Application Security News and Articles


Hackathon: Authenticating header-based apps

One of the most exciting things about working at a startup is influencing how the company grows over time. Strata’s CEO loves it when people tell him something is impossible, and that “challenge, accepted” mentality has clearly filtered ...

Google Extends Generative AI Reach Deeper into Security

The Google Chronicle cybersecurity platform extensions are based on the Gemini LLM with the addition of cybersecurity data. The post Google Extends Generative AI Reach Deeper into Security appeared first on Security Boulevard.

Simbian Unveils Generative AI Platform to Automate Cybersecurity Tasks

Simbian TrustedLLM promises to automate complex cybersecurity tasks by continuously learning about IT environments. The post Simbian Unveils Generative AI Platform to Automate Cybersecurity Tasks appeared first on Security Boulevard.

Are you prepared for Google’s 90-day validity period on TLS certificates?

Are you prepared for Google's 90-day validity period on TLS certificates? Learn what's to come and how to prepare. The post Are you prepared for Google’s 90-day validity period on TLS certificates? appeared first on Akeyless. The post Are you ...

How to Create a Cybersecurity Incident Response Plan

Editor’s note: With the increased prevalence of ransomware and other cyberattacks, now is the time to take a moment to review your cyber response plan and examine the security of your key information security systems. Hyperproof has updated ...

How to find AMI MegaRAC BMCs running lighttpd with runZero

Binarly Research discovered that AMI MegaRAC Baseboard Management Controllers (BMC) on servers running lighttpd before version 1.4.51 are susceptible to an out-of-bounds (OOB) heap memory read. The post How to find AMI MegaRAC BMCs running ...

Our Security of AI Papers and Blogs Explained

Moderately relevant AI made image about AI papers :-) steampunk ofc! Recently our team has written several papers and blogs focused on securing AI. What you will not see in these papers is anything to do with robot rebellion or some such ...

Defending AI Apps Against Abuse: A Real-World Case Study

Gain insights on defending your AI apps from abuse based on our real-world experiences helping customers combat emerging adversarial threats. The post Defending AI Apps Against Abuse: A Real-World Case Study appeared first on Security Boulevard.

USENIX Security ’23 – You Can’t See Me: Physical Removal Attacks on LiDAR-based Autonomous Vehicles Driving Frameworks

Authors/Presenters: Yulong Cao, S. Hrushikesh Bhupathiraju, Pirouz Naghavi, Takeshi Sugawara, Z. Morley Mao, Sara Rampazzi Permalink The post USENIX Security ’23 – You Can’t See Me: Physical Removal Attacks on LiDAR-based ...

Apple Warns of ‘Mercenary Spyware Attacks’ on iPhone Users

Apple reportedly is alerting iPhone users in 92 countries that they may have been the targets of attacks using “mercenary spyware,” a term that the company is now using in such alerts in place of “state-sponsored” malware. Apple’s ...

Considering an Under Attack-as-a-Service Model? Hold Your Horses

In the ever-evolving digital landscape, the sophistication of cyber threats is not just increasing; it’s transforming. One of the most pervasive threats that businesses across all sectors face today comes from automated software attacks, ...

Cybersecurity Market Faces Funding Downturn in Q1 2024

Industry experts remain cautiously optimistic about future funding trends, emphasizing investor interest in emerging technologies including blockchain and AI security. The post Cybersecurity Market Faces Funding Downturn in Q1 2024 appeared first ...

Introducing the Customizable Dashboard layout, Wiz integration, and more

Introducing the Customizable Dashboard layout, Wiz Integration, and other Q2 2024 Feature Enhancements to the runZero Platform. The post Introducing the Customizable Dashboard layout, Wiz integration, and more appeared first on Security Boulevard.

From Alert Fatigue to Actionable Insights: How SCA Fits Into Active ASPM

Using third-party components in application development has become a norm rather than an exception. While boosting efficiency and innovation, this trend also opens up a Pandora’s box of security vulnerabilities that adversaries can exploit. The ...

Rooting out Risky SCCM Configs with Misconfiguration Manager

tl;dr: I wrote a script to identify every TAKEOVER and ELEVATE attack in Misconfiguration Manager. Ever since Garrett Foster, Duane Michael, and I released Misconfiguration Manager at SO-CON last month, we’ve had tons of great conversations ...

The Hidden Impact of Ad Fraud on Your Marketing Budget

Bot-driven click fraud and ad fraud could be siphoning off large portions of your advertising budget. Learn how ad fraud could be impacting you and how to protect your business. The post The Hidden Impact of Ad Fraud on Your Marketing Budget ...

Demonstrating the Value of Data-Centric Security in Retail: Two Case Studies

The retail sector is undergoing profound changes to support digital commerce, personalization and automated buying experiences. It’s not hard to see why. In the US alone, e-commerce sales exceeded $1.1 trillion in 2023, a healthy increase of ...

The Importance of a Multi-Layer Security Stack

Multi-layer security is an essential business consideration for the best possible cyber defense  When cyber threats are evolving at an unprecedented pace, multi-layer security has become the best practice, and relying on a single line of ...

CISA warns about Sisense data breach

Business intelligence / data analytics software vendor Sisense has apparently suffered a data breach that spurred the company and the US Cybersecurity and Infrastructure Security Agency to push the company’s customers to “reset ...

Ivanti empowers IT and security teams with new solutions and enhancements

Ivanti released Ivanti Neurons for External Attack Surface management (EASM), which helps combat attack surface expansion with full visibility of external-facing assets and actionable intelligence on exposures. With the evolution of Everywhere ...