News

Your work apps are quietly handing 19 data points to someone

Your work apps are quietly handing 19 data points to someone 2026-05-04 at 09:46 By Mirko Zorz Office work in 2026 runs through a stack of mobile apps that sit on the same phones people use for banking, messaging family, and tracking their location. Ten of the most common workplace apps in use across U.S. […]

Your work apps are quietly handing 19 data points to someone Read More »

Brush shell 0.4.0 tightens script safety, widens platform support

Brush shell 0.4.0 tightens script safety, widens platform support 2026-05-04 at 09:16 By Sinisa Markovic Rust-based alternatives to traditional Unix shells continue to attract users who want bash compatibility alongside built-in features like syntax highlighting and history-based suggestions. Brush, a bash- and POSIX-compatible shell written in Rust, sits in that group, and version 0.4.0 brings […]

Brush shell 0.4.0 tightens script safety, widens platform support Read More »

ChatGPT advanced account security adds passkeys and hardware keys

ChatGPT advanced account security adds passkeys and hardware keys 2026-05-04 at 02:31 By Anamarija Pogorelec Journalists, elected officials, researchers, and political dissidents have spent years adapting their accounts to phishing-resistant authentication on consumer platforms. ChatGPT now joins that list. OpenAI has introduced Advanced Account Security, an opt-in setting that strips password-based sign-in from ChatGPT and […]

ChatGPT advanced account security adds passkeys and hardware keys Read More »

Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months

Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months 2026-05-03 at 12:54 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: The AI criminal mastermind is already hiring on gig platforms Labor-hire platforms let anyone with a credit card […]

Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Read More »

Download: Automating Pentest Delivery Guide

Download: Automating Pentest Delivery Guide 2026-05-01 at 18:21 By Help Net Security Pentesting remains one of the most effective ways to identify real-world weaknesses, but the method for delivering results hasn’t evolved. Manual workflows involving static documents and email threads introduce delays, create inefficiencies, and diminish the value of the work. This guide on Automating […]

Download: Automating Pentest Delivery Guide Read More »

Shadow AI risks deepen as 31% of users get no employer training

Shadow AI risks deepen as 31% of users get no employer training 2026-05-01 at 11:49 By Anamarija Pogorelec Between one-fifth and one-third of workers use AI outside the influence and governance of the IT function, according to a global survey of 6,000 full-time employees at enterprise organizations. Researchers found a widening gap between employee AI […]

Shadow AI risks deepen as 31% of users get no employer training Read More »

Open-source privacy proxy masks PII before prompts reach external AI services

Open-source privacy proxy masks PII before prompts reach external AI services 2026-05-01 at 11:49 By Sinisa Markovic Enterprise developers routinely send prompts to external large language models that contain customer emails, support transcripts, and other identifying information, often without a sanitization layer between the application and the API. Dataiku has released Kiji Privacy Proxy, an […]

Open-source privacy proxy masks PII before prompts reach external AI services Read More »

AI traffic is getting bigger, louder, and less predictable

AI traffic is getting bigger, louder, and less predictable 2026-05-01 at 11:49 By Anamarija Pogorelec AI workflows need storage that supports repeated movement across the model lifecycle. Large datasets are ingested, transformed, exported for training, pulled back for evaluation, and refreshed as models evolve. Backblaze’s Q1 2026 Network Stats report says this creates a shift […]

AI traffic is getting bigger, louder, and less predictable Read More »

New infosec products of the month: April 2026

New infosec products of the month: April 2026 2026-05-01 at 07:03 By Anamarija Pogorelec Here’s a look at the most interesting products from the past month, featuring releases from Advenica, Aptori, Axonius, Broadcom, GlobalSign, Intruder, IP Fabric, Mallory, Secureframe, Siemens, Sitehop, and Virtue AI. Mallory brings contextual threat intelligence to security operations Mallory is launching […]

New infosec products of the month: April 2026 Read More »

Incident Response Retainers Are Now Foundational to Cyber Resilience

Incident Response Retainers Are Now Foundational to Cyber Resilience 2026-04-30 at 17:35 By LevelBlue has been named a Representative Service Provider in the Gartner® Market Guide for Cybersecurity Incident Response Retainer Services (CIRR), marking the fifth consecutive time the company has been included in the report. We believe this continued recognition reflects LevelBlue’s ongoing focus […]

Incident Response Retainers Are Now Foundational to Cyber Resilience Read More »

cPanel zero-day exploited for months before patch release (CVE-2026-41940)

cPanel zero-day exploited for months before patch release (CVE-2026-41940) 2026-04-30 at 16:45 By Zeljka Zorz A critical authentication bypass vulnerability (CVE-2026-41940) in cPanel, a popular web-based control panel for managing web hosting accounts, is being exploited by attackers in the wild. What’s more, attackers didn’t have to wait for watchTowr security researchers to release technical […]

cPanel zero-day exploited for months before patch release (CVE-2026-41940) Read More »

Cisco releases open-source toolkit for verifying AI model lineage

Cisco releases open-source toolkit for verifying AI model lineage 2026-04-30 at 16:02 By Mirko Zorz Enterprises pulling models from Hugging Face and other open repositories rarely keep records of how those models are altered after download, leaving organizations with little ability to confirm what they are running in production. The State of AI Security 2026 […]

Cisco releases open-source toolkit for verifying AI model lineage Read More »

Met Police face criticism for using AI to spy on their own officers

Met Police face criticism for using AI to spy on their own officers 2026-04-30 at 15:31 By Sinisa Markovic London police officers have been warned by the Metropolitan Police Federation to watch their backs after the force deployed controversial AI software to investigate misconduct. The staff association, representing more than 30,000 officers in London, reported […]

Met Police face criticism for using AI to spy on their own officers Read More »

Proxmox Backup Server 4.2 arrives with S3 storage support and parallel sync jobs

Proxmox Backup Server 4.2 arrives with S3 storage support and parallel sync jobs 2026-04-30 at 15:31 By Anamarija Pogorelec Proxmox Backup Server 4.2 is a maintenance and feature update built on Debian 13.4 “Trixie” that adds S3-compatible object storage as a supported backend and introduces parallel processing for sync jobs. The server ships the new […]

Proxmox Backup Server 4.2 arrives with S3 storage support and parallel sync jobs Read More »

Researchers develop tool to expose GPS signal spoofing in transit networks

Researchers develop tool to expose GPS signal spoofing in transit networks 2026-04-30 at 15:31 By Anamarija Pogorelec The Oak Ridge National Laboratory (ORNL) has developed a portable detector that identifies GPS spoofing in real time, including during motion, to help protect transportation systems. Spoofing involves transmitting counterfeit signals that imitate authentic GPS transmissions and produce […]

Researchers develop tool to expose GPS signal spoofing in transit networks Read More »

Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431)

Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) 2026-04-30 at 15:31 By Zeljka Zorz Security researchers at Theori have disclosed a high-severity local privilege escalation (LPE) vulnerability (CVE-2026-31431) in the Linux kernel. The flaw, nicknamed “Copy Fail”, has affected virtually every major Linux distribution shipped since 2017, and a working proof-of-concept (PoC) exploit […]

Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Read More »

Hackers arrested for stealing and reselling 600,000 Roblox accounts

Hackers arrested for stealing and reselling 600,000 Roblox accounts 2026-04-30 at 15:31 By Sinisa Markovic Ukrainian police detained three suspects accused of hacking into Roblox accounts and reselling the data on Russian websites, with payments made in cryptocurrency. Police raid (Source: The Prosecutor General’s Office of Ukraine) “Prosecutors of the Lviv region, together with the […]

Hackers arrested for stealing and reselling 600,000 Roblox accounts Read More »

FIDO Alliance wants to keep AI agents from going rogue on online payments

FIDO Alliance wants to keep AI agents from going rogue on online payments 2026-04-29 at 05:30 By Sinisa Markovic AI agents are beginning to shop, log in, and complete tasks with little direct input. That shift is pushing the security industry to rethink how trust works when actions are carried out on a user’s behalf. […]

FIDO Alliance wants to keep AI agents from going rogue on online payments Read More »

ShinyHunters claims it stole 1.4 million records from Udemy

ShinyHunters claims it stole 1.4 million records from Udemy 2026-04-28 at 22:35 By Sinisa Markovic The ShinyHunters group claims it has breached the Udemy, one of the world’s largest online learning platforms. According to Have I Been Pwned, the leaked dataset contained 1.4 million unique email addresses of customers and instructors, along with names, physical […]

ShinyHunters claims it stole 1.4 million records from Udemy Read More »

Police arrest 10 suspected members of Black Axe cybercrime gang

Police arrest 10 suspected members of Black Axe cybercrime gang 2026-04-28 at 22:35 By Sinisa Markovic A coordinated police operation in Switzerland has targeted suspected members of the Black Axe criminal network. On 28 April 2026, authorities carried out house searches across several Swiss cantons, leading to 10 arrests, including the Black Axe ‘Regional Head’ […]

Police arrest 10 suspected members of Black Axe cybercrime gang Read More »

Scroll to Top