News

Top must-visit companies at RSAC 2026

Top must-visit companies at RSAC 2026 2026-03-23 at 17:17 By Mirko Zorz RSAC 2026 Conference is taking place at the Moscone Center in San Francisco March 23 – 26. With hundreds of booths, countless product demos, and nonstop buzz, navigating RSAC can be overwhelming. That’s why we’ve done the legwork to highlight the standout companies […]

Top must-visit companies at RSAC 2026 Read More »

LevelBlue Takes Home Twin 2026 Global Info Sec Awards

LevelBlue Takes Home Twin 2026 Global Info Sec Awards 2026-03-23 at 16:13 By LevelBlue is proud to announce thatCyber Defense Magazine has named it the winner of its Global InfoSec Awards 2026 for TrailblazingManaged Security Service Provider (MSSP) and Market DisruptorThreat Detection, Incident Response, Hunting and Triage Platform. This article is an excerpt from LevelBlue Blog View […]

LevelBlue Takes Home Twin 2026 Global Info Sec Awards Read More »

Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992)

Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) 2026-03-23 at 13:50 By Zeljka Zorz Oracle has released an out-of-band patch for a critical and easily exploitable vulnerability (CVE-2026-21992) in Oracle Identity Manager and Oracle Web Services Manager. The company did not say whether the vulnerability has been exploited as a zero-day, but […]

Oracle issues emergency fix for pre-auth RCE in Identity Manager (CVE-2026-21992) Read More »

Russian hackers go after high-value targets through Signal

Russian hackers go after high-value targets through Signal 2026-03-23 at 11:20 By Sinisa Markovic Russian intelligence-linked hackers are targeting commercial messaging platforms, with Signal a primary focus, the FBI and CISA warn. The campaign is aimed at individuals of intelligence interest, including government personnel, journalists, and others with access to sensitive communications. It is believed […]

Russian hackers go after high-value targets through Signal Read More »

Plumber: Open-source scanner of GitLab CI/CD pipelines for compliance gaps

Plumber: Open-source scanner of GitLab CI/CD pipelines for compliance gaps 2026-03-23 at 09:18 By Anamarija Pogorelec GitLab CI/CD pipelines often accumulate configuration decisions that drift from security baselines over time. Container images get pinned to mutable tags, branches lose protection settings, and required templates go missing. An open-source tool called Plumber automates the detection of […]

Plumber: Open-source scanner of GitLab CI/CD pipelines for compliance gaps Read More »

Your AI agents are moving sensitive data. Do you know where?

Your AI agents are moving sensitive data. Do you know where? 2026-03-23 at 09:18 By Mirko Zorz In this Help Net Security interview, Gidi Cohen, CEO at Bonfy.AI, addresses what he sees as the most pressing gap in AI agent security: data-layer risk. While the industry focuses on prompt injection and model behavior, Cohen argues […]

Your AI agents are moving sensitive data. Do you know where? Read More »

NIST updates its DNS security guidance for the first time in over a decade

NIST updates its DNS security guidance for the first time in over a decade 2026-03-23 at 09:18 By Mirko Zorz DNS infrastructure underpins nearly every network connection an organization makes, yet security configurations for it have gone largely unrevised at the federal guidance level for more than twelve years. NIST published SP 800-81r3, the Secure […]

NIST updates its DNS security guidance for the first time in over a decade Read More »

Week in review: ScreenConnect servers open to attack, exploited Microsoft SharePoint flaw

Week in review: ScreenConnect servers open to attack, exploited Microsoft SharePoint flaw 2026-03-22 at 12:37 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What smart factories keep getting wrong about cybersecurity In this Help Net Security interview, Packsize CSO Troy Rydman breaks down the […]

Week in review: ScreenConnect servers open to attack, exploited Microsoft SharePoint flaw Read More »

Terminated contract led to $2.5 million cyber extortion scheme

Terminated contract led to $2.5 million cyber extortion scheme 2026-03-20 at 19:32 By Sinisa Markovic A federal jury convicted Cameron Curry, 27, a Charlotte resident, of carrying out an extensive cyber extortion scheme targeting a Washington, D.C.-based international technology company. He faces up to two years in prison on each of the six charges. Curry, […]

Terminated contract led to $2.5 million cyber extortion scheme Read More »

Google slows Android sideloading to trip up scammers

Google slows Android sideloading to trip up scammers 2026-03-20 at 19:32 By Anamarija Pogorelec Google’s advanced flow for Android changes how apps from unverified developers are installed, adding steps to reduce scam-driven sideloading. The feature is aimed at experienced users and allows sideloading through a controlled, one-time setup. It addresses scam scenarios where attackers pressure […]

