News

European AI spending set to hit $290 billion by 2029

European AI spending set to hit $290 billion by 2029 2026-04-16 at 07:47 By Sinisa Markovic European enterprises are committing serious money to AI, and the numbers are accelerating. According to IDC’s Worldwide AI and Generative AI Spending Guide, AI spending across Europe will reach $290 billion by 2029, growing at a compound annual growth […]

European AI spending set to hit $290 billion by 2029 Read More »

Wi-Fi roaming security practices for access network providers and identity providers

Wi-Fi roaming security practices for access network providers and identity providers 2026-04-16 at 07:47 By Anamarija Pogorelec Public Wi-Fi roaming networks carry authentication credentials across multiple administrative boundaries, and the protocols governing that process vary widely in their security properties. The Wireless Broadband Alliance published a set of guidelines that specifies which authentication, encryption, and […]

Wi-Fi roaming security practices for access network providers and identity providers Read More »

Windows is getting stronger RDP file protections to fight phishing attacks

Windows is getting stronger RDP file protections to fight phishing attacks 2026-04-16 at 01:19 By Sinisa Markovic Microsoft has introduced new Windows protections starting with the April 2026 security update to reduce phishing attacks that abuse Remote Desktop (.rdp) files. With these updates, the Remote Desktop Connection app displays stronger warning dialogs before a connection […]

Windows is getting stronger RDP file protections to fight phishing attacks Read More »

Webinar: The IT Leader’s Guide to AI Governance

Webinar: The IT Leader’s Guide to AI Governance 2026-04-15 at 16:07 By Help Net Security Generative AI is moving from experimentation to everyday enterprise use, often faster than governance models were designed to support. As adoption accelerates, organizations are navigating the evolving landscape with new questions around security, data privacy, compliance, and control, all while […]

Webinar: The IT Leader’s Guide to AI Governance Read More »

Raspberry Pi OS 6.2 disables passwordless sudo by default

Raspberry Pi OS 6.2 disables passwordless sudo by default 2026-04-15 at 14:29 By Anamarija Pogorelec Raspberry Pi OS 6.2, based on the Trixie version, introduces small changes, bug fixes, and disables passwordless sudo by default for new installations. Screenshot of password prompt (Source: Raspberry Pi) “We continually review the security of Raspberry Pi OS to […]

Raspberry Pi OS 6.2 disables passwordless sudo by default Read More »

What changed in nginx 1.30.0 and what it means for your upstream config

What changed in nginx 1.30.0 and what it means for your upstream config 2026-04-15 at 14:29 By Anamarija Pogorelec nginx 1.30.0 brings together features accumulated across the 1.29.x mainline series. The release covers a broad range of changes, from protocol support additions to security-relevant fixes and new configuration options. Keepalive to upstreams is now on […]

What changed in nginx 1.30.0 and what it means for your upstream config Read More »

OpenAI expands its cyber defense program with GPT-5.4-Cyber for vetted researchers

OpenAI expands its cyber defense program with GPT-5.4-Cyber for vetted researchers 2026-04-15 at 10:02 By Sinisa Markovic Defending critical software has long depended on the ability to find and fix vulnerabilities faster than attackers can exploit them. OpenAI is expanding a program designed to give professional defenders prioritized access to AI tools built for that […]

OpenAI expands its cyber defense program with GPT-5.4-Cyber for vetted researchers Read More »

The exploit gap is closing, and your patch cycle wasn’t built for this

The exploit gap is closing, and your patch cycle wasn’t built for this 2026-04-15 at 10:02 By Mirko Zorz The Cloud Security Alliance has published a briefing on what it calls a turning point in the threat landscape: the time between a vulnerability being discovered and a working exploit is shrinking fast. The briefing centers […]

The exploit gap is closing, and your patch cycle wasn’t built for this Read More »

Coordinated vulnerability disclosure is now an EU obligation, but cultural change takes time

Coordinated vulnerability disclosure is now an EU obligation, but cultural change takes time 2026-04-15 at 10:02 By Mirko Zorz In this Help Net Security interview, Nuno Rodrigues Carvalho, Head of Sector for Incident and Vulnerability Services at ENISA, discusses the recent CVE funding scare and what it exposed about the fragility of global vulnerability disclosure […]

Coordinated vulnerability disclosure is now an EU obligation, but cultural change takes time Read More »

Legitify: Open-source scanner for security misconfigurations on GitHub and GitLab

Legitify: Open-source scanner for security misconfigurations on GitHub and GitLab 2026-04-15 at 08:18 By Anamarija Pogorelec Misconfigured source code management platforms remain a common entry point in software supply chain attacks, and organizations often lack visibility into which settings put them at risk. Legitify, an open-source tool from Legit Security, addresses that gap by scanning […]

