News

Elementary OS 8.1 rolls out with a stronger focus on system security

Elementary OS 8.1 rolls out with a stronger focus on system security 2025-12-24 at 08:17 By Anamarija Pogorelec Elementary OS 8.1 is now available for download and shipping on select hardware from retailers such as Star Labs, Slimbook, and Laptop with Linux. The update arrives after more than a year of refinements based on community […]

Elementary OS 8.1 rolls out with a stronger focus on system security Read More »

What happens to enterprise data when GenAI shows up everywhere

What happens to enterprise data when GenAI shows up everywhere 2025-12-24 at 08:17 By Anamarija Pogorelec Generative AI is spreading across enterprise workflows, shaping how employees create, share, and move information between systems. Security teams are working to understand where data ends up, who can access it, and how its use reshapes security assumptions. This […]

What happens to enterprise data when GenAI shows up everywhere Read More »

Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits

Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits 2025-12-23 at 14:47 By Zeljka Zorz Malware peddlers are targeting infosec enthusiasts, budding security professionals, and aspiring hackers with the Webrat malware, masquerading the threat as proof-of-concept (PoC) exploits for known vulnerabilities. Delivering the malware The recently uncovered Webrat can steal data from […]

Budding infosec pros and aspiring cyber crooks targeted with fake PoC exploits Read More »

Weak enforcement keeps PCI DSS compliance low

Weak enforcement keeps PCI DSS compliance low 2025-12-23 at 09:41 By Sinisa Markovic Payment card breaches continue to surface across industries, even after years of investment in security standards. A new study links this pattern to enforcement, showing that PCI DSS compliance trails behind HIPAA, GDPR, and the EU’s NIS2 Directive. A compliance gap that […]

Weak enforcement keeps PCI DSS compliance low Read More »

Formal proofs expose long standing cracks in DNSSEC

Formal proofs expose long standing cracks in DNSSEC 2025-12-23 at 09:41 By Sinisa Markovic DNSSEC is meant to stop attackers from tampering with DNS answers. It signs records so resolvers can verify that data is authentic and unchanged. Many security teams assume that if DNSSEC validation passes, the answer can be trusted. New academic research […]

Formal proofs expose long standing cracks in DNSSEC Read More »

Cloud security is stuck in slow motion

Cloud security is stuck in slow motion 2025-12-23 at 08:23 By Anamarija Pogorelec Cloud environments are moving faster than the systems meant to protect them. A new Palo Alto Networks study shows security teams struggling to keep up with development cycles, growing cloud sprawl, and attacker tactics that now compress breaches into minutes instead of […]

Cloud security is stuck in slow motion Read More »

AI code looks fine until the review starts

AI code looks fine until the review starts 2025-12-23 at 08:23 By Anamarija Pogorelec Software teams have spent the past year sorting through a rising volume of pull requests generated with help from AI coding tools. New research puts numbers behind what many reviewers have been seeing during work. The research comes from CodeRabbit and […]

AI code looks fine until the review starts Read More »

Cybersecurity jobs available right now: December 23, 2025

Cybersecurity jobs available right now: December 23, 2025 2025-12-23 at 07:06 By Anamarija Pogorelec Application Security Architect ARRISE | UAE | Hybrid – View job details As an Application Security Architect, you will define and mature the application security architecture strategy, standards, and guardrails across products and platforms. You will lead threat modeling and architecture […]

Cybersecurity jobs available right now: December 23, 2025 Read More »

Docker makes hardened images free open and transparent for everyone

Docker makes hardened images free open and transparent for everyone 2025-12-22 at 15:09 By Sinisa Markovic Docker has made its open source Docker Hardened Images project available at no cost for every developer and organization. The catalog contains more than 1,000 container images built on open source distributions such as Debian and Alpine and is […]

Docker makes hardened images free open and transparent for everyone Read More »

574 arrests, $3 million recovered in Africa-wide cybercrime crackdown

574 arrests, $3 million recovered in Africa-wide cybercrime crackdown 2025-12-22 at 15:09 By Anamarija Pogorelec Law enforcement agencies across 19 countries arrested 574 suspects and recovered approximately $3 million during a major cybercrime operation spanning Africa. Suspects were arrested in Ghana in connection to the cyber-fraud case, with over 100 digital devices seized. (Source: Europol) […]

574 arrests, $3 million recovered in Africa-wide cybercrime crackdown Read More »

WatchGuard Firebox firewalls under attack (CVE-2025-14733)

