One day after Atlassian released patches fixing a critical arbitrary file access vulnerability (CVE-2026-21589) in its self-managed Data Center products,…
Category: Help Net Security
Gremlin Foresight AI finds system weaknesses and verifies the fixes
Gremlin has announced the general availability of Gremlin Foresight AI. Following a successful beta, Gremlin Foresight AI has proven it can identify and…
Vijil DART tests AI agents for security flaws and policy violations
Vijil has released Diamond Adaptive Red Teaming for Agents (DART), an automated testing system that finds security vulnerabilities and policy violations…
FortiBleed is still active, with attackers locking admins out of Fortinet firewalls
Some organizations hit by the FortiBleed campaign have been locked out of their own Fortinet firewalls, according to a joint FBI and U.S. Secret Service…
Imply Lumi connects SIEM tools and AI agents to more security data
Imply has unveiled its expanded vision for the security information and event management (SIEM) market, with Imply Lumi providing the data platform for…
Trustero automates vendor document reviews with human approval
Trustero has announced the launch of Trustero Third-Party Risk Management (TPRM). TPRM extends Trustero’s AI engine beyond a company’s own compliance…
Edgescan Atomic validates attack paths with controlled AI testing
Edgescan announced the launch of Edgescan Atomic, an autonomous penetration-testing capability built on agentic AI and Edgescan’s existing security…
Tanium adds endpoint behavior detection and AI-assisted threat hunting
Tanium has relaunched Tanium Security Operations to address AI-assisted attacks in which adversaries use legitimate administrative tools to blend into…
Hoxhunt expands Respond to automate phishing investigations and email removal
Hoxhunt has announced expanded capabilities for Hoxhunt Respond, its email incident response automation platform for security operations teams. Respond…
Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains
Attackers who took control of three country-code top-level domains (ccTLDs) used that access to obtain HTTPS certificates for several Google domains and…
SonicWall fixes pre-auth SSRF flaw in SMA 1000 appliances (CVE-2026-102255)
SonicWall has patched four vulnerabilities in its popular Secure Mobile Access (SMA) 1000 series of appliances, including one (CVE-2026-102255) that could…
Your Windows PC can now reach other PCs through Windows App
Microsoft has made remote PC connections generally available in Windows App on Windows. Users can access physical or virtual Windows PCs alongside Windows…
ASOS confirms data breach after “hacked” app alert reaches shoppers
UK fashion retailer ASOS has confirmed a data breach after a notification claiming hackers had broken into its data was sent to shoppers through its app.…
ASOS confirms data breach after shoppers receive “hacked” app alert
UK fashion retailer ASOS has confirmed a data breach after a notification claiming hackers had broken into its data was sent to shoppers through its app.…
Anthropic loosens Claude’s cyber restrictions for verified defenders
Anthropic expanded its Cyber Verification Program (CVP), giving approved security professionals access to advanced Claude capabilities with fewer…
Check your X.Org server version because a dozen vulnerabilities have been patched
X.Org fixed 12 security flaws in the X server and Xwayland, with the repairs shipping in xorg-server 21.1.25 and xwayland-24.1.14. Nine of the flaws can…
AI Agent Gateway: Open-source tool keeps credentials out of agent configs
Tuskira’s AI Agent Gateway is an open-source solution that sits between AI agents and everything they call: the MCP tool servers that connect them to…
AI endpoint management: Visibility, compliance, and remediation
Endpoint estates are growing faster than the teams that look after them. Hybrid work, cloud adoption, contractor laptops, a steady stream of new CVEs, and…
OpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing
The OpenSSH team released version 10.6 on Oct. 6 and said it will ship releases more often for now to get bugfixes into users’ hands more quickly. The…
Even with OT network visibility, critical infrastructure operators struggle with legacy equipment
Large critical infrastructure operators run seven separate security tools on average, and most still cannot see every asset on their operational…
