Application Security News and Articles


Kaseya Connect Global 2024 Day 3 Recap

Navigating Cybersecurity at Kaseya Connect Global 2024 The final day of Kaseya Connect Global 2024 offered a deep dive intoRead More The post Kaseya Connect Global 2024 Day 3 Recap appeared first on Kaseya. The post Kaseya Connect Global 2024 ...

Google Continues Mixing Generative AI into Cybersecurity

Google is combining multiple streams of threat intelligence with a Gemini generative AI model to create a new cloud service that is designed to help security teams to more quickly and accurately sort through massive amounts of data to better ...

USENIX Security ’23 – The Space of Adversarial Strategies

Authors/Presenters: Ryan Sheatsley, Blaine Hoak, Eric Pauley, Patrick McDaniel Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open ...

HYPR and Microsoft Partner on Entra ID External Authentication Methods

Last week, Microsoft announced the public preview of external authentication methods (EAM) for Entra ID. As a close partner, HYPR has worked extensively with Microsoft on the new offering and we are excited to be one of the first external ...

2024 OWASP Mobile Top Ten Risks

What is OWASP MASVS? In case you didn't notice, the OWASP Mobile Top 10 List was just updated, for the first time since 2016! This is important for developers since this list represents the list of the most crucial mobile application security ...

Google Makes Implementing 2FA Simpler

Google is encouraging the adoption of multi-factor authentication to protect against phishing and other cyberattacks. It hopes 2-Step Verification (2SV) can help. The post Google Makes Implementing 2FA Simpler appeared first on Security Boulevard.

RSAC 2024: IoT Security Questions (and Answers)

The 2024 RSA Conference is underway, and Viakoo is out in force.  During the conference as we meet with customers, prospects, media, and analysts I will try to cherry pick some of the more interesting questions related to IoT Security.  Over ...

Danile Stori’s ‘Vulnerable Code’

via the inimitable Daniel Stori at Turnoff.US! Permalink The post Danile Stori’s ‘Vulnerable Code’ appeared first on Security Boulevard.

Balancing AI Workloads and Energy Demands with DCIM Software

The rapid expansion of artificial intelligence (AI) applications has presented new challenges for data center management, particularly in balancing workload efficiency with energy consumption. Data Center Infrastructure Management (DCIM) software ...

Introducing Aembit Access Management for CI/CD Platforms

4 min read Our identity federation capability better secures and streamlines CI/CD workflows, like in GitHub Actions and GitLab, with short-lived, secretless credentials. The post Introducing Aembit Access Management for CI/CD Platforms appeared ...

Guts & Greed: How Bug Hunter Arrogance and Apathy Hurts Us All

Explore why bug hunters should be more patient as vendors try to improve their application security maturity from a VDP to a BBP. The post Guts & Greed: How Bug Hunter Arrogance and Apathy Hurts Us All appeared first on Dana Epp's Blog. The ...

LockBit leader unmasked: US charges Russian national

Russian national Dmitry Khoroshev is “LockBitSupp”, the creator, developer and administator of the infamous LockBit ransomware group, according to UK, US and Australia law enforcement agencies. The US Justice Deparment has unsealed ...

New Attack on VPNs

This attack has been feasible for over two decades: Researchers have devised an attack against nearly all virtual private network applications that forces them to send and receive some or all traffic outside of the encrypted tunnel designed to ...

Hunters Announces Full Adoption of OCSF and Introduces OCSF-Native Search

San Francisco, United States, May 7th, 2024, CyberNewsWire Hunters, the pioneer in modern SOC platforms, today announced its full adoption of the Open Cybersecurity Schema Framework (OCSF), coupled with the launch of groundbreaking OCSF-native ...

USENIX Security ’23 – Place Your Locks Well: Understanding and Detecting Lock Misuse Bugs

Authors/Presenters: Yuandao Cai, Peisen Yao, Chengfeng Ye, Charles Zhang Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating ...

Sonatype Lifecycle best practices: Reference policies, backup and restore

Fortifying your software development processes against security threats and compliance issues is not just necessary — it's imperative to maintain resilience in today's unpredictable cyber environment. Managing software dependencies effectively ...

Overcoming Limitations of SAST and Other Traditional Software Security Testing Tools

What is Static Application Security Testing? What are the benefits and limitations? How can you expand your testing scope?Continue reading on Medium »

Abnormal extends Account Takeover Protection to cloud apps, introduces AI Security Mailbox

Abnormal Security is expanding its Account Takeover Protection product line beyond email to provide visibility into cross-platform user behavior and centralize compromised account detection and remediation across identity, collaboration, and ...

Dynatrace enhances its platform with new Kubernetes Security Posture Management capabilities

Dynatrace is enhancing its platform with new Kubernetes Security Posture Management (KSPM) capabilities for observability-driven security, configuration, and compliance monitoring. This announcement follows the rapid integration of Runecast ...

Mend.io and Sysdig Launch Joint Solution for Container Security

Learn how Mend.io and Sysdig together cover your cloud native applications throughout the software life cycle. The post Mend.io and Sysdig Launch Joint Solution for Container Security appeared first on Mend. The post Mend.io and Sysdig Launch ...