“Advanced and suspected state-sponsored threat actors” are likely to be behind the initial targeted intrusions that leveraged CVE-2026-88772, one of the…
Category: Help Net Security
AI coding agents leaked 13,000 internal company screenshots to public GitHub repos
When developers ask AI coding agents to prove that a user interface fix works, some agents have been posting the evidence where anyone can find it,…
OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised
Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a…
Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore
Signal users who switch from an Android phone to an iPhone, or the other way around, can take their message history with them, and backups can be restored…
Former US Air Force members behind million-dollar BEC scheme head to prison
Two men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal…
Genea brings AI agents to access control with role-based permissions
Genea has announced the release of Genea MCP, a Model Context Protocol (MCP) server that connects AI agents directly to the Genea Access Control platform.…
Security tools can now scan Claude Enterprise chats and uploads for sensitive data
More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the…
OWASP Noir: Open-source static analysis tool
OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods,…
EU Cyber Resilience Act requirements for containers and Kubernetes
Starting in full force on Dec. 10, 2024, the EU Cyber Resilience Act (CRA) is a regulation (EU 2024/2847) that defines mandatory cybersecurity…
In this new SME cybersecurity service, the AI assists and the consultants decide
BH Consulting, the Irish cybersecurity and data protection consultancy, has launched BH Haven, an ongoing service that gives Irish small and medium-sized…
Most open critical and high flaws are over 90 days old
Detectify analyzed exposure data from 1,293 of its customers in the US, the UK and the Nordics and found that most serious flaws still open on their…
WSL containers are generally available on Windows
Microsoft made WSL containers generally available and shipped the feature with controls that let administrators switch it off or limit where it pulls…
Most organizations need six months or longer to roll out new security controls
Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top…
Post-quantum website certificates from Cloudflare are scheduled for early 2027
Cloudflare plans to become a public certificate authority (CA), an organization that issues the digital certificates websites use to encrypt traffic and…
NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)
The hacking of internet-exposed, vulnerable Citrix NetScaler ADC and Gateway deployments has escalated. What started as stealthy targeting via zero-day…
LastPass warns employees before they share sensitive data with AI tools
LastPass has announced an expansion of its Business Max offering to include AI Monitoring & Protect and Web Monitoring & Protect, new visibility and…
Postman adds security controls for AI agents, APIs, and MCP servers
Postman has announced the general availability of Fabric Gateway, a protocol-agnostic control plane for governing how AI agents, LLMs, and MCP servers…
Webinar: Closing the accountability gap in AI-assisted delivery
Source control records who committed code. It does not record who made the decisions behind it, and that gap is widening as AI agents take on more of the…
Vega II brings security-trained AI and lasting memory to the SOC
Vega has introduced Vega II, its biggest platform release since emerging from stealth. The update brings frontier AI trained for security operations into…
Meta gives small businesses an AI agent that knows their work
Meta has introduced Muse for Small Business, adding skills and connectors to its personal AI agent to help business owners get work done using the tools…
