A California federal judge has once again dismissed a lawsuit brought by journalists from Salvadoran investigative outlet El Faro against NSO Group, the…
Tag: EN
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said…
Chinese Hackers Impersonate US Officials for AI Cyber Espionage
An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks,…
Three questions a hospital CISO should ask a healthcare fintech vendor
In this Help Net Security interview, Drew McCombs, CTO and CISO at Cylerity, explains how he balances both roles. Security work is scheduled into every…
FBI Warns FortiBleed Attack Compromised 80,000+ Devices and Locked Out Admins
The FBI and U.S. Secret Service have issued a joint cybersecurity advisory warning that the ongoing FortiBleed campaign is targeting internet-facing…
Building Enterprise File-Heavy AI Workflows: From Secure Uploads to Governed Document Intelligence
Enterprise AI is increasingly moving beyond clean, structured datasets and into the much larger world of documents, files, images, forms, emails, reports,…
Microsoft, Adobe, Apple, and Foxit vulnerabilities
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft. The vulnerabilities…
China’s Ministry Allegedly Funded Research Involving 100+ Academics
The U.K.’s domestic intelligence agency, MI5, has warned that more than 100 U.K.-linked academics have contributed to research projects allegedly funded…
AI slop submissions force Google to freeze its open-source bug bounty
Google has stopped accepting new product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP), after a wave of…
Alert Overload, Tool Sprawl and Evasive Phishing: The 5 Bottlenecks Slowing Down US SOCs
US security operations centers are not short on security products. They are short on time, people and context. Current industry research suggests the…
China-Aligned TA419 Uses Microsoft AitM Phishing Against U.S. AI Policy Experts
A China-linked cyber-espionage group is targeting Microsoft credentials belonging to U.S. policy and regulatory specialists in artificial intelligence,…
How RMM abuse gives attackers a way in that looks like business as usual
Huntress found attackers using legitimate remote monitoring and management (RMM) software in 45% of the endpoint-related incidents it recorded in the…
Discord Users’ Data Exposed in Security Bot Double Counter Security Breach
Double Counter, a Discord security bot, has disclosed a breach that exposed user data after an attacker broke into its cloud systems on October 4, 2026.…
Keyorix: Open-source secrets management for teams that can’t use SaaS
Keyorix is an open-source secrets manager that runs entirely on a company’s own servers. A secrets manager is the locked store where an application…
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats…
Nueva EPS, Colombia’s largest regional healthcare promoting entity has allegedly been hacked (1)
Colombia’s largest health-promoting entity, Nueva EPS, has allegedly been hacked by an individual demanding $15 million not to leak the data. Colombia’s…
Citrix issues patch for third exploited flaw in NetScaler
The memory overflow vulnerability could lead to a denial-of-service condition under certain circumstances.
SonicWall Fixes Max Severity Pre-Auth Flaw in SMA1000 Appliances
SonicWall patched a CVSS 10 pre-auth SSRF flaw in SMA1000 appliances that could let unauthenticated attackers reach internal functions. SonicWall released…
Legacy sign-on service comes back to bite school software provider Bromcom
Intruders retrieved email addresses from superseded tech kept running for an internal system
California Man Charged in Alleged $300M AI Server Smuggling Scheme to China
A California tech executive faces federal charges over an alleged $300 million scheme to route export-controlled AI servers to China through Southeast…