Legitify: Open-source scanner for security misconfigurations on GitHub and GitLab Read More »

Product showcase: Stop secrets from leaking through AI coding tools with GitGuardian

Product showcase: Stop secrets from leaking through AI coding tools with GitGuardian 2026-04-15 at 07:32 By Help Net Security AI coding assistants are quickly becoming part of everyday development. Tools like Cursor, Claude Code, and GitHub Copilot can now do more than suggest code. They can read files, run shell commands, and call external tools […]

Product showcase: Stop secrets from leaking through AI coding tools with GitGuardian Read More »

Network segmentation projects fail in predictable patterns

Network segmentation projects fail in predictable patterns 2026-04-15 at 07:25 By Mirko Zorz Most enterprise networks have segmentation on the roadmap. Many have had it there for years. A survey of 400 U.S.-based network security practitioners who lived through failed segmentation projects finds that failure clusters into four distinct patterns, and the type of failure […]

Network segmentation projects fail in predictable patterns Read More »

Microsoft ends desktop detour for sensitivity labels in Office web apps

Microsoft ends desktop detour for sensitivity labels in Office web apps 2026-04-15 at 01:42 By Sinisa Markovic Microsoft is rolling out an update to Office for the web that removes a long-standing limitation around document protection, adding new control to browser-based apps. Specifying users in the Permissions dialog (Source: Microsoft) Users can now apply sensitivity […]

Microsoft ends desktop detour for sensitivity labels in Office web apps Read More »

OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support

OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support 2026-04-14 at 18:57 By Anamarija Pogorelec OpenSSL 4.0.0 removes several long-deprecated features, adds support for Encrypted Client Hello, and introduces API-level changes that will require code updates for applications built against older versions. SSLv3, SSLv2 client hello, and engines are gone SSLv3 support has been […]

OpenSSL 4.0.0 release cuts deprecated protocols and gains post-quantum support Read More »

Testing reveals Claude Mythos’s offensive capabilities and limits

Testing reveals Claude Mythos’s offensive capabilities and limits 2026-04-14 at 18:15 By Zeljka Zorz Could Claude Mythos Preview, Anthropic’s latest large language model, be leveraged for fully automated cyber attacks? The UK government’s AI Security Institute (AISI) tested its capability to successfully engage in capture-the-flag (CTF) challenges and multi-step attack scenarios, and found that that […]

Testing reveals Claude Mythos’s offensive capabilities and limits Read More »

W3LL phishing service sold for $500 dismantled by the FBI

W3LL phishing service sold for $500 dismantled by the FBI 2026-04-14 at 18:15 By Sinisa Markovic The W3LL phishing kit, a cybercrime tool used to impersonate legitimate login pages and steal usernames and passwords, has been dismantled by the FBI and Indonesian law enforcement authorities. Officials estimate the operation was tied to more than $20 […]

W3LL phishing service sold for $500 dismantled by the FBI Read More »

DavMail 6.6.0 patches a regex flaw and advances its Microsoft Graph backend

DavMail 6.6.0 patches a regex flaw and advances its Microsoft Graph backend 2026-04-14 at 16:21 By Anamarija Pogorelec Organizations that run DavMail to bridge standard mail clients to Microsoft Exchange or Office 365 received an update this week. Version 6.6.0 addresses a code-scanning alert tied to a regex vulnerability, adjusts OAuth redirect handling to match […]

DavMail 6.6.0 patches a regex flaw and advances its Microsoft Graph backend Read More »

Basic-Fit hack compromises data of up to 1 million members

Basic-Fit hack compromises data of up to 1 million members 2026-04-14 at 16:21 By Sinisa Markovic Basic-Fit, a European gym chain, disclosed that hackers breached one of its internal systems, exposing members’ personal data in several countries. The company operates more than 2,150 clubs in 12 countries under two brands, with more than 5.8 million […]

Basic-Fit hack compromises data of up to 1 million members Read More »

Booking.com data breach: Customer reservation data exposed

Booking.com data breach: Customer reservation data exposed 2026-04-14 at 16:21 By Zeljka Zorz “Unauthorized third parties may have been able to access certain booking information associated with your reservation,” email alerts sent out by Booking.com over the weekend warn. The online travel agency did not say which system(s) were accessed by the unauthorized third parties […]

Booking.com data breach: Customer reservation data exposed Read More »

Google to penalize sites that hijack the back button

Google to penalize sites that hijack the back button 2026-04-14 at 13:32 By Anamarija Pogorelec Google is broadening its spam policies to crack down on “back button hijacking,” a deceptive practice where websites interfere with browser navigation, blocking users from returning to the page they came from. Instead, users are usually redirected to pages they […]

Google to penalize sites that hijack the back button Read More »

Scroll to Top