cybersecurity

Stop building security goals around controls

Stop building security goals around controls 2026-03-18 at 09:27 By Mirko Zorz In this Help Net Security interview, Devin Rudnicki, CISO at Fitch Group, argues that security strategy fails when it loses its connection to business outcomes. Rudnicki walks through how to align security goals with corporate priorities, why CISOs must present risk in terms […]

Stop building security goals around controls Read More »

EU sanctions Chinese company behind 65,000-device hack

EU sanctions Chinese company behind 65,000-device hack 2026-03-17 at 14:26 By Sinisa Markovic The EU Council has sanctioned companies from China and Iran, along with two individuals, over cyberattacks targeting its member states and partners. “Those listed are subject to an asset freeze, while EU citizens and companies are prohibited from providing them with funds

EU sanctions Chinese company behind 65,000-device hack Read More »

Middle East Cyber Warfare Intensifies: Rising Attacks, Hacktivist Surge, and Global Risk Exposure 

Middle East Cyber Warfare Intensifies: Rising Attacks, Hacktivist Surge, and Global Risk Exposure  2026-03-17 at 12:22 By Ashish Khaitan The ongoing Middle East war has evolved into a cyber battlefield, with state-sponsored operations targeting critical infrastructure and essential services. Analysts warn that the region is witnessing an unprecedented escalation in Middle East cyber warfare, with attacks affecting governments, energy networks, finance,

Middle East Cyber Warfare Intensifies: Rising Attacks, Hacktivist Surge, and Global Risk Exposure  Read More »

Hidden instructions in README files can make AI agents leak data

Hidden instructions in README files can make AI agents leak data 2026-03-17 at 08:02 By Sinisa Markovic Developers rely on AI coding agents to set up projects, install dependencies, and run commands by following instructions in repository README files, which provide setup guidance for software projects. New research identifies a security risk when attackers hide

Hidden instructions in README files can make AI agents leak data Read More »

What to do in the first 24 hours of a breach

What to do in the first 24 hours of a breach 2026-03-17 at 07:59 By Help Net Security In this Help Net Security video, Arvind Parthasarathi, CEO of CYGNVS, walks through a 10-step process for handling a cybersecurity breach. The first five steps cover preparation: setting up an out-of-band communication platform, identifying internal stakeholders, selecting

What to do in the first 24 hours of a breach Read More »

Certificate lifespans are shrinking and most organizations aren’t ready

Certificate lifespans are shrinking and most organizations aren’t ready 2026-03-16 at 08:32 By Mirko Zorz The push for shorter TLS certificate lifespans has been building for years. It started with Google’s internal push toward 90-day certificates, which gained traction inside the industry before resistance from enterprise customers slowed things down. Then Apple proposed 47-day certificates,

Certificate lifespans are shrinking and most organizations aren’t ready Read More »

What smart factories keep getting wrong about cybersecurity

What smart factories keep getting wrong about cybersecurity 2026-03-16 at 08:24 By Mirko Zorz In this Help Net Security interview, Packsize CSO Troy Rydman breaks down the biggest vulnerabilities in smart factory environments today, from IoT devices and legacy systems to human error. He explains how unmanaged devices, from sensors to robotic components, often go

What smart factories keep getting wrong about cybersecurity Read More »

AI coding agents keep repeating decade-old security mistakes

AI coding agents keep repeating decade-old security mistakes 2026-03-13 at 08:01 By Anamarija Pogorelec Coding agents are now writing production features on real development teams, and a new report from DryRun Security shows that those agents introduce security vulnerabilities at a high rate across nearly every type of application they build. “AI coding agents can

AI coding agents keep repeating decade-old security mistakes Read More »

ENISA advisory examines package manager security risks

ENISA advisory examines package manager security risks 2026-03-12 at 15:24 By Anamarija Pogorelec Developers install external libraries with a single command, and that step can introduce more code than expected into a project environment. Dependency resolution inside package managers extends software supply chains across large collections of external components. ENISA’s Technical Advisory for Secure Use

ENISA advisory examines package manager security risks Read More »

Stop fixing OT security with IT thinking

Stop fixing OT security with IT thinking 2026-03-12 at 08:35 By Mirko Zorz In this Help Net Security interview, Ejona Preçi, Group CISO at Lindal Group, discusses the specific cybersecurity challenges in manufacturing environments. The conversation covers why standard IT security practices break down on shop floors, where PLCs and decade-old firmware were never designed

Stop fixing OT security with IT thinking Read More »

Does Anthropic deserve the trust of the cybersecurity community?

