cybersecurity

Ransom demands are down, email is the top way attackers get in

Ransom demands are down, email is the top way attackers get in 2026-07-16 at 08:00 By Mirko Zorz An employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later. […]

Ransom demands are down, email is the top way attackers get in Read More »

Companies keep getting breached by vulnerabilities they already knew about

Companies keep getting breached by vulnerabilities they already knew about 2026-07-16 at 07:30 By Mirko Zorz Scanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that

Companies keep getting breached by vulnerabilities they already knew about Read More »

Finance phishing works because it sounds boringly normal

Finance phishing works because it sounds boringly normal 2026-07-16 at 06:53 By Anamarija Pogorelec Finance departments process a constant stream of invoices, contracts, payment notices, and procurement emails, making email one of the most common initial access vectors for threat actors. According to Cofense, attackers exploit those workflows with phishing emails that resemble legitimate business

Finance phishing works because it sounds boringly normal Read More »

SingGuard-NSFA: Open-source guardrails for agentic AI

SingGuard-NSFA: Open-source guardrails for agentic AI 2026-07-15 at 08:30 By Anamarija Pogorelec SingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones. Risk taxonomy The NSFA risk taxonomy organizes threats along the CIA triad of confidentiality,

SingGuard-NSFA: Open-source guardrails for agentic AI Read More »

The MDR renewal question: What changes when AI can handle the alerts

The MDR renewal question: What changes when AI can handle the alerts 2026-07-15 at 08:00 By Help Net Security For most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a

The MDR renewal question: What changes when AI can handle the alerts Read More »

An AI overthinking attack can tie a robot up for over a minute

An AI overthinking attack can tie a robot up for over a minute 2026-07-15 at 07:30 By Anamarija Pogorelec Robots that read the world through cameras now lean on large vision-language models to interpret what they see and decide what to do next. These models handle images and text together, so any words that fall

An AI overthinking attack can tie a robot up for over a minute Read More »

Google adds FIDO2 keys and phone passkeys to Windows login via GCPW

Google adds FIDO2 keys and phone passkeys to Windows login via GCPW 2026-07-14 at 13:35 By Anamarija Pogorelec Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign

Google adds FIDO2 keys and phone passkeys to Windows login via GCPW Read More »

No one knows how many old shims can still bypass UEFI Secure Boot

No one knows how many old shims can still bypass UEFI Secure Boot 2026-07-14 at 13:26 By Mirko Zorz The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot

No one knows how many old shims can still bypass UEFI Secure Boot Read More »

The best defense against AI attacks turns out to be a skeptical human

The best defense against AI attacks turns out to be a skeptical human 2026-07-14 at 09:00 By Mirko Zorz Analysts across the security industry now run generative AI through their daily work, from log triage to incident write-ups. Active use in cybersecurity strategy reached 78% of practitioners in 2026, up from half the field a

The best defense against AI attacks turns out to be a skeptical human Read More »

Fake smart home residents could stand in for real ones in security research

Fake smart home residents could stand in for real ones in security research 2026-07-14 at 08:30 By Anamarija Pogorelec Smart home security research runs on a scarce ingredient: recordings of how real people use the gadgets in their homes. Getting that data means wiring up someone’s house and watching for months, which is slow, costly,

Fake smart home residents could stand in for real ones in security research Read More »

Why SBOMs, signing, and provenance still don’t tell you if software is safe

Why SBOMs, signing, and provenance still don’t tell you if software is safe 2026-07-13 at 09:30 By Help Net Security We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprises

Why SBOMs, signing, and provenance still don’t tell you if software is safe Read More »

Cynative: Open-source deep research agent

Cynative: Open-source deep research agent 2026-07-13 at 09:00 By Mirko Zorz Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can delete a bucket, flip a permission, or leak a secret on

Cynative: Open-source deep research agent Read More »

Microsoft demystifies how Windows updates work

Microsoft demystifies how Windows updates work 2026-07-13 at 08:30 By Anamarija Pogorelec Microsoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regularly deploy monthly security updates, released

Microsoft demystifies how Windows updates work Read More »

A hardware security AI assistant that checks chips for hidden backdoors

A hardware security AI assistant that checks chips for hidden backdoors 2026-07-13 at 08:00 By Sinisa Markovic Chip designers license blocks of circuitry from outside vendors and drop them into larger products. A single processor can carry components from a range of suppliers, each written by a company the buyer may never deal with directly.

A hardware security AI assistant that checks chips for hidden backdoors Read More »

99.9% of fixable AI vulnerabilities remain unpatched

99.9% of fixable AI vulnerabilities remain unpatched 2026-07-13 at 07:30 By Anamarija Pogorelec Organizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security Report. Building AI without security Fifty-six percent of AI adopters have deployed agent frameworks into

99.9% of fixable AI vulnerabilities remain unpatched Read More »

Enterprises are rethinking where their AI applications run

Enterprises are rethinking where their AI applications run 2026-07-13 at 07:00 By Anamarija Pogorelec Growing demand for compute capacity, power, cooling and low-latency connectivity is prompting organizations to reassess where AI applications run, according to CoreSite. Public cloud continues to support experimentation and rapid deployment, while colocation is increasingly used for workloads that require predictable

Enterprises are rethinking where their AI applications run Read More »

Only 28% of financial workforce MFA is phishing-resistant

Only 28% of financial workforce MFA is phishing-resistant 2026-07-10 at 08:41 By Anamarija Pogorelec Passwords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant MFA (Source: Secret Double Octopus) Workforce

Only 28% of financial workforce MFA is phishing-resistant Read More »

Turning software supply chain security into a daily habit

Turning software supply chain security into a daily habit 2026-07-10 at 08:30 By Help Net Security In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every

Turning software supply chain security into a daily habit Read More »

Your coding agent says no in chat and yes in the code

Your coding agent says no in chat and yes in the code 2026-07-09 at 13:44 By Mirko Zorz Millions of developers share their keyboard with GitHub Copilot. Inside Visual Studio Code, it opens their files, writes and edits code, runs scripts, and reworks its own output across many turns. The safety testing that vets these

Your coding agent says no in chat and yes in the code Read More »

Malicious AI agent skills can slip past the scanners built to stop them

Malicious AI agent skills can slip past the scanners built to stop them 2026-07-09 at 10:24 By Sinisa Markovic Developers who build with AI coding agents grab capabilities off public marketplaces the same way they grab packages from npm or PyPI. The add-ons are called agent skills. Each one is a little bundle of plain-English

Malicious AI agent skills can slip past the scanners built to stop them Read More »

Scroll to Top