Application Security News and Articles


Federal, State, Local Cyber Leaders Meet to Discuss Threats

Cybersecurity experts from state and local government, as well as top federal agencies, gathered this week to discuss everything from critical infrastructure attacks to concerns about China. Here are some top takeaways. The post Federal, State, ...

Week in review: Ivanti fixes RCE vulnerability, Nissan breach affects 100,000 individuals

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Outsmarting cybercriminal innovation with strategies for enterprise resilience In this Help Net Security interview, Pedro Cameirão, Head of ...

Get A Day’s Schedule From Fantastical On The Command Line With Shortcuts

I use Fantastical as it’s a much cleaner and native interface than Google Calendar, which I’m stuck using. I do like to use the command line more than GUIs and, while I have other things set up to work with Google Calendar from the CLI, ...

USENIX Security ’23 – Yijie Bai, Yanjiao Chen, Hanlei Zhang, Wenyuan Xu, Haiqin Weng, Dou Goodman – VILLAIN: Backdoor Attacks Against Vertical Split Learning

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

VulnCheck’s Free Community KEV & CVE APIs (Code & Golang CLI Utility)

VulnCheck has some new, free API endpoints for the cybersecurity community. Two extremely useful ones are for their extended version of CISA’s KEV, and an in-situ replacement for NVD’s sad excuse for an API and soon-to-be-removed JSON feeds. ...

Splunk, Azure, or Sentinel for FedRAMP/NIST Compliance

Whenever a business wants to work with the federal government, they are going to have to comply with certain frameworks to guarantee that, as part of the federal supply chain, it is secured to an appropriate level. The specific frameworks and ...

Unsafelok Threat Highlights It’s About Both IoT Devices and Applications

IoT devices and applications exist all over the place, and in high volume.  Today’s news brought yet another example of how the scale of IoT systems leads to the conclusion that their security is deeply dependent on automation.  Security ...

USENIX Security ’23 – ASSET: Robust Backdoor Data Detection Across a Multiplicity of Deep Learning Paradigms

Authors/Presenters:Minzhou Pan and Yi Zeng, Lingjuan Lyu, Xue Lin, Ruoxi Jia Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating ...

Apple M-Series FAIL: GoFetch Flaw Finds Crypto Keys

GoFAIL: Researchers worm their way into broken cache-filling microcode in most Macs and iPads. The post Apple M-Series FAIL: GoFetch Flaw Finds Crypto Keys appeared first on Security Boulevard.

RaaS Groups Go Recruiting in Wake of LockBit, BlackCat Takedowns

The effects of the recent high-profile disruptions of LockBit’s and BlackCat ransomware operations by law enforcement agencies are rippling through the dark web, with smaller threat gangs looking to scoop up the larger groups’ disaffected ...

SAST vs DAST vs SCA

Introduction Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis…Continue reading on Medium »

Fueling Efficiency and Safety with FireMon

Fueling Efficiency and Safety with FireMon The High Stakes of Network Security in Oil & Gas The FireMon Approach: Fortifying Oil & Gas Cyber Networks Why FireMon Excels in Oil & Gas Engaging FireMon for Your Oil & Gas ...

I asked 40 security experts to share their best advice, it didn’t disappoint.

This post explores the best security advice we have received over the past almost 2 years from various different security professionals. The post I asked 40 security experts to share their best advice, it didn’t disappoint. appeared first ...

Randall Munroe’s XKCD ‘Moon Armor Index’

Permalink The post Randall Munroe’s XKCD ‘Moon Armor Index’ appeared first on Security Boulevard.

Why SSH Certificates Can Be A Better Option For Remote Access Than SSH Keys

SSH (Secure Shell) is a secure communication protocol widely used to enable secure access to remote devices and servers over an unsecured network like the Internet. stands as a strong and reliable guardian of data integrity and confidentiality. ...

CISA, NSA, FBI and Five Eyes Issue New Alert on Chinese APT Volt Typhoon 

The Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the National Security Agency (NSA) and their international partners from the Five Eyes alliance have issued a new advisory concerning the ...

Maximizing Your Ad Spend: The DataDome Ad Protect Advantage

DataDome Ad Protect stops ad fraud and click fraud in its tracks, improving the ROI of your ad spend and safeguarding your metrics. The post Maximizing Your Ad Spend: The DataDome Ad Protect Advantage appeared first on Security Boulevard.

What is PPC Bot Traffic? 5 Methods for Securing Ad Campaigns

Learn how to identify and mitigate PPC bot traffic to enhance your digital advertising ROI with advanced bot management solutions and strategies. The post What is PPC Bot Traffic? 5 Methods for Securing Ad Campaigns appeared first on Security ...

USENIX Security ’23 – Cheng’an Wei, Yeonjoon Lee, Kai Chen, Guozhu Meng, Peizhuo Lv – Aliasing Backdoor Attacks on Pre-trained Models

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

The Crucial Role of Threat Exposure Management in MSSP Success

The role of Managed Security Service Providers (MSSPs) has never been more critical. Yet, as threats multiply, the need for MSSPs to differentiate their services becomes imperative. The key? Proactive threat exposure management that leads to ...