Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans…
Category: Help Net Security
Download: The Agentic Software Development Guide
AI makes it easy to ship more code. It does not make that code easier to trust. Most teams don’t fail because their developers can’t use AI. They fail…
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and…
Attackers are going after prominent individuals through OAuth phishing, FBI warns
Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails…
SonicWall SMA 1000 appliances under attack via zero-day flaws
Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor…
A battery storage cyberattack would look exactly like a badly tuned controller
Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them…
Global sinkhole operation ends Sality botnet’s 23-year run
Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint…
Keepnet launches free SMS/Call Reporter for iOS
Keepnet, an Extended Human Risk Management (xHRM) and Secure Behavior Management platform, today launched the Keepnet SMS/Call Reporter. It is a free app…
DuckDB stays open source while the team behind it goes to work for Amazon
Hannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a…
Edge Case launches Guardian, an AI platform for tracking risk across autonomous systems
Edge Case launched Guardian, an AI-driven platform that connects safety analysis, engineering data, and operational signals to give teams a continuous…
Visa enhances A2A Protect to stop fraud before money leaves the account
Visa announced an enhanced version of A2A Protect, delivering real-time risk insights that help banks stop account-to-account fraud before money leaves…
National Life Group CISO expects more vulnerabilities in six months than in thirty years
In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks.…
Vali Cyber ZeroLock 5 brings MFA to the hypervisor command line
Vali Cyber released ZeroLock 5, a major release focused on closing the two most dangerous gaps in hypervisor security: insider threats and stolen…
F5 speeds up virtual patching to counter AI-driven threats
F5 announced innovations to block frontier AI-driven threats in the data path and enable faster virtual patching, giving security leaders time to make…
Scareware ads keep running on Google’s transparency tool, even after they’re reported
A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works.…
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira
Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work:…
Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud
Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi,…
An AI CAPTCHA solver talked itself out of the right answer
You have probably spent a few seconds of your life turning a picture until it lines up. Some sites, instead of asking you to tick a box, show you a…
CISA review makes the case for eliminating vulnerability classes
For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely…
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing…