Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and…
Category: Help Net Security
North Korea’s job interview scam runs both ways
Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to…
Fastly gives enterprises real-time control over AI models and agents
Fastly has announced AI Runtime Control, AI Firewall, and new API Security capabilities designed to give organizations real-time visibility and control…
Google hit with €403 million GDPR fine over location tracking
Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the…
Scammers impersonate cops, use arrest threats to extort victims
Scammers are posing as police officers and federal agents, threatening arrest unless victims pay up, the FBI warns. The FBI’s Internet Crime Complaint…
Siemba brings continuous IDOR testing to production APIs
Siemba has announced automated testing for insecure direct object reference (IDOR) as part of its API Security Testing capability, which tests REST,…
Hackers exploit Gyazo server flaw to steal 23.6 million user records
Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in…
Know what was tested before your SAP ECC migration goes live
In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and…
Product showcase: Helmit alerts parents when online conversations show signs of trouble
Helmit is a parental control app that combines AI-powered social media monitoring with screen time management, web filtering, location tracking, and…
Gopass: Open-source command-line password manager for teams
Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a…
Intent injection attacks are a new worry for AI-native 6G networks
Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native…
AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor
Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and…
Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far…
Bots with good manners are better at fooling people on social media
Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The…
Android apps can now check security patches down to individual device components
New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0…
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an…
Arcjet brings security controls and audit trails to AI agents
Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams…
Abandoned IoT apps keep sending sensitive data to broken servers
Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped…
Hardcoded MCP credentials found in public GitHub files
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub,…
98% of fraudulent hires have company credentials by the time they’re caught
A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud…
