Don’t miss

Who will be the Stanislav Petrov in your organization?

Who will be the Stanislav Petrov in your organization? 2026-08-11 at 09:00 By Help Net Security The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported […]

Who will be the Stanislav Petrov in your organization? Read More »

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix 2026-08-11 at 08:30 By Mirko Zorz Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix Read More »

Metabase zero-day exploited to access Framework customer data

Metabase zero-day exploited to access Framework customer data 2026-08-10 at 16:42 By Zeljka Zorz Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers

Metabase zero-day exploited to access Framework customer data Read More »

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 2026-08-10 at 14:34 By Zeljka Zorz To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix.

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 Read More »

OpenAI locks down Astra over potential critical cyber capabilities

OpenAI locks down Astra over potential critical cyber capabilities 2026-08-10 at 10:09 By Anamarija Pogorelec OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Framework. The

OpenAI locks down Astra over potential critical cyber capabilities Read More »

Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop: Open-source evidence store and policy engine for the software supply chain 2026-08-10 at 08:30 By Sinisa Markovic Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable

Chainloop: Open-source evidence store and policy engine for the software supply chain Read More »

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? 2026-08-07 at 09:00 By Help Net Security July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? Read More »

What the first year of EU AI Act transparency enforcement could look like

What the first year of EU AI Act transparency enforcement could look like 2026-08-07 at 08:30 By Mirko Zorz In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders

What the first year of EU AI Act transparency enforcement could look like Read More »

US fuel gauge exposure fell by more than half in three months

US fuel gauge exposure fell by more than half in three months 2026-08-07 at 08:00 By Anamarija Pogorelec Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May,

US fuel gauge exposure fell by more than half in three months Read More »

Three in four AI-generated vulnerability patches leave something broken

Three in four AI-generated vulnerability patches leave something broken 2026-08-06 at 15:45 By Mirko Zorz Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time

Three in four AI-generated vulnerability patches leave something broken Read More »

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers 2026-08-05 at 21:45 By Mirko Zorz An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers Read More »

Top product launches at Black Hat USA 2026

Top product launches at Black Hat USA 2026 2026-08-05 at 18:00 By Anamarija Pogorelec Black Hat USA 2026 is underway in Las Vegas, and vendors are using the moment to unveil what they hope will define the next year of defense. Here are the announcements drawing the most attention on the ground, and why they

Top product launches at Black Hat USA 2026 Read More »

AI agent deception moves from theory to reality in UK cyber tests

AI agent deception moves from theory to reality in UK cyber tests 2026-08-05 at 15:05 By Zeljka Zorz “During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute (AISI) disclosed on Tuesday. The agents’ actions included an attempted supply-chain attack that saw them create

AI agent deception moves from theory to reality in UK cyber tests Read More »

Code review used to be the only way to catch these bugs

Code review used to be the only way to catch these bugs 2026-08-05 at 14:30 By Mirko Zorz An automated system called NOVA read the source code of 3,915 open-source projects over two months and came back with 14,090 vulnerabilities, each one confirmed through the system’s validation pipeline. Vulnerability researchers at Palo Alto Networks’ Unit

Code review used to be the only way to catch these bugs Read More »

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic 2026-08-05 at 12:35 By Mirko Zorz TP-Link prints the serial number of an Omada router on its packaging and on a label attached to the device. Those numbers run in sequence, and feeding a guessed one to the Omada cloud service returns the

15 TP-Link Omada vulnerabilities let attackers hijack routers and intercept camera traffic Read More »

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove 2026-08-05 at 11:43 By Zeljka Zorz A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it. Different traps for Mac and Windows users By

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Read More »

Future AGI: Open-source platform for shipping self-improving AI agents

Future AGI: Open-source platform for shipping self-improving AI agents 2026-08-05 at 08:30 By Anamarija Pogorelec Future AGI is an open-source platform for tracing, evaluating, simulating, and guardrailing LLM agents, licensed Apache 2.0 and self-hostable. Self-hosted instances register with Future AGI on first boot and send an instance ID, a version string, a deployment type, and

Future AGI: Open-source platform for shipping self-improving AI agents Read More »

What stops attackers wrecking industrial plants is knowing how

What stops attackers wrecking industrial plants is knowing how 2026-08-05 at 07:30 By Mirko Zorz Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The

What stops attackers wrecking industrial plants is knowing how Read More »

Digital executive protection is a strategic imperative for CEOs

Digital executive protection is a strategic imperative for CEOs 2026-08-04 at 09:00 By Mirko Zorz In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email

Digital executive protection is a strategic imperative for CEOs Read More »

OWASP’s subtractive security project measures the attack paths you erased

OWASP’s subtractive security project measures the attack paths you erased 2026-08-04 at 08:30 By Mirko Zorz An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz

OWASP’s subtractive security project measures the attack paths you erased Read More »

Scroll to Top