July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was…
Category: Help Net Security
US fuel gauge exposure fell by more than half in three months
Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the…
What the first year of EU AI Act transparency enforcement could look like
In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of…
Gut feeling does nothing against AI spear phishing texts
A banker at a credit union sat down at a table with a dozen printed text messages, all of them written for that banker personally, and put them in order…
ShieldFont fights AI scraping by handing crawlers the wrong words
Isaque Seneda and Gabriel Abrucio built a web font that draws one set of words on screen and leaves a different set in the page’s source code. A person…
Photos: Black Hat USA 2026, part two
Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured…
Novel-reading apps used users’ phones to generate fake ad traffic
A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab.…
Photos: Black Hat USA 2026
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors:…
Snowflake hacker pleads guilty, faces up to 32 years in prison
A Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165…
Three in four AI-generated vulnerability patches leave something broken
Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write.…
Discounted Claude access bought on the gray market may expose every prompt you send
More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or “unlimited” token access to frontier AI…
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root…
Microsoft extends zero trust deeper into enterprise AI
Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help…
Photos: Black Hat USA 2026 Arsenal
This week Help Net Security is at the Mandalay Bay, where Arsenal is running alongside the Briefings. If you’ve never been, it’s the corner of Black Hat…
OWASP 2026 LLM Top 10: “The model will be fooled”
The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by…
Suppliers, logins, and AI tools are all becoming attack paths
Cybercriminals and state-backed hacking groups are abusing trusted identities, cloud services, AI tools, and software supply chains to gain access while…
Browser security is where software, data, and AI meet
In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not…
Non-human identities are 91% of everything active in production
A backup job fires at two in the morning. A scanner walks the same AWS account an hour later, a deployment pipeline assumes a role at four, and a logging…
Cloudflare OS goes open source with a record of everything its agents read
Cloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets…
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives…