News

NIS2 compliance: Fixing IAM and access control before the 2026 audit

NIS2 compliance: Fixing IAM and access control before the 2026 audit 2026-09-01 at 08:00 By Help Net Security The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into […]

NIS2 compliance: Fixing IAM and access control before the 2026 audit Read More »

What your vendor says about PQC tells you if they are ready

What your vendor says about PQC tells you if they are ready 2026-09-01 at 07:30 By Mirko Zorz In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity

What your vendor says about PQC tells you if they are ready Read More »

Cybersecurity jobs available right now: September 1, 2026

Cybersecurity jobs available right now: September 1, 2026 2026-09-01 at 07:00 By Sinisa Markovic Security Engineer, PSO Google | USA | On-site – View job details As a Security Engineer, you will provide technical guidance to customers adopting Google Cloud Platform, helping them navigate their cloud journey with the Professional Services team. The role includes

Cybersecurity jobs available right now: September 1, 2026 Read More »

Attackers plant remote access tools on compromised PaperCut servers

Attackers plant remote access tools on compromised PaperCut servers 2026-08-31 at 17:54 By Zeljka Zorz The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools The vendor

Attackers plant remote access tools on compromised PaperCut servers Read More »

Threat actors are posing as AI crawlers to hunt for exposed credentials

Threat actors are posing as AI crawlers to hunt for exposed credentials 2026-08-31 at 17:54 By Sinisa Markovic Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: GreyNoise) “Every program that visits

Threat actors are posing as AI crawlers to hunt for exposed credentials Read More »

AWS Console Private Access can block sign-ins to personal accounts

AWS Console Private Access can block sign-ins to personal accounts 2026-08-31 at 14:57 By Anamarija Pogorelec The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private clouds, the isolated networks customers run inside AWS, that have no

AWS Console Private Access can block sign-ins to personal accounts Read More »

ShinyHunters claims it stole 284 million patient records from McKesson

ShinyHunters claims it stole 284 million patient records from McKesson 2026-08-31 at 14:57 By Sinisa Markovic Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company that distributes pharmaceuticals, medical supplies and other healthcare products to pharmacies, hospitals and clinics. According

ShinyHunters claims it stole 284 million patient records from McKesson Read More »

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails 2026-08-31 at 12:45 By Sinisa Markovic Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails Read More »

Debian developers rejected an LLM ban and left disclosure voluntary

Debian developers rejected an LLM ban and left disclosure voluntary 2026-08-31 at 11:08 By Anamarija Pogorelec A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and Kurt Roeckx, the project secretary, announced the result:

Debian developers rejected an LLM ban and left disclosure voluntary Read More »

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree 2026-08-31 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity,

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree Read More »

Halo-record: Open-source audit trails for AI agents

Halo-record: Open-source audit trails for AI agents 2026-08-31 at 08:30 By Mirko Zorz Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each action becomes one line in a file that only ever gets appended to,

Halo-record: Open-source audit trails for AI agents Read More »

AI AppSec tools agree on just 5% of security findings

AI AppSec tools agree on just 5% of security findings 2026-08-31 at 08:23 By Sinisa Markovic Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Top types of viable application attacks (Source: Contrast Security) Contrast Security’s AppSec Overflow 2026 report draws on telemetry collected from

AI AppSec tools agree on just 5% of security findings Read More »

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited 2026-08-30 at 11:41 By Anamarija Pogorelec Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Unpatched Zimbra servers are falling to CVE-2026-73570 attacks At least 274 internet-facing Zimbra instances have been compromised by unknown attackers via CVE-2026-73570,

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited Read More »

North Korean remote workers are broadening their job hunt beyond IT

North Korean remote workers are broadening their job hunt beyond IT 2026-08-28 at 14:16 By Sinisa Markovic North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in sales and marketing and the medical profession. “DPRK workers present a unique detection challenge

North Korean remote workers are broadening their job hunt beyond IT Read More »

Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping

Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping 2026-08-28 at 12:28 By Sinisa Markovic Google introduced a batch of network security changes coming in Android 17, aimed at making it harder for network operators, snoops, and scammers to track what you do on your phone. “When you visit a website or

Android 17 adds new protections against sneaky Wi-Fi tracking and web snooping Read More »

Manchester Airports Group breached, millions of customers’ data stolen

Manchester Airports Group breached, millions of customers’ data stolen 2026-08-28 at 10:56 By Sinisa Markovic Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a “quantity” of customer data from three UK airports, the company has confirmed. The post Manchester Airports Group breached, millions of customers’ data stolen appeared first

Manchester Airports Group breached, millions of customers’ data stolen Read More »

What 90 days and a small budget can buy in AI agent security

What 90 days and a small budget can buy in AI agent security 2026-08-28 at 08:30 By Mirko Zorz In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing,

What 90 days and a small budget can buy in AI agent security Read More »

Scroll to Top