Application Security News and Articles


March 2024 Patch Tuesday: Microsoft fixes critical bugs in Windows Hyper-V

On this March 2024 Patch Tuesday, Microsoft has released fixes for 59 CVE-numbered vulnerabilities, but – welcome news! – none of them are currently publicly known or actively exploited. Last month, though, several days after Patch ...

DOJ Warns Using AI in Crimes Will Mean Harsher Sentences

U.S. Deputy Attorney General Lisa Monaco last month was in the UK speaking at the University of Oxford and outlining the different paths the Justice Department is taking to address the benefits and threats associated with AI. Monaco spoke about ...

USENIX Security ’23 – Piet De Vaere, Adrian Perrig – Hey Kimya, Is My Smart Speaker Spying On Me? Taking Control Of Sensor Privacy Through Isolation And Amnesia

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

NIST CSF 2.0 Updates in CyberStrong

The National Institute of Standards and Technology’s Cybersecurity Framework (CSF) is known in cybersecurity as the gold standard framework for cybersecurity and risk guidance; it can assess and improve an organization’s ability to prevent, ...

How to Customize a Risk Register Template for Your Needs

Cybersecurity threats are rising, posing significant challenges to organizations that strive to protect their assets and maintain compliance. As projects get more complicated, keeping track becomes difficult at best and dangerous at worst.  A ...

BlackCloak Identifies Rising Cyber Threats Against Crypto-Invested Venture Capital and Private Equity Firm

The BlackCloak Threat Intelligence Team is currently observing and pinpointing new strategies deployed by cybercriminals targeting venture capital and private equity firms with investments in cryptocurrency. These malicious actors are not just ...

A Faster Path to Memory Safety: CHERI, Memory Tagging, and Control Flow Integrity

Recently, the White House published a technical paper asking organizations to develop roadmaps for implementing memory safety in their software applications. The goal is to eliminate a broad class of software defects that make up to 70 percent of ...

The Balancing Act: Innovation and Data Security in Healthcare | Eureka Security

By adopting a proactive approach to data security with the help of solutions like Eureka Security, healthcare organizations can achieve the perfect balance of innovation and compliance. | Eureka Security The post The Balancing Act: ...

Daniel Stori’s ‘PHP v. Banana’

via the inimitable Daniel Stori at Turnoff.US. Permalink The post Daniel Stori’s ‘PHP v. Banana’ appeared first on Security Boulevard.

Control the Network, Control the Universe

March 19, 2024Time: 1:00 pm ET | 10:00 am PT The ever-evolving landscape of network security faced new challenges in 2023 as hackers developed sophisticated methods to exploit vulnerabilities in network devices. Join Nate Warfield, Director ...

How Scalpers Scored Thousands of Fred again.. Tickets

See how scalpers and sneakerbots, typically used for limited-edition releases, exploited ticket sales for Fred again..'s latest tour announcement in Australia. The post How Scalpers Scored Thousands of Fred again.. Tickets appeared first on ...

How NIST CSF 2.0 Helps Small Businesses

The NIST CSF Cybersecurity Framework (CSF 2.0) has had its first update in a decade.... The post How NIST CSF 2.0 Helps Small Businesses appeared first on Security Boulevard.

5 more Burp extensions for API hacking

Check out these five Burp Suite extensions that can help your API hacking. From bypassing WAFs to generating wordlists, it can all help. The post 5 more Burp extensions for API hacking appeared first on Dana Epp's Blog. The post 5 more Burp ...

Broadcom Merging Carbon Black, Symantec to Create Security Unit

Carbon Black’s uncertain future following the closing of Broadcom’s $69 billion acquisition of VMware in November is now settled, with the security software business merging with Symantec to form Broadcom’s new Enterprise Security Group. ...

Aviatrix releases Distributed Cloud Firewall for Kubernetes

Aviatrix introduced Aviatrix Distributed Cloud Firewall for Kubernetes, a distributed cloud networking and network security solution for containerized enterprise applications and workloads. With this solution, Aviatrix bridges the gap between ...

DTEX i³ Issues Threat Advisory for Detecting the Use of Multiple Identities

The DTEX i3 team has issued a new Threat Advisory following recent investigations linking the use of multiple personal accounts on corporate devices with side gigs and the spread of extremist materials. The i3 Threat Advisory highlights how ...

Rubrik EPE secures enterprise data from cyberattacks

Artificial intelligence (AI), digital transformation, and the Internet of Things have caused a data explosion, leading organizations to grapple with a surging amount of fragmented data where it lives. Rubrik released Rubrik Enterprise Proactive ...

ChatGPT and Beyond: Generative AI in Security

The application of generative AI in security is a game-changer, offering novel solutions to pressing challenges in cybersecurity. The post ChatGPT and Beyond: Generative AI in Security appeared first on Security Boulevard.

Unveiling The Applications and Distinctions of Machine Learning and Artificial Intelligence in Cybersecurity

The terms "machine learning" and "artificial intelligence" are frequently used in cybersecurity, often interchangeably, leading to confusion about their precise meanings and applications. Both machine learning and artificial intelligence play ...

What is Compliance in Cybersecurity? Frameworks and Best Practices

If you're secure, are you compliant? If you're compliant, are you secure? The post What is Compliance in Cybersecurity? Frameworks and Best Practices appeared first on Security Boulevard.