Application Security News and Articles


B+ security rating masks healthcare supply chain risks

While the healthcare sector gets a “B+” security rating for the first half of 2024, it faces a critical vulnerability: supply chain cyber risk, according to SecurityScorecard. The US healthcare industry’s security ratings were better ...

Understanding and Mitigating Jump Server Security Risks

Many organizations today use a jump server (also known as jump box or jump host) as the intermediary device to access a remote network securely. It is the go-to solution for remote administration of servers and devices and for development and ...

Efficiency is Key to Cybersecurity in the Post-Cloud Era

SANTA CLARA, Calif., June 26, 2024 — At the 16th Information Security Forum and 2024 RSAC Hot Topics Seminar held on June 7, 2024, Richard Zhao, Chief Operating Officer of International Business at NSFOCUS, presented the new picture of ...

Announcement – LoginRadius Launches PassKeys to Redefine Authentication Security and User Experience

Passwords pose significant security risks and inconvenience for users. Passkeys by LoginRadius is a revolutionary authentication mechanism offering a secure, passwordless process that enhances security and simplifies the user experience. Learn ...

Snowflake Breach

Snowflakes has become the latest corporate victim in a cyberattack but how it is playing out is a little different than many breaches. The post Snowflake Breach appeared first on Security Boulevard.

LockBit Claims Ransomware Attack on U.S. Federal Reserve

The LockBit ransomware group is claiming that it hacked into systems at the U.S. Federal Reserve and stole 33TB of data that it will begin leaking as early as Tuesday if the institution doesn’t pay the unspecified ransom. The notorious ...

USENIX Security ’23 – Catch You and I Can: Revealing Source Voiceprint Against Voice Conversion

Authors/Presenters:Jiangyi Deng, Yanjiao Chen, Yinan Zhong, Qianhao Miao, Xueluan Gong, Wenyuan Xu Many thanks to USENIX for publishing their outstanding USENIX Security ’23 Presenter’s content, and the organizations strong commitment to ...

Why Shadow AI is a Bigger Challenge than Shadow IT | Grip

Explore why shadow AI poses a greater risk than shadow IT. See how unmanaged AI tools in the workplace can jeopardize security and lead to harmful consequences. The post Why Shadow AI is a Bigger Challenge than Shadow IT | Grip appeared first on ...

Proxies as a Service: How to Identify Proxy Providers via Bots as a Service

See how DataDome learns about proxy networks from bots as a service, how BaaS can be detected, and what kind of IP addresses are behind BaaS. The post Proxies as a Service: How to Identify Proxy Providers via Bots as a Service appeared first on ...

Progress quietly fixes MOVEit auth bypass flaws (CVE-2024-5805, CVE-2024-5806)

Progress Software has patched one critical (CVE-2024-5805) and one high-risk (CVE-2024-5806) vulnerability in MOVEit, its widely used managed file transfer (MFT) software product. According to WatchTowr Labs researchers, the company has been ...

$50 Million in BEC Losses

The Eastern District of New York has announced charges against four men for their roles in a Business Email Compromise (BEC) and romance ...

Patch or Perish: Secure Your Data Center with Firmware Management

In the dynamic world of data centers, where uptime and security are paramount, firmware management often goes under the radar. However, as data centers become increasingly sophisticated, efficient firmware management is crucial for maintaining ...

Why SaaS Identity Abuse is This Year’s Ransomware

Let’s explore some of the details behind this escalating threat to SaaS applications, what may be driving it, and what you can do to better protect your SaaS footprint from these types of threats. The post Why SaaS Identity Abuse is This ...

Daniel Stori’s ‘The Over Engineer’

via the inimitable Daniel Stori at Turnoff.US! Permalink The post Daniel Stori’s ‘The Over Engineer’ appeared first on Security Boulevard.

SonarQube 10.6 Release Announcement

The 10.6 release of SonarQube includes some significant changes, such as autoscaling in Kubernetes, auto-configuration for C and C++ projects, support for running in a FIPS-enforced environment, set rule priority to uphold your coding standards, ...

Google’s Project Naptime Aims for AI-Based Vulnerability Research

Security analysts at Google are developing a framework that they hope will enable large language models (LLMs) to eventually be able to run automated vulnerability research, particularly analyses of malware variants. The analysts with Google’s ...

Microsoft Privacy FAIL: Windows 11 Silently Backs Up to OneDrive

Copying users’ files and deleting some? Even a cartoon hound knows this isn’t fine. The post Microsoft Privacy FAIL: Windows 11 Silently Backs Up to OneDrive appeared first on Security Boulevard.

Five Signs You’re Using “Good Enough” Automation

The post Five Signs You’re Using “Good Enough” Automation appeared first on AI Enabled Security Automation. The post Five Signs You’re Using “Good Enough” Automation appeared first on Security Boulevard.

Hacking APIs with HTTPie

Learn why HTTPie is a great replacement for curl and how to use it when conducting your own API security testing. The post Hacking APIs with HTTPie appeared first on Dana Epp's Blog. The post Hacking APIs with HTTPie appeared first on Security ...

Airbnb’s Ban on Indoor Security Cameras: What It Means for Your Personal Cybersecurity

Effective April 30, 2024 Airbnb, the global vacation rental giant, announced a significant policy change: the prohibition of all indoor security cameras in its listings worldwide. This decision, aims to bolster the privacy of guests and address ...