Don’t miss

AI took more than junior developer jobs and the bill comes later

AI took more than junior developer jobs and the bill comes later 2026-07-28 at 08:30 By Sinisa Markovic A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it […]

AI took more than junior developer jobs and the bill comes later Read More »

Download: The High-Performance Team Playbook

Download: The High-Performance Team Playbook 2026-07-28 at 08:00 By Help Net Security Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. Most engineering teams don’t fail because of bad engineers. They fail because performance is assumed. This playbook shows how high-performance teams are built intentionally across people, structure,

Download: The High-Performance Team Playbook Read More »

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) 2026-07-27 at 15:04 By Zeljka Zorz Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) Read More »

The automotive software vulnerabilities hiding in your dashboard

The automotive software vulnerabilities hiding in your dashboard 2026-07-24 at 09:30 By Anamarija Pogorelec Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux.

The automotive software vulnerabilities hiding in your dashboard Read More »

Governing Al agents at scale: Lessons from the leaders who’ve done it

Governing Al agents at scale: Lessons from the leaders who’ve done it 2026-07-24 at 09:00 By Help Net Security Enterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at scale. What you’ll take away: What an AI Center

Governing Al agents at scale: Lessons from the leaders who’ve done it Read More »

How attackers hosted a fake Claude download page on the claude.ai domain

How attackers hosted a fake Claude download page on the claude.ai domain 2026-07-23 at 16:12 By Zeljka Zorz A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app

How attackers hosted a fake Claude download page on the claude.ai domain Read More »

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) 2026-07-23 at 13:42 By Zeljka Zorz Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) Read More »

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process 2026-07-23 at 13:38 By Mirko Zorz Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process Read More »

Shadow AI is becoming enterprise security’s biggest blind spot

Shadow AI is becoming enterprise security’s biggest blind spot 2026-07-23 at 09:00 By Help Net Security Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly every business function. Microsoft’s 2026

Shadow AI is becoming enterprise security’s biggest blind spot Read More »

Product Showcase: AppViewX Agent Identity Security

Product Showcase: AppViewX Agent Identity Security 2026-07-23 at 08:30 By Help Net Security AI is multiplying enterprise identities as quantum computing reshapes the cryptographic trust that secures them, and enterprises need to solve both together. Traditional identity security was built for people with predictable, auditable access, not autonomous, short-lived agents that share credentials and break

Product Showcase: AppViewX Agent Identity Security Read More »

Multi-patch vulnerability fixes can leave open source exposed

Multi-patch vulnerability fixes can leave open source exposed 2026-07-23 at 08:00 By Mirko Zorz Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two

Multi-patch vulnerability fixes can leave open source exposed Read More »

The AI code vulnerabilities that grow with your app

The AI code vulnerabilities that grow with your app 2026-07-23 at 07:30 By Mirko Zorz Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten

The AI code vulnerabilities that grow with your app Read More »

OpenAI: Our models breached Hugging Face during a cyber capability test

OpenAI: Our models breached Hugging Face during a cyber capability test 2026-07-22 at 17:42 By Zeljka Zorz The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share

OpenAI: Our models breached Hugging Face during a cyber capability test Read More »

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) 2026-07-22 at 14:47 By Zeljka Zorz Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code,

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) Read More »

Small teams are the heaviest users of AI coding agents

Small teams are the heaviest users of AI coding agents 2026-07-22 at 09:00 By Sinisa Markovic The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually

Small teams are the heaviest users of AI coding agents Read More »

Snowpick: Open-source ServiceNow exposure scanner

Snowpick: Open-source ServiceNow exposure scanner 2026-07-22 at 08:30 By Mirko Zorz An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances

Snowpick: Open-source ServiceNow exposure scanner Read More »

JadePuffer returns with ransomware built to target AI models and infrastructure

JadePuffer returns with ransomware built to target AI models and infrastructure 2026-07-21 at 16:38 By Zeljka Zorz JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in

JadePuffer returns with ransomware built to target AI models and infrastructure Read More »

Cisco’s open-weight Antares models make vulnerability localization cheaper

Cisco’s open-weight Antares models make vulnerability localization cheaper 2026-07-21 at 16:01 By Mirko Zorz A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands

Cisco’s open-weight Antares models make vulnerability localization cheaper Read More »

SonicWall SMA zero-days were exploited weeks before disclosure

SonicWall SMA zero-days were exploited weeks before disclosure 2026-07-21 at 13:35 By Zeljka Zorz Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22,

SonicWall SMA zero-days were exploited weeks before disclosure Read More »

The air gap is a myth and other OT security truths

The air gap is a myth and other OT security truths 2026-07-21 at 09:00 By Mirko Zorz Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth.

The air gap is a myth and other OT security truths Read More »

Scroll to Top