Application Security News and Articles


GUEST ESSAY: Taking a systematic approach to achieving secured, ethical AI model development

AI has the potential to revolutionize industries and improve lives, but only if we can trust it to operate securely and ethically. Related: The key to the GenAI revolution By prioritizing security and responsibility in AI development, we can ...

The 8 P’s to Mitigate Risks in Software Product Development Initiatives

Software product development initiatives are not an easy feat especially when 80% of the projects fail for one reason or another. Executing software development is...Read More The post The 8 P’s to Mitigate Risks in Software Product Development ...

Alert: Kimsuky Hacking Group Targets Human Rights Activists

As per recent reports a new social engineering attack attributed to the North Korea-linked Kimsuky hacking group is targeting human rights activists using fake Facebook accounts. This tactic, involving fictitious identities, marks a significant ...

How to Spot a Fake University Email

Reading Time: 4 min Scammers impersonate universities in phishing emails. Learn 5 red flags to identify fake university emails and avoid giving away personal information. The post How to Spot a Fake University Email appeared first on Security ...

What is ISO 27701 PIMS?

In today’s data-driven world, protecting personal information is of greater significance. The International Organisation for Standardisation (ISO) has developed ISO 27701, a comprehensive Privacy Information Management System (PIMS) standard ...

Lack of skills and budget slow zero-trust implementation

The risk of a cyber breach is the number one global driver for zero trust strategy implementation, according to Entrust. The 2024 State of Zero Trust & Encryption Study surveyed over 4,000 IT security practitioners worldwide. The survey ...

Encrypted Notepad: Open-source text editor

Encrypted Notepad, an open-source text editor, ensures your files are saved and loaded encrypted with AES-256. With no ads, no network connection required, and no unnecessary features, it’s a tool that simply works. “Like the Windows ...

New infosec products of the week: May 31, 2024

Here’s a look at the most interesting products from the past week, featuring releases from Adaptive Shield, Dashlane, Detectify, and Truecaller. Adaptive Shield unveils platform enhancements to improve SaaS security Adaptive Shield has extended ...

From Phishing to Fraud: How AI Can Safeguard Your Customers

Is your website vulnerable to web-automated attacks? Learn how AI can help protect your business and customers from the growing threat of cybercrime. The post From Phishing to Fraud: How AI Can Safeguard Your Customers appeared first on Security ...

How to find Westermo EDW-100 devices

Westermo has disclosed (direct PDF link) multiple vulnerabilities in their EDW-100 Serial to Ethernet converter product. The post How to find Westermo EDW-100 devices appeared first on Security Boulevard.

DarkGate Malware

Threat Overview – DarkGate Malware DarkGate malware variant was first observed in the wild in 2018 (seemingly in production since 2017), evolving into a more dangerous and widespread version of itself in recent years – more notably after the ...

AI Threat Scenario, GuLoader, DarkGate, MirrorBlast, Kutaki Stealer and More – Hacker’s Playbook Threat Coverage Round-up: May 2024

New and updated coverage for ransomware and malware variants, including AI Threat Scenario, GuLoader, DarkGate, MirrorBlast, & Kutaki Stealer The post AI Threat Scenario, GuLoader, DarkGate, MirrorBlast, Kutaki Stealer and More – Hacker’s ...

USENIX Security ’23 – BalanceProofs: Maintainable Vector Commitments with Fast Aggregation

Authors/Presenters: Weijie Wang, Annie Ulichney, Charalampos Papamanthou Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating ...

Is Imitation A Form Of Flattery? Scarlett Johansson Doesn’t Think So | Avast

It all started when Open AI’s CEO Sam Altman unveiled a new ChatGPT version that included a new voice assistant seemingly inspired by the movie Her. Altman had professed his love for the movie before, declaring it his favorite. Controversy ...

Daniel Stori’s ‘Poprocks and Coke’

Permalink The post Daniel Stori’s ‘Poprocks and Coke’ appeared first on Security Boulevard.

Mitigate Http/2 continuations with Imperva WAF

As the threat landscape continues to grow, with new breaches being announced every day, Imperva continues to stay one step ahead of attackers. HTTP/2 exploits seem to be growing every quarter as more attackers use this vulnerability in new ...

Why Every Multi-Cloud Environment Needs an Application Owner Dashboard

Organizations have moved to multi-cloud environments to achieve the benefits of business resilience, agility, best-of-breed capabilities, compliance, and cost containment, or due to the result of a merger or acquisition. But distributed ...

Ticketmaster Hack Ticks Off 560M Customers in 1.3TB Breach

What we know so far: A Ticketmaster AWS instance was penetrated by unknown perpetrators; “ShinyHunters” is selling stolen data on their behalf. Don’t forget to add the hidden 5% fee to the ransom. The post Ticketmaster Hack Ticks Off 560M ...

How Old Are Your Kubernetes Nodes?

How old are your Kubernetes nodes? Most often, people don’t know the answer to this question, or if they do, they know that “most” of their nodes are a certain age, and some are newer. Knowing the age of your nodes is important, ...

To Infinity and Beyond!

Increasing our understanding of EDR capabilities in the face of impossible odds. Introduction I recently had a discussion with our chief strategist, Jared Atkinson, about purple teaming. We believe that large quantities of procedures per ...