Don’t miss

Pharma’s most underestimated cyber risk isn’t a breach

Pharma’s most underestimated cyber risk isn’t a breach 2026-01-05 at 08:47 By Mirko Zorz Chirag Shah, Global Information Security Officer & DPO at Model N examines how cyber risk in pharma and life sciences is shifting beyond traditional breaches toward data misuse, AI-driven exposure and regulatory pressure. He explains why executives still underestimate silent control […]

Pharma’s most underestimated cyber risk isn’t a breach Read More »

AI security risks are also cultural and developmental

AI security risks are also cultural and developmental 2026-01-05 at 08:32 By Anamarija Pogorelec Security teams spend much of their time tracking vulnerabilities, abuse patterns, and system failures. A new study argues that many AI risks sit deeper than technical flaws. Cultural assumptions, uneven development, and data gaps shape how AI systems behave, where they

AI security risks are also cultural and developmental Read More »

OpenAEV: Open-source adversarial exposure validation platform

OpenAEV: Open-source adversarial exposure validation platform 2026-01-05 at 08:02 By Sinisa Markovic OpenAEV is an open source platform designed to plan, run, and review cyber adversary simulation campaigns used by security teams. The project focuses on organizing exercises that blend technical actions with operational and human response elements, all managed through a single system. Scenarios

OpenAEV: Open-source adversarial exposure validation platform Read More »

Understanding AI insider risk before it becomes a problem

Understanding AI insider risk before it becomes a problem 2026-01-05 at 07:31 By Help Net Security In this Help Net Security video, Greg Pollock, Head of Research and Insights at UpGuard, discusses AI use inside organizations and the risks tied to insiders. He explains two problems. One involves employees who use AI tools to speed

Understanding AI insider risk before it becomes a problem Read More »

What shadow AI means for SaaS security and integrations

What shadow AI means for SaaS security and integrations 2026-01-02 at 08:30 By Help Net Security In this Help Net Security video, Jaime Blasco, CTO at Nudge Security, discusses why shadow AI matters to security teams. He describes how AI adoption happens in two ways, through company led programs and through employees choosing tools on

What shadow AI means for SaaS security and integrations Read More »

Duplicati: Free, open-source backup client

Duplicati: Free, open-source backup client 2025-12-31 at 09:29 By Sinisa Markovic Duplicati is an open source backup client that creates encrypted, incremental, compressed backup sets and sends them to cloud storage services or remote file servers. What the project is and where it runs Duplicati operates as a client side application designed to back up

Duplicati: Free, open-source backup client Read More »

Radio signals could give attackers a foothold inside air-gapped devices

Radio signals could give attackers a foothold inside air-gapped devices 2025-12-30 at 09:25 By Sinisa Markovic Air-gapped systems are meant to stay quiet. Remove network ports, lock down inputs, and the device should have nothing to hear. A new study shows that this breaks down when software control is lost. Embedded devices with no radios

Radio signals could give attackers a foothold inside air-gapped devices Read More »

Product showcase: RoboForm password manager for iOS

Product showcase: RoboForm password manager for iOS 2025-12-30 at 08:41 By Anamarija Pogorelec RoboForm is a password manager that helps users store and manage login credentials, identities, and other sensitive information in one place. The app is available on macOS, Windows, Android, and iOS. It uses AES-256-bit encryption and a master password to protect stored

Product showcase: RoboForm password manager for iOS Read More »

LLMs are automating the human part of romance scams

LLMs are automating the human part of romance scams 2025-12-29 at 09:03 By Sinisa Markovic Romance scams succeed because they feel human. New research shows that feeling no longer requires a person on the other side of the chat. The three stages of a romance-baiting scam Romance scams depend on scripted conversation Romance baiting scams

LLMs are automating the human part of romance scams Read More »

Superagent: Open-source framework for guardrails around agentic AI

Superagent: Open-source framework for guardrails around agentic AI 2025-12-29 at 09:03 By Sinisa Markovic Superagent is an open-source framework for building, running, and controlling AI agents with safety built into the workflow. The project focuses on giving developers and security teams tools to manage what agents can do, what they can access, and how they

Superagent: Open-source framework for guardrails around agentic AI Read More »

