Application Security News and Articles


Risks of GenAI Rising as Employees Remain Divided About its Use in the Workplace

One in three office workers who use GenAI admit to sharing customer info, employee details and financial data with the platforms. Are you worried yet? The post Risks of GenAI Rising as Employees Remain Divided About its Use in the Workplace ...

Questions You Need to Ask When Evaluating a Security Automation Vendor

The post Questions You Need to Ask When Evaluating a Security Automation Vendor appeared first on AI Enabled Security Automation. The post Questions You Need to Ask When Evaluating a Security Automation Vendor appeared first on Security Boulevard.

VFCFinder Highlights Security Patches in Open Source Software

VFCFinder analyzes commit histories to pinpoint the most likely commits associated with vulnerability fixes. The post VFCFinder Highlights Security Patches in Open Source Software appeared first on Security Boulevard.

Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnaravi – #290 – How Project Milestones Are Set

via the respected Software Engineering expertise of Mikkel Noe-Nygaard and the lauded Software Engineering / Enterprise Agile Coaching work of Luxshan Ratnaravi at Comic Agilé! Permalink The post Comic Agilé – Mikkel Noe-Nygaard, ...

Palo Alto Networks and IBM Align Cybersecurity Strategies

Palo Alto Networks this week revealed it has agreed to acquire the QRadar software-as-a-service (SaaS) offerings from IBM to migrate organizations using this platform, to the Cortex XSIAM security operations center (SOC) delivered as a cloud ...

The Premier Choice for CJIS Compliance in Law Enforcement

Introduction From criminal histories to fingerprints and other highly confidential information , U.S. law enforcement agencies rely on vast amounts of FBI data to solve crimes. Access to this data requires strict adherence to the FBI’s ...

Counting the Cost of PCI DSS Non-Compliance

For two decades, the Payment Card Industry Data Security Standard (PCI DSS) has been the only show in town when it comes to regulating cardholder data. Created by the five big card companies (Visa, Mastercard, Discover, JCB and American Express) ...

Activating end-to-end secrets security with CyberArk and GitGuardian

In this guide, we'll walk you through integrating CyberArk Conjur with GitGuardian, step by step. The post Activating end-to-end secrets security with CyberArk and GitGuardian appeared first on Security Boulevard.

The new Sonatype Learn: Self-service educational materials where and when you need them

Sonatype Learn — your trusted DevOps and Sonatype product training resource — is all new. We've launched an industry-leading Learning Management System (LMS) with updated courses, fresh videos, and a whole new learning vibe! The post The new ...

Unveiling the Underworld of Bank Breaches: Navigating the Digital Frontlines of Financial Cybersecurity

Bank breaches and the banking world are now a front line in cybersecurity, where hidden networks thrive in the shadows of the dark web and encrypted chats. As technology advances, the dangers of bank hacks grow, transforming old-school bank ...

Ensuring Election Security and Integrity

As the United States approaches the 2024 presidential election, the integrity of our electoral process remains a critical issue. Despite persistent claims and efforts to undermine public confidence, there is no credible evidence of widespread ...

Vulnerabilities prioritization funnel: Focus on what matters

We are excited to announce updates to our vulnerability prioritization funnel, which will help you focus on vulnerabilities that pose a real danger to your business. The post Vulnerabilities prioritization funnel: Focus on what matters appeared ...

Is the VPN Era Ending? Insights for Security Leaders 

The landscape of VPN technology is rapidly changing, signaling potential obsolescence as new threats specifically target these technologies. In recent research by Veriti, we’ve observed a significant increase in attacks on VPN infrastructures, ...

Understanding AddressSanitizer: Better memory safety for your code

By Dominik Klemba and Dominik Czarnota This post will guide you through using AddressSanitizer (ASan), a compiler plugin that helps developers detect memory issues in code that can lead to remote code execution attacks (such as WannaCry or this ...

Enhance security with Sonatype Lifecycle and ServiceNow Application Vulnerability Response (AVR) integration

We are excited to announce an innovative partnership that integrates Sonatype's open source software (OSS) security intelligence directly into ServiceNow workstreams. For this partnership, we've launched a new Sonatype and ServiceNow ...

2024 Verizon DBIR: Key Thoughts

It’s DBIR season once again, and, as usual, the Verizon team has produced a detailed and comprehensive (and humorous) exemplar of statistical cybersecurity analysis and reporting. Last year, we noted that the data breach landscape was largely ...

When it comes to threat modeling, not all threats are created equal

One fundamental principle every threat modeler learns very early in their career is that not all threats are created equal. Some threats can be fixed more easily than others. Among the threats most difficult to fix — if they can be fixed at all ...

Stop “applying Lipstick on a Pig”, it’s about time you Innovate

The phrase “putting lipstick on a pig” is a colloquial way to describe trying to make superficial improvements to something fundamentally flawed. In the context...Read More The post Stop “applying Lipstick on a Pig”, it’s about time you ...

The Role of Identity and Access Management in K-12 Cybersecurity

We’re all familiar with the concept of a driver’s license or passport. As a form of identification, these documents serve two purposes: They verify someone is who they claim to be. They authorize access to buildings, services, and so on. But ...

Navigating Yesterday’s Battles: Insights from Cybersecurity Reports

We often find ourselves entrenched in yesterday’s battles, grappling with legacy systems, applying products launched last year, responding to attack methods from last year’s, aligning with regulations published 3 years ago, and so on. While ...