News

The Windows 10 hangover is becoming a security problem

The Windows 10 hangover is becoming a security problem 2026-07-20 at 11:37 By Anamarija Pogorelec Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered […]

The Windows 10 hangover is becoming a security problem Read More »

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform 2026-07-20 at 09:00 By Anamarija Pogorelec Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform Read More »

More alerts are making your team slower, and an outcome-based SOC fixes that

More alerts are making your team slower, and an outcome-based SOC fixes that 2026-07-20 at 08:30 By Help Net Security In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like

More alerts are making your team slower, and an outcome-based SOC fixes that Read More »

A forensic tool for backdoored code completions in AI assistants

A forensic tool for backdoored code completions in AI assistants 2026-07-20 at 08:00 By Sinisa Markovic Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and

A forensic tool for backdoored code completions in AI assistants Read More »

Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security

Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security 2026-07-20 at 07:30 By Anamarija Pogorelec ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon

Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security Read More »

Nearly half of open-source AI projects never reach production

Nearly half of open-source AI projects never reach production 2026-07-20 at 07:00 By Anamarija Pogorelec Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as

Nearly half of open-source AI projects never reach production Read More »

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs 2026-07-19 at 10:09 By Anamarija Pogorelec Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security

Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs Read More »

Two new high severity WordPress vulnerabilities, patch immediately!

Two new high severity WordPress vulnerabilities, patch immediately! 2026-07-18 at 17:57 By Help Net Security The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 – A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-60137

Two new high severity WordPress vulnerabilities, patch immediately! Read More »

Spirals ransomware locks down victim systems in under 24 hours

Spirals ransomware locks down victim systems in under 24 hours 2026-07-17 at 15:25 By Sinisa Markovic A previously unknown ransomware strain called Spirals was used last month in an attack against an IT services company in South Asia, where attackers went from initial access to data theft and encrypting the network in less than 24

Spirals ransomware locks down victim systems in under 24 hours Read More »

Scammers weaponize FaceTime to drain bank accounts

Scammers weaponize FaceTime to drain bank accounts 2026-07-17 at 13:02 By Sinisa Markovic Apple is warning iPhone and iPad users that scammers are using FaceTime calls to trick them into handing over money and account details. The company says scammers use social engineering, posing as representatives of a trusted company or entity, and contacting people

Scammers weaponize FaceTime to drain bank accounts Read More »

Claude can now sign into websites with 1Password without exposing your credentials

Claude can now sign into websites with 1Password without exposing your credentials 2026-07-17 at 12:17 By Anamarija Pogorelec 1Password has introduced 1Password for Claude, a beta integration that lets Anthropic’s AI assistant complete browser tasks requiring authentication without accessing users’ passwords or other secrets. The integration is available to paid Claude subscribers (Pro, Max, Team,

Claude can now sign into websites with 1Password without exposing your credentials Read More »

Ransomware attack halts Coca-Cola’s Fairlife US milk production

Ransomware attack halts Coca-Cola’s Fairlife US milk production 2026-07-17 at 11:04 By Sinisa Markovic A ransomware attack has stopped milk production at Fairlife, the Coca-Cola dairy brand known for its high-protein milk, protein shakes, and nutrition drinks. Coca-Cola disclosed the incident on July 16, 2026, in a Form 8-K filed with the U.S. Securities and

Ransomware attack halts Coca-Cola’s Fairlife US milk production Read More »

The script, not the voice, is what makes AI voice phishing work

The script, not the voice, is what makes AI voice phishing work 2026-07-17 at 10:31 By Sinisa Markovic The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry,

The script, not the voice, is what makes AI voice phishing work Read More »

Prompt injection is becoming the XSS of the web agent era

Prompt injection is becoming the XSS of the web agent era 2026-07-17 at 09:00 By Anamarija Pogorelec Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted site menus on a single page. An agent that reads all of that

Prompt injection is becoming the XSS of the web agent era Read More »

The five step plan that cuts security budget waste

The five step plan that cuts security budget waste 2026-07-17 at 08:00 By Help Net Security In this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, and that mismatch is

The five step plan that cuts security budget waste Read More »

A hard drive reliability check on 341,263 drives, from 4TB to past 20TB

A hard drive reliability check on 341,263 drives, from 4TB to past 20TB 2026-07-17 at 07:30 By Anamarija Pogorelec Large cloud storage operators track their hard drives every day, recording which units keep running and which ones drop off the racks. Backblaze does this at scale, and its Q1 2026 report covers a fleet built

A hard drive reliability check on 341,263 drives, from 4TB to past 20TB Read More »

New infosec products of the week: July 17, 2026

New infosec products of the week: July 17, 2026 2026-07-17 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetings Polygraf AI has announced Meeting Guard, a

New infosec products of the week: July 17, 2026 Read More »

Scattered Spider members jailed over Transport for London hack that cost £29 million

Scattered Spider members jailed over Transport for London hack that cost £29 million 2026-07-16 at 16:48 By Sinisa Markovic Two members of the notorious “Scattered Spider” hacking collective have been sentenced to five years and six months in prison each for a cyberattack on Transport for London (TfL) that disrupted services for thousands of commuters

Scattered Spider members jailed over Transport for London hack that cost £29 million Read More »

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance 2026-07-16 at 16:23 By Zeljka Zorz On Wednesday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) and four allied cyber authorities published a guide telling software vendors how to build a coordinated vulnerability disclosure (CVD) program. Six days earlier, CISA published a blog post

CISA folds its own hard-won lessons into coordinated vulnerability disclosure guidance Read More »

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes 2026-07-16 at 15:08 By Sinisa Markovic A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to Trend Micro. Operational overview (Source: Trend Micro) In

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes Read More »

Scroll to Top