News

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers 2026-08-03 at 16:51 By Sinisa Markovic A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s […]

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers Read More »

CISA lays out new guidance for using open-source software

CISA lays out new guidance for using open-source software 2026-08-03 at 14:53 By Anamarija Pogorelec The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, and evaluating open

CISA lays out new guidance for using open-source software Read More »

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) 2026-08-03 at 14:42 By Zeljka Zorz A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) Read More »

Qodana 2026.2 adds post-quantum crypto checks for JVM code

Qodana 2026.2 adds post-quantum crypto checks for JVM code 2026-08-03 at 14:21 By Anamarija Pogorelec Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports. The security work sits in the .NET linter and runs by default. Qodana tracks

Qodana 2026.2 adds post-quantum crypto checks for JVM code Read More »

OpenAI reveals how criminals used ChatGPT to run scams

OpenAI reveals how criminals used ChatGPT to run scams 2026-08-03 at 11:40 By Anamarija Pogorelec OpenAI banned a coordinated network of ChatGPT accounts that likely originated in Cambodia’s Preah Sihanouk province, a region reports have linked to online scam compounds and human trafficking operations. The network used the company’s models to create and manage fake

OpenAI reveals how criminals used ChatGPT to run scams Read More »

Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support

Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support 2026-08-03 at 11:31 By Mirko Zorz Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them enough room to tamper with memory

Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support Read More »

Mapping the malware blast radius a single alert won’t show you

Mapping the malware blast radius a single alert won’t show you 2026-08-03 at 09:00 By Mirko Zorz In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through

Mapping the malware blast radius a single alert won’t show you Read More »

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills 2026-08-03 at 08:30 By Anamarija Pogorelec SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a Git URL, and it returns a list of

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills Read More »

AI cut phishing from hours to seconds, which is where DMARC and BIMI come in

AI cut phishing from hours to seconds, which is where DMARC and BIMI come in 2026-08-03 at 08:00 By Help Net Security In this Help Net Security video, Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, unpack the evolution of email security and why it

AI cut phishing from hours to seconds, which is where DMARC and BIMI come in Read More »

Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan

Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan 2026-08-03 at 07:30 By Anamarija Pogorelec Guardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and receive alerts about emerging threats from a single application. It is available on smartphones and

Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan Read More »

Buying TikTok followers can expose users to scams and account theft

Buying TikTok followers can expose users to scams and account theft 2026-08-03 at 07:00 By Anamarija Pogorelec Buying TikTok followers, likes, or views could do more than inflate engagement metrics. According to Malwarebytes, many services selling social media growth operate through deceptive practices that can expose customers to scams, stolen accounts, and financial loss. The

Buying TikTok followers can expose users to scams and account theft Read More »

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released 2026-08-02 at 11:00 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released Read More »

Cybercrime goes subscription: AI, malware and infrastructure on demand

Cybercrime goes subscription: AI, malware and infrastructure on demand 2026-07-31 at 16:55 By Anamarija Pogorelec Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling

Cybercrime goes subscription: AI, malware and infrastructure on demand Read More »

Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire

Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire 2026-07-31 at 15:19 By Sinisa Markovic A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses

Criminals used AI and children’s coding software to build a multimillion-dollar ad fraud empire Read More »

Anthropic’s Claude breached three companies during security tests

Anthropic’s Claude breached three companies during security tests 2026-07-31 at 12:41 By Sinisa Markovic Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting

Anthropic’s Claude breached three companies during security tests Read More »

Aviation cyber risk sits on the ground, the blindness sits in the air

Aviation cyber risk sits on the ground, the blindness sits in the air 2026-07-31 at 08:30 By Mirko Zorz In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in

Aviation cyber risk sits on the ground, the blindness sits in the air Read More »

Companies push AI, sysadmins keep it on a short leash

Companies push AI, sysadmins keep it on a short leash 2026-07-31 at 08:00 By Anamarija Pogorelec In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic. The largest shortfalls appeared

Companies push AI, sysadmins keep it on a short leash Read More »

AI agents are changing where cybersecurity seed funding lands

AI agents are changing where cybersecurity seed funding lands 2026-07-31 at 07:30 By Anamarija Pogorelec Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed

AI agents are changing where cybersecurity seed funding lands Read More »

New infosec products of the week: July 31, 2026

New infosec products of the week: July 31, 2026 2026-07-31 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm Security, Reco, Root Evidence, and ZeroFox. BlackCloak extends deepfake protection to the executive’s trusted circle Deepfakes have made

New infosec products of the week: July 31, 2026 Read More »

AI takes on a bigger role in finding Chrome vulnerabilities

AI takes on a bigger role in finding Chrome vulnerabilities 2026-07-30 at 20:01 By Sinisa Markovic Google has expanded the use of AI in Chrome’s security workflow, using it to find vulnerabilities, triage bug reports, generate patches, and review code to shorten the time between discovering software flaws and delivering security updates. “Historically, triaging a

AI takes on a bigger role in finding Chrome vulnerabilities Read More »

Scroll to Top