News

Downtime pushes resilience planning into security operations

Downtime pushes resilience planning into security operations 2026-01-12 at 07:18 By Anamarija Pogorelec CISOs describe a shift in how they define success. New research from Absolute Security shows broad agreement that resilience outweighs security goals centered on prevention alone. Security leaders increasingly define their role around keeping the business operating through disruption. The cost of […]

Downtime pushes resilience planning into security operations Read More »

Week in review: PoC for Trend Micro Apex Central RCE released, Patch Tuesday forecast

Week in review: PoC for Trend Micro Apex Central RCE released, Patch Tuesday forecast 2026-01-11 at 11:27 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Pharma’s most underestimated cyber risk isn’t a breach Chirag Shah, Global Information Security Officer & DPO at Model N […]

Week in review: PoC for Trend Micro Apex Central RCE released, Patch Tuesday forecast Read More »

European Commission opens consultation on EU digital ecosystems

European Commission opens consultation on EU digital ecosystems 2026-01-09 at 15:44 By Sinisa Markovic The European Commission has opened a public call for evidence on European open digital ecosystems, a step toward a planned Communication that will examine the role of open source in EU’s digital infrastructure. The consultation runs from January 6 to February […]

European Commission opens consultation on EU digital ecosystems Read More »

January 2026 Patch Tuesday forecast: And so it continues

January 2026 Patch Tuesday forecast: And so it continues 2026-01-09 at 11:26 By Help Net Security Welcome to a new year of my Patch Tuesday forecast blog where I provide a summary of Microsoft and other vendor’s security patch activity (and reported issues) for the month, talk about some of the latest trends, processes, and […]

January 2026 Patch Tuesday forecast: And so it continues Read More »

How AI agents are turning security inside-out

How AI agents are turning security inside-out 2026-01-09 at 09:30 By Help Net Security AppSec teams have spent the last decade hardening externally facing applications, API security, software supply chain risk, CI/CD controls, and cloud-native attack paths. But a growing class of security threats is emerging from a largely underestimated and undefended source: internally built […]

How AI agents are turning security inside-out Read More »

Product showcase: TrackerControl lets Android users see who’s tracking them

Product showcase: TrackerControl lets Android users see who’s tracking them 2026-01-09 at 08:34 By Anamarija Pogorelec TrackerControl is an open-source Android application designed to give users visibility into and control over the hidden data within mobile apps. Many apps routinely communicate with third-party services that collect information about usage. TrackerControl makes this activity visible and […]

Product showcase: TrackerControl lets Android users see who’s tracking them Read More »

Security teams are paying more attention to the energy cost of detection

Security teams are paying more attention to the energy cost of detection 2026-01-09 at 08:02 By Anamarija Pogorelec Security teams spend a lot of time explaining why detection systems need more compute. Cloud bills rise, models retrain more often, and new analytics pipelines get added to existing stacks. Those conversations usually stay focused on coverage […]

Security teams are paying more attention to the energy cost of detection Read More »

Wi-Fi evolution tightens focus on access control

Wi-Fi evolution tightens focus on access control 2026-01-09 at 07:33 By Anamarija Pogorelec Wi-Fi networks are taking on heavier workloads, more devices, and higher expectations from users who assume constant access everywhere. A new Wireless Broadband Alliance industry study shows that this expansion is reshaping priorities around security, identity, and trust, alongside adoption of new […]

Wi-Fi evolution tightens focus on access control Read More »

Recently fixed HPE OneView flaw is being exploited (CVE-2025-37164)

Recently fixed HPE OneView flaw is being exploited (CVE-2025-37164) 2026-01-08 at 16:43 By Zeljka Zorz An unauthenticated remote code execution vulnerability (CVE-2025-37164) affecting certain versions of HPE OneView is being leveraged by attackers, CISA confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog. The vulnerability’s inclusion in the catalog is unsurprising, as technical […]

Recently fixed HPE OneView flaw is being exploited (CVE-2025-37164) Read More »

PoC released for unauthenticated RCE in Trend Micro Apex Central (CVE-2025-69258)

PoC released for unauthenticated RCE in Trend Micro Apex Central (CVE-2025-69258) 2026-01-08 at 14:08 By Zeljka Zorz Trend Micro has released a critical patch fixing several remotely exploitable vulnerabilities in Apex Central (on-premise), including a flaw (CVE-2025-69258) that may allow unauthenticated attackers to achieve code execution on affected installations. The three vulnerabilities were unearthed and […]

