News

Vulnerability reports are arriving faster than GitHub can review them

Vulnerability reports are arriving faster than GitHub can review them 2026-06-30 at 08:25 By Anamarija Pogorelec Across the open source world, people are reporting software flaws in record numbers, and the systems built to verify those reports are straining under the weight. The GitHub Advisory Database, which feeds automated security alerts to millions of projects, […]

Vulnerability reports are arriving faster than GitHub can review them Read More »

Hottest cybersecurity open-source tools of the month: June 2026

Hottest cybersecurity open-source tools of the month: June 2026 2026-06-30 at 08:00 By Anamarija Pogorelec Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory AI

Hottest cybersecurity open-source tools of the month: June 2026 Read More »

JSP webshells being dropped on unpatched PTC Windchill instances

JSP webshells being dropped on unpatched PTC Windchill instances 2026-06-29 at 19:18 By Zeljka Zorz The US Cybersecurity and Infrastructure Security Agency (CISA) added a vulnerability (CVE-2026-12569) in Windchill and FlexPLM, two product lifecycle management software platforms developed by PTC, to its Known Exploited Vulnerabilities (KEV) catalog. Entries in the KEV catalog don’t contain links

JSP webshells being dropped on unpatched PTC Windchill instances Read More »

Mozilla warns of indirect prompt injection risk in AI coding agents

Mozilla warns of indirect prompt injection risk in AI coding agents 2026-06-29 at 13:48 By Zeljka Zorz A malicious GitHub repository can silently compromise a developer’s machine without containing a single line of malicious code, security researchers at Mozilla’s Zero Day Investigative Network (0DIN) warned. The attack The proof-of-concept attack targets AI-powered coding agents such

Mozilla warns of indirect prompt injection risk in AI coding agents Read More »

DarkMoon: Open-source AI pentesting platform

DarkMoon: Open-source AI pentesting platform 2026-06-29 at 08:30 By Mirko Zorz Penetration testing has long run on expert time, with specialists spending days probing a network or web application by hand. Manual engagements stretch across weeks, expert consultants run into thousands of dollars a day, and results vary with the tester. Automation promises to narrow

DarkMoon: Open-source AI pentesting platform Read More »

Sycophantic chatbots and the harms that build over many chats

Sycophantic chatbots and the harms that build over many chats 2026-06-29 at 08:00 By Sinisa Markovic People use AI chatbots for company, advice, and emotional support, and these systems answer in ways meant to hold their attention. Researchers describe the resulting risks as affective safety, a class of harm that exists because humans are emotional

Sycophantic chatbots and the harms that build over many chats Read More »

Companies keep bolting AI onto their products, and the security bill is coming due

Companies keep bolting AI onto their products, and the security bill is coming due 2026-06-29 at 07:30 By Mirko Zorz Companies keep bolting AI and LLM features onto their products, and the security results are starting to show a pattern. The vulnerabilities those features create get rated high risk far more often than anything else,

Companies keep bolting AI onto their products, and the security bill is coming due Read More »

Most teams accept higher risk for faster AI database work

Most teams accept higher risk for faster AI database work 2026-06-29 at 07:00 By Anamarija Pogorelec Database professionals are using AI for everyday work like writing queries, building schemas, and reviewing code, and a growing share rely on autonomous tools that act on the database itself. The use of AI in database management has almost

Most teams accept higher risk for faster AI database work Read More »

Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited

Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited 2026-06-28 at 11:00 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS,

Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited Read More »

Critical open-source projects get a new security framework

Critical open-source projects get a new security framework 2026-06-26 at 14:41 By Anamarija Pogorelec Open source software projects are getting a new framework for handling security vulnerabilities as AI shortens the time between flaw discovery and exploitation. The Linux Foundation has launched Akrites, an industry initiative that brings together technology companies, financial institutions, security vendors,

Critical open-source projects get a new security framework Read More »