Google slows Android sideloading to trip up scammers Read More »

Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131)

Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131) 2026-03-20 at 15:21 By Zeljka Zorz A critical vulnerability (CVE-2026-20131) in Cisco Secure Firewall Management Center (FMC) that Cisco disclosed and patched in early March 2026 has been exploited as a zero-day by the Interlock ransomware gang, Amazon CISO and VP of Security Engineering […]

Cisco FMC flaw was exploited by Interlock weeks before patch (CVE-2026-20131) Read More »

Authorities disrupt four IoT botnets behind record DDoS attacks

Authorities disrupt four IoT botnets behind record DDoS attacks 2026-03-20 at 12:46 By Sinisa Markovic The U.S. Justice Department and international partners have disrupted four IoT botnets linked to DDoS attacks that reached 30 terabits per second, among the largest ever recorded. The post Authorities disrupt four IoT botnets behind record DDoS attacks appeared first […]

Authorities disrupt four IoT botnets behind record DDoS attacks Read More »

Fake AI songs streamed billions of times, netting fraudster $10 million

Fake AI songs streamed billions of times, netting fraudster $10 million 2026-03-20 at 12:20 By Anamarija Pogorelec Michael Smith, 54, of Cornelius, North Carolina, has pleaded guilty in federal court to running a scheme that exploited music streaming platforms and diverted royalty payments from artists. He admitted to one count of conspiracy to commit wire […]

Fake AI songs streamed billions of times, netting fraudster $10 million Read More »

Unpatched ScreenConnect servers open to attack (CVE-2026-3564)

Unpatched ScreenConnect servers open to attack (CVE-2026-3564) 2026-03-20 at 11:44 By Zeljka Zorz ConnectWise has patched a critical vulnerability (CVE-2026-3564) that could enable attackers to hijack ScreenConnect sessions by abusing ASP.NET machine keys to forge trusted authentication. About CVE-2026-3564 The ScreenConnect remote access platform is popular with managed service providers, IT departments, and technology solution […]

Unpatched ScreenConnect servers open to attack (CVE-2026-3564) Read More »

ConductorOne unveils AI Access Management to accelerate secure, compliant AI adoption

ConductorOne unveils AI Access Management to accelerate secure, compliant AI adoption 2026-03-20 at 09:39 By Industry News ConductorOne has announced its AI Access Management product extension, a unified control plane for managing access to AI tools, agents, and MCP connections across the enterprise. The platform enables organizations to accelerate AI adoption while maintaining full visibility, […]

ConductorOne unveils AI Access Management to accelerate secure, compliant AI adoption Read More »

DarkSword: Researchers uncover another iOS exploit kit

DarkSword: Researchers uncover another iOS exploit kit 2026-03-19 at 16:54 By Zeljka Zorz A powerful iPhone hacking toolkit dubbed “DarkSword” has been used since November 2025 to compromise devices by exploiting zero-day iOS vulnerabilities, Google researchers have shared. iOS vulnerabilities exploited by DarkSword Two weeks ago, Google Threat Intelligence Group (GTIG) and iVerify disclosed the […]

DarkSword: Researchers uncover another iOS exploit kit Read More »

4chan shrugs off UK regulator, refuses to pay £520,000 in fines over online safety violations

4chan shrugs off UK regulator, refuses to pay £520,000 in fines over online safety violations 2026-03-19 at 16:54 By Sinisa Markovic The U.K.’s media regulator Ofcom fined 4chan £450,000 under the Online Safety Act for failing to introduce age checks to stop children from accessing pornographic content on its platform. 4chan is an online forum […]

4chan shrugs off UK regulator, refuses to pay £520,000 in fines over online safety violations Read More »

Secure endpoint management systems immediately, CISA urges

Secure endpoint management systems immediately, CISA urges 2026-03-19 at 14:59 By Sinisa Markovic The US Cybersecurity and Infrastructure Security Agency (CISA) warns that the cyberattack on Stryker Corporation serves as a signal to U.S. organizations that foreign cyber activity tied to Middle East conflicts may be spilling into their operations. Attackers breached Stryker’s internal Microsoft […]

Secure endpoint management systems immediately, CISA urges Read More »

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963)

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) 2026-03-19 at 13:32 By Zeljka Zorz CVE-2026-20963, a remote code execution (RCE) SharePoint vulnerability Microsoft fixed in January 2026, is being exploited by attackers. The confirmation comes from the US Cybersecurity and Infrastructure Security Agency (CISA), which added the flaw to its Known Exploited Vulnerabilities […]

CISA warns of active exploitation of Microsoft SharePoint vulnerability (CVE-2026-20963) Read More »

Scroll to Top