Don’t miss

This supercomputer encrypts your data even while it’s running it

This supercomputer encrypts your data even while it’s running it 2026-07-01 at 08:30 By Sinisa Markovic Most people who handle sensitive data already encrypt it in two places. They lock it down when it sits on a hard drive, and they lock it down when it moves across a network. There has always been a […]

This supercomputer encrypts your data even while it’s running it Read More »

AI-generated code risks reach security, legal, and compliance teams

AI-generated code risks reach security, legal, and compliance teams 2026-07-01 at 08:00 By Mirko Zorz Most engineering organizations write code with AI, and a good number of them keep that code away from customers. A Flux survey of engineering leaders and practitioners found that nearly half run AI-generated code in production. Almost every company in […]

AI-generated code risks reach security, legal, and compliance teams Read More »

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) 2026-06-30 at 16:58 By Zeljka Zorz Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploitation attempts (Source: Defused) “On 27 June 2026 […]

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) Read More »

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) 2026-06-30 at 13:25 By Zeljka Zorz Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud […]

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) Read More »

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin 2026-06-30 at 09:15 By Mirko Zorz Phones and laptops ship with a feature that sends files to nearby devices over the air, with no cables, accounts, or prior pairing. Apple calls its version AirDrop. Google and Samsung call theirs Quick Share. […]

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin Read More »

Vulnerability reports are arriving faster than GitHub can review them

Vulnerability reports are arriving faster than GitHub can review them 2026-06-30 at 08:25 By Anamarija Pogorelec Across the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub Advisory Database, which feeds automated security alerts to millions of projects, […]

Vulnerability reports are arriving faster than GitHub can review them Read More »

JSP webshells being dropped on unpatched PTC Windchill instances

JSP webshells being dropped on unpatched PTC Windchill instances 2026-06-29 at 19:18 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog don’t contain links […]

JSP webshells being dropped on unpatched PTC Windchill instances Read More »

Mozilla warns of indirect prompt injection risk in AI coding agents

Mozilla warns of indirect prompt injection risk in AI coding agents 2026-06-29 at 13:48 By Zeljka Zorz A malicious GitHub repository can silently compromise a developer’s machine without containing a single line of malicious code, security researchers at Mozilla’s Zero Day Investigative Network (0DIN) warned. The attack The proof-of-concept attack targets AI-powered coding agents such […]

Mozilla warns of indirect prompt injection risk in AI coding agents Read More »

DarkMoon: Open-source AI pentesting platform

DarkMoon: Open-source AI pentesting platform 2026-06-29 at 08:30 By Mirko Zorz Penetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert consultants run into thousands of dollars a day, and results vary with the tester. Automation promises to narrow […]

DarkMoon: Open-source AI pentesting platform Read More »

Sycophantic chatbots and the harms that build over many chats

Sycophantic chatbots and the harms that build over many chats 2026-06-29 at 08:00 By Sinisa Markovic People use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional […]

Sycophantic chatbots and the harms that build over many chats Read More »

Companies keep bolting AI onto their products, and the security bill is coming due

Companies keep bolting AI onto their products, and the security bill is coming due 2026-06-29 at 07:30 By Mirko Zorz Companies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern. The vulnerabilities those features create get rated high risk far more often than anything else, […]

Companies keep bolting AI onto their products, and the security bill is coming due Read More »

Synology issues critical fix for MailPlus Server vulnerabilities

Synology issues critical fix for MailPlus Server vulnerabilities 2026-06-26 at 13:57 By Zeljka Zorz Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or […]

Synology issues critical fix for MailPlus Server vulnerabilities Read More »

Mystery hackers use novel SharkLoader dropper against governments, software devs

Mystery hackers use novel SharkLoader dropper against governments, software devs 2026-06-26 at 12:13 By Zeljka Zorz Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization in Indonesia. What initially […]

Mystery hackers use novel SharkLoader dropper against governments, software devs Read More »

A privacy-first take on local malware analysis

A privacy-first take on local malware analysis 2026-06-26 at 09:00 By Sinisa Markovic Submitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these services to get a quick verdict on whether a binary is dangerous. The convenience […]

A privacy-first take on local malware analysis Read More »

Two CEOs on why security and AI readiness belong together

Two CEOs on why security and AI readiness belong together 2026-06-26 at 08:30 By Mirko Zorz SuperOps and Guardz are bundling PSA, RMM, MDM, and agentic SecOps into one offering for MSPs. In this Help Net Security Q&A, SuperOps CEO Arvind Parthiban and Guardz CEO Dor Eisner explain how a connected stack cuts the time […]

Two CEOs on why security and AI readiness belong together Read More »

The uptime questions every engineering leader should ask this week

The uptime questions every engineering leader should ask this week 2026-06-25 at 09:30 By Mirko Zorz In this interview with Help Net Security, Mattias Geniar, CTO at Oh Dear, explains why most outages start quietly, as creeping latency or a slow rise in errors. He argues teams alert on the wrong things: absolute numbers instead […]

The uptime questions every engineering leader should ask this week Read More »

LLM security advice looks solid until you check the hard cases

LLM security advice looks solid until you check the hard cases 2026-06-25 at 09:00 By Anamarija Pogorelec Plenty of people now type their security worries straight into a chatbot. A hacked account, a suspicious email, a stalker who might be tracking a phone, all of it lands in the same window someone would use to […]

LLM security advice looks solid until you check the hard cases Read More »

Law enforcement hits StealC and Amadey malware networks

Law enforcement hits StealC and Amadey malware networks 2026-06-24 at 18:05 By Zeljka Zorz Operation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey. The notice on disrupted websites (Source: Microsoft) While developed by separate criminal groups, those two […]

Law enforcement hits StealC and Amadey malware networks Read More »

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) 2026-06-24 at 14:36 By Zeljka Zorz CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells, all […]

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) Read More »

Scroll to Top