Application Security News and Articles


Threat Hunting 101: Five Common Threats to Look For

Learn more about supply chain threats and where to find them. The post Threat Hunting 101: Five Common Threats to Look For appeared first on Mend. The post Threat Hunting 101: Five Common Threats to Look For appeared first on Security Boulevard.

Elevate Your IAM Strategy with Thales at EIC 2024

Elevate Your IAM Strategy with Thales at EIC 2024 madhav Thu, 05/30/2024 - 05:23 From 4 to 7 June, Berlin will host Europe’s premier identity and cloud experts gathering. The European Identity and Cloud Conference 2024 (EIC), now in its 17th ...

Operation Endgame | Botnets disrupted after international action

On Thursday, May 30th, 2024, a coalition of international law enforcement agencies announced "Operation Endgame". This effort targeted multiple botnets, such as IcedID, Smokeloader, SystemBC, Pikabot, and Bumblebee, as well as their operators, ...

59% of public sector apps carry long-standing security flaws

Applications developed by public sector organizations have more security debt than those created by the private sector, according to Veracode. Security debt, defined for this report as flaws that remain unfixed for longer than a year, exists in ...

NIST unveils ARIA to evaluate and verify AI capabilities, impacts

The National Institute of Standards and Technology (NIST) is launching a new testing, evaluation, validation and verification (TEVV) program intended to help improve understanding of artificial intelligence’s capabilities and impacts. Assessing ...

Identity-related incidents becoming severe, costing organizations a fortune

With the rise of identity sprawl and system complexity, more businesses are suffering identity-related incidents than ever before, according to IDSA. Identity-related incidents in headlines Identity-related incidents continue to dominate ...

What is Security Orchestration?

The post What is Security Orchestration? appeared first on AI Enabled Security Automation. The post What is Security Orchestration? appeared first on Security Boulevard.

Malicious PyPI Package ‘Pytoileur’ Targets Windows and Leverages Stack Overflow for Distribution

Another day, another PyPI malware package. But this one has a new way to (try to) sneak into your computer. The post Malicious PyPI Package ‘Pytoileur’ Targets Windows and Leverages Stack Overflow for Distribution appeared first on ...

NIST Struggles with NVD Backlog as 93% of Flaws Remain Unanalyzed

The funding cutbacks announced in February have continued to hobble NIST’s ability to keep the government’s National Vulnerabilities Database (NVD) up to date, with one cybersecurity company finding that more than 93% of the flaws added have ...

Ticketmaster Hacked, Personal Data of 560 Million Customers Leaked, ShinyHunters Claim

Ticket to Hide: A threat group hacked 1.3 terabytes of Ticketmaster customer data, including payment information. It’s threatening to release the personal data unless a ransom is paid. The post Ticketmaster Hacked, Personal Data of 560 Million ...

I have an SBOM, now what?

Just as the food industry tracks the origins and safety of ingredients to ensure product quality, the software industry requires a similar level of oversight and transparency. The post I have an SBOM, now what? appeared first on Security Boulevard.

The Top 11 Metrics for Successful Vulnerability Management

Introduction In our latest ebook, The Ultimate Guide to Vulnerability Management (VM) Metrics, we uncover the top 11 VM metrics you should measure and report, why these metrics matter to the success of your team and your business, and how to use ...

News Alert: DNSFilter joins the WeProtect Global Alliance to help protect children online

Washington D.C., May 29, 2024, PRNewswire — DNSFilter announced today that it has joined the WeProtect Global Alliance to help prevent the spread of child sex abuse material (CSAM) online. This partnership will help further WeProtect’s ...

Scammers Build Fraud Campaigns Around Free Piano Offers

Scammers are betting that if people are offered a free – yet unsolicited – piano, some will jump at the deal. That appears to be happening. According to threat researchers at cybersecurity firm Proofpoint, bad actors running multiple ongoing ...

Weighing the Risk: The Cost of Skipping Pen Tests

The post Weighing the Risk: The Cost of Skipping Pen Tests appeared first on Digital Defense. The post Weighing the Risk: The Cost of Skipping Pen Tests appeared first on Security Boulevard.

USENIX Security ’23 – Dubhe: Succinct Zero-Knowledge Proofs for Standard AES and related Applications

Authors/Presenters:Changchang Ding and Yan Huang Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s ...

Must-See Sessions at IT Nation Secure 2024

As we gear up for IT Nation Secure 2024 in Orlando, Florida and we can’t wait to meet up with our partners The post Must-See Sessions at IT Nation Secure 2024 appeared first on Seceon. The post Must-See Sessions at IT Nation Secure 2024 ...

Christie’s Auction House Hacked, Sensitive Data from 500,000 Customers Stolen

A hacker group claims to have stolen sensitive data from at least 500,000 Christie's customers. Now they are threatening to publish it. The post Christie’s Auction House Hacked, Sensitive Data from 500,000 Customers Stolen appeared first on ...

Randall Munroe’s XKCD ‘Local Group’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Local Group’ appeared first on Security Boulevard.

Top 5 Evaluation Criteria For Choosing The Right ITDR Tool 

Identity is now a top priority for security decision makers. The need to overcome malicious TTPs, such as credential access, privilege escalation and lateral movement, has never been more urgent. When over 80% of breaches involve the use of ...