Hot stuff

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) 2026-07-28 at 14:04 By Zeljka Zorz JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo, […]

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) Read More »

Shadow AI incident response begins with logs that may already be gone

Shadow AI incident response begins with logs that may already be gone 2026-07-28 at 09:00 By Mirko Zorz In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound

Shadow AI incident response begins with logs that may already be gone Read More »

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) 2026-07-27 at 15:04 By Zeljka Zorz Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) Read More »

How attackers hosted a fake Claude download page on the claude.ai domain

How attackers hosted a fake Claude download page on the claude.ai domain 2026-07-23 at 16:12 By Zeljka Zorz A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app

How attackers hosted a fake Claude download page on the claude.ai domain Read More »

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) 2026-07-23 at 13:42 By Zeljka Zorz Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) Read More »

Shadow AI is becoming enterprise security’s biggest blind spot

Shadow AI is becoming enterprise security’s biggest blind spot 2026-07-23 at 09:00 By Help Net Security Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly every business function. Microsoft’s 2026

Shadow AI is becoming enterprise security’s biggest blind spot Read More »

Multi-patch vulnerability fixes can leave open source exposed

Multi-patch vulnerability fixes can leave open source exposed 2026-07-23 at 08:00 By Mirko Zorz Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two

Multi-patch vulnerability fixes can leave open source exposed Read More »

OpenAI: Our models breached Hugging Face during a cyber capability test

OpenAI: Our models breached Hugging Face during a cyber capability test 2026-07-22 at 17:42 By Zeljka Zorz The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share

OpenAI: Our models breached Hugging Face during a cyber capability test Read More »

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) 2026-07-22 at 14:47 By Zeljka Zorz Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code,

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) Read More »

Small teams are the heaviest users of AI coding agents

Small teams are the heaviest users of AI coding agents 2026-07-22 at 09:00 By Sinisa Markovic The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually

Small teams are the heaviest users of AI coding agents Read More »

JadePuffer returns with ransomware built to target AI models and infrastructure

JadePuffer returns with ransomware built to target AI models and infrastructure 2026-07-21 at 16:38 By Zeljka Zorz JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in

JadePuffer returns with ransomware built to target AI models and infrastructure Read More »

SonicWall SMA zero-days were exploited weeks before disclosure

SonicWall SMA zero-days were exploited weeks before disclosure 2026-07-21 at 13:35 By Zeljka Zorz Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22,

SonicWall SMA zero-days were exploited weeks before disclosure Read More »

The air gap is a myth and other OT security truths

The air gap is a myth and other OT security truths 2026-07-21 at 09:00 By Mirko Zorz Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth.

The air gap is a myth and other OT security truths Read More »

Nobody was checking the drives that encrypt your laptop

Nobody was checking the drives that encrypt your laptop 2026-07-21 at 08:30 By Anamarija Pogorelec A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG

Nobody was checking the drives that encrypt your laptop Read More »

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) 2026-07-20 at 17:32 By Zeljka Zorz Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) Read More »

Hugging Face breached by autonomous AI agent

Hugging Face breached by autonomous AI agent 2026-07-20 at 13:52 By Zeljka Zorz Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16),

Hugging Face breached by autonomous AI agent Read More »

Two new high severity WordPress vulnerabilities, patch immediately!

Two new high severity WordPress vulnerabilities, patch immediately! 2026-07-18 at 17:57 By Help Net Security The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137

Two new high severity WordPress vulnerabilities, patch immediately! Read More »

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance 2026-07-16 at 16:23 By Zeljka Zorz On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance Read More »

Romania’s land registry hit by cyber attack, data allegedly for sale

Romania’s land registry hit by cyber attack, data allegedly for sale 2026-07-16 at 13:21 By Zeljka Zorz Romania’s National Agency for Cadastre and Land Registration (ANCPI) suffered a major disruption on Tuesday, July 14, when its e-Terra cadastre and land registry app became unavailable to users. What was first declared to be a “major technical

Romania’s land registry hit by cyber attack, data allegedly for sale Read More »

Reading between the lines of a cyber insurance policy

Reading between the lines of a cyber insurance policy 2026-07-16 at 09:00 By Mirko Zorz Enterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024. Coverage has become widespread. Payouts have

Reading between the lines of a cyber insurance policy Read More »

Scroll to Top