Don’t miss

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page 2026-09-22 at 16:46 By Zeljka Zorz Three domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future […]

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page Read More »

The latest deepfake numbers give CISOs plenty to worry about

The latest deepfake numbers give CISOs plenty to worry about 2026-09-22 at 15:05 By Sinisa Markovic AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to […]

The latest deepfake numbers give CISOs plenty to worry about Read More »

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) 2026-09-22 at 13:42 By Zeljka Zorz A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the […]

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) Read More »

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions 2026-09-22 at 11:54 By Sinisa Markovic Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this […]

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions Read More »

A cheap fake base station can still track 5G subscribers

A cheap fake base station can still track 5G subscribers 2026-09-22 at 09:30 By Anamarija Pogorelec Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G […]

A cheap fake base station can still track 5G subscribers Read More »

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit 2026-09-22 at 08:00 By Help Net Security By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable […]

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit Read More »

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files 2026-09-21 at 17:00 By Mirko Zorz Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi […]

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files Read More »

Hackers exploit Gyazo server flaw to steal 23.6 million user records

Hackers exploit Gyazo server flaw to steal 23.6 million user records 2026-09-21 at 11:57 By Sinisa Markovic Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions […]

Hackers exploit Gyazo server flaw to steal 23.6 million user records Read More »

Know what was tested before your SAP ECC migration goes live

Know what was tested before your SAP ECC migration goes live 2026-09-21 at 09:00 By Mirko Zorz In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that […]

Know what was tested before your SAP ECC migration goes live Read More »

Bots with good manners are better at fooling people on social media

Bots with good manners are better at fooling people on social media 2026-09-18 at 13:15 By Sinisa Markovic Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability […]

Bots with good manners are better at fooling people on social media Read More »

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched 2026-09-18 at 11:49 By Sinisa Markovic Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the […]

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched Read More »

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys 2026-09-17 at 15:51 By Zeljka Zorz Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and […]

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys Read More »

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) 2026-09-17 at 13:24 By Zeljka Zorz Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460 Cisco ISE is […]

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) Read More »

Scammers leave AI fingerprints all over fake antivirus renewal page

Scammers leave AI fingerprints all over fake antivirus renewal page 2026-09-17 at 13:10 By Sinisa Markovic AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that was more polished than most sites […]

Scammers leave AI fingerprints all over fake antivirus renewal page Read More »

Fake AI trading agent steals crypto wallet passwords

Fake AI trading agent steals crypto wallet passwords 2026-09-17 at 11:00 By Anamarija Pogorelec Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between […]

Fake AI trading agent steals crypto wallet passwords Read More »

The AI security question leaders should be asking instead

The AI security question leaders should be asking instead 2026-09-17 at 08:30 By Mirko Zorz In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why […]

The AI security question leaders should be asking instead Read More »

A flat cybersecurity budget doesn’t have to mean weaker coverage

A flat cybersecurity budget doesn’t have to mean weaker coverage 2026-09-17 at 08:00 By Help Net Security Cheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader. In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut. […]

A flat cybersecurity budget doesn’t have to mean weaker coverage Read More »

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) 2026-09-16 at 15:36 By Zeljka Zorz A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger […]

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) Read More »

What happens when AI agent governance is missing at scale

What happens when AI agent governance is missing at scale 2026-09-16 at 09:00 By Mirko Zorz In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does, since […]

What happens when AI agent governance is missing at scale Read More »

Scroll to Top