Expert analysis

From critical to controlled: Cutting vulnerabilities in a live manufacturing environment

From critical to controlled: Cutting vulnerabilities in a live manufacturing environment 2026-06-04 at 09:26 By Help Net Security A vulnerability scanner flags a critical CVSS 10 vulnerability on an industrial asset. The report lands in the boss’ inbox and now he wants to know why we’re sitting on a critical vulnerability. In a normal IT […]

From critical to controlled: Cutting vulnerabilities in a live manufacturing environment Read More »

Why you need BAS and autonomous pentesting together

Why you need BAS and autonomous pentesting together 2026-06-02 at 09:09 By Help Net Security Most security teams know the drill: A new autonomous penetration testing tool gets deployed, and the first run is genuinely impressive. The dashboard surfaces critical findings, maps lateral movement paths nobody had documented before, and exposes a legacy service account […]

Why you need BAS and autonomous pentesting together Read More »

Manage machine identities: The hidden privileged access layer you need to manage

Manage machine identities: The hidden privileged access layer you need to manage 2026-05-26 at 08:37 By Help Net Security Why are machine identities becoming the majority of “things with access”? Every automation, integration, and workload needs a way to authenticate and the right permissions to act. That quiet requirement has created a massive population of […]

Manage machine identities: The hidden privileged access layer you need to manage Read More »

Lessons for organizations from the Verizon 2026 Data Breach Investigations Report

Lessons for organizations from the Verizon 2026 Data Breach Investigations Report 2026-05-25 at 08:59 By Help Net Security This is my favourite time of the year, not just because spring is here and the promise of summer is on the way. But also, because one of my must reads each year gets published. There are […]

Lessons for organizations from the Verizon 2026 Data Breach Investigations Report Read More »

7 hard truths security pros should know: 2026 DevOps Threats Report

7 hard truths security pros should know: 2026 DevOps Threats Report 2026-05-20 at 09:34 By Help Net Security In 2025, trusted Git hosting platforms became a playground for cyber criminals. This is the main conclusion from the latest “DevOps Threat Unwrapped Report 2026” by GitProtect. If you want to effectively counter attacks targeted at your […]

7 hard truths security pros should know: 2026 DevOps Threats Report Read More »

Your IAM was built for humans, AI agents don’t care

Your IAM was built for humans, AI agents don’t care 2026-04-27 at 11:18 By Help Net Security Identity and access management was built for a simpler world. One where the hardest problem was a human logging in, and where “Who are you?” was sufficient to decide what someone could do. That model served enterprises well […]

Your IAM was built for humans, AI agents don’t care Read More »

What the EU AI Act requires for AI agent logging

What the EU AI Act requires for AI agent logging 2026-04-16 at 09:02 By Help Net Security The EU AI Act is 144 pages long. The logging requirements that matter for AI agent developers sit across four articles that keep referencing each other. Here’s what they say, when the deadlines hit, and where the gaps […]

What the EU AI Act requires for AI agent logging Read More »

29 million leaked secrets in 2025: Why AI agents credentials are out of control

29 million leaked secrets in 2025: Why AI agents credentials are out of control 2026-04-14 at 08:11 By Help Net Security AI agents need credentials to work. They authenticate with LLM platforms, connect to databases, call SaaS APIs, access cloud resources, and orchestrate across dozens of external services. Every integration point requires an identity. Most […]

29 million leaked secrets in 2025: Why AI agents credentials are out of control Read More »

April 2026 Patch Tuesday forecast: Spring-cleaning of a preview

April 2026 Patch Tuesday forecast: Spring-cleaning of a preview 2026-04-10 at 10:37 By Help Net Security I just blinked and the first quarter of the year is GONE. Where does the time go? I looked back at my article from last month where I touched on the use of AI and some of the vulnerabilities […]

April 2026 Patch Tuesday forecast: Spring-cleaning of a preview Read More »

Why I’m done calling humans the weakest link

Why I’m done calling humans the weakest link 2026-03-31 at 11:22 By Help Net Security Cybersecurity has long suffered from a people problem, but not in the way we often hear about. As industry that is based on enabling communication across the globe via the internet and many types of devices, many of us practitioners […]

Why I’m done calling humans the weakest link Read More »

Why risk alone doesn’t get you to yes

Why risk alone doesn’t get you to yes 2026-03-30 at 09:29 By Help Net Security I have been in security rooms for years, from military operations centers to corporate boardrooms. In all those years I can tell you that the hardest mission that most security leaders will face is not identifying a threat, but getting […]

Why risk alone doesn’t get you to yes Read More »

Does Anthropic deserve the trust of the cybersecurity community?

Does Anthropic deserve the trust of the cybersecurity community? 2026-03-12 at 08:35 By Help Net Security The cybersecurity industry runs on trust. The belief that when a vendor says they will behave a certain way, they will, that critical CVEs are in fact critical, or when companies say they’re GDPR compliant, they really are. But […]

Does Anthropic deserve the trust of the cybersecurity community? Read More »

March 2026 Patch Tuesday forecast: Is AI security an oxymoron?

March 2026 Patch Tuesday forecast: Is AI security an oxymoron? 2026-03-06 at 10:47 By Help Net Security Developers and analysts are using more AI tools to produce code and to test both the performance and security of the finished products. They are also embedding AI functionality in their products directly. But just how secure are […]

March 2026 Patch Tuesday forecast: Is AI security an oxymoron? Read More »

February 2026 Patch Tuesday forecast: Lots of OOB love this month

February 2026 Patch Tuesday forecast: Lots of OOB love this month 2026-02-06 at 09:54 By Help Net Security Valentine’s Day is just around the corner and Microsoft has been giving us a lot of love with a non-stop supply of patches starting with January 2026 Patch Tuesday. The January releases addressed 92 vulnerabilities in Windows […]

February 2026 Patch Tuesday forecast: Lots of OOB love this month Read More »

Open-source AI pentesting tools are getting uncomfortably good

Open-source AI pentesting tools are getting uncomfortably good 2026-02-02 at 09:10 By Help Net Security AI has come a long way in the pentesting world. We are now seeing open-source tools that can genuinely mimic how a human tester works, not just fire off scans. I dug into three of them, BugTrace-AI, Shannon, and CAI, […]

Open-source AI pentesting tools are getting uncomfortably good Read More »

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever 2026-01-21 at 07:34 By Help Net Security Penetration testing has evolved significantly over the past several years. While uncovering exploitable vulnerabilities remains the core goal, the real differentiator today is how findings are handled after the testing concludes. The method of reporting, […]

The 2026 State of Pentesting: Why delivery and follow-through matter more than ever Read More »

January 2026 Patch Tuesday forecast: And so it continues

January 2026 Patch Tuesday forecast: And so it continues 2026-01-09 at 11:26 By Help Net Security Welcome to a new year of my Patch Tuesday forecast blog where I provide a summary of Microsoft and other vendor’s security patch activity (and reported issues) for the month, talk about some of the latest trends, processes, and […]

January 2026 Patch Tuesday forecast: And so it continues Read More »

How AI agents are turning security inside-out

How AI agents are turning security inside-out 2026-01-09 at 09:30 By Help Net Security AppSec teams have spent the last decade hardening externally facing applications, API security, software supply chain risk, CI/CD controls, and cloud-native attack paths. But a growing class of security threats is emerging from a largely underestimated and undefended source: internally built […]

How AI agents are turning security inside-out Read More »

Clipping Scripted Sparrow’s wings: Tracking a global phishing ring

Clipping Scripted Sparrow’s wings: Tracking a global phishing ring 2025-12-18 at 16:12 By Help Net Security Between June 2024 and December 2025, Fortra analysts tracked a persistent business email compromise (BEC) operation that we have now classified as Scripted Sparrow. The group carries out well-crafted highly targeted phishing campaigns that masquerade as professional services firms […]

Clipping Scripted Sparrow’s wings: Tracking a global phishing ring Read More »

December 2025 Patch Tuesday forecast: And it’s a wrap

December 2025 Patch Tuesday forecast: And it’s a wrap 2025-12-08 at 09:56 By Help Net Security It’s hard to believe that we’re in December of 2025 already and the end of the year is fast approaching. Looking back on the year, there are two major items that really stand out in my mind. First, there […]

December 2025 Patch Tuesday forecast: And it’s a wrap Read More »

Scroll to Top