Don’t miss

Ransomware negotiation tactics have turned into a business process

Ransomware negotiation tactics have turned into a business process 2026-09-08 at 08:40 By Help Net Security In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations. Ross walks through the tactics groups use once an attack begins, from […]

Ransomware negotiation tactics have turned into a business process Read More »

September 2026 Patch Tuesday forecast: All we need is more time

September 2026 Patch Tuesday forecast: All we need is more time 2026-09-04 at 09:00 By Help Net Security The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs:

September 2026 Patch Tuesday forecast: All we need is more time Read More »

OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets

OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets 2026-09-04 at 07:35 By Anamarija Pogorelec OpenAI committed $1 billion to subsidize access to its Daybreak cyber models, along with training and technical support, for organizations defending water and wastewater systems, the electric grid, state and local government, community and regional banks,

OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets Read More »

Thomson Reuters reveals breach that exposed U.S. and Canadian court records

Thomson Reuters reveals breach that exposed U.S. and Canadian court records 2026-09-03 at 16:50 By Zeljka Zorz Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and

Thomson Reuters reveals breach that exposed U.S. and Canadian court records Read More »

Your threat feed is someone else’s database: What ingesting malware intel at scale takes

Your threat feed is someone else’s database: What ingesting malware intel at scale takes 2026-09-03 at 08:30 By Help Net Security The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is

Your threat feed is someone else’s database: What ingesting malware intel at scale takes Read More »

When AI quietly breaks things, who pays?

When AI quietly breaks things, who pays? 2026-09-03 at 08:00 By Mirko Zorz David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance

When AI quietly breaks things, who pays? Read More »

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) 2026-09-02 at 15:42 By Zeljka Zorz A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unified communications platform built on

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) Read More »

SonicWall SMA 1000 appliances under attack via zero-day flaws

SonicWall SMA 1000 appliances under attack via zero-day flaws 2026-09-02 at 13:13 By Zeljka Zorz Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built

SonicWall SMA 1000 appliances under attack via zero-day flaws Read More »

A battery storage cyberattack would look exactly like a badly tuned controller

A battery storage cyberattack would look exactly like a badly tuned controller 2026-09-02 at 12:00 By Mirko Zorz Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should

A battery storage cyberattack would look exactly like a badly tuned controller Read More »

National Life Group CISO expects more vulnerabilities in six months than in thirty years

National Life Group CISO expects more vulnerabilities in six months than in thirty years 2026-09-02 at 09:00 By Mirko Zorz In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot

National Life Group CISO expects more vulnerabilities in six months than in thirty years Read More »

Scareware ads keep running on Google’s transparency tool, even after they’re reported

Scareware ads keep running on Google’s transparency tool, even after they’re reported 2026-09-02 at 08:30 By Mirko Zorz A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to

Scareware ads keep running on Google’s transparency tool, even after they’re reported Read More »

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira 2026-09-02 at 08:00 By Mirko Zorz Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows file shares, an entire Active Directory domain,

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira Read More »

CISA review makes the case for eliminating vulnerability classes

CISA review makes the case for eliminating vulnerability classes 2026-09-01 at 18:23 By Zeljka Zorz For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of

CISA review makes the case for eliminating vulnerability classes Read More »

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers 2026-09-01 at 08:30 By Mirko Zorz Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The startup,

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers Read More »

NIS2 compliance: Fixing IAM and access control before the 2026 audit

NIS2 compliance: Fixing IAM and access control before the 2026 audit 2026-09-01 at 08:00 By Help Net Security The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into

NIS2 compliance: Fixing IAM and access control before the 2026 audit Read More »

What your vendor says about PQC tells you if they are ready

What your vendor says about PQC tells you if they are ready 2026-09-01 at 07:30 By Mirko Zorz In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity

What your vendor says about PQC tells you if they are ready Read More »

Attackers plant remote access tools on compromised PaperCut servers

Attackers plant remote access tools on compromised PaperCut servers 2026-08-31 at 17:54 By Zeljka Zorz The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools The vendor

Attackers plant remote access tools on compromised PaperCut servers Read More »

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree 2026-08-31 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity,

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree Read More »

Scroll to Top