News

Gopass: Open-source command-line password manager for teams

Gopass: Open-source command-line password manager for teams 2026-09-21 at 08:00 By Anamarija Pogorelec Gopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager. Out of the box, Gopass encrypts each […]

Gopass: Open-source command-line password manager for teams Read More »

Intent injection attacks are a new worry for AI-native 6G networks

Intent injection attacks are a new worry for AI-native 6G networks 2026-09-21 at 07:30 By Sinisa Markovic Intent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have moved to the forefront. Researchers at the University of Ottawa and Nokia Bell […]

Intent injection attacks are a new worry for AI-native 6G networks Read More »

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor 2026-09-21 at 07:00 By Anamarija Pogorelec Forty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said […]

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor Read More »

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach 2026-09-20 at 11:00 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What we know about the Revolut data breach so far Someone impersonating a government agency, using an email address on that agency’s […]

Week in review: Cisco patches exploited email gateway 0-day, Revolut breach Read More »

Bots with good manners are better at fooling people on social media

Bots with good manners are better at fooling people on social media 2026-09-18 at 13:15 By Sinisa Markovic Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability […]

Bots with good manners are better at fooling people on social media Read More »

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched 2026-09-18 at 11:49 By Sinisa Markovic Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the […]

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched Read More »

Android apps can now check security patches down to individual device components

Android apps can now check security patches down to individual device components 2026-09-18 at 11:38 By Anamarija Pogorelec New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status […]

Android apps can now check security patches down to individual device components Read More »

Abandoned IoT apps keep sending sensitive data to broken servers

Abandoned IoT apps keep sending sensitive data to broken servers 2026-09-18 at 09:00 By Sinisa Markovic Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned […]

Abandoned IoT apps keep sending sensitive data to broken servers Read More »

Hardcoded MCP credentials found in public GitHub files

Hardcoded MCP credentials found in public GitHub files 2026-09-18 at 08:30 By Anamarija Pogorelec Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The […]

Hardcoded MCP credentials found in public GitHub files Read More »

98% of fraudulent hires have company credentials by the time they’re caught

98% of fraudulent hires have company credentials by the time they’re caught 2026-09-18 at 08:00 By Anamarija Pogorelec A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can […]

98% of fraudulent hires have company credentials by the time they’re caught Read More »

Most WordPress pros still lack a breach recovery plan

Most WordPress pros still lack a breach recovery plan 2026-09-18 at 07:30 By Anamarija Pogorelec Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners […]

Most WordPress pros still lack a breach recovery plan Read More »

New infosec products of the week: September 18, 2026

New infosec products of the week: September 18, 2026 2026-09-18 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Dataminr Advanced for Corporate […]

New infosec products of the week: September 18, 2026 Read More »

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE 2026-09-17 at 16:12 By Sinisa Markovic Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS […]

Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE Read More »

A fake ChatGPT billing email is after your OpenAI password

A fake ChatGPT billing email is after your OpenAI password 2026-09-17 at 16:01 By Anamarija Pogorelec A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google […]

A fake ChatGPT billing email is after your OpenAI password Read More »

Download: The IT leader’s guide to AI code sprawl

Download: The IT leader’s guide to AI code sprawl 2026-09-17 at 16:00 By Help Net Security AI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, often without knowing they’ve created something that needs governing at all. The result: AI code […]

Download: The IT leader’s guide to AI code sprawl Read More »

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys 2026-09-17 at 15:51 By Zeljka Zorz Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and […]

CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys Read More »

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) 2026-09-17 at 13:24 By Zeljka Zorz Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460 Cisco ISE is […]

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) Read More »

Scammers leave AI fingerprints all over fake antivirus renewal page

Scammers leave AI fingerprints all over fake antivirus renewal page 2026-09-17 at 13:10 By Sinisa Markovic AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that was more polished than most sites […]

Scammers leave AI fingerprints all over fake antivirus renewal page Read More »

Spain reports first data breach involving autonomous AI agent

Spain reports first data breach involving autonomous AI agent 2026-09-17 at 11:39 By Sinisa Markovic Spain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company’s network, found a way to alter personal records, and pulled invoice data. […]

Spain reports first data breach involving autonomous AI agent Read More »

Fake AI trading agent steals crypto wallet passwords

Fake AI trading agent steals crypto wallet passwords 2026-09-17 at 11:00 By Anamarija Pogorelec Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between […]

Fake AI trading agent steals crypto wallet passwords Read More »

Scroll to Top