Don’t miss

Nobody was checking the drives that encrypt your laptop

Nobody was checking the drives that encrypt your laptop 2026-07-21 at 08:30 By Anamarija Pogorelec A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG […]

Nobody was checking the drives that encrypt your laptop Read More »

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) 2026-07-20 at 17:32 By Zeljka Zorz Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) Read More »

Hugging Face breached by autonomous AI agent

Hugging Face breached by autonomous AI agent 2026-07-20 at 13:52 By Zeljka Zorz Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16),

Hugging Face breached by autonomous AI agent Read More »

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform 2026-07-20 at 09:00 By Anamarija Pogorelec Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform Read More »

More alerts are making your team slower, and an outcome-based SOC fixes that

More alerts are making your team slower, and an outcome-based SOC fixes that 2026-07-20 at 08:30 By Help Net Security In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like

More alerts are making your team slower, and an outcome-based SOC fixes that Read More »

A forensic tool for backdoored code completions in AI assistants

A forensic tool for backdoored code completions in AI assistants 2026-07-20 at 08:00 By Sinisa Markovic Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and

A forensic tool for backdoored code completions in AI assistants Read More »

Two new high severity WordPress vulnerabilities, patch immediately!

Two new high severity WordPress vulnerabilities, patch immediately! 2026-07-18 at 17:57 By Help Net Security The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137

Two new high severity WordPress vulnerabilities, patch immediately! Read More »

The script, not the voice, is what makes AI voice phishing work

The script, not the voice, is what makes AI voice phishing work 2026-07-17 at 10:31 By Sinisa Markovic The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry,

The script, not the voice, is what makes AI voice phishing work Read More »

Prompt injection is becoming the XSS of the web agent era

Prompt injection is becoming the XSS of the web agent era 2026-07-17 at 09:00 By Anamarija Pogorelec Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted site menus on a single page. An agent that reads all of that

Prompt injection is becoming the XSS of the web agent era Read More »

The five step plan that cuts security budget waste

The five step plan that cuts security budget waste 2026-07-17 at 08:00 By Help Net Security In this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, and that mismatch is

The five step plan that cuts security budget waste Read More »

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance 2026-07-16 at 16:23 By Zeljka Zorz On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance Read More »

Romania’s land registry hit by cyber attack, data allegedly for sale

Romania’s land registry hit by cyber attack, data allegedly for sale 2026-07-16 at 13:21 By Zeljka Zorz Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical

Romania’s land registry hit by cyber attack, data allegedly for sale Read More »

Reading between the lines of a cyber insurance policy

Reading between the lines of a cyber insurance policy 2026-07-16 at 09:00 By Mirko Zorz Enterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024. Coverage has become widespread. Payouts have

Reading between the lines of a cyber insurance policy Read More »

What public money does to open-source projects

What public money does to open-source projects 2026-07-16 at 08:30 By Mirko Zorz Most of the software running inside a typical company was written by volunteers the company never paid. Open-source code sits under web apps, build pipelines, and the machine learning stacks getting so much attention right now. Roughly 96 percent of codebases carry

What public money does to open-source projects Read More »

Ransom demands are down, email is the top way attackers get in

Ransom demands are down, email is the top way attackers get in 2026-07-16 at 08:00 By Mirko Zorz An employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later.

Ransom demands are down, email is the top way attackers get in Read More »

Companies keep getting breached by vulnerabilities they already knew about

Companies keep getting breached by vulnerabilities they already knew about 2026-07-16 at 07:30 By Mirko Zorz Scanning tools have gotten good at their work. Organizations now find more weaknesses across more of their systems than at any earlier point in the industry’s history. A survey from the security firm Vicarius points to a gap that

Companies keep getting breached by vulnerabilities they already knew about Read More »

GPT-Red beat human red teamers on a prompt injection test

GPT-Red beat human red teamers on a prompt injection test 2026-07-16 at 06:49 By Mirko Zorz GPT-Red is an automated red-teaming model that OpenAI trains to find prompt injection weaknesses. It works the way a human red-teamer does. It sends a prompt, watches how a GPT model responds, and iterates toward a goal such as

GPT-Red beat human red teamers on a prompt injection test Read More »

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware 2026-07-15 at 16:52 By Zeljka Zorz A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling,

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware Read More »

SingGuard-NSFA: Open-source guardrails for agentic AI

SingGuard-NSFA: Open-source guardrails for agentic AI 2026-07-15 at 08:30 By Anamarija Pogorelec SingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones. Risk taxonomy The NSFA risk taxonomy organizes threats along the CIA triad of confidentiality,

SingGuard-NSFA: Open-source guardrails for agentic AI Read More »

The MDR renewal question: What changes when AI can handle the alerts

The MDR renewal question: What changes when AI can handle the alerts 2026-07-15 at 08:00 By Help Net Security For most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a

The MDR renewal question: What changes when AI can handle the alerts Read More »

Scroll to Top