Researchers at Graz University of Technology have used the file-notification systems in Windows, Linux, and macOS to spy on activity in other accounts. On…
Category: Help Net Security
NVIDIA wants AI agent safety enforced in silicon, not left to the agent
NVIDIA has introduced an open software platform and a hardware-based reference design intended to keep AI agents within the limits set by the…
“Drunk” AI is terrible at keeping secrets
AI models taught to write like drunk people became easier to jailbreak and more likely to leak secrets shared in confidence. That is the finding of UNSW…
Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)
Citrix has patched eight critical and high-severity vulnerabilities in NetScaler ADC and NetScaler Gateway, two of which (CVE-2026-88771, CVE-2026-88772)…
Ex-US soldier gets 70 months for role in AT&T, Snowflake data thefts
A former U.S. Army soldier who was part of a group that stole data from telecom companies, including AT&T, has been sentenced to 70 months in prison.…
LinkedIn tests a way for connections to verify your work history
LinkedIn is testing a way for members to verify the work and education history of people they know. The platform prompts verified members to confirm that…
If you do one security check this quarter, make it agent memory
In this interview with Help Net Security, Chris Latimer, CEO of Vectorize, talks about the security risks hiding in AI agent memory. He found coding…
Authorizer: Open-source authentication and authorization for your apps
Authorizer is an open-source server for sign-in and access control in web and mobile apps. Teams run it on their own infrastructure and keep user accounts…
AI tests the limits of enterprise security governance
AI agents are forcing enterprises to rethink security governance, human accountability and oversight as deployments scale. AWS’s Reimagine 2026 argues…
Product showcase: A photo can fool your eyes, Verdict checks the evidence
Verdict is an AI image and video detector designed for iPhone. It works offline and requires no account. Choose a photo or video, run a scan, and the app…
Quantum random numbers can pass the tests and still leak clues to attackers
The European Telecommunications Standards Institute’s (ETSI) technical report, ETSI TR 104 171, offers guidance on building and evaluating quantum random…
Week in review: Gyazo breach exposes 23.6M user data, TASK#STOMP steals documents
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Know what was tested before your SAP ECC migration goes…
Threat detection dashboards are masking security coverage gaps
A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers…
MacSync info-stealing malware hides malicious commands in an iCloud calendar
A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files,…
Docker introduces OCI-based Kits to package agents and their guardrails
Docker has announced Docker Cloud Sandboxes, a new solution for secure, isolated AI agent execution that enables complex agentic workflows to continue…
Abnormal AI brings governance, cloud security, and threat investigation into one suite
Abnormal AI has unveiled the newest additions to its AI Security suite, designed to help enterprises adopt AI securely while protecting against new…
Dataiku Agent Management reveals unmonitored AI agents
Dataiku has announced the launch of Agent Management, a standalone product that finds every AI agent an enterprise is running, regardless of which…
Fake payroll desktop apps hand attackers a route to company paychecks
An attacker has been offering “desktop apps” for three large US payroll and HR platforms that have never released one, Allure Security have found. Anyone…
SentinelOne extends Wayfinder coverage across endpoints, identities, and cloud workloads
SentinelOne has announced the expansion of Wayfinder Threat Hunting to the major public cloud services: AWS, Azure, and Google Cloud. It’s the latest…
Stop watching what AI agents say and start watching what they do
In this interview with Help Net Security, Ariel Assaraf, CEO of Coralogix, explains why a system prompt can describe a boundary for an AI agent but cannot…
