’m not just talking about cybersecurity education in schools shaping the technical workforce of the future – America’s schools themselves are prime targets for ...

How AI-powered attacks are accelerating the shift to zero trust strategies

In this Help Net Security interview, Jenn Markey, Advisor to The Entrust Cybersecurity Institute, discusses the increasing adoption of enterprise-wide zero trust strategies in response to evolving cyber threats. Markey discusses the impact of ...

Cybersecurity jobs available right now: June 5, 2024

Corporate Data Protection Manager GLS | Germany | Hybrid – View job details As a Corporate Data Protection Manager, you will develop the Corporate Data Protection Framework with a special focus on compliance with the EU General ...

Find out which cyber threats you should be concerned about

This article includes excerpts from various reports that offer statistics and insights into the current cyber threat landscape. Human error still perceived as the Achilles’ heel of cybersecurity Proofpoint | 2024 Voice of the CISO | ...

8 Takeaways from Apple 2023 Threat Research

The newly-released Apple cybersecurity threat study reveals interesting data points and demonstrates how the threat landscape is evolving. The post 8 Takeaways from Apple 2023 Threat Research appeared first on Security Boulevard.

The CJIS Compliance Deadline is Fast Approaching | Is your state / local government ready?

The deadline for CJIS compliance is rapidly approaching – it is mandated that all entities accessing criminal justice information (CJI) must have an acceptable multi-factor authentication (MFA) solution in place by October 1st, 2024. As per ...

SecOps Teams Shift Strategy as AI-Powered Threats, Deepfakes Evolve 

An escalation in AI-based attacks requires security operations leaders to change cybersecurity strategies to defend against them. The study found 61% of respondents had experienced a deepfake incident in the past year, with 75% of those attacks ...

Aprende que es SIEM y cómo funciona

¿Que es una SIEM?  SIEM significa seguridad, información y gestión de eventos. Las herramientas SIEM agregan datos de registro, alertas de seguridad y eventos en una plataforma centralizada para proporcionar análisis en tiempo real para el ...

Russian Threat Groups Turn Eyes to the Paris Olympic Games

Russian threat groups are using old tactics and generative AI to run malicious disinformation campaigns meant to discredit the Paris Olympic Games, France and its president, and the IOC fewer than two months before the Games begin. The post ...

Key Takeaways from Upstream’s 2024 Automotive Cybersecurity Report

Upstream’s annual Automotive Cybersecurity Report reaches its sixth year of publication in 2024. With the full report stretching to 138 pages, you might not have time to go in-depth with it and read the whole thing. This blog presents some of ...

USENIX Security ’23 – Systematic Assessment of Fuzzers using Mutation Analysis

Authors/Presenters: Philipp Görz, Björn Mathis, Keno Hassler, Emre Güler, Thorsten Holz, Andreas Zeller, Rahul Gopinath Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the ...

The Role of DevSecOps in Enhancing CNAPP Efficiency

Incorporating DevSecOps into CNAPP strategies can improve the way organizations develop and secure their applications. The post The Role of DevSecOps in Enhancing CNAPP Efficiency appeared first on Security Boulevard.

Life in the Swimlane with Emily Spector, Senior SDR

The post Life in the Swimlane with Emily Spector, Senior SDR appeared first on AI Enabled Security Automation. The post Life in the Swimlane with Emily Spector, Senior SDR appeared first on Security Boulevard.

One Phish Two Phish, Red Teams Spew Phish

PHISHING SCHOOL How to Give your Phishing Domains a Reputation Boost “Armed with the foreknowledge of my own death, I knew the giant couldn’t kill me. All the same, I preferred to keep my bones unbroken” — Big Phish When we send out ...

NIST 2.0: Securing Workload Identities and Access

5 min read The updated framework addresses the need to secure non-human identities. Here's how that can extend across the guidance's five key functions. The post NIST 2.0: Securing Workload Identities and Access appeared first on Aembit. The post ...

Daniel Stori’s ‘Beware of Dog’

via the inimitable Daniel Stori at Turnoff.US! Permalink The post Daniel Stori’s ‘Beware of Dog’ appeared first on Security Boulevard.

Security challenges in the financial sector⎪Max Imbiel (CISO, Bitpanda)

This blog is based on the podcast episode with Max Imbiel, CISO at Bitpanda. It covers the unique challenges of building secure financial applications. The post Security challenges in the financial sector⎪Max Imbiel (CISO, Bitpanda) appeared ...

Was the Ticketmaster Leak Snowflake’s Fault?

Snowflake, Inc. says NO, threatening legal action against those who say it was. But reports are coming in of several more massive leaks from other Snowflake customers. The post Was the Ticketmaster Leak Snowflake’s Fault? appeared first on ...

Why HAST is important to API hackers

Learn why Human Application Security Testing (HAST) is important to API hackers. The post Why HAST is important to API hackers appeared first on Dana Epp's Blog. The post Why HAST is important to API hackers appeared first on Security Boulevard.