A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen…
Category: Help Net Security
Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)
Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the…
RightCrowd Pass unifies mobile, physical, and biometric credentials
RightCrowd announced RightCrowd Pass, a credentialing solution that issues and manages mobile, physical and biometric access credentials from a single…
Bogus recruiters go after high-value corporate credentials on mobile
Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to…
Meta adds three new features to keep WhatsApp accounts secure
Meta has added new security enhancements to WhatsApp, this time in the form of stronger two-step verification, additional information about calls from…
Production data in testing is still common, and Tricentis’ CISO wants it gone
In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the…
Linux Foundation takes on TRACE, a hardware-backed runtime evidence specification for AI agents
The Linux Foundation announced the contribution of TRACE (Trust, Runtime Attestation and Compliance Evidence), from OPAQUE. Collaboratively developed by…
AI vulnerability discovery scores the highest impact of 20 emerging risks
Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber…
Hottest cybersecurity open-source tools of the month: August 2026
Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security…
INTERPOL crackdown on West African crime rings uncovers troubling new trend
Police across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime…
Citrix UniconOS dual boot turns Windows endpoints into their own recovery device
Citrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes —…
Fideo Lens reveals connections across identities, accounts and devices
Fideo Intelligence introduced Fideo Lens, an investigative intelligence platform that helps fraud and financial crime teams discover hidden relationships…
Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal…
Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday.…
ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack
Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a…
AI supply chain risk is showing up in developer workflows first
In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still…
TruffleHog AWS Analyze reduces remediation time on leaked AWS credentials
Truffle Security announced TruffleHog AWS Analyze, a new addition to TruffleHog Enterprise. TruffleHog AWS Analyze enriches found AWS credentials to…
HOL Guard: Open-source antivirus for AI agents
HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool…
The cybercrime supply chain has five stages, each with a price
In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He…
New TCG guidance gives buyers a way to test PQC-ready TPM claims
The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM…