Expert analysis

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results 2026-09-09 at 08:00 By Help Net Security In the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment […]

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results Read More »

What breach and attack simulation needs to become in the AI era

What breach and attack simulation needs to become in the AI era 2026-09-09 at 07:30 By Help Net Security Breach and attack simulation (BAS) has always had a supply chain. Somebody has to read the threat report, pull out the techniques, and turn them into something that will actually run against your controls. That somebody […]

What breach and attack simulation needs to become in the AI era Read More »

September 2026 Patch Tuesday forecast: All we need is more time

September 2026 Patch Tuesday forecast: All we need is more time 2026-09-04 at 09:00 By Help Net Security The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs: […]

September 2026 Patch Tuesday forecast: All we need is more time Read More »

Your threat feed is someone else’s database: What ingesting malware intel at scale takes

Your threat feed is someone else’s database: What ingesting malware intel at scale takes 2026-09-03 at 08:30 By Help Net Security The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is […]

Your threat feed is someone else’s database: What ingesting malware intel at scale takes Read More »

NIS2 compliance: Fixing IAM and access control before the 2026 audit

NIS2 compliance: Fixing IAM and access control before the 2026 audit 2026-09-01 at 08:00 By Help Net Security The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into […]

NIS2 compliance: Fixing IAM and access control before the 2026 audit Read More »

Who will be the Stanislav Petrov in your organization?

Who will be the Stanislav Petrov in your organization? 2026-08-11 at 09:00 By Help Net Security The recent news coverage of “rogue AI” systems hacking innocent companies reminded me of one of the world’s most unsung heroes and genuinely someone who may well have saved the world. In 1983, the USSR’s early warning systems reported […]

Who will be the Stanislav Petrov in your organization? Read More »

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? 2026-08-07 at 09:00 By Help Net Security July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs […]

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? Read More »

Shadow AI is becoming enterprise security’s biggest blind spot

Shadow AI is becoming enterprise security’s biggest blind spot 2026-07-23 at 09:00 By Help Net Security Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly every business function. Microsoft’s 2026 […]

Shadow AI is becoming enterprise security’s biggest blind spot Read More »

The MDR renewal question: What changes when AI can handle the alerts

The MDR renewal question: What changes when AI can handle the alerts 2026-07-15 at 08:00 By Help Net Security For most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a […]

The MDR renewal question: What changes when AI can handle the alerts Read More »

Why SBOMs, signing, and provenance still don’t tell you if software is safe

Why SBOMs, signing, and provenance still don’t tell you if software is safe 2026-07-13 at 09:30 By Help Net Security We have made real progress in software supply chain security, improving visibility into software components, authenticity and build integrity. Much of this progress traces back to Executive Order 14028, which pushed agencies, contractors and enterprises […]

Why SBOMs, signing, and provenance still don’t tell you if software is safe Read More »

July 2026 Patch Tuesday forecast: Is CVE tracking still practical?

July 2026 Patch Tuesday forecast: Is CVE tracking still practical? 2026-07-10 at 10:30 By Help Net Security I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 […]

July 2026 Patch Tuesday forecast: Is CVE tracking still practical? Read More »

How to implement a continuous offensive security testing program

How to implement a continuous offensive security testing program 2026-07-08 at 07:30 By Help Net Security The hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still hold tomorrow. A penetration test answers this question for […]

How to implement a continuous offensive security testing program Read More »

How to prioritize AI agent security by business impact

How to prioritize AI agent security by business impact 2026-07-06 at 09:30 By Help Net Security Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected […]

How to prioritize AI agent security by business impact Read More »

What a financial planner taught me about cybersecurity

What a financial planner taught me about cybersecurity 2026-07-01 at 09:30 By Help Net Security When I spoke at a recent cybersecurity awareness event for financial planners and tax advisors, the audience really engaged with the subject. As happens at conferences the world over, people often come up to speakers to ask follow-up questions, or […]

What a financial planner taught me about cybersecurity Read More »

EU Cybersecurity Act 2.0: When good regulation goes bad

EU Cybersecurity Act 2.0: When good regulation goes bad 2026-06-16 at 08:30 By Help Net Security Over recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But good intentions and good policy […]

EU Cybersecurity Act 2.0: When good regulation goes bad Read More »

How to use NIST and ISO frameworks to govern AI agents

How to use NIST and ISO frameworks to govern AI agents 2026-06-12 at 11:07 By Help Net Security Security leaders no longer need convincing that AI agents introduce risk. What’s missing is how to govern them once they move into production and begin operating autonomously across enterprise environments. AI agents already read sensitive documents, invoke […]

How to use NIST and ISO frameworks to govern AI agents Read More »

The architecture of subtraction: Why it’s time to erase the roads, not just map the traffic

The architecture of subtraction: Why it’s time to erase the roads, not just map the traffic 2026-06-09 at 09:42 By Help Net Security The advent of AI-assisted vulnerability discovery and autonomous exploit development has brought about a new age in cybersecurity—one in which we can no longer rely on patching as a primary defense mechanism. […]

The architecture of subtraction: Why it’s time to erase the roads, not just map the traffic Read More »

June 2026 Patch Tuesday forecast: Where are the CVEs?

June 2026 Patch Tuesday forecast: Where are the CVEs? 2026-06-05 at 10:16 By Help Net Security My forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in […]

June 2026 Patch Tuesday forecast: Where are the CVEs? Read More »

The modern-day business can learn a lot about risk from this year’s mega events

The modern-day business can learn a lot about risk from this year’s mega events 2026-06-04 at 13:17 By Help Net Security Every year brings its share of global events, but 2026 is proving to be a banner year for mega-scale entertainment. The year got off to a roaring start with the Winter Olympics, and now […]

The modern-day business can learn a lot about risk from this year’s mega events Read More »

Attackers already know the secrets are on your developers’ machines. Do you?

Attackers already know the secrets are on your developers’ machines. Do you? 2026-06-04 at 09:26 By Help Net Security In a recent GitGuardian analysis, an average of 150 secrets were found on a sample of developer endpoints. Private keys accounted for 38% of unique secrets, while cloud, identity provider, and secret management credentials (AWS IAM, […]

Attackers already know the secrets are on your developers’ machines. Do you? Read More »

Scroll to Top