News

Microsoft gives Windows 10 users an unexpected extra year of free security updates

Microsoft gives Windows 10 users an unexpected extra year of free security updates 2026-06-26 at 09:32 By Sinisa Markovic Microsoft has given Windows 10 users another year of free security updates, extending its consumer Extended Security Updates (ESU) program until October 12, 2027. “Windows 10 support has ended. You can enroll in ESU any time […]

Microsoft gives Windows 10 users an unexpected extra year of free security updates Read More »

A privacy-first take on local malware analysis

A privacy-first take on local malware analysis 2026-06-26 at 09:00 By Sinisa Markovic Submitting a suspicious file to VirusTotal or MalwareBazaar places a copy of that file on a platform other people can search. Analysts across the industry rely on these services to get a quick verdict on whether a binary is dangerous. The convenience […]

A privacy-first take on local malware analysis Read More »

Two CEOs on why security and AI readiness belong together

Two CEOs on why security and AI readiness belong together 2026-06-26 at 08:30 By Mirko Zorz SuperOps and Guardz are bundling PSA, RMM, MDM, and agentic SecOps into one offering for MSPs. In this Help Net Security Q&A, SuperOps CEO Arvind Parthiban and Guardz CEO Dor Eisner explain how a connected stack cuts the time […]

Two CEOs on why security and AI readiness belong together Read More »

Healthcare leaders see a fatal cyber incident as inevitable

Healthcare leaders see a fatal cyber incident as inevitable 2026-06-26 at 08:00 By Mirko Zorz Healthcare practices run on a chain of outside vendors. An EMR system holds clinical records, a billing platform processes claims, a telehealth tool supports remote visits, and a cloud provider stores data. Every one of those connections gives an outside […]

Healthcare leaders see a fatal cyber incident as inevitable Read More »

Modelplane: Open-source control plane for AI inference

Modelplane: Open-source control plane for AI inference 2026-06-26 at 07:30 By Anamarija Pogorelec Organizations that run open-weight models on hardware they own operate GPU fleets spread across clouds, neoclouds, and on-premise data centers. Each fleet handles model placement, replica scaling, infrastructure provisioning, weight distribution, and traffic routing. Teams have built this coordination layer by hand, […]

Modelplane: Open-source control plane for AI inference Read More »

New infosec products of the month: June 2026

New infosec products of the month: June 2026 2026-06-26 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past month, featuring releases from AISLE, Asimily, Blue Planet, depthfirst, Diligent, Drata, Elastic, Filigran, Flip, Hyland, IDnow, Legit Security, MazeBolt, Noma, Qodo, Ridge Security, Tigera, and WitnessAI. Asimily turns device risk […]

New infosec products of the month: June 2026 Read More »

Stealthy new backdoor surfaces in attacks on multiple sectors

Stealthy new backdoor surfaces in attacks on multiple sectors 2026-06-25 at 17:07 By Sinisa Markovic A relatively new backdoor called Mistic has been deployed in multiple attacks since April 2026 targeting organizations in the insurance, education, IT, and professional services sectors, according to Symantec. The malware appears to be associated with Woodgnat, also known as […]

Stealthy new backdoor surfaces in attacks on multiple sectors Read More »

Hacker gets 18 months for attack that compromised 60,000 betting accounts

Hacker gets 18 months for attack that compromised 60,000 betting accounts 2026-06-25 at 13:18 By Sinisa Markovic A 21-year-old man known online as “Snoopy” was sentenced to 18 months in prison for his role in a scheme that hacked user accounts on a fantasy sports and betting website and sold access to them, causing hundreds […]

Hacker gets 18 months for attack that compromised 60,000 betting accounts Read More »

The uptime questions every engineering leader should ask this week

The uptime questions every engineering leader should ask this week 2026-06-25 at 09:30 By Mirko Zorz In this interview with Help Net Security, Mattias Geniar, CTO at Oh Dear, explains why most outages start quietly, as creeping latency or a slow rise in errors. He argues teams alert on the wrong things: absolute numbers instead […]

The uptime questions every engineering leader should ask this week Read More »

LLM security advice looks solid until you check the hard cases

LLM security advice looks solid until you check the hard cases 2026-06-25 at 09:00 By Anamarija Pogorelec Plenty of people now type their security worries straight into a chatbot. A hacked account, a suspicious email, a stalker who might be tracking a phone, all of it lands in the same window someone would use to […]

LLM security advice looks solid until you check the hard cases Read More »

Best practices for AI in open-source work

Best practices for AI in open-source work 2026-06-25 at 08:00 By Anamarija Pogorelec Free and open source software developers us AI coding assistants such as Claude Code, Copilot CLI, Antigravity, and OpenCode in their daily work. The Software Freedom Conservancy responded to that trend with a set of recommendations for contributors who use these tools, […]

Best practices for AI in open-source work Read More »

What your next cyber insurance renewal will demand

What your next cyber insurance renewal will demand 2026-06-25 at 07:30 By Help Net Security In this Help Net Security video, Michael Loewy, co-founder, Tide Foundation, explains how cyber insurance is rewriting security programs at renewal time. Insurers want more questionnaires, more evidence, and more attestations, because the market is moving from trusting your answers […]

What your next cyber insurance renewal will demand Read More »

Law enforcement hits StealC and Amadey malware networks

Law enforcement hits StealC and Amadey malware networks 2026-06-24 at 18:05 By Zeljka Zorz Operation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey. The notice on disrupted websites (Source: Microsoft) While developed by separate criminal groups, those two […]

Law enforcement hits StealC and Amadey malware networks Read More »

Algerian national accused of running cybercrime marketplaces extradited to US

Algerian national accused of running cybercrime marketplaces extradited to US 2026-06-24 at 17:09 By Sinisa Markovic An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges. The post Algerian national accused of running cybercrime marketplaces […]

Algerian national accused of running cybercrime marketplaces extradited to US Read More »

Anthropic’s Claude Tag gives AI agents independent identities

Anthropic’s Claude Tag gives AI agents independent identities 2026-06-24 at 16:56 By Anamarija Pogorelec Anthropic introduced an agent identity model for Claude Tag, its AI assistant designed for team collaboration in shared workspaces. The model gives Claude its own identity, permissions, and tool access, configured by administrators and tied to a workspace or channel. Because […]

Anthropic’s Claude Tag gives AI agents independent identities Read More »

Phishing attack on healthcare firm Xsolis impacts 1.4 million people

Phishing attack on healthcare firm Xsolis impacts 1.4 million people 2026-06-24 at 15:00 By Sinisa Markovic Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January […]

Phishing attack on healthcare firm Xsolis impacts 1.4 million people Read More »

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230)

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) 2026-06-24 at 14:36 By Zeljka Zorz CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells, all […]

Cisco Unified CM flaw actively exploited to drop webshells (CVE-2026-20230) Read More »

LastPass customer data exposed through Klue supply chain attack

LastPass customer data exposed through Klue supply chain attack 2026-06-24 at 12:59 By Sinisa Markovic LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. “On June 12th […]

LastPass customer data exposed through Klue supply chain attack Read More »

Google Workspace expands password reset alerts to all admins

Google Workspace expands password reset alerts to all admins 2026-06-24 at 12:07 By Anamarija Pogorelec Google’s Alert Center, a dashboard in the Google Admin console that displays security and administrative alerts and helps administrators identify, investigate, and respond to issues affecting their organization, is expanding the “Super Admin password reset” alert into the “Admin password […]

Google Workspace expands password reset alerts to all admins Read More »

Scroll to Top