News

Prismor: Open-source runtime control plane for AI agents

Prismor: Open-source runtime control plane for AI agents 2026-09-23 at 08:30 By Anamarija Pogorelec Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before […]

Prismor: Open-source runtime control plane for AI agents Read More »

Product showcase: Scamwise checks the red flags before you take the bait

Product showcase: Scamwise checks the red flags before you take the bait 2026-09-23 at 08:00 By Anamarija Pogorelec Scamwise is a free scam-checking service from Savi that examines suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud. The service works in any web browser on desktop, mobile, or tablet, with […]

Product showcase: Scamwise checks the red flags before you take the bait Read More »

Researchers uncover malware that uses AI to choose its next move

Researchers uncover malware that uses AI to choose its next move 2026-09-22 at 16:56 By Sinisa Markovic To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata […]

Researchers uncover malware that uses AI to choose its next move Read More »

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page 2026-09-22 at 16:46 By Zeljka Zorz Three domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future […]

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page Read More »

The latest deepfake numbers give CISOs plenty to worry about

The latest deepfake numbers give CISOs plenty to worry about 2026-09-22 at 15:05 By Sinisa Markovic AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to […]

The latest deepfake numbers give CISOs plenty to worry about Read More »

The next intellectual property thief may sound like your CEO

The next intellectual property thief may sound like your CEO 2026-09-22 at 15:00 By Anamarija Pogorelec Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most […]

The next intellectual property thief may sound like your CEO Read More »

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) 2026-09-22 at 13:42 By Zeljka Zorz A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the […]

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) Read More »

Somewhere in your traffic logs, a bot is doing more than looking

Somewhere in your traffic logs, a bot is doing more than looking 2026-09-22 at 13:30 By Mirko Zorz Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of its global customers, ecommerce accounted for 44.8% of those AI bot POST transactions, […]

Somewhere in your traffic logs, a bot is doing more than looking Read More »

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions 2026-09-22 at 11:54 By Sinisa Markovic Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this […]

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions Read More »

A cheap fake base station can still track 5G subscribers

A cheap fake base station can still track 5G subscribers 2026-09-22 at 09:30 By Anamarija Pogorelec Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G […]

A cheap fake base station can still track 5G subscribers Read More »

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit 2026-09-22 at 08:00 By Help Net Security By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable […]

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit Read More »

European AI spending is on track to reach nearly $470 billion by 2030

European AI spending is on track to reach nearly $470 billion by 2030 2026-09-22 at 07:30 By Mirko Zorz European organizations will spend nearly $470 billion on AI in 2030, IDC forecasts, with spending growing at a compound annual rate of 35% from 2025. At that rate, the market more than quadruples in five years. […]

European AI spending is on track to reach nearly $470 billion by 2030 Read More »

Cybersecurity jobs available right now: September 22, 2026

Cybersecurity jobs available right now: September 22, 2026 2026-09-22 at 07:00 By Anamarija Pogorelec Analyst Threat Intelligence Optimum | USA | On-site – View job details As an Analyst Threat Intelligence, you will collect and analyze intelligence to identify threats, threat actors, malware campaigns, and relevant TTPs. You will map adversary behavior to MITRE ATT&CK, […]

Cybersecurity jobs available right now: September 22, 2026 Read More »

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files 2026-09-21 at 17:00 By Mirko Zorz Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi […]

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files Read More »

Google hit with €403 million GDPR fine over location tracking

Google hit with €403 million GDPR fine over location tracking 2026-09-21 at 15:23 By Anamarija Pogorelec Ireland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six months. The inquiry examined Google’s practices from […]

Google hit with €403 million GDPR fine over location tracking Read More »

Scammers impersonate cops, use arrest threats to extort victims

Scammers impersonate cops, use arrest threats to extort victims 2026-09-21 at 13:53 By Sinisa Markovic Scammers are posing as police officers and federal agents, threatening arrest unless victims pay up, the FBI warns. The FBI’s Internet Crime Complaint Center (IC3) updated an alert it first issued in 2022, citing “losses totaling more than $1.6 billion” […]

Scammers impersonate cops, use arrest threats to extort victims Read More »

Hackers exploit Gyazo server flaw to steal 23.6 million user records

Hackers exploit Gyazo server flaw to steal 23.6 million user records 2026-09-21 at 11:57 By Sinisa Markovic Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions […]

Hackers exploit Gyazo server flaw to steal 23.6 million user records Read More »

Know what was tested before your SAP ECC migration goes live

Know what was tested before your SAP ECC migration goes live 2026-09-21 at 09:00 By Mirko Zorz In this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that […]

Know what was tested before your SAP ECC migration goes live Read More »

Product showcase: Helmit alerts parents when online conversations show signs of trouble

Product showcase: Helmit alerts parents when online conversations show signs of trouble 2026-09-21 at 08:30 By Anamarija Pogorelec Helmit is a parental control app that combines AI-powered social media monitoring with screen time management, web filtering, location tracking, and safety alerts. It identifies potentially concerning interactions and surface the messages associated with an alert. Helmit […]

Product showcase: Helmit alerts parents when online conversations show signs of trouble Read More »

Scroll to Top