PoC released for unauthenticated RCE in Trend Micro Apex Central (CVE-2025-69258) Read More »

IPFire update brings new network and security features to firewall deployments

IPFire update brings new network and security features to firewall deployments 2026-01-08 at 10:57 By Anamarija Pogorelec Security and operations teams often work with firewall platforms that require frequent tuning or upgrades to meet evolving network demands. IPFire has released its 2.29 Core Update 199, aimed at network and protection teams that manage this open […]

IPFire update brings new network and security features to firewall deployments Read More »

Cybercriminals are scaling phishing attacks with ready-made kits

Cybercriminals are scaling phishing attacks with ready-made kits 2026-01-08 at 09:10 By Anamarija Pogorelec Phishing-as-a-Service (PhaaS) kits lower the barrier to entry, enabling less-skilled attackers to run large-scale, targeted phishing campaigns that impersonate legitimate services and institutions, according to Barracuda Networks. Phishing kits grow more sophisticated and scalable Barracuda threat analysts found that in 2025 […]

Cybercriminals are scaling phishing attacks with ready-made kits Read More »

StackRox: Open-source Kubernetes security platform

StackRox: Open-source Kubernetes security platform 2026-01-08 at 08:31 By Anamarija Pogorelec Security teams spend a lot of time stitching together checks across container images, running workloads, and deployment pipelines. The work often happens under time pressure, with engineers trying to keep clusters stable while meeting internal policy requirements. The StackRox open source project sits in […]

StackRox: Open-source Kubernetes security platform Read More »

What happens to insider risk when AI becomes a coworker

What happens to insider risk when AI becomes a coworker 2026-01-08 at 08:04 By Help Net Security In this Help Net Security video, Ashley Rose, CEO at Living Security, discusses how AI is changing insider risk. AI is now built into daily work across departments, which shifts how risk shows up and how security teams […]

What happens to insider risk when AI becomes a coworker Read More »

Passwords are where PCI DSS compliance often breaks down

Passwords are where PCI DSS compliance often breaks down 2026-01-08 at 07:36 By Sinisa Markovic Most PCI DSS failures do not start with malware or a targeted attack. They start with everyday behavior. Reused passwords. Credentials stored in spreadsheets. Shared logins are passed around during busy periods. For CISOs, password hygiene remains one of the […]

Passwords are where PCI DSS compliance often breaks down Read More »

Voice cloning defenses are easier to undo than expected

Voice cloning defenses are easier to undo than expected 2026-01-08 at 07:01 By Sinisa Markovic Many voice protection tools promise to block cloning by adding hidden noise to speech. Researchers at a Texas university found that widely used voice protection methods can be stripped away, restoring speaker identity and allowing fake voices to pass automated […]

Voice cloning defenses are easier to undo than expected Read More »

UK announces grand plan to secure online public services

UK announces grand plan to secure online public services 2026-01-07 at 15:32 By Zeljka Zorz The UK has announced a new Government Cyber Action Plan aimed at making online public services more secure and resilient, and has allocated £210 million (approximately $283 million) to implement it. Setting up a Government Cyber Unit “Cyber attacks can […]

UK announces grand plan to secure online public services Read More »

Debian seeks volunteers to rebuild its data protection team

Debian seeks volunteers to rebuild its data protection team 2026-01-07 at 13:46 By Anamarija Pogorelec The Debian Project is asking for volunteers to step in after its Data Protection Team became inactive. All three members of the team stepped down at the same time, leaving no dedicated group to handle privacy and data protection work. […]

Debian seeks volunteers to rebuild its data protection team Read More »

Fake Booking.com emails and BSODs used to infect hospitality staff

Fake Booking.com emails and BSODs used to infect hospitality staff 2026-01-07 at 13:06 By Zeljka Zorz Suspected Russian attackers are targeting the hospitality sector with fake Booking.com emails and a fake “Blue Screen of Death” to deliver the DCRat malware. The malware delivery campaign starts with phishing emails that feature room charge details in euros, […]

Fake Booking.com emails and BSODs used to infect hospitality staff Read More »

Gen AI data violations more than double

Gen AI data violations more than double 2026-01-07 at 08:32 By Sinisa Markovic Security teams track activity that moves well beyond traditional SaaS platforms, with employees interacting daily with generative AI tools, personal cloud services, and automated systems that exchange data without direct human input. These patterns shape how sensitive information moves across corporate environments […]

Gen AI data violations more than double Read More »

Scroll to Top