Don’t miss

Airline brands become launchpads for phishing, crypto fraud

Airline brands become launchpads for phishing, crypto fraud 2026-02-25 at 08:05 By Sinisa Markovic Airline brands sit at the center of peak travel booking cycles, loyalty programs, and high value transactions. Criminal groups continue to register thousands of lookalike domains tied to these brands, targeting travelers, employees, and business partners. Recent threat intelligence from BforeAI’s […]

Airline brands become launchpads for phishing, crypto fraud Read More »

Self-spreading npm malware targets developers in new supply chain attack

Self-spreading npm malware targets developers in new supply chain attack 2026-02-24 at 15:10 By Zeljka Zorz Security researchers have uncovered another supply chain attack targeting developers: 19 typosquatting npm packages published on npmjs.com that steal credentials, infect projects, and propagate themselves across developer environments. The operation, dubbed “SANDWORM_MODE,” represents a (still) rare example of worm-like […]

Self-spreading npm malware targets developers in new supply chain attack Read More »

Microsoft extends security patching for three Windows products at a price

Microsoft extends security patching for three Windows products at a price 2026-02-24 at 11:38 By Sinisa Markovic Support is ending for three Windows products released in 2016, with deadlines beginning in October 2026. Windows 10 Enterprise LTSB 2016 and Windows 10 IoT Enterprise 2016 LTSB will reach end of support on October 13, 2026, followed […]

Microsoft extends security patching for three Windows products at a price Read More »

AI is becoming part of everyday criminal workflows

AI is becoming part of everyday criminal workflows 2026-02-24 at 09:00 By Mirko Zorz Underground forums include long threads about chatbots drafting phishing emails, generating code snippets, and coaching social engineering calls. A new study examined conversations captured between January 1, 2025 and July 31, 2025 across dozens of cybercrime forums to map how AI […]

AI is becoming part of everyday criminal workflows Read More »

Ransomware group breached SmarterTools via flaw in its SmarterMail deployment

Ransomware group breached SmarterTools via flaw in its SmarterMail deployment 2026-02-09 at 17:18 By Zeljka Zorz SmarterTools, the company behind the popular Microsoft Exchange alternative SmarterMail, has been breached by a ransomware-wielding group that leveraged a recently fixed vulnerability in that solution. How did the SmarterTools breach happen? Derek Curtis, the firm’s Chief Operating Officer, […]

Ransomware group breached SmarterTools via flaw in its SmarterMail deployment Read More »

European Commission hit by cyberattackers targeting mobile management platform

European Commission hit by cyberattackers targeting mobile management platform 2026-02-09 at 16:02 By Zeljka Zorz The European Commission’s mobile device management platform was hacked but the incident was swiftly contained and no compromise of mobile devices was detected, EU’s executive branch announced on Friday. The intrusion was detected on January 30, 2026, by CERT-EU, the […]

European Commission hit by cyberattackers targeting mobile management platform Read More »

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731)

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) 2026-02-09 at 13:36 By Zeljka Zorz BeyondTrust fixed a critical remote code execution vulnerability (CVE-2026-1731) in its Remote Support (RS) and Privileged Remote Access (PRA) solutions and is urging self-hosted customers to apply the patch as soon a possible. Unlike the Remote Support zero-day […]

BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) Read More »

United Airlines CISO on building resilience when disruption is inevitable

United Airlines CISO on building resilience when disruption is inevitable 2026-02-09 at 09:09 By Mirko Zorz Aviation runs on complex digital systems built for stability, safety, and long lifecycles. That reality creates a unique cybersecurity challenge for airlines, where disruption can quickly become an operational and public trust crisis. In this Help Net Security interview, […]

United Airlines CISO on building resilience when disruption is inevitable Read More »

Allama: Open-source AI security automation

Allama: Open-source AI security automation 2026-02-09 at 08:19 By Sinisa Markovic Allama is an open-source security automation platform that lets teams build visual workflows for threat detection and response. It includes integrations with 80+ types of tools and services typical in security operations, including SIEM systems, endpoint detection and response products, identity providers, and ticketing […]

Allama: Open-source AI security automation Read More »

CISA orders US federal agencies to replace unsupported edge devices

CISA orders US federal agencies to replace unsupported edge devices 2026-02-06 at 18:24 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) issued a new binding operational directive aimed at reducing a long-standing cyber risk across federal networks: outdated “edge devices” that are not longer supported by vendors and aren’t receiving timely security […]

CISA orders US federal agencies to replace unsupported edge devices Read More »

State-backed phishing attacks targeting military officials and journalists on Signal