Does Anthropic deserve the trust of the cybersecurity community? 2026-03-12 at 08:35 By Help Net Security The cybersecurity industry runs on trust. The belief that when a vendor says they will behave a certain way, they will, that critical CVEs are in fact critical, or when companies say they’re GDPR compliant, they really are. But

Does Anthropic deserve the trust of the cybersecurity community? Read More »

Wireless vulnerabilities are doubling every few years

Wireless vulnerabilities are doubling every few years 2026-03-12 at 07:00 By Anamarija Pogorelec Wireless vulnerabilities are being disclosed at a rate that has no precedent in the fifteen-year history of systematic tracking. In 2025, researchers published 937 new wireless-related CVEs, an average of 2.5 per day, according to a threat report from Bastille Networks based

Wireless vulnerabilities are doubling every few years Read More »

Meta turns to AI to sniff out scams on Facebook, Messenger and WhatsApp

Meta turns to AI to sniff out scams on Facebook, Messenger and WhatsApp 2026-03-11 at 18:31 By Anamarija Pogorelec Meta’s new tools on Facebook, Messenger, and WhatsApp protect users from scams. They use advanced AI systems to analyze text, images, and surrounding context and identify sophisticated scam patterns. Facebook alerts for suspicious friend requests (Source:

Meta turns to AI to sniff out scams on Facebook, Messenger and WhatsApp Read More »

Zero trust, zero buzzwords: Here’s what it means

Zero trust, zero buzzwords: Here’s what it means 2026-03-11 at 09:21 By Help Net Security In this Help Net Security video, Murat Balaban, CEO of Zenarmor, breaks down zero trust and zero trust network access (ZTNA) without the buzzwords. The video covers why this approach matters, including the risk of lateral movement after a breach

Zero trust, zero buzzwords: Here’s what it means Read More »

Software vulnerabilities push credential abuse aside in cloud intrusions

Software vulnerabilities push credential abuse aside in cloud intrusions 2026-03-11 at 07:17 By Sinisa Markovic Cloud intrusions are unfolding on shorter timelines, with attackers leaning more on unpatched software and compromised identities. H2 2025 distribution of initial access vectors exploited in Google Cloud (Source: Google) Google Cloud’s Cloud Threat Horizons Report H1 2026 reflects incident

Software vulnerabilities push credential abuse aside in cloud intrusions Read More »

Bug bounties are broken, and the best security pros are moving on

Bug bounties are broken, and the best security pros are moving on 2026-03-10 at 08:33 By Anamarija Pogorelec Penetration testing engagements are organized as scheduled contracts with defined scope, set testing windows, and direct communication channels with client teams. Cobalt’s 2026 Pentester Profile Report describes growing preference for penetration testing as a service (PTaaS) and

Bug bounties are broken, and the best security pros are moving on Read More »

Airbus CSO on supply chain blind spots, space threats, and the limits of AI red-teaming

Airbus CSO on supply chain blind spots, space threats, and the limits of AI red-teaming 2026-03-10 at 08:30 By Mirko Zorz Pascal Andrei, CSO at Airbus, knows that the aerospace and defense sector is facing a threat environment that is evolving faster than most organizations can track. From sub-tier suppliers quietly becoming entry points for

Airbus CSO on supply chain blind spots, space threats, and the limits of AI red-teaming Read More »

The people behind cyber extortion are often in their forties

The people behind cyber extortion are often in their forties 2026-03-10 at 08:00 By Anamarija Pogorelec Many cybercrime investigations end with arrests or indictments that reveal little about the people behind the operations. When authorities do disclose demographic details, the pattern that emerges does not match the common assumption that cyber offenders are mostly very

The people behind cyber extortion are often in their forties Read More »

Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks

Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks 2026-03-09 at 15:37 By Ashish Khaitan Cybersecurity agencies across the Pacific region are sharing concerns about the ransomware group INC Ransom’s expanding activities and the growing influence of its affiliate network. A joint advisory issued by the Australian Cyber Security Centre (ACSC), National

Australia, New Zealand, Tonga, Warn of Rising INC Ransom Attacks Targeting Pacific Networks Read More »

No more soft play, President Trump warns in new cyber strategy

No more soft play, President Trump warns in new cyber strategy 2026-03-09 at 15:37 By Sinisa Markovic The White House released “President Trump’s Cyber Strategy for America,” a policy framework outlining the administration’s priorities for maintaining U.S. leadership in cyberspace. The seven-page cyber strategy commits to a coordinated, government-wide response to cyber threats that extends

No more soft play, President Trump warns in new cyber strategy Read More »

Scroll to Top