A China-aligned espionage group has been posing as a former White House official and a prominent economist to get into the cloud accounts of AI policy…
Category: Help Net Security
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet…
Criminal recruiters want people on your payroll
Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine…
Android 17 makes it harder for spyware to cover its tracks
When a journalist suspects their phone has been hacked, the first question is whether any trace of the attack is left. Google has added six features to…
Botnets, adversarial attacks and data poisoning top leaders’ AI threat list
Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and…
AI agents keep access to company data after their work is done
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf,…
New infosec products of the week: October 2, 2026
Here’s a look at the most interesting products from the past week, featuring releases from BlackFog, Genea, Vega, and Thales. Vega II brings…
Exabeam brings AI-assisted security investigations to data that must stay on-premises
Exabeam has introduced a new wave of capabilities that bring the Agentic SOC to life in the cloud and on-premises environments, combining AI-driven…
RadarFirst helps teams investigate AI bias, data exposure and unintended actions
RadarFirst has announced the general availability of Radar AI Incident Management, a purpose-built solution that helps organizations investigate, manage,…
DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval
DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software…
16-year-old suspected leader of KillSec ransomware group arrested
A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide.…
Legit Security extends automated fixes to vulnerable open-source dependencies
Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just…
Sophos uses agentic AI to show businesses which security fixes deserve funding
Sophos has launched Sophos CISO Advantage, an agentic AI-enabled solution that connects security operations to security strategy. The solution gives…
AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in…
Pentagon breach exposes personal data of more than 3 million people
The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of people that hackers gained access to their personal data. The breach affects…
Armadin raises $255.5 million to expand AI offensive security platform
Armadin has raised $255.5 million in Series B funding co-led by Andreessen Horowitz (a16z) and Accel that brings the company’s valuation to over $2.5…
New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
For the fifth time this year, Cisco revealed attackers have exploited a vulnerability (CVE-2026-76504) in its SD-WAN solution in zero-day attacks. The…
Some car apps are slipping owners’ data to big tech companies
The app that comes with your car may be sharing what it knows about you with some of the biggest tech companies. Northeastern University researchers…
BlackFog adds prompt protection and governance for agentic AI
BlackFog has announced the launch of ADX Vision 2.0, expanding its AI security capabilities to help organizations govern and control the use of generative…
Sentinel Envelope Plus adds software protection without source code changes
Thales has announced Sentinel Envelope Plus, a new addition to its Sentinel Envelope software protection solution that significantly hardens compiled…
