News

Google’s newest sign-in method asks you to look at the camera

Google’s newest sign-in method asks you to look at the camera 2026-07-24 at 11:33 By Anamarija Pogorelec Google’s selfie video sign-in option verifies that an account owner is a real person and that the account wasn’t created or used by computer programs or bots for the purpose of abuse, such as spamming. It is not […]

Google’s newest sign-in method asks you to look at the camera Read More »

The automotive software vulnerabilities hiding in your dashboard

The automotive software vulnerabilities hiding in your dashboard 2026-07-24 at 09:30 By Anamarija Pogorelec Pop the hood on a new car and you won’t find much you can fix with a wrench. What you’ll find is software, and a lot of it. The screen in the dash probably runs Android or a flavor of Linux. […]

The automotive software vulnerabilities hiding in your dashboard Read More »

Governing Al agents at scale: Lessons from the leaders who’ve done it

Governing Al agents at scale: Lessons from the leaders who’ve done it 2026-07-24 at 09:00 By Help Net Security Enterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at scale. What you’ll take away: What an AI Center […]

Governing Al agents at scale: Lessons from the leaders who’ve done it Read More »

How attackers hosted a fake Claude download page on the claude.ai domain

How attackers hosted a fake Claude download page on the claude.ai domain 2026-07-23 at 16:12 By Zeljka Zorz A threat actor abused Anthropic’s Claude Artifacts feature to funnel users toward malware, Huntress researchers have disclosed. Employees at at least 29 organizations were compromised over two days in July, after searching for the Claude desktop app […]

How attackers hosted a fake Claude download page on the claude.ai domain Read More »

Months-long breach exposes South Korean diplomats’ personal data

Months-long breach exposes South Korean diplomats’ personal data 2026-07-23 at 14:04 By Sinisa Markovic South Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data belonging to current and former ministry staff and diplomats stationed abroad. The Korea National Diplomatic Academy launched the online training platform […]

Months-long breach exposes South Korean diplomats’ personal data Read More »

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) 2026-07-23 at 13:42 By Zeljka Zorz Attackers are exploiting a critical authentication bypass vulnerability (CVE-2026-16232) that affects Check Point Security Management and Multi-Domain Security Management, the management servers that push policy to Check Point security gateways (i.e., firewalls). “An unauthenticated attacker can obtain […]

Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232) Read More »

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process 2026-07-23 at 13:38 By Mirko Zorz Cisco Talos has identified a Rust-based remote access trojan it attributes to the Chaos ransomware group, named msaRAT after four of the binding names left in the binary. The tool starts its own instance of Chrome or […]

Chaos ransomware msaRAT hides its C2 channel inside a legitimate browser process Read More »

PyPI hardens package security with new upload restrictions

PyPI hardens package security with new upload restrictions 2026-07-23 at 12:31 By Anamarija Pogorelec The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s publishing tokens or release workflows are compromised. “This change will protect Python users and […]

PyPI hardens package security with new upload restrictions Read More »

Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack

Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack 2026-07-23 at 11:54 By Sinisa Markovic Cybercriminal group Everest is demanding 10 million Swiss francs ($12.3 million) from Swiss rail vehicle manufacturer Stadler after breaching a data exchange platform shared with one of its suppliers through compromised credentials. Stadler operates 16 production and […]

Swiss rail manufacturer Stadler refuses to pay $12.3 million ransom after cyberattack Read More »

GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub revamps bug bounty program with new VIP tier, payout changes 2026-07-23 at 11:35 By Anamarija Pogorelec GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will take effect on July 27, 2026. Reports submitted before that date will be honored under the […]

GitHub revamps bug bounty program with new VIP tier, payout changes Read More »

Shadow AI is becoming enterprise security’s biggest blind spot

Shadow AI is becoming enterprise security’s biggest blind spot 2026-07-23 at 09:00 By Help Net Security Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft communications, analyze spreadsheets, write code, build automations, and create AI-powered workflows across nearly every business function. Microsoft’s 2026 […]

Shadow AI is becoming enterprise security’s biggest blind spot Read More »

Product Showcase: AppViewX Agent Identity Security

Product Showcase: AppViewX Agent Identity Security 2026-07-23 at 08:30 By Help Net Security AI is multiplying enterprise identities as quantum computing reshapes the cryptographic trust that secures them, and enterprises need to solve both together. Traditional identity security was built for people with predictable, auditable access, not autonomous, short-lived agents that share credentials and break […]

Product Showcase: AppViewX Agent Identity Security Read More »

Multi-patch vulnerability fixes can leave open source exposed

Multi-patch vulnerability fixes can leave open source exposed 2026-07-23 at 08:00 By Mirko Zorz Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two […]

Multi-patch vulnerability fixes can leave open source exposed Read More »

The AI code vulnerabilities that grow with your app

The AI code vulnerabilities that grow with your app 2026-07-23 at 07:30 By Mirko Zorz Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps written from a spec, thrown together from a casual prompt, and rewritten […]

The AI code vulnerabilities that grow with your app Read More »

Building a defense in depth strategy for sensitive data

Building a defense in depth strategy for sensitive data 2026-07-23 at 07:00 By Help Net Security In this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data. He argues that a single control, like encrypting a disk or […]

Building a defense in depth strategy for sensitive data Read More »

OpenAI: Our models breached Hugging Face during a cyber capability test

OpenAI: Our models breached Hugging Face during a cyber capability test 2026-07-22 at 17:42 By Zeljka Zorz The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share […]

OpenAI: Our models breached Hugging Face during a cyber capability test Read More »

OpenAI Presence connects AI agents to enterprise data with built-in guardrails

OpenAI Presence connects AI agents to enterprise data with built-in guardrails 2026-07-22 at 17:01 By Sinisa Markovic OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a […]

OpenAI Presence connects AI agents to enterprise data with built-in guardrails Read More »

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) 2026-07-22 at 14:47 By Zeljka Zorz Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, […]

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) Read More »

US seizes over 1,000 domains used for illegal World Cup 2026 streams

US seizes over 1,000 domains used for illegal World Cup 2026 streams 2026-07-22 at 13:51 By Sinisa Markovic The US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves […]

US seizes over 1,000 domains used for illegal World Cup 2026 streams Read More »

Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter

Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter 2026-07-22 at 11:21 By Anamarija Pogorelec Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through […]

Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter Read More »

Scroll to Top