Application Security News and Articles


Differential privacy in AI: A solution creating more problems for developers?

In the push for secure AI models, many organizations have turned to differential privacy. But is the very tool meant to protect user data holding back innovation? Developers face a tough choice: balance data privacy or prioritize precise results. ...

How digital wallets work, and best practices to use them safely

With the adoption of digital wallets and the increasing embedding of consumer digital payments into daily life, ensuring security measures is essential. According to a McKinsey report, digital payments are now mainstream and continually evolving, ...

Essential metrics for effective security program assessment

In this Help Net Security interview, Alex Spivakovsky, VP of Research & Cybersecurity at Pentera, discusses essential metrics for evaluating the success of security programs. Spivakovsky explains how automation and proactive testing can ...

Data disposal and cyber hygiene: Building a culture of security within your organization

Data breach episodes have been constantly rising with the number of data breach victims crossing 1 billion in the first half of 2024. A recent Data Breach Report 2023 by Verizon confirms that 74% of data breaches are due to human errors. Although ...

Security leaders consider banning AI coding due to security risks

92% of security leaders have concerns about the use of AI-generated code within their organization, according to Venafi. Tension between security and developer teams 83% of security leaders say their developers currently use AI to generate code, ...

Understanding the 7 A’s of IAM

How the seven functions of IAM power identity-first security Today’s corporate security architecture is built on the cornerstone of identity and access management (IAM). And seven underlying functions, all beginning with the letter “A”, ...

Rethinking TPRM: Managing Third-Party SaaS Risks | Grip

Discover how to close the gaps in TPRM with better third-party risk management. Learn how Grip and SecurityScorecard protect against hidden shadow SaaS risks. The post Rethinking TPRM: Managing Third-Party SaaS Risks | Grip appeared first on ...

AT&T to Pay $13 Million to Settle FCC Case of 2023 Data Breach

AT&T agreed to pay $13 million to settle an FCC investigation into a data breach in January 2023 that put a focus on the evolving security landscape and the growing threat to customer data that organizations store in the cloud. The post ...

FBI Disrupts Another Massive Chinese-Linked Botnet

The FBI and other U.S. and international law enforcement agencies disrupted a massive botnet created by China-linked threat group Flax Typhoon that had pulled in more than 200,000 IoT and other connected devices over the past for years. The post ...

USENIX NSDI ’24 – Making Kernel Bypass Practical for the Cloud with Junction

Authors/Presenters:Joshua Fried, Gohar Irfan Chaudhry, Enrique Saurez, Esha Choukse, Íñigo Goiri, Sameh Elnikety, Rodrigo Fonseca, Adam Belay Our sincere thanks to USENIX, and the Presenters & Authors for publishing their superb 21st USENIX ...

Betting, Gambling, and Sports Betting Sites: The Costs of ATO

The most prevalent and damaging attack plaguing the online betting and gambling industry is fraud stemming from account takeover. The post Betting, Gambling, and Sports Betting Sites: The Costs of ATO appeared first on Security Boulevard.

Navigating the Workplace Violence Threat Management Process 

An overview of how to investigate workplace violence incidents, make an assessment, and intervene when necessary  The purpose of the threat management process is to evaluate threatening or alarming behavior, determine whether there is any actual ...

News alert: SpyCloud study reveals ‘infostealer’ malware can be a precursor to a ransomware attack

Austin, TX, Sept. 18, 2024, CyberNewsWire — SpyCloud, the leader in Cybercrime Analytics, today announced new cybersecurity research highlighting the growing and alarming threat of infostealers – a type of malware designed to exfiltrate ...

Pulumi Adds Cloud Security Intelligence Tool to Portfolio

Pulumi today added a Pulumi Insights application for discovering cloud assets in addition to generally making available a previously launched tool for centralizing the management of cloud security. The post Pulumi Adds Cloud Security Intelligence ...

News alert: INE Security’s cybersecurity training service earns 2024 SC Excellence Award

Cary, NC, Sept.18, 2024, CyberNewsWire — INE Security is proud to announce that it has been named a winner in the prestigious 2024 SC Awards, named Best IT Security-Related Training Program. This designation underscores INE Security’s ...

Daniel Stori’s Turnoff.US: ‘Chat GPT Code Smell’

via the inimitable Daniel Stori at Turnoff.US! Permalink The post Daniel Stori’s Turnoff.US: ‘Chat GPT Code Smell’ appeared first on Security Boulevard.

E2EE is MIA in iPhone/Android Chat — GSMA Gonna Fix it

No More Barf-Green Bubbles? GSM Association is “excited” to bring Apple and Google closer together, but encryption is still lacking. The post E2EE is MIA in iPhone/Android Chat — GSMA Gonna Fix it appeared first on Security Boulevard.

Honeytokens [Security Zines]

Buckle up, buttercup, because we're about to dive into the sticky-sweet world of honeytokens! The post Honeytokens [Security Zines] appeared first on Security Boulevard.

New CJIS Security Policy Changes the Game for MFA for Criminal Justice Organizations

Criminal Justice Information Services (CJIS), a division of the FBI that collects, stores, and shares... The post New CJIS Security Policy Changes the Game for MFA for Criminal Justice Organizations appeared first on Axiad. The post New CJIS ...

USENIX NSDI ’24 – LoLKV: The Logless, Linearizable, RDMA-Based Key-Value Storage System

Authors/Presenters:Ahmed Alquraan, Sreeharsha Udayashankar, Virendra Marathe, Bernard Wong. Samer Al-Kiswany Our sincere thanks to USENIX, and the Presenters & Authors for publishing their superb 21st USENIX Symposium on Networked Systems ...