News

Building a defense in depth strategy for sensitive data

Building a defense in depth strategy for sensitive data 2026-07-23 at 07:00 By Help Net Security In this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data. He argues that a single control, like encrypting a disk or […]

Building a defense in depth strategy for sensitive data Read More »

OpenAI: Our models breached Hugging Face during a cyber capability test

OpenAI: Our models breached Hugging Face during a cyber capability test 2026-07-22 at 17:42 By Zeljka Zorz The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share

OpenAI: Our models breached Hugging Face during a cyber capability test Read More »

OpenAI Presence connects AI agents to enterprise data with built-in guardrails

OpenAI Presence connects AI agents to enterprise data with built-in guardrails 2026-07-22 at 17:01 By Sinisa Markovic OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a

OpenAI Presence connects AI agents to enterprise data with built-in guardrails Read More »

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) 2026-07-22 at 14:47 By Zeljka Zorz Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code,

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) Read More »

US seizes over 1,000 domains used for illegal World Cup 2026 streams

US seizes over 1,000 domains used for illegal World Cup 2026 streams 2026-07-22 at 13:51 By Sinisa Markovic The US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves

US seizes over 1,000 domains used for illegal World Cup 2026 streams Read More »

Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter

Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter 2026-07-22 at 11:21 By Anamarija Pogorelec Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a limited-access pilot program that will soon be available to governments and trusted partners through

Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter Read More »

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns 2026-07-22 at 11:02 By Sinisa Markovic German and US law enforcement have dismantled the infrastructure behind Kratos, a notorious phishing-as-a-service (PhaaS) platform. Its alleged developer and administrator was arrested in Indonesia by local police. Seizure banner (Source: BKA) The takedown was led by the Frankfurt public

Police dismantle Kratos phishing platform behind 15,000 monthly campaigns Read More »

Small teams are the heaviest users of AI coding agents

Small teams are the heaviest users of AI coding agents 2026-07-22 at 09:00 By Sinisa Markovic The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually

Small teams are the heaviest users of AI coding agents Read More »

Snowpick: Open-source ServiceNow exposure scanner

Snowpick: Open-source ServiceNow exposure scanner 2026-07-22 at 08:30 By Mirko Zorz An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and get records back. Bishop Fox ran that test across 166 ServiceNow instances

Snowpick: Open-source ServiceNow exposure scanner Read More »

Security teams keep finding critical flaws after scheduled testing ends

Security teams keep finding critical flaws after scheduled testing ends 2026-07-22 at 08:00 By Anamarija Pogorelec Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of Continuous Security Validation report found that 95% of surveyed organizations identified high- or critical-severity vulnerabilities outside planned testing windows

Security teams keep finding critical flaws after scheduled testing ends Read More »

AI can’t fix cybersecurity’s hiring problem

AI can’t fix cybersecurity’s hiring problem 2026-07-22 at 07:30 By Anamarija Pogorelec Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doubled over the past year,

AI can’t fix cybersecurity’s hiring problem Read More »

Cloud operations become the next big role for agentic AI

Cloud operations become the next big role for agentic AI 2026-07-22 at 07:00 By Anamarija Pogorelec Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. To

Cloud operations become the next big role for agentic AI Read More »

AI agents tricked into recommending malicious GitHub repositories

AI agents tricked into recommending malicious GitHub repositories 2026-07-21 at 17:27 By Sinisa Markovic Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island)

AI agents tricked into recommending malicious GitHub repositories Read More »

JadePuffer returns with ransomware built to target AI models and infrastructure

JadePuffer returns with ransomware built to target AI models and infrastructure 2026-07-21 at 16:38 By Zeljka Zorz JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in

JadePuffer returns with ransomware built to target AI models and infrastructure Read More »

Cisco’s open-weight Antares models make vulnerability localization cheaper

Cisco’s open-weight Antares models make vulnerability localization cheaper 2026-07-21 at 16:01 By Mirko Zorz A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands

Cisco’s open-weight Antares models make vulnerability localization cheaper Read More »

SonicWall SMA zero-days were exploited weeks before disclosure

SonicWall SMA zero-days were exploited weeks before disclosure 2026-07-21 at 13:35 By Zeljka Zorz Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22,

SonicWall SMA zero-days were exploited weeks before disclosure Read More »

Fake FBI agents target people who already got scammed

Fake FBI agents target people who already got scammed 2026-07-21 at 13:21 By Sinisa Markovic Scammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier

Fake FBI agents target people who already got scammed Read More »

AWS wants GuardDuty to automate the first steps of threat investigations

AWS wants GuardDuty to automate the first steps of threat investigations 2026-07-21 at 12:14 By Anamarija Pogorelec Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at

AWS wants GuardDuty to automate the first steps of threat investigations Read More »

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

Estée Lauder discloses data breach tied to Oracle EBS vulnerability 2026-07-21 at 12:01 By Sinisa Markovic Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its

Estée Lauder discloses data breach tied to Oracle EBS vulnerability Read More »

Open-source maintainers still work underfunded as sponsorship crosses $100 million

Open-source maintainers still work underfunded as sponsorship crosses $100 million 2026-07-21 at 11:37 By Anamarija Pogorelec A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend

Open-source maintainers still work underfunded as sponsorship crosses $100 million Read More »

Scroll to Top