Application Security News and Articles


What are SBOM standards and formats?

The growing importance of software bills of materials (SBOMs) marks a significant shift towards better transparency and security in software management. The post What are SBOM standards and formats? appeared first on Security Boulevard.

USENIX Security ’23 – Bug Hunters’ Perspectives on the Challenges and Benefits of the Bug Bounty Ecosystem

*Distinguished Paper Award Winner* Authors/Presenters:*Omer Akgul, Taha Eghtesad, Amit Elazari, Omprakash Gnawali, Jens Grossklags, Michelle L. Mazurek, Daniel Votipka, Aron Laszka* Many thanks to USENIX for publishing their outstanding USENIX ...

Out of the kernel, into the tokens

By Max Ammann and Emilio López Our application security team leaves no stone unturned; our audits dive deeply into areas ranging from device firmware, operating system kernels, and cloud systems to widely used technology such as mobile and web ...

Are You Ready to Protect Your Company From Insider Threats? Probably Not

The bad news is insider threats are on the rise. The worse news is that most companies are unprepared to meet the moment. The post Are You Ready to Protect Your Company From Insider Threats? Probably Not appeared first on Security Boulevard.

13 Women to Know in Cybersecurity

Conservative estimates have the current cybersecurity workforce as about 25% female, but that number is... The post 13 Women to Know in Cybersecurity appeared first on Security Boulevard.

A Taxonomy of Prompt Injection Attacks

Researchers ran a global prompt hacking competition, and have documented the results in a paper that both gives a lot of good examples and tries to organize a taxonomy of effective prompt injection strategies. It seems as if the most common ...

Identiv releases bitse.io 3.0, simplifying the deployment of IoT applications

Identiv launched bitse.io 3.0, the latest iteration of its global IoT connecting cloud platform. The updated platform offers advanced features designed to transform applications in supply chain management, brand protection, and customer ...

Cisco patches Secure Client VPN flaw that could reveal authentication tokens (CVE-2024-20337)

Cisco has fixed two high-severity vulnerabilities affecting its Cisco Secure Client enterprise VPN and endpoint security solution, one of which (CVE-2024-20337) could be exploited by unauthenticated, remote attackers to grab users’ valid ...

Secure ERP Cloud Migration Infrastructure Access Governance

Securing Your ERP Cloud Migration:Managing Infrastructure Access GovernanceIn today's constantly changing environment, remote work has become widespread, causing businesses to rely heavily on cloud hosting. They do so to improve scalability, cost ...

Why Edtech Industries Need Cybersecurity?

As educational technology (edtech) industries gets better, it changes the way how students learn. But now, keeping student information safe is a big worry. People like parents and teachers are really concerned, especially because some edtech ...

Emerging Trends in Embedded Linux IoT Security

Mitigating potential vulnerabilities requires proactive measures due to the complexity of embedded Linux IoT devices The use of containerization and virtualization reduces the attack surface and minimizes the impact of security breaches ...

OWASP’s top 10 for secure coding

The OWASP Top 10 is an essential resource for developers and security professionals, highlighting the ten most critical web application…Continue reading on Medium »

March 2024 Patch Tuesday forecast: A popular framework updated

We’re almost at our third Patch Tuesday and wrapping up the first quarter 2024. Time flies by! Microsoft is starting to push users to update their operating systems as their active version is approaching end-of-support. The February 2024 Patch ...

Immediate AI risks and tomorrow’s dangers

“At the most basic level, AI has given malicious attackers superpowers,” Mackenzie Jackson, developer and security advocate at GitGuardian, told the audience last week at Bsides Zagreb. These superpowers are most evident in the ...

How new and old security threats keep persisting

Security leaders recognize that the pattern of buying new tech and the frantic state of find-fix vulnerability management is not working, according to Cymulate. Security leaders take proactive approach to cybersecurity Rather than waiting for the ...

Leveraging AI and automation for enhanced cloud communication security

In this Help Net Security interview, Sanjay Macwan, CIO and CISO at Vonage, addresses emerging threats to cloud communications and the role of AI and automation in cybersecurity. What emerging threats to cloud communications are you most ...

Making Waves: Empowering Women in Cybersecurity

Making Waves: Empowering Women in Cybersecurity madhav Fri, 03/08/2024 - 05:01 As International Women’s Day approaches, it’s a perfect moment to reflect on the pivotal role of diversity in technology, especially as this year’s theme is ...

Securing the future: Addressing cybersecurity challenges in the education sector

In this Help Net Security video, Kory Daniels, CISO at Trustwave, shines a light on the impact the current threat environment can have for both universities and students. Key findings from a recent Trustwave report include: – 1.8 million ...

OpenARIA: Open-source edition of the Aviation Risk Identification and Assessment (ARIA)

MITRE now offers an open-source version of its Aviation Risk Identification and Assessment (ARIA) software suite, OpenARIA. This initiative is dedicated to enhancing aviation safety and efficiency through the active involvement of the aviation ...

New infosec products of the week: March 8, 2024

Here’s a look at the most interesting products from the past week, featuring releases from Check Point, Delinea, Pentera, and Sentra. Delinea Privilege Control for Servers enforces least privilege principles on critical systems In Privilege ...