Application Security News and Articles


USENIX Security ’23 – (M)WAIT for It: Bridging the Gap between Microarchitectural and Architectural Side Channels

Authors/Presenters:Ruiyi Zhang, Taehyun Kim, Daniel Weber, Michael Schwarz Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. Originating ...

Mobile App Security

Whether we are developing a B2B or a B2C app, designing our mobile app security should always be the first step. If our app is consuming…Continue reading on Medium »

Protecting NATO Secret and Foreign Government Information

We’ve talked a lot on this blog about protecting controlled unclassified information, and we’ve mentioned in places some other kinds of information, like classified and secret information, covered defense information, and other protected ...

Let’s create a SAST … sort of.

In simple words, this article explored the intricacies of SAST (Static Application Security Testing) using our micro SAST, which I…Continue reading on Medium »

Talking DSPM: Episode 4 – Dr. Mohit Tiwari

I’m Mohit Tiwari. I’m one of the co-founders of Symmetry Systems, and the CEO. Symmetry was spun out of Spark... The post Talking DSPM: Episode 4 – Dr. Mohit Tiwari appeared first on Symmetry Systems. The post Talking DSPM: Episode 4 – ...

Threat Actors Abuse Red Team Tool MacroPack to Deliver Malware

Cisco Talos researchers found that multiple bad actors were abusing the MacroPack framework, continuing an ongoing trend of hackers repurposing legitimate security software tools to run cyber campaigns against organizations. The post Threat ...

Unify & Conquer: How Open XDR Streamlines Your Security Operations

In today’s rapidly evolving cybersecurity landscape, staying ahead of threats requires innovation, agility, and robust partnerships. At Assura, we’re dedicated to providing our clients with the most advanced and effective cybersecurity ...

Cyber Insurers Are Not Your Friend – Why a Warranty May Be a Better Option

Gary Perkins, Chief Information Security Officer In this landscape, organizations need a multi-faceted approach that includes prevention, detection, and response capabilities. A warranty tied to a comprehensive security solution supports this ...

Fintech Compliance and How to Maintain It

Fintech compliance requires vigilance, proactive measures, and a deep understanding of regulations. Overall, regulation seeks to protect consumers, ensure financial stability, and prevent financial crimes — but it can be extremely complex. ...

USENIX Security ’23 – GlitchHiker: Uncovering Vulnerabilities of Image Signal Transmission with IEMI

Authors/Presenters:Qinhong Jiang, Xiaoyu Ji, Chen Yan, Zhixin Xie, Haina Lou Wenyuan Xu Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open ...

SafeBreach Coverage for AA24-249A (GRU Unit 29155)

GRU Unit 29155 is well known for carrying out cyber attacks with the sole purpose of espionage, sabotage, and reputational harm. The post SafeBreach Coverage for AA24-249A (GRU Unit 29155) appeared first on SafeBreach. The post SafeBreach ...

Comic Agilé – Mikkel Noe-Nygaard, Luxshan Ratnaravi – #305 – Two Full Days on Big Room Planning

via the respected Software Engineering expertise of Mikkel Noe-Nygaard and the lauded Software Engineering / Enterprise Agile Coaching work of Luxshan Ratnaravi at Comic Agilé! Permalink The post Comic Agilé – Mikkel Noe-Nygaard, ...

Russian ‘WhisperGate’ Hacks: 5 More Indicted

Eaten by a GRU: Fake ransomware created by Russian GRU Unit 29155 attacked Ukraine and NATO—a month before the full scale invasion. The post Russian ‘WhisperGate’ Hacks: 5 More Indicted appeared first on Security Boulevard.

Product Updates: Persisted GraphQL Query Support

You can now test the security of persisted GraphQL Queries with Escape's platform. This new capability enhances our GraphQL API security testing The post Product Updates: Persisted GraphQL Query Support appeared first on Security Boulevard.

Navigating Certificate Lifecycle Management in Multi-Cloud Environments

Cryptography and digital certificates form the security backbone of modern digital enterprises. As organizations increasingly adopt multi-cloud strategies to leverage the best services from different cloud providers, they face significant ...

Customer Story | How Porter-Gaud School Built A Better Google Workspace Security Strategy

Porter-Gaud School Takes Student Safety and Data Security in Google Workspace Seriously by Partnering with ManagedMethods Porter-Gaud School in South Carolina is among the premier independent schools in the Southeast United States. It boasts a ...

USENIX Security ’23 – Fairness Properties of Face Recognition and Obfuscation Systems

Authors/Presenters:Harrison Rosenberg, Brian Tang, Kassem Fawaz, Somesh Jha Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to Open Access. ...

Exploring the cost savings & business benefits of Sectigo Certificate Manager

Digital certificates are key to modern web security, and automating their deployment and renewals can greatly enhance their potential. A recent Forrester study commissioned by Sectigo reveals that automating certificate lifecycle management (CLM) ...

Understanding the Types of Cybersecurity Breaches

What are the different types of cybersecurity breaches, and what can your organization do to protect against them? Cybersecurity breaches have been a top concern for organizations and individuals across the world. An independent study found that ...

Exposed: Russian military Unit 29155 does digital sabotage, espionage

The US Department of Justice has named five Russian computer hackers as members of Unit 29155 – i.e., the 161st Specialist Training Center of the Russian General Staff Main Intelligence Directorate (GRU) – which they deem resposible ...