Don’t miss

The endpoint recovery gap many teams discover during an incident

The endpoint recovery gap many teams discover during an incident 2026-07-02 at 09:00 By Mirko Zorz In this interview with Help Net Security, IGEL CTO Matthias Haas explains why backups alone do not equal recovery. He makes the case that endpoint recovery is often overlooked, leaving organizations exposed when thousands of devices go down at […]

The endpoint recovery gap many teams discover during an incident Read More »

Catching ransomware on the wire before it locks the file server

Catching ransomware on the wire before it locks the file server 2026-07-02 at 08:00 By Sinisa Markovic Corporate networks keep sensitive files off individual workstations and store them on shared servers that staff reach through mapped network drives. That arrangement hands ransomware operators a target worth chasing. A single compromised laptop can begin encrypting files

Catching ransomware on the wire before it locks the file server Read More »

The ARToken phishing panel targets Microsoft 365 accounts

The ARToken phishing panel targets Microsoft 365 accounts 2026-07-01 at 13:00 By Sinisa Markovic Accounts-payable staff at U.S. companies keep receiving invoice emails that look like they come from vendors they already work with. One landed at a life-sciences company in April 2026, addressed to the person who handles payments and written in the voice

The ARToken phishing panel targets Microsoft 365 accounts Read More »

What a financial planner taught me about cybersecurity

What a financial planner taught me about cybersecurity 2026-07-01 at 09:30 By Help Net Security When I spoke at a recent cybersecurity awareness event for financial planners and tax advisors, the audience really engaged with the subject. As happens at conferences the world over, people often come up to speakers to ask follow-up questions, or

What a financial planner taught me about cybersecurity Read More »

Nika: Open-source code analysis tool

Nika: Open-source code analysis tool 2026-07-01 at 09:00 By Mirko Zorz Many serious security bugs in web applications sit across several files at once. Request data enters through a controller, moves through data objects and service layers, and turns dangerous only when it reaches a sensitive operation such as a database query or a file

Nika: Open-source code analysis tool Read More »

This supercomputer encrypts your data even while it’s running it

This supercomputer encrypts your data even while it’s running it 2026-07-01 at 08:30 By Sinisa Markovic Most people who handle sensitive data already encrypt it in two places. They lock it down when it sits on a hard drive, and they lock it down when it moves across a network. There has always been a

This supercomputer encrypts your data even while it’s running it Read More »

AI-generated code risks reach security, legal, and compliance teams

AI-generated code risks reach security, legal, and compliance teams 2026-07-01 at 08:00 By Mirko Zorz Most engineering organizations write code with AI, and a good number of them keep that code away from customers. A Flux survey of engineering leaders and practitioners found that nearly half run AI-generated code in production. Almost every company in

AI-generated code risks reach security, legal, and compliance teams Read More »

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) 2026-06-30 at 16:58 By Zeljka Zorz Exploitation attempts targeting a critical vulnerability (CVE-2026-46817) in Oracle Payments, the payment-processing module within Oracle’s E-Business Suite (EBS), have been spotted over the weekend, threat intelligence company Defused warned on Monday. The detected exploitation attempts (Source: Defused) “On 27 June 2026

Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) Read More »

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) 2026-06-30 at 13:25 By Zeljka Zorz Attackers are exploiting CVE-2026-48558, a recently patched authentication bypass vulnerability in SimpleHelp RMM, to drop the novel Djinn Stealer malware on victim computers. The malware is capable of targeting Windows, macOS, and Linux systems, and “collects credentials associated with cloud

SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) Read More »

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin 2026-06-30 at 09:15 By Mirko Zorz Phones and laptops ship with a feature that sends files to nearby devices over the air, with no cables, accounts, or prior pairing. Apple calls its version AirDrop. Google and Samsung call theirs Quick Share.

AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin Read More »

Vulnerability reports are arriving faster than GitHub can review them

Vulnerability reports are arriving faster than GitHub can review them 2026-06-30 at 08:25 By Anamarija Pogorelec Across the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub Advisory Database, which feeds automated security alerts to millions of projects,

Vulnerability reports are arriving faster than GitHub can review them Read More »

JSP webshells being dropped on unpatched PTC Windchill instances

JSP webshells being dropped on unpatched PTC Windchill instances 2026-06-29 at 19:18 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog don’t contain links

JSP webshells being dropped on unpatched PTC Windchill instances Read More »

Mozilla warns of indirect prompt injection risk in AI coding agents

Mozilla warns of indirect prompt injection risk in AI coding agents 2026-06-29 at 13:48 By Zeljka Zorz A malicious GitHub repository can silently compromise a developer’s machine without containing a single line of malicious code, security researchers at Mozilla’s Zero Day Investigative Network (0DIN) warned. The attack The proof-of-concept attack targets AI-powered coding agents such

Mozilla warns of indirect prompt injection risk in AI coding agents Read More »

DarkMoon: Open-source AI pentesting platform

DarkMoon: Open-source AI pentesting platform 2026-06-29 at 08:30 By Mirko Zorz Penetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert consultants run into thousands of dollars a day, and results vary with the tester. Automation promises to narrow

DarkMoon: Open-source AI pentesting platform Read More »

Sycophantic chatbots and the harms that build over many chats

Sycophantic chatbots and the harms that build over many chats 2026-06-29 at 08:00 By Sinisa Markovic People use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional

Sycophantic chatbots and the harms that build over many chats Read More »

Companies keep bolting AI onto their products, and the security bill is coming due

Companies keep bolting AI onto their products, and the security bill is coming due 2026-06-29 at 07:30 By Mirko Zorz Companies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern. The vulnerabilities those features create get rated high risk far more often than anything else,

Companies keep bolting AI onto their products, and the security bill is coming due Read More »

Synology issues critical fix for MailPlus Server vulnerabilities

Synology issues critical fix for MailPlus Server vulnerabilities 2026-06-26 at 13:57 By Zeljka Zorz Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or

Synology issues critical fix for MailPlus Server vulnerabilities Read More »

Mystery hackers use novel SharkLoader dropper against governments, software devs

Mystery hackers use novel SharkLoader dropper against governments, software devs 2026-06-26 at 12:13 By Zeljka Zorz Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization in Indonesia. What initially

Mystery hackers use novel SharkLoader dropper against governments, software devs Read More »

A privacy-first take on local malware analysis

A privacy-first take on local malware analysis 2026-06-26 at 09:00 By Sinisa Markovic Submitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these services to get a quick verdict on whether a binary is dangerous. The convenience

A privacy-first take on local malware analysis Read More »

Scroll to Top