News

A five-part inventory for your AI agent credentials

A five-part inventory for your AI agent credentials 2026-09-04 at 08:30 By Help Net Security In this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI studios, connect them to enterprise tools, and give them accounts to do useful […]

A five-part inventory for your AI agent credentials Read More »

Scammers have figured out the best time to text you

Scammers have figured out the best time to text you 2026-09-04 at 08:00 By Sinisa Markovic The suspicious calls, texts, and DMs you got recently aren’t a coincidence, according to Malwarebytes. Scammers have worked out which platform gets them the best results for each type of con, and they stick to that formula. (Source: Malwarebytes) […]

Scammers have figured out the best time to text you Read More »

OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets

OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets 2026-09-04 at 07:35 By Anamarija Pogorelec OpenAI committed $1 billion to subsidize access to its Daybreak cyber models, along with training and technical support, for organizations defending water and wastewater systems, the electric grid, state and local government, community and regional banks, […]

OpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgets Read More »

Most of the bugs Claude Mythos found have never been checked by a human

Most of the bugs Claude Mythos found have never been checked by a human 2026-09-04 at 07:30 By Anamarija Pogorelec Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings […]

Most of the bugs Claude Mythos found have never been checked by a human Read More »

Thomson Reuters reveals breach that exposed U.S. and Canadian court records

Thomson Reuters reveals breach that exposed U.S. and Canadian court records 2026-09-03 at 16:50 By Zeljka Zorz Thomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and […]

Thomson Reuters reveals breach that exposed U.S. and Canadian court records Read More »

Google’s Gemini 3.8 Flash takes on bigger AI models at a lower cost

Google’s Gemini 3.8 Flash takes on bigger AI models at a lower cost 2026-09-03 at 16:34 By Sinisa Markovic Google has introduced Gemini 3.8 Flash, available to developers today, and a gated sibling, Gemini 3.8 Flash Cyber, reserved for vetted security teams. “Our 3rd Flash release in just 6 wks,” Google CEO Sundar Pichai said […]

Google’s Gemini 3.8 Flash takes on bigger AI models at a lower cost Read More »

Russian man indicted for spreading malware to 80,000 freelancers

Russian man indicted for spreading malware to 80,000 freelancers 2026-09-03 at 13:43 By Sinisa Markovic A Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a federal grand jury in California. Searzhudin Tamirlanovich Aktulaev, 40, faces charges of conspiracy, transmission of […]

Russian man indicted for spreading malware to 80,000 freelancers Read More »

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms 2026-09-03 at 12:23 By Sinisa Markovic Most of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone […]

Researchers built a $7 gadget for anyone paranoid about hidden cameras in hotel rooms Read More »

Your AI agent’s system prompt is not a security control

Your AI agent’s system prompt is not a security control 2026-09-03 at 10:53 By Anamarija Pogorelec An AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, […]

Your AI agent’s system prompt is not a security control Read More »

Your threat feed is someone else’s database: What ingesting malware intel at scale takes

Your threat feed is someone else’s database: What ingesting malware intel at scale takes 2026-09-03 at 08:30 By Help Net Security The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is […]

Your threat feed is someone else’s database: What ingesting malware intel at scale takes Read More »

When AI quietly breaks things, who pays?

When AI quietly breaks things, who pays? 2026-09-03 at 08:00 By Mirko Zorz David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance […]

When AI quietly breaks things, who pays? Read More »

Windows memory integrity switches on automatically for eligible devices in October 2026

Windows memory integrity switches on automatically for eligible devices in October 2026 2026-09-03 at 07:30 By Anamarija Pogorelec Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory […]

Windows memory integrity switches on automatically for eligible devices in October 2026 Read More »

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) 2026-09-02 at 16:24 By Sinisa Markovic Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026-62911 […]

Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911) Read More »

Download: The Agentic Software Development Guide

Download: The Agentic Software Development Guide 2026-09-02 at 16:00 By Help Net Security AI makes it easy to ship more code. It does not make that code easier to trust. Most teams don’t fail because their developers can’t use AI. They fail because the dev’s job changed and nobody redefined it. Under AI, cracks appear: […]

Download: The Agentic Software Development Guide Read More »

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) 2026-09-02 at 15:42 By Zeljka Zorz A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unified communications platform built on […]

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586) Read More »

Attackers are going after prominent individuals through OAuth phishing, FBI warns

Attackers are going after prominent individuals through OAuth phishing, FBI warns 2026-09-02 at 13:58 By Sinisa Markovic Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned. The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses […]

Attackers are going after prominent individuals through OAuth phishing, FBI warns Read More »

SonicWall SMA 1000 appliances under attack via zero-day flaws

SonicWall SMA 1000 appliances under attack via zero-day flaws 2026-09-02 at 13:13 By Zeljka Zorz Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote access appliances (SSL VPN gateways) built […]

SonicWall SMA 1000 appliances under attack via zero-day flaws Read More »

A battery storage cyberattack would look exactly like a badly tuned controller

A battery storage cyberattack would look exactly like a badly tuned controller 2026-09-02 at 12:00 By Mirko Zorz Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should […]

A battery storage cyberattack would look exactly like a badly tuned controller Read More »

Global sinkhole operation ends Sality botnet’s 23-year run

Global sinkhole operation ends Sality botnet’s 23-year run 2026-09-02 at 11:56 By Sinisa Markovic Sality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation […]

Global sinkhole operation ends Sality botnet’s 23-year run Read More »

DuckDB stays open source while the team behind it goes to work for Amazon

DuckDB stays open source while the team behind it goes to work for Amazon 2026-09-02 at 09:29 By Anamarija Pogorelec Hannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to administer. If you ship anything on […]

DuckDB stays open source while the team behind it goes to work for Amazon Read More »

Scroll to Top