News

Cybercriminals are scaling phishing attacks with ready-made kits

Cybercriminals are scaling phishing attacks with ready-made kits 2026-01-08 at 09:10 By Anamarija Pogorelec Phishing-as-a-Service (PhaaS) kits lower the barrier to entry, enabling less-skilled attackers to run large-scale, targeted phishing campaigns that impersonate legitimate services and institutions, according to Barracuda Networks. Phishing kits grow more sophisticated and scalable Barracuda threat analysts found that in 2025 […]

Cybercriminals are scaling phishing attacks with ready-made kits Read More »

StackRox: Open-source Kubernetes security platform

StackRox: Open-source Kubernetes security platform 2026-01-08 at 08:31 By Anamarija Pogorelec Security teams spend a lot of time stitching together checks across container images, running workloads, and deployment pipelines. The work often happens under time pressure, with engineers trying to keep clusters stable while meeting internal policy requirements. The StackRox open source project sits in

StackRox: Open-source Kubernetes security platform Read More »

What happens to insider risk when AI becomes a coworker

What happens to insider risk when AI becomes a coworker 2026-01-08 at 08:04 By Help Net Security In this Help Net Security video, Ashley Rose, CEO at Living Security, discusses how AI is changing insider risk. AI is now built into daily work across departments, which shifts how risk shows up and how security teams

What happens to insider risk when AI becomes a coworker Read More »

Passwords are where PCI DSS compliance often breaks down

Passwords are where PCI DSS compliance often breaks down 2026-01-08 at 07:36 By Sinisa Markovic Most PCI DSS failures do not start with malware or a targeted attack. They start with everyday behavior. Reused passwords. Credentials stored in spreadsheets. Shared logins are passed around during busy periods. For CISOs, password hygiene remains one of the

Passwords are where PCI DSS compliance often breaks down Read More »

Voice cloning defenses are easier to undo than expected

Voice cloning defenses are easier to undo than expected 2026-01-08 at 07:01 By Sinisa Markovic Many voice protection tools promise to block cloning by adding hidden noise to speech. Researchers at a Texas university found that widely used voice protection methods can be stripped away, restoring speaker identity and allowing fake voices to pass automated

Voice cloning defenses are easier to undo than expected Read More »

UK announces grand plan to secure online public services

UK announces grand plan to secure online public services 2026-01-07 at 15:32 By Zeljka Zorz The UK has announced a new Government Cyber Action Plan aimed at making online public services more secure and resilient, and has allocated £210 million (approximately $283 million) to implement it. Setting up a Government Cyber Unit “Cyber attacks can

UK announces grand plan to secure online public services Read More »

Debian seeks volunteers to rebuild its data protection team

Debian seeks volunteers to rebuild its data protection team 2026-01-07 at 13:46 By Anamarija Pogorelec The Debian Project is asking for volunteers to step in after its Data Protection Team became inactive. All three members of the team stepped down at the same time, leaving no dedicated group to handle privacy and data protection work.

Debian seeks volunteers to rebuild its data protection team Read More »

Fake Booking.com emails and BSODs used to infect hospitality staff

Fake Booking.com emails and BSODs used to infect hospitality staff 2026-01-07 at 13:06 By Zeljka Zorz Suspected Russian attackers are targeting the hospitality sector with fake Booking.com emails and a fake “Blue Screen of Death” to deliver the DCRat malware. The malware delivery campaign starts with phishing emails that feature room charge details in euros,

Fake Booking.com emails and BSODs used to infect hospitality staff Read More »

Gen AI data violations more than double

Gen AI data violations more than double 2026-01-07 at 08:32 By Sinisa Markovic Security teams track activity that moves well beyond traditional SaaS platforms, with employees interacting daily with generative AI tools, personal cloud services, and automated systems that exchange data without direct human input. These patterns shape how sensitive information moves across corporate environments

Gen AI data violations more than double Read More »

What European security teams are struggling to operationalize

What European security teams are struggling to operationalize 2026-01-07 at 08:32 By Anamarija Pogorelec European security and compliance teams spend a lot of time talking about regulation. A new forecast report from Kiteworks suggests the harder problem sits elsewhere. According to the report, many European organizations have strong regulatory frameworks on paper, driven by GDPR

