Don’t miss

New observational auditing framework takes aim at machine learning privacy leaks

New observational auditing framework takes aim at machine learning privacy leaks 2025-11-28 at 08:34 By Sinisa Markovic Machine learning (ML) privacy concerns continue to surface, as audits show that models can reveal parts of the labels (the user’s choice, expressed preference, or the result of an action) used during training. A new research paper explores […]

New observational auditing framework takes aim at machine learning privacy leaks Read More »

Why password management defines PCI DSS success

Why password management defines PCI DSS success 2025-11-28 at 08:03 By Sinisa Markovic Most CISOs spend their days dealing with noisy dashboards and vendor pitches that all promise a shortcut to compliance. It can be overwhelming to sort out what matters. When you dig into real incidents involving payment data, a surprising number come down to

Why password management defines PCI DSS success Read More »

Hottest cybersecurity open-source tools of the month: November 2025

Hottest cybersecurity open-source tools of the month: November 2025 2025-11-27 at 09:00 By Anamarija Pogorelec This month’s roundup features exceptional open-source cybersecurity tools that are gaining attention for strengthening security across various environments. Heisenberg: Open-source software supply chain health check tool Heisenberg is an open-source tool that checks the health of a software supply chain.

Hottest cybersecurity open-source tools of the month: November 2025 Read More »

Gainsight breach: Salesforce details attack window, issues investigation guidance

Gainsight breach: Salesforce details attack window, issues investigation guidance 2025-11-26 at 16:30 By Zeljka Zorz The number of Salesforce customers affected by the recent compromise of Gainsight-published applications is yet to be publicly confirmed, but Salesforce released indicators of compromise (IoCs) and simultaneously shed some light on when the attack likely started. The provided list

Gainsight breach: Salesforce details attack window, issues investigation guidance Read More »

New “HashJack” attack can hijack AI browsers and assistants

New “HashJack” attack can hijack AI browsers and assistants 2025-11-26 at 14:18 By Zeljka Zorz Security researchers at Cato Networks have uncovered a new indirect prompt injection technique that can force popular AI browsers and assistants to deliver phishing links or disinformation (e.g., incorrect medicine dosage guidance or investment advice), send sensitive data to the

New “HashJack” attack can hijack AI browsers and assistants Read More »

Heineken CISO champions a new risk mindset to unlock innovation

Heineken CISO champions a new risk mindset to unlock innovation 2025-11-26 at 09:16 By Mirko Zorz In this Help Net Security interview, Marina Marceta, CISO at Heineken, discusses what it takes for CISOs to be seen as business-aligned leaders rather than technical overseers. She shares how connecting security to business impact can shift perceptions and

Heineken CISO champions a new risk mindset to unlock innovation Read More »

Small language models step into the fight against phishing sites

Small language models step into the fight against phishing sites 2025-11-26 at 08:31 By Sinisa Markovic Phishing sites keep rising, and security teams are searching for ways to sort suspicious pages at speed. A recent study explores whether small language models (SLMs) can scan raw HTML to catch these threats. The work reviews a range

Small language models step into the fight against phishing sites Read More »

Black Friday 2025 for InfoSec: How to spot real value and avoid the noise

Black Friday 2025 for InfoSec: How to spot real value and avoid the noise 2025-11-26 at 08:09 By Help Net Security Your inbox is probably drowning in Black Friday emails right now. Another “limited time offer” that’ll reappear next month, countdown timer creating artificial urgency. You’re right to be skeptical — most of it is

Black Friday 2025 for InfoSec: How to spot real value and avoid the noise Read More »

DeepTeam: Open-source LLM red teaming framework

DeepTeam: Open-source LLM red teaming framework 2025-11-26 at 07:37 By Sinisa Markovic Security teams are pushing large language models into products faster than they can test them, which makes any new red teaming method worth paying attention to. DeepTeam is an open-source framework built to probe these systems before they reach users, and it takes

DeepTeam: Open-source LLM red teaming framework Read More »

How board members think about cyber risk and what CISOs should tell them

How board members think about cyber risk and what CISOs should tell them 2025-11-26 at 07:11 By Help Net Security In this Help Net Security video, Jonathan Trull, EVP & CISO at Qualys, discusses which cybersecurity metrics matter most to a board of directors. Drawing on more than two decades in the field, he explains

