News

Threat actors are giving AI agents a bigger role in cyberattacks

Threat actors are giving AI agents a bigger role in cyberattacks 2026-09-08 at 17:55 By Sinisa Markovic AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incident response […]

Threat actors are giving AI agents a bigger role in cyberattacks Read More »

Trezor customers hit with phishing calls and letters after shipping-partner breach

Trezor customers hit with phishing calls and letters after shipping-partner breach 2026-09-08 at 14:30 By Zeljka Zorz Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed. “The leaked information could be used for […]

Trezor customers hit with phishing calls and letters after shipping-partner breach Read More »

IT help-desk vishing tricks executives into handing over Microsoft 365 access

IT help-desk vishing tricks executives into handing over Microsoft 365 access 2026-09-08 at 14:17 By Sinisa Markovic IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf. The company is tracking the […]

IT help-desk vishing tricks executives into handing over Microsoft 365 access Read More »

Mathspace breach exposes data on over a million students and parents

Mathspace breach exposes data on over a million students and parents 2026-09-08 at 11:45 By Sinisa Markovic Mathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million students, parents, and school staff. The Sydney-based maths education company wrote in a […]

Mathspace breach exposes data on over a million students and parents Read More »

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins 2026-09-08 at 11:41 By Anamarija Pogorelec Jellyfin shipped version 12.0 of its media server. Several of the security fixes in it block requests built to reach files outside the folders the server is supposed to hand out. The rest of the security work […]

Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins Read More »

Ransomware negotiation tactics have turned into a business process

Ransomware negotiation tactics have turned into a business process 2026-09-08 at 08:40 By Help Net Security In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations. Ross walks through the tactics groups use once an attack begins, from […]

Ransomware negotiation tactics have turned into a business process Read More »

Product showcase: Doppler secures secrets for humans, pipelines, and AI agents

Product showcase: Doppler secures secrets for humans, pipelines, and AI agents 2026-09-08 at 08:00 By Help Net Security Every engineering team has spent years trying to keep credentials out of source code. Then AI agents moved the problem. Coding agents review code, agents run workflows, and MCP servers broker access to databases, cloud providers, and […]

Product showcase: Doppler secures secrets for humans, pipelines, and AI agents Read More »

Microsoft’s Project Zenith puts large AI models directly on developer PCs

Microsoft’s Project Zenith puts large AI models directly on developer PCs 2026-09-08 at 07:30 By Anamarija Pogorelec Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without relying on metered cloud tokens. Designed for systems with at least 64 GB […]

Microsoft’s Project Zenith puts large AI models directly on developer PCs Read More »

Cybersecurity jobs available right now: September 8, 2026

Cybersecurity jobs available right now: September 8, 2026 2026-09-08 at 07:00 By Anamarija Pogorelec CISO AudioCodes | Israel | Hybrid – View job details As a CISO, you will lead security strategy, governance, and risk management across SaaS, managed services, and customer-hosted environments. You will oversee security controls, incident response, Secure SDLC, customer security engagements, […]

Cybersecurity jobs available right now: September 8, 2026 Read More »

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication 2026-09-07 at 17:07 By Sinisa Markovic Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national CSIRT team, have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTik. […]

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication Read More »

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) 2026-09-07 at 14:55 By Sinisa Markovic N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability […]

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) Read More »

Attackers spread malware through ScreenConnect file transfers

Attackers spread malware through ScreenConnect file transfers 2026-09-07 at 12:13 By Sinisa Markovic A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A CVE identifier and an official fix will be issued within the week,” the company wrote in its September 3 advisory. ScreenConnect […]

Attackers spread malware through ScreenConnect file transfers Read More »

OpenAI just hit a milestone on the road to self-improving AI

OpenAI just hit a milestone on the road to self-improving AI 2026-09-07 at 12:05 By Anamarija Pogorelec OpenAI has announced that it has reached a goal set last fall of having an automated research intern by September 2026. The milestone means a system can carry out well-defined research tasks under human direction, including work that […]

OpenAI just hit a milestone on the road to self-improving AI Read More »

ToolHive: The open-source way to run any MCP server securely

ToolHive: The open-source way to run any MCP server securely 2026-09-07 at 08:30 By Anamarija Pogorelec ToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude Code reach an outside tool, and Stacklok ships ToolHive under Apache […]

ToolHive: The open-source way to run any MCP server securely Read More »

Zero trust AI agents demand a different kind of security

Zero trust AI agents demand a different kind of security 2026-09-07 at 08:00 By Help Net Security In this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and […]

Zero trust AI agents demand a different kind of security Read More »

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast 2026-09-06 at 11:27 By Sinisa Markovic Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers hijack login sessions Anthropic has started locking users out of their Claude accounts due to their […]

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast Read More »

Google patches actively exploited Chrome zero-day (CVE-2026-85046)

Google patches actively exploited Chrome zero-day (CVE-2026-85046) 2026-09-04 at 15:09 By Sinisa Markovic Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thursday security advisory. The fix […]

Google patches actively exploited Chrome zero-day (CVE-2026-85046) Read More »

Microsoft Teams is about to make QR code phishing much harder

Microsoft Teams is about to make QR code phishing much harder 2026-09-04 at 11:28 By Sinisa Markovic Microsoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the organization. Users will need to reveal the image […]

Microsoft Teams is about to make QR code phishing much harder Read More »

Scroll to Top