A developer has released RemoveMacAI, a free command-line tool that turns off Apple Intelligence on macOS 27 and deletes about 12 GB of downloaded AI…
Category: Help Net Security
Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940)
Microsoft has pushed out an out-of-band security update for Exchange Server that fixes a high-severity vulnerability (CVE-2026-96940) that may allow…
Detained ShinyHunters hacker reportedly helping FBI track down fellow members
A suspected ShinyHunters member known as Rey has been detained in Jordan and is reportedly helping the FBI track down the rest of the group. Reuters…
MAKERphone 2: A DIY 4G phone with plug-in camera, speaker and prototyping board
CircuitMess, a Croatian electronics kit maker, is selling MAKERphone 2.0, a build-it-yourself 4G phone on Kickstarter that buyers program in MicroPython…
Apple tightens macOS disk access as AI agents become more powerful
Apple plans to introduce additional controls for Full Disk Access in macOS, citing growing privacy risks as AI agents become more capable and autonomous.…
doxx.net opens Agentic Defined Networking public beta, raises $38 million
doxx.net has launched the open beta of its Agentic Defined Networking (ADN) platform, which lets people and their agents create their own private, secure…
AI slop submissions force Google to freeze its open-source bug bounty
Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), after a wave of…
Keyorix: Open-source secrets management for teams that can’t use SaaS
Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. A secrets manager is the locked store where an application…
Three questions a hospital CISO should ask a healthcare fintech vendor
In this Help Net Security video, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every…
How RMM abuse gives attackers a way in that looks like business as usual
Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the…
Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 16-year-old researcher breaks into Microsoft analytics…
DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval
DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software…
16-year-old suspected leader of KillSec ransomware group arrested
A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide.…
AI is giving attackers a head start, Microsoft warns
Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft’s 2026 Digital Defense Report,…
Chinese spies impersonate White House, Anthropic figures to phish AI policy experts
A China-aligned espionage group has been posing as a former White House official and a prominent economist to get into the cloud accounts of AI policy…
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet…
Criminal recruiters want people on your payroll
Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine…
Android 17 makes it harder for spyware to cover its tracks
When a journalist suspects their phone has been hacked, the first question is whether any trace of the attack is left. Google has added six features to…
Botnets, adversarial attacks and data poisoning top leaders’ AI threat list
Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and…
AI agents keep access to company data after their work is done
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf,…
