The FBI and French law enforcement have seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and…
Category: Help Net Security
Anthropic’s new budget model gets much better at ignoring hidden commands
Anthropic’s Claude Haiku 5.5 model, designed for quick, repetitive workloads and speed-sensitive tasks, is now better at finding vulnerabilities and…
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The…
What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
ESET researchers traced almost two years of changes to MATCHBOIL, a downloader that the Russia-aligned group UAC-0099 uses to plant a second program on…
GitHub adds AI to catch passwords before a code push
GitHub has announced an AI detector, developed with Microsoft Applied Sciences, to help prevent developers from uploading passwords and other credentials…
Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims
The owner of Florida-based ransomware remediation company MonsterCloud has been charged with fraud for allegedly paying ransomware gangs behind his…
Pricing your bad days and how to build an economic model for security decisions
Ivan Milenkovic, VP Risk Technology EMEA at Qualys, explains how security leaders can build an economic model that puts money behind their decisions. He…
Who watches the AI watching your street?
Yusaku Fujii, a professor at Gunma University in Japan, has designed audits and penalties to stop operators from misusing AI that analyzes street camera…
How AI can fix cybersecurity compliance: From dashboards to continuous execution
Most compliance work goes into proving security, not improving it. That isn’t because the rules are unreasonable. Regulators, customers, and cyber…
The people who know passkeys best are still typing passwords
Yubico and Okta asked 1,890 technology and security professionals across nine countries how they sign in to work accounts. The most common answer was a…
Java library vulnerabilities: IBM and Red Hat fix 400+ previously unknown flaws
IBM and Red Hat have found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries through Lightwell, their program for…
Medical devices patients rely on most are least prepared for quantum attacks
Threat actors are exploiting IT, IoMT, OT and IoT devices across healthcare delivery organizations (HDOs) to deploy ransomware, demand payments and…
Cisco quantum network controller lets apps order entanglement on demand
Cisco has built a Quantum Network Controller, a research prototype that lets an application ask a quantum network for entanglement and leaves the network…
Exploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)
One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products,…
Gremlin Foresight AI finds system weaknesses and verifies the fixes
Gremlin has announced the general availability of Gremlin Foresight AI. Following a successful beta, Gremlin Foresight AI has proven it can identify and…
Vijil DART tests AI agents for security flaws and policy violations
Vijil has released Diamond Adaptive Red Teaming for Agents (DART), an automated testing system that finds security vulnerabilities and policy violations…
FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, according to a joint FBI and U.S. Secret Service…
Imply Lumi connects SIEM tools and AI agents to more security data
Imply has unveiled its expanded vision for the security information and event management (SIEM) market, with Imply Lumi providing the data platform for…
Trustero automates vendor document reviews with human approval
Trustero has announced the launch of Trustero Third-Party Risk Management (TPRM). TPRM extends Trustero’s AI engine beyond a company’s own compliance…
Edgescan Atomic validates attack paths with controlled AI testing
Edgescan announced the launch of Edgescan Atomic, an autonomous penetration-testing capability built on agentic AI and Edgescan’s existing security…
