Hot stuff

When AI quietly breaks things, who pays?

When AI quietly breaks things, who pays? 2026-09-03 at 08:00 By Mirko Zorz David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance […]

When AI quietly breaks things, who pays? Read More »

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) 2026-09-02 at 15:42 By Zeljka Zorz A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unified communications platform built on […]

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) Read More »

SonicWall SMA 1000 appliances under attack via zero-day flaws

SonicWall SMA 1000 appliances under attack via zero-day flaws 2026-09-02 at 13:13 By Zeljka Zorz Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built […]

SonicWall SMA 1000 appliances under attack via zero-day flaws Read More »

A battery storage cyberattack would look exactly like a badly tuned controller

A battery storage cyberattack would look exactly like a badly tuned controller 2026-09-02 at 12:00 By Mirko Zorz Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should […]

A battery storage cyberattack would look exactly like a badly tuned controller Read More »

National Life Group CISO expects more vulnerabilities in six months than in thirty years

National Life Group CISO expects more vulnerabilities in six months than in thirty years 2026-09-02 at 09:00 By Mirko Zorz In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot […]

National Life Group CISO expects more vulnerabilities in six months than in thirty years Read More »

Scareware ads keep running on Google’s transparency tool, even after they’re reported

Scareware ads keep running on Google’s transparency tool, even after they’re reported 2026-09-02 at 08:30 By Mirko Zorz A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to […]

Scareware ads keep running on Google’s transparency tool, even after they’re reported Read More »

CISA review makes the case for eliminating vulnerability classes

CISA review makes the case for eliminating vulnerability classes 2026-09-01 at 18:23 By Zeljka Zorz For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of […]

CISA review makes the case for eliminating vulnerability classes Read More »

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers 2026-09-01 at 08:30 By Mirko Zorz Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The startup, […]

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers Read More »

NIS2 compliance: Fixing IAM and access control before the 2026 audit

NIS2 compliance: Fixing IAM and access control before the 2026 audit 2026-09-01 at 08:00 By Help Net Security The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into […]

NIS2 compliance: Fixing IAM and access control before the 2026 audit Read More »

What your vendor says about PQC tells you if they are ready

What your vendor says about PQC tells you if they are ready 2026-09-01 at 07:30 By Mirko Zorz In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity […]

What your vendor says about PQC tells you if they are ready Read More »

Attackers plant remote access tools on compromised PaperCut servers

Attackers plant remote access tools on compromised PaperCut servers 2026-08-31 at 17:54 By Zeljka Zorz The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools The vendor […]

Attackers plant remote access tools on compromised PaperCut servers Read More »

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree 2026-08-31 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, […]

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree Read More »

What 90 days and a small budget can buy in AI agent security

What 90 days and a small budget can buy in AI agent security 2026-08-28 at 08:30 By Mirko Zorz In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, […]

What 90 days and a small budget can buy in AI agent security Read More »

Unknown PaperCut NG/MF vulnerability is under active attack

Unknown PaperCut NG/MF vulnerability is under active attack 2026-08-27 at 14:59 By Zeljka Zorz A yet unspecified vulnerability affecting print management solutions PaperCut NG and PaperCut MF is being exploited by attackers, PaperCut Software warned today. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the vendor said. […]

Unknown PaperCut NG/MF vulnerability is under active attack Read More »

AI will not fix a governance problem in your camera estate

AI will not fix a governance problem in your camera estate 2026-08-27 at 08:30 By Mirko Zorz Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody […]

AI will not fix a governance problem in your camera estate Read More »

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 2026-08-26 at 13:59 By Zeljka Zorz Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details […]

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Read More »

Production data in testing is still common, and Tricentis’ CISO wants it gone

Production data in testing is still common, and Tricentis’ CISO wants it gone 2026-08-26 at 08:30 By Mirko Zorz In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught […]

Production data in testing is still common, and Tricentis’ CISO wants it gone Read More »

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over […]

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Read More »

AI supply chain risk is showing up in developer workflows first

AI supply chain risk is showing up in developer workflows first 2026-08-25 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and […]

AI supply chain risk is showing up in developer workflows first Read More »

Scroll to Top