Application Security News and Articles


New infosec products of the week: April 5, 2024

Here’s a look at the most interesting products from the past week, featuring releases from Fastly, LogRhythm, Owl Cyber Defense Solutions, and TrueMedia.org. Owl Talon 3 provides hardware-enforced, one-way data transfers Owl Cyber Defense ...

Policy Adjustment Based on Attack Events in ADS

This article provides a brief explanation of policy fine-tuning in ADS. Please note that fine-tuning the protection policy is a time-consuming process. This article focuses on how to check attack details in ADS based on attack events and optimize ...

HTTP/2 CONTINUATION Flood Vulnerability

HTTP/2, a widely adopted web communication protocol, organizes data transmission through a binary framing layer, wherein all communication is divided into smaller messages called frames, each identified by a specific type, such as headers, data, ...

Smart SOAR’s Innovative Approach to Error-Handling Explained

Our commitment to innovation is deeply rooted in the feedback we receive from those who use our Smart SOAR platform daily. It was through listening to feedback from our customers that we identified and addressed a crucial opportunity for ...

How to Correctly Use Client IP Addresses in Okta Audit Logs to Improve Identity Security 

Being able to identify client IP addresses is essential for detecting and preventing identity-related threats. These IP addresses help establish a baseline of identity activities and highlight deviations often associated with threat actors. By ...

Testing in Detection Engineering (Part 8)

This blog series was written jointly with Amine Besson, Principal Cyber Engineer, Behemoth CyberDefence and one more anonymous collaborator. This blog involved one more anonymous contributor. Testing the pens... In this blog (#8 in the series), ...

How to Future-Proof Your Business Against Evolving Bot Threats (& Bot Solution Checklist)

Learn what features your bot management provider should offer and narrow down your shortlist using our downloadable bot solution checklist. The post How to Future-Proof Your Business Against Evolving Bot Threats (& Bot Solution Checklist) ...

Google Chrome Enlists Emerging DBSC Standard to Fight Cookie Theft

Google is prototyping a new technology in Chrome that is designed to thwart the growing trend among cybercriminals of stealing browser session cookies, which enables hackers to bypass multifunction authentication (MFA) protections and gain access ...

Mastering MITRE: Enhancing Cybersecurity with Device Log Mapping

In the dynamic realm of cybersecurity, the MITRE ATT&CK framework has become a pivotal tool for organizations striving to fortify their defenses against the myriad of cyber threats that loom in the digital age. The webinar, “The MITRE ...

XZ and the Threats to the Digital Supply Chain

The discovery of the backdoor in xz utils compression software last week has shone a spotlight on the threats to the digital supply chain. Wired has an excellent analysis on the attack, theorizing the years-long campaign may have been by the ...

Safeguarding Data Security and Privacy on IBM Mainframe: A Comprehensive Approach

In today's digitally driven world, data security and privacy are paramount concerns for organizations across all industries. With the increasing sophistication of cyber threats and the ever-evolving landscape of privacy regulations, safeguarding ...

Omni Hotels suffer prolonged IT outage due to cyberattack

Texas-based Omni Hotels & Resorts has been responding to a cyberattack that started last Friday, which resulted in the unavailability of many of its IT systems. According to people staying at some of the 50 properties the company operates ...

Leadership in the Age of AI: Skills You Need to Succeed

The artificial intelligence (AI) revolution is upon us, transforming every facet of our lives, and the workplace is no exception. A recent study by McKinsey...Read More The post Leadership in the Age of AI: Skills You Need to Succeed appeared ...

Why Swimlane Should Be Your Next SOC Vendor

The post Why Swimlane Should Be Your Next SOC Vendor appeared first on AI Enabled Security Automation. The post Why Swimlane Should Be Your Next SOC Vendor appeared first on Security Boulevard.

From Promising to Practical: The Transformative Impact of Homomorphic Encryption

When the impact of a relatively unfamiliar technology sounds too good to be true, it’s natural to question those claims. Homomorphic encryption has been described as the ‘holy grail’ of encryption for its unique ability to allow users to ...

NIST awards $3.6 million to address the cybersecurity workforce gap

The US Department of Commerce’s National Institute of Standards and Technology (NIST) has awarded cooperative agreements totaling nearly $3.6 million aimed at building the workforce needed to safeguard enterprises from cybersecurity risks. The ...

Strata Identity Promotes Gerry Gebel to Vice President of Product and Standards

Longtime identity veteran assumes product management leadership role and will continue to drive standards initiatives for unifying identity management and policy orchestration  BOULDER, Colo. April 4, 2024 – Strata Identity, the Identity ...

Cyber Sorcery: Confronting Lazarus Group – MagicRAT and TigerRAT Campaign

Discover the origin, tactics and future of Remote Access Trojan (RAT) dubbed MagicRAT and how leveraging AttackIQ Flex can help your organization simulate real-world attack scenarios, enabling you to assess and validate their security posture ...

The Five Essentials of Immutable Storage: Why They Matter

Organizations need a robust backup strategy that can outsmart bad actors. And these days, that strategy must include immutability. The post The Five Essentials of Immutable Storage: Why They Matter appeared first on Security Boulevard.

What is API Security Testing?

In short, API security testing involves the systematic assessment of APIs to identify vulnerabilities, coding errors, and other weaknesses that could be exploited by malicious actors. Application Programming Interfaces, or APIs, provide much of ...