WatchGuard Firebox firewalls under attack (CVE-2025-14733) 2025-12-22 at 13:24 By Zeljka Zorz More than 115,000 internet-facing WatchGuard Firebox firewalls may be vulnerable to compromise via CVE-2025-14733, a remote code execution vulnerability actively targeted by attackers, Shadowserver’s latest scanning reveals. About CVE-2025-14733 WatchGuard Firebox firewalls, which also incorporate VPN and unified threat management capabilities, are used […]

WatchGuard Firebox firewalls under attack (CVE-2025-14733) Read More »

DIG AI: Uncensored darknet AI assistant at the service of criminals and terrorists

DIG AI: Uncensored darknet AI assistant at the service of criminals and terrorists 2025-12-22 at 13:00 By Help Net Security Resecurity has identified the emergence of uncensored darknet AI assistants, enabling threat actors to leverage advanced data processing capabilities for malicious purposes. One of these – DIG AI – was identified on September 29 of […]

DIG AI: Uncensored darknet AI assistant at the service of criminals and terrorists Read More »

Building cyber talent through competition, residency, and real-world immersion

Building cyber talent through competition, residency, and real-world immersion 2025-12-22 at 09:01 By Mirko Zorz In this Help Net Security interview, Chrisma Jackson, Director of Cybersecurity & Mission Computing Center and CISO at Sandia National Laboratories, reflects on where the cyber talent pipeline breaks down and what it takes to fix it. She discusses skill […]

Building cyber talent through competition, residency, and real-world immersion Read More »

Browser agents don’t always respect your privacy choices

Browser agents don’t always respect your privacy choices 2025-12-22 at 08:49 By Sinisa Markovic Browser agents promise to handle online tasks without constant user input. They can shop, book reservations, and manage accounts by driving a web browser through an AI model. A new academic study warns that this convenience comes with privacy risks that […]

Browser agents don’t always respect your privacy choices Read More »

Anubis: Open-source web AI firewall to protect from scraper bots

Anubis: Open-source web AI firewall to protect from scraper bots 2025-12-22 at 08:49 By Sinisa Markovic Anubis is an open-source tool designed to protect websites from automated scraping and abusive traffic by adding computational friction before a request is served. Maintained by TecharoHQ, the project targets a growing problem for site operators who want to […]

Anubis: Open-source web AI firewall to protect from scraper bots Read More »

Session tokens give attackers a shortcut around MFA

Session tokens give attackers a shortcut around MFA 2025-12-22 at 07:45 By Help Net Security In this Help Net Security video, Simon Wijckmans, CEO at cside, discusses why session token theft is rising and why security teams miss it. He walks through how web applications rely on browsers to store session tokens after login often […]

Session tokens give attackers a shortcut around MFA Read More »

NIST issues guidance on securing smart speakers

NIST issues guidance on securing smart speakers 2025-12-22 at 07:02 By Sinisa Markovic Smart home devices, such as voice-activated digital assistants, are increasingly used in home health care, with risks involved. An attacker could change a prescription, steal medical data, or connect a patient to an impostor. To reduce cybersecurity risks tied to this use, […]

NIST issues guidance on securing smart speakers Read More »

Week in review: Exploited zero-day in Cisco email security appliances, Kali Linux 2025.4 released

Week in review: Exploited zero-day in Cisco email security appliances, Kali Linux 2025.4 released 2025-12-21 at 11:06 By Help Net Security Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: How researchers are teaching AI agents to ask for permission the right way People are starting to hand more […]

Week in review: Exploited zero-day in Cisco email security appliances, Kali Linux 2025.4 released Read More »

AI isn’t one system, and your threat model shouldn’t be either

AI isn’t one system, and your threat model shouldn’t be either 2025-12-19 at 09:02 By Mirko Zorz In this Help Net Security interview, Naor Penso, CISO at Cerebras Systems, explains how to threat model modern AI stacks without treating them as a single risk. He discusses why partitioning AI systems by function and impact matters, […]

AI isn’t one system, and your threat model shouldn’t be either Read More »

LLMs work better together in smart contract audits

LLMs work better together in smart contract audits 2025-12-19 at 08:42 By Sinisa Markovic Smart contract bugs continue to drain real money from blockchain systems, even after years of tooling and research. A new academic study suggests that large language models can spot more of those flaws when they work in coordinated groups instead of […]

LLMs work better together in smart contract audits Read More »

Scroll to Top