Hot stuff

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix 2026-08-11 at 08:30 By Mirko Zorz Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws […]

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix Read More »

Metabase zero-day exploited to access Framework customer data

Metabase zero-day exploited to access Framework customer data 2026-08-10 at 16:42 By Zeljka Zorz Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers

Metabase zero-day exploited to access Framework customer data Read More »

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 2026-08-10 at 14:34 By Zeljka Zorz To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix.

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 Read More »

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? 2026-08-07 at 09:00 By Help Net Security July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? Read More »

What the first year of EU AI Act transparency enforcement could look like

What the first year of EU AI Act transparency enforcement could look like 2026-08-07 at 08:30 By Mirko Zorz In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders

What the first year of EU AI Act transparency enforcement could look like Read More »

Three in four AI-generated vulnerability patches leave something broken

Three in four AI-generated vulnerability patches leave something broken 2026-08-06 at 15:45 By Mirko Zorz Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time

Three in four AI-generated vulnerability patches leave something broken Read More »

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers 2026-08-05 at 21:45 By Mirko Zorz An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there the attacker runs code on the host. Bonita BPM handles

Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers Read More »

AI agent deception moves from theory to reality in UK cyber tests

AI agent deception moves from theory to reality in UK cyber tests 2026-08-05 at 15:05 By Zeljka Zorz “During a routine cyber evaluation, AI agents took sustained, unsanctioned action directed at real people and organisations,” UK’s AI Security Institute (AISI) disclosed on Tuesday. The agents’ actions included an attempted supply-chain attack that saw them create

AI agent deception moves from theory to reality in UK cyber tests Read More »

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove 2026-08-05 at 11:43 By Zeljka Zorz A phishing campaign impersonating Bank of America (BoA) is underway, trying to trick Windows users into installing ScreenConnect remote access software and then making it difficult to uninstall it. Different traps for Mac and Windows users By

Bank of America impersonators weaponize ScreenConnect, then make it hard to remove Read More »

Future AGI: Open-source platform for shipping self-improving AI agents

Future AGI: Open-source platform for shipping self-improving AI agents 2026-08-05 at 08:30 By Anamarija Pogorelec Future AGI is an open-source platform for tracing, evaluating, simulating, and guardrailing LLM agents, licensed Apache 2.0 and self-hostable. Self-hosted instances register with Future AGI on first boot and send an instance ID, a version string, a deployment type, and

Future AGI: Open-source platform for shipping self-improving AI agents Read More »

What stops attackers wrecking industrial plants is knowing how

What stops attackers wrecking industrial plants is knowing how 2026-08-05 at 07:30 By Mirko Zorz Engineers at an Israeli food producer spent most of a week rebuilding a refrigeration system after an intruder switched the gas cooler and receiver valves to manual and pinned them open. Liquid CO2 flooded the compressors and destroyed them. The

What stops attackers wrecking industrial plants is knowing how Read More »

Digital executive protection is a strategic imperative for CEOs

Digital executive protection is a strategic imperative for CEOs 2026-08-04 at 09:00 By Mirko Zorz In this interview with Help Net Security, Brian Hill, Field CISO, Client Advisory for BlackCloak, explains how attackers reach companies through the personal lives of executives. He describes a case where a draft report sat in an executive’s personal email

Digital executive protection is a strategic imperative for CEOs Read More »

OWASP’s subtractive security project measures the attack paths you erased

OWASP’s subtractive security project measures the attack paths you erased 2026-08-04 at 08:30 By Mirko Zorz An attacker who talks a user into opening an attachment gets whatever that machine still permits: a service account with rights across the domain, an outbound route to anywhere, a scripting engine sitting there for the taking. Christopher Frenz

OWASP’s subtractive security project measures the attack paths you erased Read More »

Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials

Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials 2026-08-04 at 08:00 By Mirko Zorz An analyst opening a queue on Monday morning will spend most of it on tickets that amount to nothing. Stellar Cyber’s Agentic Auto Triage closed 8,047 of those tickets on its own during customer trials,

Analysts got 19 minutes back every hour in Stellar Cyber’s agentic auto triage trials Read More »

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) 2026-08-03 at 17:33 By Zeljka Zorz Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026,

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) Read More »

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) 2026-08-03 at 14:42 By Zeljka Zorz A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) Read More »

Mapping the malware blast radius a single alert won’t show you

Mapping the malware blast radius a single alert won’t show you 2026-08-03 at 09:00 By Mirko Zorz In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through

Mapping the malware blast radius a single alert won’t show you Read More »

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills 2026-08-03 at 08:30 By Anamarija Pogorelec SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a Git URL, and it returns a list of

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills Read More »

Aviation cyber risk sits on the ground, the blindness sits in the air

Aviation cyber risk sits on the ground, the blindness sits in the air 2026-07-31 at 08:30 By Mirko Zorz In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in

Aviation cyber risk sits on the ground, the blindness sits in the air Read More »

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897)

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) 2026-07-30 at 17:23 By Zeljka Zorz Russia-affiliated cyber espionage group Laundry Bear (aka Void Blizzard, aka TA488) is exploiting CVE-2026-42897, a cross-site scripting vulnerability in Microsoft Exchange, to target US and European government entities and a variety of private sector organizations via email. The

Laundry Bear’s new Microsoft Exchange attack triggers on email open (CVE-2026-42897) Read More »

Scroll to Top