News

Microsoft demystifies how Windows updates work

Microsoft demystifies how Windows updates work 2026-07-13 at 08:30 By Anamarija Pogorelec Microsoft has published a guide explaining the Windows servicing model, outlining the purpose of monthly security updates, optional preview releases, hotpatch updates, and the mechanisms used to deliver new features throughout the year. “Most individuals and organizations regularly deploy monthly security updates, released […]

Microsoft demystifies how Windows updates work Read More »

A hardware security AI assistant that checks chips for hidden backdoors

A hardware security AI assistant that checks chips for hidden backdoors 2026-07-13 at 08:00 By Sinisa Markovic Chip designers license blocks of circuitry from outside vendors and drop them into larger products. A single processor can carry components from a range of suppliers, each written by a company the buyer may never deal with directly.

A hardware security AI assistant that checks chips for hidden backdoors Read More »

99.9% of fixable AI vulnerabilities remain unpatched

99.9% of fixable AI vulnerabilities remain unpatched 2026-07-13 at 07:30 By Anamarija Pogorelec Organizations build, deploy, and operate AI in the cloud, but basic cybersecurity hygiene is often sacrificed for speed, according to Orca Security’s 2026 State of AI Security Report. Building AI without security Fifty-six percent of AI adopters have deployed agent frameworks into

99.9% of fixable AI vulnerabilities remain unpatched Read More »

Enterprises are rethinking where their AI applications run

Enterprises are rethinking where their AI applications run 2026-07-13 at 07:00 By Anamarija Pogorelec Growing demand for compute capacity, power, cooling and low-latency connectivity is prompting organizations to reassess where AI applications run, according to CoreSite. Public cloud continues to support experimentation and rapid deployment, while colocation is increasingly used for workloads that require predictable

Enterprises are rethinking where their AI applications run Read More »

Debian 13.6 security update patches over a hundred advisories in trixie

Debian 13.6 security update patches over a hundred advisories in trixie 2026-07-13 at 01:25 By Anamarija Pogorelec Most PCs still run with a UEFI Secure Boot certificate authority, installed by default since 2013, that has now expired. That certificate signed the bootloaders letting machines start with Secure Boot turned on. Its expiry sits at the

Debian 13.6 security update patches over a hundred advisories in trixie Read More »

Week in review: Accenture data breach, great open-source cybersecurity tools

Week in review: Accenture data breach, great open-source cybersecurity tools 2026-07-12 at 11:00 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security meet Getting a verified logo to appear next to your email has traditionally meant having

Week in review: Accenture data breach, great open-source cybersecurity tools Read More »

July 2026 Patch Tuesday forecast: Is CVE tracking still practical?

July 2026 Patch Tuesday forecast: Is CVE tracking still practical? 2026-07-10 at 10:30 By Help Net Security I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11

July 2026 Patch Tuesday forecast: Is CVE tracking still practical? Read More »

The open source library holding up your stack might have one maintainer

The open source library holding up your stack might have one maintainer 2026-07-10 at 10:00 By Sinisa Markovic Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful

The open source library holding up your stack might have one maintainer Read More »

Most data brokers won’t tell you what happened to your deletion request

Most data brokers won’t tell you what happened to your deletion request 2026-07-10 at 09:30 By Sinisa Markovic Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask

Most data brokers won’t tell you what happened to your deletion request Read More »

Microsoft is rewriting Windows patch guidance because of AI

Microsoft is rewriting Windows patch guidance because of AI 2026-07-10 at 09:00 By Anamarija Pogorelec Microsoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess how quickly they

Microsoft is rewriting Windows patch guidance because of AI Read More »

Only 28% of financial workforce MFA is phishing-resistant

Only 28% of financial workforce MFA is phishing-resistant 2026-07-10 at 08:41 By Anamarija Pogorelec Passwords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant MFA (Source: Secret Double Octopus) Workforce

Only 28% of financial workforce MFA is phishing-resistant Read More »

Turning software supply chain security into a daily habit

Turning software supply chain security into a daily habit 2026-07-10 at 08:30 By Help Net Security In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every

Turning software supply chain security into a daily habit Read More »

AWS gives its ERP agent deny-by-default rules and a separate identity

AWS gives its ERP agent deny-by-default rules and a separate identity 2026-07-10 at 08:00 By Sinisa Markovic Accounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across

AWS gives its ERP agent deny-by-default rules and a separate identity Read More »

New infosec products of the week: July 10, 2026

New infosec products of the week: July 10, 2026 2026-07-10 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from Attestiv, Automox, Codenotary, and First Recon AI. Codenotary launches AI security platform that learns from AI agent behavior Codenotary has announced AgentMon 3, the latest

New infosec products of the week: July 10, 2026 Read More »

Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)

Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) 2026-07-09 at 15:14 By Zeljka Zorz Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to improper link resolution before

Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656) Read More »

5,811 arrests, $293 million seized over social engineering scams

5,811 arrests, $293 million seized over social engineering scams 2026-07-09 at 14:14 By Sinisa Markovic Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrests

5,811 arrests, $293 million seized over social engineering scams Read More »

Your coding agent says no in chat and yes in the code

Your coding agent says no in chat and yes in the code 2026-07-09 at 13:44 By Mirko Zorz Millions of developers share their keyboard with GitHub Copilot. Inside Visual Studio Code, it opens their files, writes and edits code, runs scripts, and reworks its own output across many turns. The safety testing that vets these

Your coding agent says no in chat and yes in the code Read More »

AWS centralizes access, spending, and governance for Claude

AWS centralizes access, spending, and governance for Claude 2026-07-09 at 11:37 By Anamarija Pogorelec Claude apps gateway for AWS is a self-hosted control plane that gives organizations a single point of control over access, costs, and policies for Claude Code and Claude Desktop. It replaces per-developer cloud credentials, manual distribution of managed settings to developer

AWS centralizes access, spending, and governance for Claude Read More »

Scroll to Top