Application Security Category - Security Boulevard https://securityboulevard.com/category/blogs/application-security/ The Home of the Security Bloggers Network Mon, 24 Jul 2023 17:05:36 +0000 en-US hourly 1 https://wordpress.org/?v=6.2.2 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png Application Security Category - Security Boulevard https://securityboulevard.com/category/blogs/application-security/ 32 32 133346385 ‘China’ Azure Breach: MUCH Worse Than Microsoft Said https://securityboulevard.com/2023/07/azure-breach-worse-richixbw/ Mon, 24 Jul 2023 17:03:58 +0000 https://securityboulevard.com/?p=1982521 Satya Nadella and President Xi Jinping

Storm-0558 Breaks: Satya and Pooh, sitting in a tree, K.I.S.S.I.N.G.

The post ‘China’ Azure Breach: MUCH Worse Than Microsoft Said appeared first on Security Boulevard.

]]>
1982521
2023 OWASP Top-10 Series: Introduction https://securityboulevard.com/2023/07/2023-owasp-top-10-series-introduction/ https://securityboulevard.com/2023/07/2023-owasp-top-10-series-introduction/#respond Sat, 22 Jul 2023 13:45:00 +0000 https://lab.wallarm.com/?p=18703 In early June 2023, OWASP released the final version of the OWASP API Security Top-10 list update. At that time we published a “hot take” on this final version and followed that up with an in-depth look at the new risk ratings for 2023. Today we’re kicking off a multi-post series in which we take [...]

The post 2023 OWASP Top-10 Series: Introduction appeared first on Wallarm.

The post 2023 OWASP Top-10 Series: Introduction appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/2023-owasp-top-10-series-introduction/feed/ 0 1982460
GitHub Developers Targeted by North Korea’s Lazarus Group https://securityboulevard.com/2023/07/github-developers-targeted-by-north-koreas-lazarus-group/ Fri, 21 Jul 2023 19:51:33 +0000 https://securityboulevard.com/?p=1982351 GitHub satellite cyberattack Strontium cyberwarfare counter-drone The Legality of Waging War in Cyberspace

The Lazarus Group is behind a social engineering campaign that uses repository invitations and malicious npm packages to target developers on GitHub.

The post GitHub Developers Targeted by North Korea’s Lazarus Group appeared first on Security Boulevard.

]]>
1982351
R.I.P. Kevin Mitnick, 1963–2023 https://securityboulevard.com/2023/07/rip-kevin-mitnick-richixbw/ Fri, 21 Jul 2023 13:33:00 +0000 https://securityboulevard.com/?p=1982320 Kevin Mitnick

Kevin is Free: Hackers’ hacker dies, aged 59.

The post R.I.P. Kevin Mitnick, 1963–2023 appeared first on Security Boulevard.

]]>
1982320
Cyber Resilience Act: The Future of Software in the European Union https://securityboulevard.com/2023/07/cyber-resilience-act-the-future-of-software-in-the-european-union/ https://securityboulevard.com/2023/07/cyber-resilience-act-the-future-of-software-in-the-european-union/#respond Thu, 20 Jul 2023 20:16:42 +0000 https://blog.sonatype.com/cyber-resilience-act-the-future-of-software-in-the-european-union Cyber Resilience Act: The Future of Software in the European Union

Representatives of member states of the European Union (EU) reached a common agreement yesterday regarding the proposed Cyber Resilience Act (CRA).

The post Cyber Resilience Act: The Future of Software in the European Union appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/cyber-resilience-act-the-future-of-software-in-the-european-union/feed/ 0 1982255
Why Generative AI is a Threat to API Security https://securityboulevard.com/2023/07/why-generative-ai-is-a-threat-to-api-security/ Thu, 20 Jul 2023 12:00:28 +0000 https://securityboulevard.com/?p=1980401 API Skyhawk Security modeling threat CosmicStrand insider threats Threat Modeling - Secure Coding - Cybersecurity - Security

Generative AI can be used to amplify cybercriminals' nefarious deeds against web applications, especially those that rely heavily on APIs.

The post Why Generative AI is a Threat to API Security appeared first on Security Boulevard.

]]>
1980401
Biden Admin. Adds ‘Mercenary Spyware’ Firms to Ban List https://securityboulevard.com/2023/07/biden-intellexa-cytrox-spyware-entity-list-richixbw/ Wed, 19 Jul 2023 16:15:57 +0000 https://securityboulevard.com/?p=1982013

European cousins Intellexa and Cytrox essentially banned by Commerce Dept. — Predator/ALIEN not welcome in U.S.

The post Biden Admin. Adds ‘Mercenary Spyware’ Firms to Ban List appeared first on Security Boulevard.

]]>
1982013
Safe programming languages: A solid first step https://securityboulevard.com/2023/07/safe-programming-languages-a-solid-first-step/ https://securityboulevard.com/2023/07/safe-programming-languages-a-solid-first-step/#respond Wed, 19 Jul 2023 14:59:38 +0000 https://www.reversinglabs.com/blog/can-safer-programming-languages Safe programming languages: A solid first step on secure code

The post Safe programming languages: A solid first step appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/safe-programming-languages-a-solid-first-step/feed/ 0 1982116
ChatGPT Provides Limited Help Identifying Malware https://securityboulevard.com/2023/07/chatgpt-provides-limited-help-identifying-malware/ Wed, 19 Jul 2023 13:00:39 +0000 https://securityboulevard.com/?p=1981977 ChatGPT Spyderbat Lacework Zerologon Malware Complacency

Current LLM-based tech like ChatGPT can accurately classify malware risk in only 5% of cases—and they may never be able to recognize novel approaches used to create malware.

The post ChatGPT Provides Limited Help Identifying Malware appeared first on Security Boulevard.

]]>
1981977
Open Source Security Incidents and How Organizations Can Respond https://securityboulevard.com/2023/07/open-source-security-incidents-and-how-organizations-can-respond/ https://securityboulevard.com/2023/07/open-source-security-incidents-and-how-organizations-can-respond/#respond Wed, 19 Jul 2023 08:00:19 +0000 https://www.rezilion.com/?p=11728 Attacks that leverage vulnerabilities in open source software are on the rise. How security teams respond to these incidents is key to what impact they will ultimately have. Oftentimes the attacks stemming from open source vulnerabilities are unpredictable, making them a big challenge for teams. Despite all the steps a security team takes to defend ... Open Source Security Incidents and How Organizations Can Respond

The post Open Source Security Incidents and How Organizations Can Respond appeared first on Rezilion.

The post Open Source Security Incidents and How Organizations Can Respond appeared first on Security Boulevard.

]]>
https://securityboulevard.com/2023/07/open-source-security-incidents-and-how-organizations-can-respond/feed/ 0 1982051