News

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes 2026-08-26 at 15:46 By Sinisa Markovic A phishing-as-a-service (PhaaS) platform called AnonyMousKIT is automating the theft of Apple ID credentials needed to remove Activation Lock from stolen iPhones, SOCRadar found. “By leveraging a critical flaw – the use of bare relative paths – the investigation […]

AnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodes Read More »

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004)

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) 2026-08-26 at 13:59 By Zeljka Zorz Attackers have begun exploiting CVE-2026-60004, a critical code injection vulnerability in the Gitea Git platform, CISA confirmed on Tuesday by adding the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. The KEV entry does not contain or point to details […]

Critical Gitea vulnerability now exploited in the wild (CVE-2026-60004) Read More »

Bogus recruiters go after high-value corporate credentials on mobile

Bogus recruiters go after high-value corporate credentials on mobile 2026-08-26 at 13:05 By Sinisa Markovic Scammers posing as HR staff at well-known companies are running interview scheduling scams that end with a stolen corporate password, according to Zimperium. Attackers are using a technique called browser-in-the-browser, or BitB, which CTM360 documented in earlier research on recruitment […]

Bogus recruiters go after high-value corporate credentials on mobile Read More »

Meta adds three new features to keep WhatsApp accounts secure

Meta adds three new features to keep WhatsApp accounts secure 2026-08-26 at 10:52 By Sinisa Markovic Meta has added new security enhancements to WhatsApp, this time in the form of stronger two-step verification, additional information about calls from unknown numbers, and the ability to add multiple passkeys to the same account. New account security features […]

Meta adds three new features to keep WhatsApp accounts secure Read More »

Production data in testing is still common, and Tricentis’ CISO wants it gone

Production data in testing is still common, and Tricentis’ CISO wants it gone 2026-08-26 at 08:30 By Mirko Zorz In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught […]

Production data in testing is still common, and Tricentis’ CISO wants it gone Read More »

AI vulnerability discovery scores the highest impact of 20 emerging risks

AI vulnerability discovery scores the highest impact of 20 emerging risks 2026-08-26 at 08:00 By Anamarija Pogorelec Risk managers, auditors and senior executives at 316 companies spent April and May ranking 20 threats they have not yet felt. AI discovery of cyber vulnerabilities came back first, according to Gartner. Three months earlier the same quarterly […]

AI vulnerability discovery scores the highest impact of 20 emerging risks Read More »

Hottest cybersecurity open-source tools of the month: August 2026

Hottest cybersecurity open-source tools of the month: August 2026 2026-08-26 at 07:30 By Anamarija Pogorelec Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an open-source scanner from […]

Hottest cybersecurity open-source tools of the month: August 2026 Read More »

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat 2026-08-25 at 18:27 By Nikita Kazymirskyi A cyber incident affecting a small UK electricity generator in July 2026 resulted in several days of operational unavailability and triggered a government and NCSC response. UK authorities confirmed that the event posed no threat to the […]

Energy Disruption in UK Critical Infrastructure and the Growing OT Cyber Threat Read More »

INTERPOL crackdown on West African crime rings uncovers troubling new trend

INTERPOL crackdown on West African crime rings uncovers troubling new trend 2026-08-25 at 17:01 By Sinisa Markovic Police across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspects detained in an operation targeting West African crime groups (Source: INTERPOL) Operation Jackal IV ran […]

INTERPOL crackdown on West African crime rings uncovers troubling new trend Read More »

Fake OpenAI Codex download tricks macOS users into installing malware

Fake OpenAI Codex download tricks macOS users into installing malware 2026-08-25 at 15:40 By Sinisa Markovic A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It’s a variation of ClickFix, a popular […]

Fake OpenAI Codex download tricks macOS users into installing malware Read More »

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks 2026-08-25 at 13:03 By Zeljka Zorz At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570, the Shadowserver Foundation shared on Monday. About CVE-2026-73570 Zimbra Collaboration Suite (ZCS) is a communication and collaboration platform popular with organizations that need to have control over […]

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks Read More »

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack 2026-08-25 at 12:24 By Sinisa Markovic Cybersecurity company ReliaQuest has confirmed that one of its own employees fell for a social engineering attack, handing attackers a password and a brief window into the company’s identity system. The admission came after the extortion group […]

ShinyHunters taunts ReliaQuest after its own employee falls for social engineering attack Read More »

AI supply chain risk is showing up in developer workflows first

AI supply chain risk is showing up in developer workflows first 2026-08-25 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and […]

AI supply chain risk is showing up in developer workflows first Read More »

HOL Guard: Open-source antivirus for AI agents

HOL Guard: Open-source antivirus for AI agents 2026-08-25 at 08:30 By Anamarija Pogorelec HOL Guard is a free, open-source tool that sits between an AI assistant and the computer it runs on. When the assistant tries something risky, the tool pauses it and asks you first. It installs in about a minute, runs on your […]

HOL Guard: Open-source antivirus for AI agents Read More »

The cybercrime supply chain has five stages, each with a price

The cybercrime supply chain has five stages, each with a price 2026-08-25 at 08:00 By Help Net Security In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five […]

The cybercrime supply chain has five stages, each with a price Read More »

New TCG guidance gives buyers a way to test PQC-ready TPM claims

New TCG guidance gives buyers a way to test PQC-ready TPM claims 2026-08-25 at 07:30 By Help Net Security The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements […]

New TCG guidance gives buyers a way to test PQC-ready TPM claims Read More »

Cybersecurity jobs available right now: August 25, 2026

Cybersecurity jobs available right now: August 25, 2026 2026-08-25 at 07:00 By Sinisa Markovic Specialist Compliance Security AT&T | USA | On-site – View job details As a Specialist Compliance Security, you will serve as AT&T’s liaison for law enforcement, first responders, and emergency personnel nationwide. Respond 24×7 to emergency requests, process subpoenas, warrants, and […]

Cybersecurity jobs available right now: August 25, 2026 Read More »

Suspected Iran-linked attack knocked UK power plant offline for days

Suspected Iran-linked attack knocked UK power plant offline for days 2026-08-24 at 17:22 By Zeljka Zorz News that suspected Iranian hackers caused the shutdown of a British power plant broke over the weekend, raising the question of whether UK’s power grid and, indeed, the country’s critical infrastructure can fend off destructive cyber attacks. According to […]

Suspected Iran-linked attack knocked UK power plant offline for days Read More »

Cybersecurity job ads demanding AI skills double in a year

Cybersecurity job ads demanding AI skills double in a year 2026-08-24 at 14:53 By Sinisa Markovic Job postings asking for AI skills in cybersecurity have doubled in a single year in G7 countries according to new research from the Cisco-founded AI Workforce Consortium. Analysis from recruitment firms Cornerstone and Indeed covering 24 months, from April […]

Cybersecurity job ads demanding AI skills double in a year Read More »

CISA’s logging guidance works beyond government

CISA’s logging guidance works beyond government 2026-08-24 at 13:56 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) wants federal agencies to (re)shape their logging strategy around one question: when an attack hits, can you actually use the logs you’ve collected to catch it and reconstruct what happened afterward? The Logging Reference Architecture […]

CISA’s logging guidance works beyond government Read More »

Scroll to Top