News

The AI security question leaders should be asking instead

The AI security question leaders should be asking instead 2026-09-17 at 08:30 By Mirko Zorz In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why […]

The AI security question leaders should be asking instead Read More »

A flat cybersecurity budget doesn’t have to mean weaker coverage

A flat cybersecurity budget doesn’t have to mean weaker coverage 2026-09-17 at 08:00 By Help Net Security Cheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader. In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut. […]

A flat cybersecurity budget doesn’t have to mean weaker coverage Read More »

AWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissions

AWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissions 2026-09-17 at 07:51 By Sinisa Markovic New AWS customers can now sign up with a Google, GitHub, or Apple login, start with $100 in Free Tier credits, and build inside a “project” where AWS and coding agents set up permissions automatically. Paid projects […]

AWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissions Read More »

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) 2026-09-16 at 15:36 By Zeljka Zorz A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger […]

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) Read More »

Self-improving AI should slow down, von der Leyen tells EU lawmakers

Self-improving AI should slow down, von der Leyen tells EU lawmakers 2026-09-16 at 14:28 By Mirko Zorz European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. In […]

Self-improving AI should slow down, von der Leyen tells EU lawmakers Read More »

CenterPoint Energy confirms data breach following claims on hacking forum

CenterPoint Energy confirms data breach following claims on hacking forum 2026-09-16 at 13:35 By Sinisa Markovic CenterPoint Energy disclosed that an unauthorized third party got into customer data through one of its external systems, after online claims by a hacker that millions of records had been stolen from the company. CenterPoint Energy is a Houston-based […]

CenterPoint Energy confirms data breach following claims on hacking forum Read More »

NIST and CISA finalize playbook to stop token theft and forgery

NIST and CISA finalize playbook to stop token theft and forgery 2026-09-16 at 10:40 By Anamarija Pogorelec NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, Theft, and Misuse (NIST IR […]

NIST and CISA finalize playbook to stop token theft and forgery Read More »

What happens when AI agent governance is missing at scale

What happens when AI agent governance is missing at scale 2026-09-16 at 09:00 By Mirko Zorz In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does, since […]

What happens when AI agent governance is missing at scale Read More »

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero: Open-source hunting for vulnerable Windows drivers 2026-09-16 at 08:30 By Mirko Zorz DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether […]

DeepZero: Open-source hunting for vulnerable Windows drivers Read More »

The modern attack chain: Rethinking Google Workspace security in the age of AI

The modern attack chain: Rethinking Google Workspace security in the age of AI 2026-09-16 at 08:00 By Help Net Security Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same […]

The modern attack chain: Rethinking Google Workspace security in the age of AI Read More »

MSPs say nearly half their customers rely on them for CISO services

MSPs say nearly half their customers rely on them for CISO services 2026-09-16 at 07:30 By Anamarija Pogorelec MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the […]

MSPs say nearly half their customers rely on them for CISO services Read More »

Postman Passport controls API access without exposing credentials

Postman Passport controls API access without exposing credentials 2026-09-15 at 16:40 By Industry News Postman has announced the general availability of Passport by Postman, marking the company’s expansion into API security with a standalone product that gives organizations a secure way to consume APIs as human and non-human identities increasingly work side by side. The […]

Postman Passport controls API access without exposing credentials Read More »

eBook: Identity-First Threat Intelligence

eBook: Identity-First Threat Intelligence 2026-09-15 at 16:00 By Help Net Security Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware accelerates credential theft, organizations need greater visibility into identity risk across Active Directory, IAM, and authentication environments. Download the […]

eBook: Identity-First Threat Intelligence Read More »

Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks

Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks 2026-09-15 at 15:32 By Sinisa Markovic A new AI subscription service called Luciferus is being marketed on a hacking forum as an alternative to jailbreaking ChatGPT or Claude, Sophos found. The Counter Threat Unit (CTU) spotted the advertisement on August 24 on […]

Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks Read More »

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) 2026-09-15 at 14:09 By Zeljka Zorz Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2025, and has shared […]

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) Read More »

Microsoft sets security and safety rules for its AI models

Microsoft sets security and safety rules for its AI models 2026-09-15 at 13:50 By Anamarija Pogorelec Microsoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during deployment. The draft is open for public consultation for six […]

Microsoft sets security and safety rules for its AI models Read More »

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz 2026-09-15 at 13:10 By Sinisa Markovic Attackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows devices with information-stealing malware. Screenshot of the fraudulent ad (Source: Alex Cutts) ClickFix has […]

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Read More »

Product showcase: mSecure makes one vault do more than remember passwords

Product showcase: mSecure makes one vault do more than remember passwords 2026-09-15 at 08:30 By Anamarija Pogorelec mSecure is a password manager and data vault for storing credentials and other sensitive information. It is available for iOS, Android, macOS, and Windows, with data synchronization across supported devices. The app uses AES-256 encryption and a zero-knowledge […]

Product showcase: mSecure makes one vault do more than remember passwords Read More »

Your employees are already using AI tools you never approved

Your employees are already using AI tools you never approved 2026-09-15 at 08:00 By Anamarija Pogorelec Seventy-four percent of respondents report departmental or scaled AI adoption at their organizations, including within individual teams or departments, across business functions, and as part of processes and operations, according to the latest OneTrust 2026 AI-Ready Governance Report. The […]

Your employees are already using AI tools you never approved Read More »

Most chief audit executives can’t tell you what AI is worth yet

Most chief audit executives can’t tell you what AI is worth yet 2026-09-15 at 07:30 By Sinisa Markovic Auditors are using AI in their daily work, and their departments have mostly left them to figure it out alone. 93% of audit leaders and auditors report some level of AI use, while 15% say their department […]

Most chief audit executives can’t tell you what AI is worth yet Read More »

Scroll to Top