State-backed phishing attacks targeting military officials and journalists on Signal 2026-02-06 at 16:53 By Zeljka Zorz German security authorities are warning that a likely state-backed hacking group is engaged in attempts at phishing senior political figures, military officials, diplomats, and investigative journalists across Germany and Europe via Signal. The authorities also noted that while these […]

State-backed phishing attacks targeting military officials and journalists on Signal Read More »

Poland’s energy control systems were breached through exposed VPN access

Poland’s energy control systems were breached through exposed VPN access 2026-02-06 at 16:27 By Sinisa Markovic On 29 December 2025, coordinated cyberattacks unfolded across Poland’s critical infrastructure, targeting energy and industrial organizations. The attackers struck numerous wind and solar farms, a private manufacturing company, and a heat and power (CHP) plant, but failed to negatively […]

Poland’s energy control systems were breached through exposed VPN access Read More »

Ransomware attackers are exploiting critical SmarterMail vulnerability (CVE-2026-24423)

Ransomware attackers are exploiting critical SmarterMail vulnerability (CVE-2026-24423) 2026-02-06 at 13:12 By Zeljka Zorz For the third time in two weeks, CISA added a vulnerability (CVE-2026-24423) affecting SmarterTools’ SmarterMail email and collaboration server to its Known Exploited Vulnerabilities catalog, and this one is being exploited in ransomware attacks. A glut of SmarterMail vulnerabilities On January […]

Ransomware attackers are exploiting critical SmarterMail vulnerability (CVE-2026-24423) Read More »

February 2026 Patch Tuesday forecast: Lots of OOB love this month

February 2026 Patch Tuesday forecast: Lots of OOB love this month 2026-02-06 at 09:54 By Help Net Security Valentine’s Day is just around the corner and Microsoft has been giving us a lot of love with a non-stop supply of patches starting with January 2026 Patch Tuesday. The January releases addressed 92 vulnerabilities in Windows […]

February 2026 Patch Tuesday forecast: Lots of OOB love this month Read More »

Mobile privacy audits are getting harder

Mobile privacy audits are getting harder 2026-02-06 at 09:28 By Anamarija Pogorelec Mobile apps routinely collect and transmit personal data in ways that are difficult for users, developers, and regulators to verify. Permissions can reveal what an app can access, and privacy policies can claim what an app should do, yet neither reliably shows what […]

Mobile privacy audits are getting harder Read More »

The hidden cost of putting off security decisions

The hidden cost of putting off security decisions 2026-02-06 at 08:01 By Help Net Security In this Help Net Security video, Hanah Darley, Chief AI Officer, Geordie AI, talks about how putting off security risk decisions creates long-term costs that often stay hidden. Drawing on her work with CISOs and security leaders, she shows how […]

The hidden cost of putting off security decisions Read More »

CISA confirms exploitation of VMware ESXi flaw by ransomware attackers

CISA confirms exploitation of VMware ESXi flaw by ransomware attackers 2026-02-05 at 18:17 By Zeljka Zorz CVE-2025-22225, a VMware ESXi arbitrary write vulnerability, is being used in ransomware campaigns, CISA confirmed on Wednesday by updating the vulnerability’s entry in its Known Exploited Vulnerabilities (KEV) catalog. Researchers linked VMware ESXi zero-day trio to single exploit toolkit […]

CISA confirms exploitation of VMware ESXi flaw by ransomware attackers Read More »

Why a decade-old EnCase driver still works as an EDR killer

Why a decade-old EnCase driver still works as an EDR killer 2026-02-05 at 14:02 By Zeljka Zorz Attackers are leaning on a new EDR killer malware that can shut down 59 widely used endpoint security products by misusing a kernel driver that once shipped with Guidance Software’s EnCase digital forensics tool, Huntress researchers warn. This […]

Why a decade-old EnCase driver still works as an EDR killer Read More »

Smart glasses are back, privacy issues included

Smart glasses are back, privacy issues included 2026-02-05 at 09:11 By Sinisa Markovic AI smart glasses are the latest addition to fashion, and they include a camera, a microphone, AI, and privacy risks. After Google Glass failed to gain traction more than a decade ago, the category is seeing renewed interest as companies redesign the […]

Smart glasses are back, privacy issues included Read More »

Cybersecurity planning keeps moving toward whole-of-society models

Cybersecurity planning keeps moving toward whole-of-society models 2026-02-05 at 09:11 By Sinisa Markovic National governments already run cybersecurity through a mix of ministries, regulators, law enforcement, and private operators that own most critical systems. In that environment, guidance circulating among policymakers outlines how national cybersecurity strategies increasingly tie together risk management, workforce planning, technology standards, […]

Cybersecurity planning keeps moving toward whole-of-society models Read More »

Scroll to Top