Don’t miss

Attackers already know the secrets are on your developers’ machines. Do you?

Attackers already know the secrets are on your developers’ machines. Do you? 2026-06-04 at 09:26 By Help Net Security In a recent GitGuardian analysis, an average of 150 secrets were found on a sample of developer endpoints. Private keys accounted for 38% of unique secrets, while cloud, identity provider, and secret management credentials (AWS IAM, […]

Attackers already know the secrets are on your developers’ machines. Do you? Read More »

From critical to controlled: Cutting vulnerabilities in a live manufacturing environment

From critical to controlled: Cutting vulnerabilities in a live manufacturing environment 2026-06-04 at 09:26 By Help Net Security A vulnerability scanner flags a critical CVSS 10 vulnerability on an industrial asset. The report lands in the boss’ inbox and now he wants to know why we’re sitting on a critical vulnerability. In a normal IT […]

From critical to controlled: Cutting vulnerabilities in a live manufacturing environment Read More »

Autonomous AI-driven worm can reason its way through corporate networks

Autonomous AI-driven worm can reason its way through corporate networks 2026-06-03 at 20:20 By Zeljka Zorz Researchers at the University of Toronto, the Vector Institute, and the University of Cambridge have built and tested a proof-of-concept AI-driven worm that does not operate on a fixed list of exploits. Instead, it analyzes each target it encounters, […]

Autonomous AI-driven worm can reason its way through corporate networks Read More »

Only 11% of production agents pass the AI agent security bar

Only 11% of production agents pass the AI agent security bar 2026-06-03 at 14:00 By Mirko Zorz Enterprise teams are running AI agents that write code, drive browsers, answer customer calls, manage cloud infrastructure, and query data warehouses with standing credentials. A new independent assessment of 100 production agents finds that nearly all of them […]

Only 11% of production agents pass the AI agent security bar Read More »

Google fixes actively exploited Android vulnerability (CVE-2025-48595)

Google fixes actively exploited Android vulnerability (CVE-2025-48595) 2026-06-02 at 15:17 By Zeljka Zorz Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.” About CVE-2025-48595 CVE-2025-48595 is an integer overflow vulnerability in the Android […]

Google fixes actively exploited Android vulnerability (CVE-2025-48595) Read More »

Zero trust physical security needs trust decisions at the edge

Zero trust physical security needs trust decisions at the edge 2026-06-02 at 09:09 By Mirko Zorz In this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the […]

Zero trust physical security needs trust decisions at the edge Read More »

This AI model backdoor attack stays hidden until you customize the model

This AI model backdoor attack stays hidden until you customize the model 2026-06-02 at 09:09 By Anamarija Pogorelec Most teams that deploy AI start with a backbone model. They download a large pre-trained system, adapt it to a specific task, and put it into production. The download step carries a security question: the origin of […]

This AI model backdoor attack stays hidden until you customize the model Read More »

Why you need BAS and autonomous pentesting together

Why you need BAS and autonomous pentesting together 2026-06-02 at 09:09 By Help Net Security Most security teams know the drill: A new autonomous penetration testing tool gets deployed, and the first run is genuinely impressive. The dashboard surfaces critical findings, maps lateral movement paths nobody had documented before, and exposes a legacy service account […]

Why you need BAS and autonomous pentesting together Read More »

Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089)

Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) 2026-06-01 at 17:17 By Zeljka Zorz CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB) warned on Friday. About CVE-2026-41089 CVE-2026-41089 is a stack-based buffer overflow vulnerability in Windows Netlogon, […]

Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) Read More »

NVIDIA goes open source with a big batch of physical AI agent tools

NVIDIA goes open source with a big batch of physical AI agent tools 2026-06-01 at 11:46 By Anamarija Pogorelec NVIDIA just dropped a big batch of open-source “physical AI” skills and tools, and they’re designed to make a roboticist’s life a whole lot easier. The idea? Take the messy, complicated work behind robots, self-driving cars, […]

NVIDIA goes open source with a big batch of physical AI agent tools Read More »

