News

Specter: Open-source NFC reader bug sweep for Flipper Zero

Specter: Open-source NFC reader bug sweep for Flipper Zero 2026-07-29 at 08:00 By Anamarija Pogorelec Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The Flipper’s own chip does the sensing The onboard ST25R3916 carries a […]

Specter: Open-source NFC reader bug sweep for Flipper Zero Read More »

Your AI agents can reach data no one approved

Your AI agents can reach data no one approved 2026-07-29 at 07:30 By Mirko Zorz A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the failure back to a non-human account no one had been logging. That agent

Your AI agents can reach data no one approved Read More »

Android malware detection collapses when the context stage comes out

Android malware detection collapses when the context stage comes out 2026-07-29 at 07:00 By Anamarija Pogorelec A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide

Android malware detection collapses when the context stage comes out Read More »

Hugging Face breach reignites open-weights debate, raises liability questions

Hugging Face breach reignites open-weights debate, raises liability questions 2026-07-28 at 18:55 By Zeljka Zorz The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident post-mortem compiled with the input from Hugging Face and several hundred members of

Hugging Face breach reignites open-weights debate, raises liability questions Read More »

Exposed BMCs hand out password hashes before login

Exposed BMCs hand out password hashes before login 2026-07-28 at 15:00 By Sinisa Markovic An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part of the IPMI 2.0 handshake, built on an authentication protocol introduced

Exposed BMCs hand out password hashes before login Read More »

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) 2026-07-28 at 14:04 By Zeljka Zorz JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. “For those who are unable to do so, we have released a security patch plugin,” noted Daniel Gallo,

JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077) Read More »

VERITAS project could change the way scientists secure AI

VERITAS project could change the way scientists secure AI 2026-07-28 at 14:02 By Sinisa Markovic The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project called VERITAS (VERified Infrastructure for Trustworthy AI in Science) aims to close that gap by

VERITAS project could change the way scientists secure AI Read More »

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 2026-07-28 at 12:23 By Anamarija Pogorelec AWS Shield Advanced, a managed service that protects applications from external threats, is adding the Anti-DDoS managed rule group, designed for application-layer (L7) DDoS protection, to eligible web access control lists (ACLs) in Count mode. The addition

AWS to retire Shield Advanced L7 automatic mitigation on January 1, 2027 Read More »

Coca-Cola confirms hackers stole data in Fairlife ransomware attack

Coca-Cola confirms hackers stole data in Fairlife ransomware attack 2026-07-28 at 12:01 By Sinisa Markovic Coca-Cola has confirmed that the ransomware attack on its dairy subsidiary Fairlife involved the theft of company data, weeks after the incident temporarily halted production at its US facilities. Fairlife is a Coca-Cola-owned dairy brand that makes ultra-filtered milk and

Coca-Cola confirms hackers stole data in Fairlife ransomware attack Read More »

Shadow AI incident response begins with logs that may already be gone

Shadow AI incident response begins with logs that may already be gone 2026-07-28 at 09:00 By Mirko Zorz In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound

Shadow AI incident response begins with logs that may already be gone Read More »

AI took more than junior developer jobs and the bill comes later

AI took more than junior developer jobs and the bill comes later 2026-07-28 at 08:30 By Sinisa Markovic A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. Describe it

AI took more than junior developer jobs and the bill comes later Read More »

Download: The High-Performance Team Playbook

Download: The High-Performance Team Playbook 2026-07-28 at 08:00 By Help Net Security Get practical insight from teams who’ve built, scaled and handed over engineering functions at enterprise level. Most engineering teams don’t fail because of bad engineers. They fail because performance is assumed. This playbook shows how high-performance teams are built intentionally across people, structure,

Download: The High-Performance Team Playbook Read More »

Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts

Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts 2026-07-28 at 07:30 By Sinisa Markovic Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are asked to log in with their email address

Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts Read More »

Cybersecurity jobs available right now: July 28, 2026

Cybersecurity jobs available right now: July 28, 2026 2026-07-28 at 07:00 By Anamarija Pogorelec Cloud Security Engineer Toyota Automated Logistics | USA | On-site – View job details As a Cloud Security Engineer, you will design and enforce security controls across Azure and on-premises environments, strengthen identity and access management, and maintain cloud security posture

Cybersecurity jobs available right now: July 28, 2026 Read More »

Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost

Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost 2026-07-27 at 22:23 By Sinisa Markovic Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. MAI-Cyber-1-Flash is Microsoft’s first model built specifically for cybersecurity work, and the company stated that it went through review by

Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost Read More »

Tech giants form alliance to put open AI in cyber defenders’ hands

Tech giants form alliance to put open AI in cyber defenders’ hands 2026-07-27 at 17:43 By Sinisa Markovic NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during

Tech giants form alliance to put open AI in cyber defenders’ hands Read More »

7AI expands platform with Federated SIEM and AI workflow builder

7AI expands platform with Federated SIEM and AI workflow builder 2026-07-27 at 16:27 By Industry News 7AI has announced two major platform capabilities: 7AI Federated SIEM, which lets security teams query, investigate, and act on data wherever it lives, including within 7AI, and 7AI Build, which lets enterprises and partners define agentic workflows, skills, and

7AI expands platform with Federated SIEM and AI workflow builder Read More »

Google changes how it names cyber threat actors

Google changes how it names cyber threat actors 2026-07-27 at 16:08 By Sinisa Markovic Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes

Google changes how it names cyber threat actors Read More »

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) 2026-07-27 at 15:04 By Zeljka Zorz Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS

PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121) Read More »

ChatGPT joins the most impersonated brands in phishing attacks

ChatGPT joins the most impersonated brands in phishing attacks 2026-07-27 at 14:08 By Anamarija Pogorelec Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts

ChatGPT joins the most impersonated brands in phishing attacks Read More »

Scroll to Top