News

Your security vendor gets the frontier cyber model, you get the findings

Your security vendor gets the frontier cyber model, you get the findings 2026-08-11 at 07:43 By Anamarija Pogorelec Selected red team specialists can now use OpenAI’s cyber models to find and exploit weaknesses in client applications and infrastructure. Those clients never get the models themselves. That split is the design of the Daybreak Cyber Partner […]

Your security vendor gets the frontier cyber model, you get the findings Read More »

Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Cyberattack on Steam hardware shipper leaks names, addresses, and order data 2026-08-10 at 17:34 By Sinisa Markovic Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data

Cyberattack on Steam hardware shipper leaks names, addresses, and order data Read More »

Metabase zero-day exploited to access Framework customer data

Metabase zero-day exploited to access Framework customer data 2026-08-10 at 16:42 By Zeljka Zorz Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers

Metabase zero-day exploited to access Framework customer data Read More »

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users 2026-08-10 at 16:19 By Sinisa Markovic Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches worldwide and GCC tenants starting

Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users Read More »

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 2026-08-10 at 14:34 By Zeljka Zorz To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix.

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 Read More »

Anthropic to put AI in charge of reviewing Claude Code actions by default

Anthropic to put AI in charge of reviewing Claude Code actions by default 2026-08-10 at 12:13 By Anamarija Pogorelec Anthropic will make auto mode in Claude Code the default for new sessions on Pro, Max, and Team plans starting August 14. Users who previously selected a different default may receive a one-time prompt asking whether

Anthropic to put AI in charge of reviewing Claude Code actions by default Read More »

OpenAI locks down Astra over potential critical cyber capabilities

OpenAI locks down Astra over potential critical cyber capabilities 2026-08-10 at 10:09 By Anamarija Pogorelec OpenAI’s internal evaluation of its upcoming model, Astra, found significant advances in agentic coding and cybersecurity, leading the company to conclude that it cannot rule out the model reaching the critical capability level for cybersecurity under its Preparedness Framework. The

OpenAI locks down Astra over potential critical cyber capabilities Read More »

GitHub Dependabot malware alerts now cover eight ecosystems

GitHub Dependabot malware alerts now cover eight ecosystems 2026-08-10 at 10:01 By Mirko Zorz GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month.

GitHub Dependabot malware alerts now cover eight ecosystems Read More »

Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop: Open-source evidence store and policy engine for the software supply chain 2026-08-10 at 08:30 By Sinisa Markovic Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what the build produced, uploads those files to content-addressable

Chainloop: Open-source evidence store and policy engine for the software supply chain Read More »

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model 2026-08-10 at 08:00 By Anamarija Pogorelec Enpass is a password manager that stores passwords, passkeys, payment cards, identities, secure notes, software licenses, and other sensitive information in encrypted vaults. Vaults remain on the device or in a cloud storage service selected by the

Product showcase: Enpass Password Manager breaks away from the proprietary cloud model Read More »

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026 2026-08-09 at 11:00 By Anamarija Pogorelec Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek,

Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026 Read More »

200 accounts compromised in Swiss government’s Microsoft SharePoint breach

200 accounts compromised in Swiss government’s Microsoft SharePoint breach 2026-08-07 at 15:29 By Sinisa Markovic Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers.

200 accounts compromised in Swiss government’s Microsoft SharePoint breach Read More »

OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens

OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens 2026-08-07 at 11:52 By Sinisa Markovic OpenAI has updated GPT-5.6 Sol, the model behind ChatGPT for Plus and Pro subscribers, and pushed a new model, GPT-5.6 Luna, out to everyone using the free tier. The company is also removing the rate

OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens Read More »

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? 2026-08-07 at 09:00 By Help Net Security July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, of course, well over 600 CVEs

August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? Read More »

What the first year of EU AI Act transparency enforcement could look like

What the first year of EU AI Act transparency enforcement could look like 2026-08-07 at 08:30 By Mirko Zorz In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders

What the first year of EU AI Act transparency enforcement could look like Read More »

US fuel gauge exposure fell by more than half in three months

US fuel gauge exposure fell by more than half in three months 2026-08-07 at 08:00 By Anamarija Pogorelec Every month for the better part of a year, about 4,800 US internet addresses answered a query in the protocol that fuel tank gauges speak. In June the number was 2,354. The count fell across April, May,

US fuel gauge exposure fell by more than half in three months Read More »

Photos: Black Hat USA 2026, part two

Photos: Black Hat USA 2026, part two 2026-08-06 at 20:50 By Help Net Security Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing

Photos: Black Hat USA 2026, part two Read More »

Novel-reading apps used users’ phones to generate fake ad traffic

Novel-reading apps used users’ phones to generate fake ad traffic 2026-08-06 at 17:07 By Sinisa Markovic A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. Sample novel-reading apps associated with Papyrus (Source: IAS Threat Lab) While a person taps

Novel-reading apps used users’ phones to generate fake ad traffic Read More »

Photos: Black Hat USA 2026

Photos: Black Hat USA 2026 2026-08-06 at 16:30 By Help Net Security Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. The second gallery is here. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air Security, Legion Security. Featured people: Kunal

Photos: Black Hat USA 2026 Read More »

Three in four AI-generated vulnerability patches leave something broken

Three in four AI-generated vulnerability patches leave something broken 2026-08-06 at 15:45 By Mirko Zorz Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time

Three in four AI-generated vulnerability patches leave something broken Read More »

Scroll to Top