Data discovery gaps that catch enterprises off guard

Data discovery gaps that catch enterprises off guard 2026-06-01 at 11:46 By Mirko Zorz In this interview with Help Net Security, Avani Desai, CEO at Schellman, talks about the gap between what organizations think they know about their data and what discovery scans turn up. She shares stories of shadow data in abandoned cloud storage, […]

Data discovery gaps that catch enterprises off guard Read More »

EU organizations buckle under rising compliance pressure

EU organizations buckle under rising compliance pressure 2026-06-01 at 08:19 By Sinisa Markovic Cybersecurity governance in the EU is shifting under expanding frameworks such as NIS2 and DORA, while AI raises new questions for security teams. What the future brings is hard to predict, and organizations must find a way to cope. Antonija Vojnović, Governance, […]

EU organizations buckle under rising compliance pressure Read More »

OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory

OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory 2026-06-01 at 08:19 By Mirko Zorz AI agents keep memory across sessions. Conversation history, vector stores, scratchpads, and RAG indexes persist between runs, and anything written into that store becomes a privileged input the agent reads back later. An attacker who […]

OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory Read More »

New infostealer reaches enterprise devices through FortiClient EMS vulnerability

New infostealer reaches enterprise devices through FortiClient EMS vulnerability 2026-05-29 at 18:31 By Zeljka Zorz Attackers are delivering a broad-spectrum infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS). “The [malicious] payload was presented as a Fortinet endpoint update and executed through FortiClient-managed VPN scripting workflows,” Arctic Wold […]

New infostealer reaches enterprise devices through FortiClient EMS vulnerability Read More »

Dutch police disrupts botnet composed of 17 million devices

Dutch police disrupts botnet composed of 17 million devices 2026-05-29 at 17:26 By Zeljka Zorz The Dutch National Police and the country’s National Cyber Security Center (NCSC) have taken offline 200 servers controlling a botnet of 17 million devices, the law enforcement agency announced on Thursday. The investigation was launched after the NCSC received a […]

Dutch police disrupts botnet composed of 17 million devices Read More »

LinkedIn-themed phishing abuses Adobe’s A/B testing platform

LinkedIn-themed phishing abuses Adobe’s A/B testing platform 2026-05-29 at 14:08 By Zeljka Zorz A newly documented phishing campaign is targeting professionals with fake LinkedIn business emails and abusing a trusted service operated by Adobe. The attack from the victim’s perspective The attack starts with an email that looks, at first glance, like a routine business […]

LinkedIn-themed phishing abuses Adobe’s A/B testing platform Read More »

Zapier exploit chain shows how known anti-patterns compose into critical risk

Zapier exploit chain shows how known anti-patterns compose into critical risk 2026-05-28 at 16:00 By Mirko Zorz A five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier’s public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in the […]

Zapier exploit chain shows how known anti-patterns compose into critical risk Read More »

The CISO selling confidence in a market full of breach headlines

The CISO selling confidence in a market full of breach headlines 2026-05-28 at 10:16 By Mirko Zorz Engineering teams across enterprise IT are writing their own software with AI coding assistants, spinning up agents that act on their behalf, and assigning those agents the same access privileges their human creators hold. The shift has pulled […]

The CISO selling confidence in a market full of breach headlines Read More »

Frontier AI models collapse under multi-turn AI attacks, Cisco finds

Frontier AI models collapse under multi-turn AI attacks, Cisco finds 2026-05-28 at 10:16 By Mirko Zorz Attackers who probe large language models rarely give up after one refusal. They reframe, build context across turns, adopt personas, and escalate gradually. New research from Cisco’s AI threat intelligence team finds that the safety benchmarks used across the […]

Frontier AI models collapse under multi-turn AI attacks, Cisco finds Read More »

Coinflow CISO on crypto payments security under AI pressure

Coinflow CISO on crypto payments security under AI pressure 2026-05-27 at 09:24 By Mirko Zorz Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs the company’s security program from Malta. Coinflow is headquartered […]

Coinflow CISO on crypto payments security under AI pressure Read More »

Scroll to Top