What European security teams are struggling to operationalize Read More »

Identity security planning for 2026 is shifting under pressure

Identity security planning for 2026 is shifting under pressure 2026-01-07 at 08:32 By Anamarija Pogorelec Identity security planning is becoming more focused on scale, governance, and operational strain, according to the Identity Security Outlook 2026 report. The ManageEngine research draws on responses from 515 identity and security leaders in the United States and Canada and

Identity security planning for 2026 is shifting under pressure Read More »

When AI agents interact, risk can emerge without warning

When AI agents interact, risk can emerge without warning 2026-01-07 at 08:30 By Sinisa Markovic System level risks can arise when AI agents interact over time, according to new research that examines how collective behavior forms inside multi agent systems. The study finds that feedback loops, shared signals, and coordination patterns can produce outcomes that

When AI agents interact, risk can emerge without warning Read More »

Turning plain language into firewall rules

Turning plain language into firewall rules 2026-01-06 at 09:00 By Sinisa Markovic Firewall rules often begin as a sentence in someone’s head. A team needs access to an application. A service needs to be blocked after hours. Translating those ideas into vendor specific firewall syntax usually involves detailed knowledge of zones, objects, ports, and rule

Turning plain language into firewall rules Read More »

Product showcase: Blokada for Android gives users control over network traffic

Product showcase: Blokada for Android gives users control over network traffic 2026-01-06 at 08:45 By Anamarija Pogorelec Blokada is a network privacy and ad-blocking application available on Android, iOS, Windows, macOS, and Linux. It is designed to reduce ads, block trackers, and limit unwanted network connections at the system level. Getting started Blokada’s interface is

Product showcase: Blokada for Android gives users control over network traffic Read More »

The roles and challenges in moving to quantum-safe cryptography

The roles and challenges in moving to quantum-safe cryptography 2026-01-06 at 08:45 By Anamarija Pogorelec A new research project examines how organizations, regulators, and technical experts coordinate the transition to quantum safe cryptography. The study draws on a structured workshop with public sector, private sector, and academic participants to document how governance, security, and innovation

The roles and challenges in moving to quantum-safe cryptography Read More »

Passwords are still breaking compliance programs

Passwords are still breaking compliance programs 2026-01-06 at 07:32 By Sinisa Markovic The security stack has grown, but audits still stumble on passwords. CISOs see this every year. An organization may have strong endpoint tools, layered network defenses, and a documented access policy. Then the audit turns to shared credentials, spreadsheet-based password storage, or accounts

Passwords are still breaking compliance programs Read More »

What security teams miss in email attacks

What security teams miss in email attacks 2026-01-06 at 07:10 By Anamarija Pogorelec Email remains the most common entry point for attackers. This article examines how phishing, impersonation, and account takeover continue to drive email breaches and expose growing security gaps across industries. Email blind spots are back to bite security teams Email remains the

What security teams miss in email attacks Read More »

New State Laws Impact AI Governance, Risk, and Compliance

New State Laws Impact AI Governance, Risk, and Compliance 2026-01-05 at 18:48 By Scott Swanson New York has started a movement to reshape the AI compliance landscape for companies doing business in the state. Other states are following suit making Governance and AI Compliance an increasingly critical endeavor. This article is an excerpt from LevelBlue

New State Laws Impact AI Governance, Risk, and Compliance Read More »

Pharma’s most underestimated cyber risk isn’t a breach

Pharma’s most underestimated cyber risk isn’t a breach 2026-01-05 at 08:47 By Mirko Zorz Chirag Shah, Global Information Security Officer & DPO at Model N examines how cyber risk in pharma and life sciences is shifting beyond traditional breaches toward data misuse, AI-driven exposure and regulatory pressure. He explains why executives still underestimate silent control

Pharma’s most underestimated cyber risk isn’t a breach Read More »

AI security risks are also cultural and developmental

AI security risks are also cultural and developmental 2026-01-05 at 08:32 By Anamarija Pogorelec Security teams spend much of their time tracking vulnerabilities, abuse patterns, and system failures. A new study argues that many AI risks sit deeper than technical flaws. Cultural assumptions, uneven development, and data gaps shape how AI systems behave, where they

AI security risks are also cultural and developmental Read More »

Scroll to Top