Application Security News and Articles


PoC exploits for critical FortiSIEM command execution flaws released (CVE-2024-23108, CVE-2023-34992)

Horizon3.ai researches have released proof-of-concept (PoC) exploits for CVE-2024-23108 and CVE-2023-34992, vulnerabilities that allow remote, unauthenticated command execution as root on certain Fortinet FortiSIEM appliances. CVE confusion ...

Dashlane Nudges reduces the risk of credential theft

Dashlane unveiled Dashlane Nudges, a new automated tool to empower admins to proactively create a more security-conscious workforce and drive better credential security behavior across their organization, reducing the risk of credential theft. ...

Transcend raises $40 million to address data privacy issues

Transcend raised $40 million in Series B funding led by new investor StepStone Group, with participation from HighlandX and existing investors Accel, Index Ventures, 01 Advisors (01A), Script Capital, and South Park Commons. This brings the total ...

Symmetry Systems Unveils State of Data+AI Security: Dormant data growing 5X Year on Year, while 1/4 of Identities haven’t accessed Any Data in over 90 days.

Symmetry’s State of Data+AI Security Report Reveals Data and Identity challenges facing organizations as AI Adoption Accelerates with Microsoft Copilot... The post Symmetry Systems Unveils State of Data+AI Security: Dormant data growing 5X Year ...

Customer Identity and Access Management (CIAM) 101

An amazing post The post Customer Identity and Access Management (CIAM) 101 appeared first on Security Boulevard.

2023 OT Cybersecurity Roundup—Strategies for 2024

If there were any doubts earlier, 2023 has shown us how important OT systems are.  Operational technology has become one of the most crucial factors for safeguarding critical infrastructure – from electrical grids, transportation networks, and ...

Avoiding the cybersecurity blame game

Cyber risk management has many components. Those who do it well will conduct comprehensive risk assessments, enact well-documented and well-communicated processes and controls, and fully implemented monitoring and review requirements. Processes ...

Contextual Intelligence is the Key

With the increasing complexity and frequency of cybersecurity threats, organizations face many network threats. The importance of threat intelligence has become increasingly prominent. During this year’s RSA Conference, Sierra Stanczyk, the ...

RansomLord: Open-source anti-ransomware exploit tool

RansomLord is an open-source tool that automates the creation of PE files, which are used to exploit ransomware pre-encryption. “I created RansomLord to demonstrate ransomware is not invincible, has vulnerabilities and its developers make ...

Cybersecurity jobs available right now: May 29, 2024

Cloud Security Engineer – Secret Clearance Required Constellation West | USA | Remote – View job details As a Cloud Security Engineer, you will establish, execute, and sustain an ISSP A&A capability that ensures the ...

A closer look at GenAI impact on businesses

This article includes excerpts from various reports that provide statistics and insights on GenAI and its impact on businesses. CEOs accelerate GenAI adoption despite workforce resistance IBM | IBM study | May 2024 63% of CEOs say their ...

Using Scary but Fun Stories to Aid Cybersecurity Training

Need to get your audience’s attention so they listen to your cybersecurity lessons? Share these true stories to engage their attention and, perhaps, make them laugh. The post Using Scary but Fun Stories to Aid Cybersecurity Training appeared ...

Threats That Hide in Your Microsoft Office Documents

By Nathaniel Raymond Microsoft Office documents in the Office365 software suite have become a mainstay for many users who need to create documents for business reports, college essays, resumes, essential notetaking, and even strategic analyses. ...

How to Turn on Two-Factor Authentication for Emails?

Reading Time: 6 min Ensure your personal information remains safe and discover the step-by-step process of adding Two-factor authentication for Emails to enhance email security. The post How to Turn on Two-Factor Authentication for Emails? ...

OpenAI Launches Security Committee Amid Ongoing Criticism

OpenAI has a new Safety and Security Committee in place fewer than two weeks after disbanding its “superalignment” team, a year-old unit that was tasked with focusing on the long-term effects of AI. In a blog post Tuesday, the ...

USENIX Security ’23 – xNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses

Authors/Presenters:Feng Wei, Hongda Li, Ziming Zhao, Hongxin Hu Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the ...

USENIX Security ’23 – xNIDS: Explaining Deep Learning-based Network Intrusion Detection Systems for Active Intrusion Responses

Feng Wei, Hongda Li, Ziming Zhao, Hongxin Hu Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events ...

Beyond CAPTCHA: Arkose MatchKey, An AI-Resistant Attack Innovation

Generative AI and general AI platforms often include advanced computer vision technologies. These systems can easily solve traditional CAPTCHAs like the “pick all the squares with motorcycles” task because they are capable of interpreting ...

Lessons Learned from Part 1 of Our Cyber Incident Response Webinar Series

Setting the Stage for Cyber Chaos  In the first installment of our two-part webinar series, Nuspire’s Mike Pedrick, VP of Cybersecurity Consulting, and Chris Roberts, Chief Strategy Executive & Evangelist, took attendees on a journey ...

Randall Munroe’s XKCD ‘Room Code’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Room Code’ appeared first on Security Boulevard.