How board members think about cyber risk and what CISOs should tell them Read More »

Popular code formatting sites are exposing credentials and other secrets

Popular code formatting sites are exposing credentials and other secrets 2025-11-25 at 19:02 By Zeljka Zorz Widely used code formatting sites JSONFormatter and CodeBeautify are exposing sensitive credentials, API keys, private keys, configuration files and other secrets, watchTowr researchers discovered. The findings JSONFormatter and CodeBeautify are free, web-based tools/services used by developers to make messy

Popular code formatting sites are exposing credentials and other secrets Read More »

Fake “Windows Update” screens fuels new wave of ClickFix attacks

Fake “Windows Update” screens fuels new wave of ClickFix attacks 2025-11-25 at 15:02 By Zeljka Zorz A convincing (but fake) “Windows Update” screen can be the perfect lure for tricking users into infecting their computers with malware. Add a multi-stage delivery chain with some offbeat techniques, and infostealer operators have everything they need to slip

Fake “Windows Update” screens fuels new wave of ClickFix attacks Read More »

How an AI meltdown could reset enterprise expectations

How an AI meltdown could reset enterprise expectations 2025-11-25 at 09:02 By Mirko Zorz In this Help Net Security interview, Graham McMillan, CTO at Redgate Software, discusses AI, security, and the future of enterprise oversight. He explains why past incidents haven’t pushed the industry to mature. McMillan also outlines the structural shifts he expects once

How an AI meltdown could reset enterprise expectations Read More »

The breaches everyone gets hit by (and how to stop them)

The breaches everyone gets hit by (and how to stop them) 2025-11-25 at 08:11 By Help Net Security Headlines scream about zero-days and nation-state attacks, but the reality is far less glamorous. Ross Haleliuk, from Venture in Security talks about the concept of humans being wired to overweight rare, dramatic events and underweight the everyday

The breaches everyone gets hit by (and how to stop them) Read More »

Black Friday 2025 cybersecurity deals to explore

Black Friday 2025 cybersecurity deals to explore 2025-11-24 at 15:30 By Help Net Security Black Friday 2025 is shaping up to be a good moment for anyone thinking about tightening their cybersecurity. A few solid deals are popping up that make it easier to improve protection for systems and data without stretching your budget. If

Black Friday 2025 cybersecurity deals to explore Read More »

Quantum encryption is pushing satellite hardware to its limits

Quantum encryption is pushing satellite hardware to its limits 2025-11-24 at 09:11 By Mirko Zorz In this Help Net Security interview, Colonel Ludovic Monnerat, Commander Space Command, Swiss Armed Forces, discusses how securing space assets is advancing in response to emerging quantum threats. He explains why satellite systems must move beyond traditional cryptography to remain

Quantum encryption is pushing satellite hardware to its limits Read More »

cnspec: Open-source, cloud-native security and policy project

cnspec: Open-source, cloud-native security and policy project 2025-11-24 at 08:32 By Sinisa Markovic cnspec is an open source tool that helps when you are trying to keep a sprawling setup of clouds, containers, APIs and endpoints under control. It checks security and compliance across all of it, which makes it easier to see what needs

cnspec: Open-source, cloud-native security and policy project Read More »

The privacy tension driving the medical data shift nobody wants to talk about

The privacy tension driving the medical data shift nobody wants to talk about 2025-11-24 at 08:02 By Anamarija Pogorelec Most people assume their medical data sits in quiet storage, protected by familiar rules. That belief gives a sense of safety, but new research argues that the world around healthcare data has changed faster than the

The privacy tension driving the medical data shift nobody wants to talk about Read More »

Salesforce Gainsight compromise: Early findings and customer guidance

Salesforce Gainsight compromise: Early findings and customer guidance 2025-11-21 at 14:16 By Zeljka Zorz In the wake of Salesforce’s announcement about “unusual activity involving Gainsight-published applications” and the company’s revocation of access and refresh tokens associated with them, Gainsight has been doing a good job keeping customers updated on current investigation findings. On the status

Salesforce Gainsight compromise: Early findings and customer guidance Read More »

Scroll to Top