News

SingGuard-NSFA: Open-source guardrails for agentic AI

SingGuard-NSFA: Open-source guardrails for agentic AI 2026-07-15 at 08:30 By Anamarija Pogorelec SingGuard-NSFA is an open-source guardrail framework aimed at operational threats in agent workflows. Four models ship at 0.8B, 2B, 4B, and 9B parameters, all built on Qwen3.5 base backbones. Risk taxonomy The NSFA risk taxonomy organizes threats along the CIA triad of confidentiality, […]

SingGuard-NSFA: Open-source guardrails for agentic AI Read More »

The MDR renewal question: What changes when AI can handle the alerts

The MDR renewal question: What changes when AI can handle the alerts 2026-07-15 at 08:00 By Help Net Security For most of the past decade, the managed detection and response (MDR) decision was a simple one: teams that couldn’t staff a 24/7 SOC outsourced detection and response to a provider who could. It solved a […]

The MDR renewal question: What changes when AI can handle the alerts Read More »

An AI overthinking attack can tie a robot up for over a minute

An AI overthinking attack can tie a robot up for over a minute 2026-07-15 at 07:30 By Anamarija Pogorelec Robots that read the world through cameras now lean on large vision-language models to interpret what they see and decide what to do next. These models handle images and text together, so any words that fall […]

An AI overthinking attack can tie a robot up for over a minute Read More »

SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410)

SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410) 2026-07-14 at 20:40 By Zeljka Zorz SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise. If the outlined […]

SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410) Read More »

New macOS malware steals passwords by posing as Apple’s crash-reporting tool

New macOS malware steals passwords by posing as Apple’s crash-reporting tool 2026-07-14 at 16:46 By Sinisa Markovic Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under […]

New macOS malware steals passwords by posing as Apple’s crash-reporting tool Read More »

Download: The ultimate guide to network operations management

Download: The ultimate guide to network operations management 2026-07-14 at 16:00 By Anamarija Pogorelec Modern network operations are too manual. Today’s IT and security teams are managing growing complexity across networks, infrastructure, tools, and workflows. The result? Slower response, duplicated effort, and operational friction. This guide explores how intelligent workflows help teams reduce manual work, […]

Download: The ultimate guide to network operations management Read More »

“Context bombs” can frustrate AI-driven attacks, researchers found

“Context bombs” can frustrate AI-driven attacks, researchers found 2026-07-14 at 15:27 By Zeljka Zorz A new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn’t the technique – prompt injection is old news – but the direction it’s pointed: not […]

“Context bombs” can frustrate AI-driven attacks, researchers found Read More »

Google adds FIDO2 keys and phone passkeys to Windows login via GCPW

Google adds FIDO2 keys and phone passkeys to Windows login via GCPW 2026-07-14 at 13:35 By Anamarija Pogorelec Google has started rolling out FIDO2-compliant physical security key support as a second factor for authentication in Google Credential Provider for Windows (GCPW) to all Google Workspace customers. GCPW is a free tool that lets users sign […]

Google adds FIDO2 keys and phone passkeys to Windows login via GCPW Read More »

No one knows how many old shims can still bypass UEFI Secure Boot

No one knows how many old shims can still bypass UEFI Secure Boot 2026-07-14 at 13:26 By Mirko Zorz The vast majority of UEFI computers carry a Microsoft certificate that will trust a small first-stage loader called a shim, a program Microsoft signs so that Linux and assorted boot tools can run with Secure Boot […]

No one knows how many old shims can still bypass UEFI Secure Boot Read More »

UK charges five persons linked to fraud platform behind more than a million scam calls

UK charges five persons linked to fraud platform behind more than a million scam calls 2026-07-14 at 12:18 By Sinisa Markovic Five people have been charged in the UK following a National Crime Agency (NCA) investigation into Russian Coms, a caller ID spoofing service used by fraudsters. Ayoub Sehailia, 28, Zakkaria Sehailia, 30, Usman Din, […]

UK charges five persons linked to fraud platform behind more than a million scam calls Read More »

Microsoft Entra ID authentication overhaul to start in September 2026

Microsoft Entra ID authentication overhaul to start in September 2026 2026-07-14 at 11:49 By Anamarija Pogorelec Microsoft will begin rolling out passkeys as the default authentication experience for Microsoft Entra ID in the public cloud on September 1, 2026. Organizations with SMS or voice authentication enabled will automatically be enabled for passkeys. The next time […]

