Application Security News and Articles


Selfie spoofing becomes popular identity document fraud technique

Document image-of-image was the most prevalent identity (ID) document fraud technique in 2023, occurring in 63% of all IDs that were rejected, according to Socure. Selfie spoofing and impersonations dominate document-related identity fraud ...

New infosec products of the week: May 10, 2024

Here’s a look at the most interesting products from the past week, featuring releases from Abnormal Security, AuditBoard, Cranium, Datadog, Eclypsium, ExtraHop, Forcepoint, SentinelOne, Splunk, Sumo Logic, and Trellix. AuditBoard enhances ...

NASA Must Improve Spacecraft Cybersecurity, GAO Report Finds

A GAO review of NASA projects found that, while some cybersecurity challenges have been addressed, many security policies and standards remain optional. The post NASA Must Improve Spacecraft Cybersecurity, GAO Report Finds appeared first on ...

Getting Started with Software Dependency Management

The biggest bang for your buck in dependency management is updates. Here are some tips for getting the ball rolling. The post Getting Started with Software Dependency Management appeared first on Mend. The post Getting Started with Software ...

Make WAAP Interesting Again by Quantifying Operational Efficiency and Secure by Design.

The adoption of the cloud is the biggest driver of the DevOps development process. Before cloud, waterfall (80’s to late 90’s) and agile (2000 to late 2000’s) were the most prominent development processes. Each re-enforces their own ...

Recent Breaches in Israel and Iran: A Closer Look at Cybersecurity Vulnerabilities

In recent times, Israel and Iran have been caught up in a series of conflicts and tensions, both on the geopolitical stage and in cyberspace posing significant challenges to regional stability but have also made both nations targets for ...

The Road to CTEM, Part 1: The Role of Validation

Future-proof your investment by determining what business and security initiatives a new tool may be able to support or streamline.  The post The Road to CTEM, Part 1: The Role of Validation appeared first on SafeBreach. The post The Road to ...

USENIX Security ’23 – SMACK: Semantically Meaningful Adversarial Audio Attack

Authors/Presenters: Zhiyuan Yu, Yuanhaur Chang, Ning Zhang, Chaowei Xiao Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating ...

Massive Online Shopping Scam Racks Up 850,000 Victims

Chinese crooks are running a global network of more than 75,000 fake online shops to steal credit card data and process fraudulent payments. The post Massive Online Shopping Scam Racks Up 850,000 Victims appeared first on Security Boulevard.

NSA: State-backed attackers are not after your data — they’re targeting CI

Companies in the crosshairs of advanced persistent threat (APT) actors look at data theft not as a primary objective of hacking crews backed by Russia, China and Iran — but rather as a means to an end, the U.S. National Security Agency (NSA) ...

What the UK’s New Password Laws Mean for Global Cybersecurity

The UK government is taking cybersecurity seriously and proving it with a new version of... The post What the UK’s New Password Laws Mean for Global Cybersecurity appeared first on Security Boulevard.

BTS #29 – Supply Chains, Firmware, And Patching – Jason Kikta

Jason joins us to discuss the current enterprise landscape for defending against supply chain attacks, remediating firmware issues, and the current challenges with patch management. Show Notes The post BTS #29 - Supply Chains, Firmware, And ...

One in Four Tech CISOs Unhappy with Compensation

Stagnating security budgets and mounting job pressures are weighing on CISOs, a quarter of whom expressed discontent with their salary and overall compensation. Show me the money: The average total compensation for tech CISOs stands at ...

Randall Munroe’s XKCD ‘Google Solar Cycle’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Google Solar Cycle’ appeared first on Security Boulevard.

Advancing Emergency Response Security with Autonomous Pentesting

In an increasingly interconnected world, where digital technologies infiltrate every aspect of society, vulnerabilities in these systems can be exploited by malicious actors to disrupt emergency services, compromise sensitive information, or even ...

London Drugs cyber attack: What businesses can learn from their week-long shutdown

The post London Drugs cyber attack: What businesses can learn from their week-long shutdown appeared first on Click Armor. The post London Drugs cyber attack: What businesses can learn from their week-long shutdown appeared first on Security ...

Securing Your Snowflake Data with Aembit Workload IAM

4 min read You’re likely seeing the explosion of workload and machine identities within organizations, and Snowflake’s ecosystem is no exception. The post Securing Your Snowflake Data with Aembit Workload IAM appeared first on Aembit. The ...

Pushing the Frontier of Information Security: Ekran System at Infosecurity 2024

Ekran System Inc., a leading provider of insider risk management solutions, will be exhibiting at Infosecurity 2024, one of Europe’s most prominent cybersecurity events. The event, which takes place in London at the beginning of June, will ...

Answering Your Top 9 Questions About Monitoring in Kubernetes

There are many things you can monitor in Kubernetes but you need to understand what is mission-critical in terms of monitoring. In a recent webinar, we explored what you should be monitoring in your Kubernetes platform, best practices to follow, ...

Whitepaper: The False Promises of AI in Cybersecurity

Cybersecurity is a battlefield where innovation is paramount. Artificial intelligence (AI) has emerged as a potential game-changer, promising to revolutionize threat detection and response. Vendors have made bold claims, promising their ...