Application Security News and Articles


What Happened in Cybersecurity in 2023: A Summary of Security Incidents, Vulnerability Information, and Cybersecurity Trends

The year 2023 witnessed a dynamic and complex cybersecurity landscape, with various security incidents, vulnerabilities, and trends emerging and evolving. Today, we released the 2023 Annual Security Incident Observation Report, based on our ...

Top 4 Essential Strategies for Securing APIs To Block Compromised Tokens

Government bodies are clamping down heavily on institutions and organizations that handle sensitive customer data. For APIs, tokens are used to authenticate users. We live in an era dominated by cloud-native and cloud-first solutions that rely on ...

News alert: Badge expands availability of ‘Enroll Once and Authenticate on Any Device’ software

San Francisco, Calif., Mar. 7, 2024 — Badge Inc., the award-winning privacy company enabling Identity without Secrets™, today launched a new Partner Program and welcomed Identity Data Management and Analytics provider Radiant Logic as its ...

Annual State of Email Security by the Numbers

Malicious email threats bypassing all secure email gateways (SEGs) on the market increased over 100% in the past year.   How do we know? Because we stop thousands of phishing threats bypassing our customers’ SEGs every day.  The email threat ...

The 10 Most Common MITRE Tactics & Techniques of 2023

SOAR solutions create a centralized queue of all incidents going on in a security team’s environment. Endpoint, SIEM, email, behavior, and network alerts are all collected inside of a holistic SOAR solution. As such, SOAR analytics are a unique ...

USENIX Security ’23 – Daniel W. Woods, Rainer Böhme, Josephine Wolff, Daniel Schwarcz – Lessons Lost: Incident Response in the Age of Cyber Insurance and Breach Attorneys

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

Response to the Revised CISA Advisory (AA23-353A): #StopRansomware: ALPHV BlackCat

AttackIQ has released an update to the BlackCat ransomware emulation in response to the recent revision of the CISA Advisory (AA23-353A) which disseminates Indicators of Compromise (IOCs) and Tactics, Techniques, and Procedures (TTPs) identified ...

WhatDR or What Detection Domain Needs Its Own Tools?

Pondering ?DR This is the blog where I really (briefly) miss my analyst life and my “awesome+” peers like Augusto and Anna. It relies on ideas and comments from my past collaborators … and my current ones. And, yes, this blog was inspired ...

LockBit Ransomware Affiliates Leverage Citrix Bleed Vulnerability (CVE-2023-4966)

Citrix Bleed is being leveraged by LockBit ransomware affiliates to compromise organizations using CVE-2023-4966. The post LockBit Ransomware Affiliates Leverage Citrix Bleed Vulnerability (CVE-2023-4966) appeared first on Security Boulevard.

Randall Munroe’s XKCD ‘Ice Core’

via the comic artistry and dry wit of Randall Munroe, creator of XKCD Permalink The post Randall Munroe’s XKCD ‘Ice Core’ appeared first on Security Boulevard.

NSA Issues Guidance for Networks Adopting Zero Trust

The National Security Agency (NSA) wants organizations adopt zero-trust framework principles to protect their enterprise networks and is releasing guidance to help them get there. The agency is arguing that adopting controls and functionality ...

Cyber Lingo: OpSec meaning & uses

The post Cyber Lingo: OpSec meaning & uses appeared first on Click Armor. The post Cyber Lingo: OpSec meaning & uses appeared first on Security Boulevard.

Secure Authenticated Traffic with Integrated JWT Decoding Functions | Impart Security

Decoding JWTs has never been easier! Impart Security is excited to announce the addition of Integrated JWT Decoding Functions to our API security platform, enabling security teams to create sophisticated security rules by leveraging business ...

The Need for East-West Observability to Protect Against Compromised IAM

In his new blog, Martin Roesch describes how leveraging an immutable source of truth you can trust – your network – provides East-West observability to get ahead of attackers when your IAM has been subverted and user accounts taken over The ...

USENIX Security ’23 – Nils Lukas, Florian Kerschbaum – PTW: Pivotal Tuning Watermarking for Pre-Trained Image Generators

Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating from the conference’s events situated at the Anaheim Marriott; and via the ...

AI and Cybersecurity: A Rob Burgundy Investigation

Attention, fellow news anchors and concerned citizens! Rob Burgundy is here to tackle a story hotter than a disco inferno in polyester pants: Artificial Intelligence (AI) and Cybersecurity. That's right, folks. In this digital age, hackers are ...

What is Zero Trust: Ensuring Security in a Digital Age

The post What is Zero Trust: Ensuring Security in a Digital Age appeared first on Votiro. The post What is Zero Trust: Ensuring Security in a Digital Age appeared first on Security Boulevard.

Bitdefender GravityZone CSPM+ automates the discovery of cloud misconfigurations

Bitdefender unveiled GravityZone CSPM+, a Cloud Security Posture Management (CSPM) solution for monitoring and managing configurations of cloud infrastructures including AWS, Google Cloud Platform, Microsoft Azure and others. In addition, ...

PSD2, the Future of Open Banking, and API Security

Open Banking Has Accelerated the Use of APIs – and the Need for API Security The landscape of open banking is rapidly evolving, fueled in no small part by the EU’s Revised Payment Services Directive (PSD2) aimed at enhancing authentication ...

Five Unintended Consequences of the New SEC Cybersecurity Disclosure Rule

The SEC's recent regulatory compliance mandate regarding breach disclosures is having some unintended consequences. The post Five Unintended Consequences of the New SEC Cybersecurity Disclosure Rule appeared first on Security Boulevard.