Microsoft Entra ID authentication overhaul to start in September 2026 Read More »

New tutorials on underground hacking forums have roughly doubled

New tutorials on underground hacking forums have roughly doubled 2026-07-14 at 09:30 By Sinisa Markovic Underground hacking forums are producing more original tutorials again, with growing attention on financial fraud, particularly the theft and fraudulent use of payment card data, known as carding, and cash-out techniques. New tutorials per month versus reposts (Source: Radware) Fraud […]

New tutorials on underground hacking forums have roughly doubled Read More »

The best defense against AI attacks turns out to be a skeptical human

The best defense against AI attacks turns out to be a skeptical human 2026-07-14 at 09:00 By Mirko Zorz Analysts across the security industry now run generative AI through their daily work, from log triage to incident write-ups. Active use in cybersecurity strategy reached 78% of practitioners in 2026, up from half the field a […]

The best defense against AI attacks turns out to be a skeptical human Read More »

Fake smart home residents could stand in for real ones in security research

Fake smart home residents could stand in for real ones in security research 2026-07-14 at 08:30 By Anamarija Pogorelec Smart home security research runs on a scarce ingredient: recordings of how real people use the gadgets in their homes. Getting that data means wiring up someone’s house and watching for months, which is slow, costly, […]

Fake smart home residents could stand in for real ones in security research Read More »

Chatto: Open-source team messenger with privacy at its core

Chatto: Open-source team messenger with privacy at its core 2026-07-14 at 07:30 By Anamarija Pogorelec Teams that want their group chats off commercial platforms have a growing menu of self-hosted options. Chatto joined that group when its developer released the code under an open-source license and posted binaries for anyone to run on their own […]

Chatto: Open-source team messenger with privacy at its core Read More »

Cybersecurity jobs available right now: July 14, 2026

Cybersecurity jobs available right now: July 14, 2026 2026-07-14 at 07:00 By Anamarija Pogorelec Cyber Network Engineer Fiserv | USA | On-site – View job details As a Cyber Network Engineer, you will lead the design, governance, and security review of enterprise network architectures across on-premises and cloud environments. You will provide expertise in network […]

Cybersecurity jobs available right now: July 14, 2026 Read More »

Hackers breach Lidl’s IT service provider, steal customer data

Hackers breach Lidl’s IT service provider, steal customer data 2026-07-13 at 19:34 By Sinisa Markovic German discount supermarket chain Lidl has notified customers in Germany, Belgium, and the Netherlands that customer data was stolen after attackers breached one of its IT service providers. In notices published on its support websites in Belgium and the Netherlands, […]

Hackers breach Lidl’s IT service provider, steal customer data Read More »

EU and UK blacklist Russia’s cyber operators over efforts to destabilize Europe

EU and UK blacklist Russia’s cyber operators over efforts to destabilize Europe 2026-07-13 at 17:52 By Sinisa Markovic The EU and the UK jointly sanctioned dozens of Russian individuals and entities, accusing Moscow of coordinating a malicious cyber ecosystem targeting Europe, its member states, and international partners. The UK sanctioned 24 individuals and entities, while […]

EU and UK blacklist Russia’s cyber operators over efforts to destabilize Europe Read More »

Ransomware negotiator who betrayed clients sentenced to 70 months in prison

Ransomware negotiator who betrayed clients sentenced to 70 months in prison 2026-07-13 at 15:22 By Sinisa Markovic A former ransomware negotiator at incident response firm DigitalMint has been sentenced to 70 months in prison after admitting he shared confidential client information with the BlackCat ransomware group and later helped carry out ransomware attacks. Prosecutors say […]

Ransomware negotiator who betrayed clients sentenced to 70 months in prison Read More »

Fake OAuth client IDs are helping attackers slip past sign-in logs

Fake OAuth client IDs are helping attackers slip past sign-in logs 2026-07-13 at 15:10 By Mirko Zorz Attackers running account enumeration against Microsoft cloud tenants have added a step that keeps their probing out of the usual telemetry. They spoof the OAuth client ID, the globally unique identifier assigned to an application and passed as […]

Fake OAuth client IDs are helping attackers slip past sign-in logs Read More »

Scroll to Top