Security chaos engineering matters when nothing is broken

Security chaos engineering matters when nothing is broken 2025-12-29 at 08:00 By Help Net Security In this Help Net Security video, Brian Blakley, CISO at Bellini Capital, explains why security chaos engineering matters beyond theory. He shares lessons from real organizations where systems did not fail outright, but uncertainty slowed the business. Login delays, certificate

Security chaos engineering matters when nothing is broken Read More »

Five identity-driven shifts reshaping enterprise security in 2026

Five identity-driven shifts reshaping enterprise security in 2026 2025-12-24 at 11:18 By Help Net Security 2026 marks the tipping point when artificial intelligence begins to fundamentally reshape cyber risk. After several years of widespread adoption, AI moves beyond influencing how we work and starts transforming the enterprise itself. AI is now embedded at every layer

Five identity-driven shifts reshaping enterprise security in 2026 Read More »

What if your face could say “don’t record me”? Researchers think it’s possible

What if your face could say “don’t record me”? Researchers think it’s possible 2025-12-24 at 10:01 By Sinisa Markovic Phones, smart glasses, and other camera-equipped devices capture scenes that include people who never agreed to be recorded. A newly published study examines what it would take for bystanders to signal their privacy choices directly to

What if your face could say “don’t record me”? Researchers think it’s possible Read More »

Conjur: Open-source secrets management and application identity

Conjur: Open-source secrets management and application identity 2025-12-24 at 08:34 By Sinisa Markovic Conjur is an open-source secrets management project designed for environments built around containers, automation, and dynamic infrastructure. It focuses on controlling access to credentials such as database passwords, API keys, and tokens that applications need at runtime. The project is maintained in

Conjur: Open-source secrets management and application identity Read More »

Counterfeit defenses built on paper have blind spots

Counterfeit defenses built on paper have blind spots 2025-12-24 at 08:17 By Anamarija Pogorelec Counterfeit protection often leans on the idea that physical materials have quirks no attacker can copy. A new study challenges that comfort by showing how systems built on paper surface fingerprints can be disrupted or bypassed. The research comes from teams

Counterfeit defenses built on paper have blind spots Read More »

Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits

Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits 2025-12-23 at 14:47 By Zeljka Zorz Malware peddlers are targeting infosec enthusiasts, budding security professionals, and aspiring hackers with the Webrat malware, masquerading the threat as proof-of-concept (PoC) exploits for known vulnerabilities. Delivering the malware The recently uncovered Webrat can steal data from

Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits Read More »

Formal proofs expose long standing cracks in DNSSEC

Formal proofs expose long standing cracks in DNSSEC 2025-12-23 at 09:41 By Sinisa Markovic DNSSEC is meant to stop attackers from tampering with DNS answers. It signs records so resolvers can verify that data is authentic and unchanged. Many security teams assume that if DNSSEC validation passes, the answer can be trusted. New academic research

Formal proofs expose long standing cracks in DNSSEC Read More »

Weak enforcement keeps PCI DSS compliance low

Weak enforcement keeps PCI DSS compliance low 2025-12-23 at 09:41 By Sinisa Markovic Payment card breaches continue to surface across industries, even after years of investment in security standards. A new study links this pattern to enforcement, showing that PCI DSS compliance trails behind HIPAA, GDPR, and the EU’s NIS2 Directive. A compliance gap that

Weak enforcement keeps PCI DSS compliance low Read More »

Docker makes hardened images free open and transparent for everyone

Docker makes hardened images free open and transparent for everyone 2025-12-22 at 15:09 By Sinisa Markovic Docker has made its open source Docker Hardened Images project available at no cost for every developer and organization. The catalog contains more than 1,000 container images built on open source distributions such as Debian and Alpine and is

Docker makes hardened images free open and transparent for everyone Read More »

574 arrests, $3 million recovered in Africa-wide cybercrime crackdown

574 arrests, $3 million recovered in Africa-wide cybercrime crackdown 2025-12-22 at 15:09 By Anamarija Pogorelec Law enforcement agencies across 19 countries arrested 574 suspects and recovered approximately $3 million during a major cybercrime operation spanning Africa. Suspects were arrested in Ghana in connection to the cyber-fraud case, with over 100 digital devices seized. (Source: Europol)

574 arrests, $3 million recovered in Africa-wide cybercrime crackdown Read More »

Scroll to Top