Don’t miss

Halo-record: Open-source audit trails for AI agents

Halo-record: Open-source audit trails for AI agents 2026-08-31 at 08:30 By Mirko Zorz Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to, […]

Halo-record: Open-source audit trails for AI agents Read More »

What 90 days and a small budget can buy in AI agent security

What 90 days and a small budget can buy in AI agent security 2026-08-28 at 08:30 By Mirko Zorz In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing,

What 90 days and a small budget can buy in AI agent security Read More »

Unknown PaperCut NG/MF vulnerability is under active attack

Unknown PaperCut NG/MF vulnerability is under active attack 2026-08-27 at 14:59 By Zeljka Zorz A yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the vendor said.

Unknown PaperCut NG/MF vulnerability is under active attack Read More »

AI will not fix a governance problem in your camera estate

AI will not fix a governance problem in your camera estate 2026-08-27 at 08:30 By Mirko Zorz Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody

AI will not fix a governance problem in your camera estate Read More »

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 2026-08-26 at 13:59 By Zeljka Zorz Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Read More »

Production data in testing is still common, and Tricentis’ CISO wants it gone

Production data in testing is still common, and Tricentis’ CISO wants it gone 2026-08-26 at 08:30 By Mirko Zorz In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught

Production data in testing is still common, and Tricentis’ CISO wants it gone Read More »

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Read More »

AI supply chain risk is showing up in developer workflows first

AI supply chain risk is showing up in developer workflows first 2026-08-25 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and

AI supply chain risk is showing up in developer workflows first Read More »

HOL Guard: Open-source antivirus for AI agents

HOL Guard: Open-source antivirus for AI agents 2026-08-25 at 08:30 By Anamarija Pogorelec HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your

HOL Guard: Open-source antivirus for AI agents Read More »

The cybercrime supply chain has five stages, each with a price

The cybercrime supply chain has five stages, each with a price 2026-08-25 at 08:00 By Help Net Security In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five

The cybercrime supply chain has five stages, each with a price Read More »

Suspected Iran-linked attack knocked UK power plant offline for days

Suspected Iran-linked attack knocked UK power plant offline for days 2026-08-24 at 17:22 By Zeljka Zorz News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks. According to

Suspected Iran-linked attack knocked UK power plant offline for days Read More »

CISA’s logging guidance works beyond government

CISA’s logging guidance works beyond government 2026-08-24 at 13:56 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture

CISA’s logging guidance works beyond government Read More »

Hazmat: Open-source containment for AI agents

Hazmat: Open-source containment for AI agents 2026-08-17 at 08:00 By Anamarija Pogorelec Hazmat is an open-source tool that runs AI coding agents inside a separate account on your own machine. It wraps the harnesses people use: Claude Code, Codex, OpenCode, Cursor Agent, and several more, plus any script you write yourself. An agent launched the

Hazmat: Open-source containment for AI agents Read More »

Four corporate investigation mistakes organizations make under pressure

Four corporate investigation mistakes organizations make under pressure 2026-08-13 at 08:00 By Help Net Security In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and

Four corporate investigation mistakes organizations make under pressure Read More »

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months 2026-08-12 at 16:51 By Mirko Zorz Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months Read More »

Post-quantum migration gets harder when every user holds a key

Post-quantum migration gets harder when every user holds a key 2026-08-12 at 09:00 By Mirko Zorz In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break

Post-quantum migration gets harder when every user holds a key Read More »

PentestGPT: Open-source automated penetration testing agentic framework

PentestGPT: Open-source automated penetration testing agentic framework 2026-08-12 at 08:30 By Anamarija Pogorelec PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and

PentestGPT: Open-source automated penetration testing agentic framework Read More »

Who will be the Stanislav Petrov in your organization?

Who will be the Stanislav Petrov in your organization? 2026-08-11 at 09:00 By Help Net Security The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported

Who will be the Stanislav Petrov in your organization? Read More »

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix 2026-08-11 at 08:30 By Mirko Zorz Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix Read More »

Metabase zero-day exploited to access Framework customer data

Metabase zero-day exploited to access Framework customer data 2026-08-10 at 16:42 By Zeljka Zorz Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers

Metabase zero-day exploited to access Framework customer data Read More »

Scroll to Top