News

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day 2026-08-16 at 11:00 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in […]

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day Read More »

New Android malware relays bank cards to fraudsters while victims still hold them

New Android malware relays bank cards to fraudsters while victims still hold them 2026-08-14 at 14:08 By Sinisa Markovic Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access […]

New Android malware relays bank cards to fraudsters while victims still hold them Read More »

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode 2026-08-14 at 13:55 By Anamarija Pogorelec OpenAI’s GPT-5.6 Sol on Ultrafast mode is available in limited preview to a select group of customers, launching first through the OpenAI API. The company says the service runs up to 14 times faster than Standard processing and […]

OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode Read More »

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals 2026-08-14 at 11:25 By Anamarija Pogorelec AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. The CA/B Forum sets standards that browsers and […]

AWS Certificate Manager sets 2027 end date for email-validated certificate renewals Read More »

Ukrainian police raid 94 fraudulent call centers, seize $2 million

Ukrainian police raid 94 fraudulent call centers, seize $2 million 2026-08-14 at 10:56 By Sinisa Markovic Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Ukrainian police raid at a fraudulent call center (Source: Cyberpolice […]

Ukrainian police raid 94 fraudulent call centers, seize $2 million Read More »

The hardest part of agentic AI may be rebuilding the business

The hardest part of agentic AI may be rebuilding the business 2026-08-14 at 08:30 By Anamarija Pogorelec Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest […]

The hardest part of agentic AI may be rebuilding the business Read More »

Weak IAM affects up to 98% of cloud environments

Weak IAM affects up to 98% of cloud environments 2026-08-14 at 08:00 By Anamarija Pogorelec Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal […]

Weak IAM affects up to 98% of cloud environments Read More »

17 draft Cyber Resilience Act standards are open for comment

17 draft Cyber Resilience Act standards are open for comment 2026-08-14 at 07:30 By Anamarija Pogorelec A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to […]

17 draft Cyber Resilience Act standards are open for comment Read More »

New infosec products of the week: August 14, 2026

New infosec products of the week: August 14, 2026 2026-08-14 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, ScienceLogic, Searchlight Cyber, and SelectHub. ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5 ScienceLogic has announced Skylar AI […]

New infosec products of the week: August 14, 2026 Read More »

White House authorizes private US companies to hack foreign criminal networks

White House authorizes private US companies to hack foreign criminal networks 2026-08-13 at 17:31 By Sinisa Markovic President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government. The post White House authorizes […]

White House authorizes private US companies to hack foreign criminal networks Read More »

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) 2026-08-13 at 16:05 By Sinisa Markovic Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday […]

Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) Read More »

Four corporate investigation mistakes organizations make under pressure

Four corporate investigation mistakes organizations make under pressure 2026-08-13 at 08:00 By Help Net Security In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and […]

Four corporate investigation mistakes organizations make under pressure Read More »

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common 2026-08-13 at 07:30 By Anamarija Pogorelec DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale […]

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common Read More »

Product showcase: Is this image real? Slop or Not investigates

Product showcase: Is this image real? Slop or Not investigates 2026-08-13 at 07:00 By Anamarija Pogorelec Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to […]

Product showcase: Is this image real? Slop or Not investigates Read More »

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers 2026-08-13 at 06:53 By Anamarija Pogorelec Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection […]

Wireshark 4.6.8 patches 28 security bugs, nine in file parsers Read More »

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months 2026-08-12 at 16:51 By Mirko Zorz Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now […]

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months Read More »

Signal’s new security feature checks if your encrypted chats were tampered with

Signal’s new security feature checks if your encrypted chats were tampered with 2026-08-12 at 16:47 By Sinisa Markovic Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, […]

Signal’s new security feature checks if your encrypted chats were tampered with Read More »

Lazarus hackers pair fake job offers with Windows zero-day exploit

Lazarus hackers pair fake job offers with Windows zero-day exploit 2026-08-12 at 14:48 By Sinisa Markovic The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a […]

Lazarus hackers pair fake job offers with Windows zero-day exploit Read More »

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily 2026-08-12 at 11:36 By Anamarija Pogorelec Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive notifications (Source: Google) Chrome revokes notification permissions for websites users […]

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily Read More »

Split-second deepfake glitch blows digital certificate fraudster’s cover

Split-second deepfake glitch blows digital certificate fraudster’s cover 2026-08-12 at 10:50 By Sinisa Markovic Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the police, the man made […]

Split-second deepfake glitch blows digital certificate fraudster’s cover Read More »

Scroll to Top