Synology issues critical fix for MailPlus Server vulnerabilities

Synology issues critical fix for MailPlus Server vulnerabilities 2026-06-26 at 13:57 By Zeljka Zorz Synology has has fixed critical vulnerabilities in MailPlus Server, a software package used to run private email infrastructure on Synology NAS devices. The security update fixes three flaws: CVE-2026-13136, stemming from faulty authorization checks, may allow remote attackers to read or

Synology issues critical fix for MailPlus Server vulnerabilities Read More »

Ransomware gangs find Europe’s weakest link in third-party suppliers

Ransomware gangs find Europe’s weakest link in third-party suppliers 2026-06-26 at 12:49 By Anamarija Pogorelec Ransomware attacks against European organizations increased during the first months of 2026, with third-party suppliers becoming a major entry point for attackers. Black Kite examined 2,066 ransomware incidents across 31 countries between January 2025 and April 2026 in its 2026

Ransomware gangs find Europe’s weakest link in third-party suppliers Read More »

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials 2026-06-26 at 12:26 By Sinisa Markovic Mirage2FA, a phishing kit that combines short-lived HTML smuggling with obfuscated JavaScript loaders to deliver fake Microsoft 365 login pages and steal credentials during MFA prompts, has been identified by researchers at Fortra. Fortra based its analysis on

Mirage2FA phishing kit uses HTML smuggling to steal Microsoft 365 credentials Read More »

Mystery hackers use novel SharkLoader dropper against governments, software devs

Mystery hackers use novel SharkLoader dropper against governments, software devs 2026-06-26 at 12:13 By Zeljka Zorz Kaspersky researchers have uncovered a previously unknown cyberattack campaign that has compromised government organizations and software development companies in multiple countries. They first stumbled onto the campaign while investigating an attack on a diplomatic organization in Indonesia. What initially

Mystery hackers use novel SharkLoader dropper against governments, software devs Read More »

SIM-swapping gang busted in international police operation

SIM-swapping gang busted in international police operation 2026-06-26 at 10:59 By Sinisa Markovic Officers from Poland’s Central Bureau for Combating Cybercrime (CBZC) arrested four suspected members of an organized cybercrime group accused of SIM swap attacks, cryptocurrency theft, and money laundering. The operation involved agents from the U.S. Federal Bureau of Investigation (FBI) and Homeland

SIM-swapping gang busted in international police operation Read More »

Microsoft gives Windows 10 users an unexpected extra year of free security updates

Microsoft gives Windows 10 users an unexpected extra year of free security updates 2026-06-26 at 09:32 By Sinisa Markovic Microsoft has given Windows 10 users another year of free security updates, extending its consumer Extended Security Updates (ESU) program until October 12, 2027. “Windows 10 support has ended. You can enroll in ESU any time

Microsoft gives Windows 10 users an unexpected extra year of free security updates Read More »

A privacy-first take on local malware analysis

A privacy-first take on local malware analysis 2026-06-26 at 09:00 By Sinisa Markovic Submitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these services to get a quick verdict on whether a binary is dangerous. The convenience

A privacy-first take on local malware analysis Read More »

Two CEOs on why security and AI readiness belong together

Two CEOs on why security and AI readiness belong together 2026-06-26 at 08:30 By Mirko Zorz SuperOps and Guardz are bundling PSA, RMM, MDM, and agentic SecOps into one offering for MSPs. In this Help Net Security Q&A, SuperOps CEO Arvind Parthiban and Guardz CEO Dor Eisner explain how a connected stack cuts the time

Two CEOs on why security and AI readiness belong together Read More »

Healthcare leaders see a fatal cyber incident as inevitable

Healthcare leaders see a fatal cyber incident as inevitable 2026-06-26 at 08:00 By Mirko Zorz Healthcare practices run on a chain of outside vendors. An EMR system holds clinical records, a billing platform processes claims, a telehealth tool supports remote visits, and a cloud provider stores data. Every one of those connections gives an outside

Healthcare leaders see a fatal cyber incident as inevitable Read More »

Scroll to Top