News

AI can’t fix cybersecurity’s hiring problem

AI can’t fix cybersecurity’s hiring problem 2026-07-22 at 07:30 By Anamarija Pogorelec Organizations are redefining cybersecurity roles through workforce frameworks and placing greater emphasis on verified skills as AI and new regulatory requirements change hiring. The SANS 2026 Cybersecurity Workforce Survey found demand for specialists in new roles more than doubled over the past year, […]

AI can’t fix cybersecurity’s hiring problem Read More »

Cloud operations become the next big role for agentic AI

Cloud operations become the next big role for agentic AI 2026-07-22 at 07:00 By Anamarija Pogorelec Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the technology as part of cloud application management, according to Unisys’ AI & Cloud Insights Report. To

Cloud operations become the next big role for agentic AI Read More »

AI agents tricked into recommending malicious GitHub repositories

AI agents tricked into recommending malicious GitHub repositories 2026-07-21 at 17:27 By Sinisa Markovic Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island)

AI agents tricked into recommending malicious GitHub repositories Read More »

JadePuffer returns with ransomware built to target AI models and infrastructure

JadePuffer returns with ransomware built to target AI models and infrastructure 2026-07-21 at 16:38 By Zeljka Zorz JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in

JadePuffer returns with ransomware built to target AI models and infrastructure Read More »

Cisco’s open-weight Antares models make vulnerability localization cheaper

Cisco’s open-weight Antares models make vulnerability localization cheaper 2026-07-21 at 16:01 By Mirko Zorz A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands

Cisco’s open-weight Antares models make vulnerability localization cheaper Read More »

SonicWall SMA zero-days were exploited weeks before disclosure

SonicWall SMA zero-days were exploited weeks before disclosure 2026-07-21 at 13:35 By Zeljka Zorz Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22,

SonicWall SMA zero-days were exploited weeks before disclosure Read More »

Fake FBI agents target people who already got scammed

Fake FBI agents target people who already got scammed 2026-07-21 at 13:21 By Sinisa Markovic Scammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier

Fake FBI agents target people who already got scammed Read More »

AWS wants GuardDuty to automate the first steps of threat investigations

AWS wants GuardDuty to automate the first steps of threat investigations 2026-07-21 at 12:14 By Anamarija Pogorelec Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at

AWS wants GuardDuty to automate the first steps of threat investigations Read More »

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

Estée Lauder discloses data breach tied to Oracle EBS vulnerability 2026-07-21 at 12:01 By Sinisa Markovic Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its

Estée Lauder discloses data breach tied to Oracle EBS vulnerability Read More »

Open-source maintainers still work underfunded as sponsorship crosses $100 million

Open-source maintainers still work underfunded as sponsorship crosses $100 million 2026-07-21 at 11:37 By Anamarija Pogorelec A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend

Open-source maintainers still work underfunded as sponsorship crosses $100 million Read More »

The air gap is a myth and other OT security truths

The air gap is a myth and other OT security truths 2026-07-21 at 09:00 By Mirko Zorz Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth.

The air gap is a myth and other OT security truths Read More »

Nobody was checking the drives that encrypt your laptop

Nobody was checking the drives that encrypt your laptop 2026-07-21 at 08:30 By Anamarija Pogorelec A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG

Nobody was checking the drives that encrypt your laptop Read More »

Cybersecurity jobs available right now: July 21, 2026

Cybersecurity jobs available right now: July 21, 2026 2026-07-21 at 07:00 By Anamarija Pogorelec Application Security Analyst Stellantis | USA | On-site – View job details As an Application Security Analyst, you will perform application security testing using SAST, DAST, IAST, and other assessment tools to identify vulnerabilities and support remediation efforts. You will integrate

Cybersecurity jobs available right now: July 21, 2026 Read More »

AI-generated reports push GNOME to shorten its disclosure window

AI-generated reports push GNOME to shorten its disclosure window 2026-07-21 at 06:53 By Anamarija Pogorelec Volunteer maintainers of open source projects now receive a steady flow of security vulnerability reports produced with AI tools. Many arrive with no mention that a language model helped write them. The volume has grown enough that GNOME is revising

AI-generated reports push GNOME to shorten its disclosure window Read More »

The Odyssey piracy scams surface hours after its theatrical debut

The Odyssey piracy scams surface hours after its theatrical debut 2026-07-20 at 21:59 By Sinisa Markovic Christopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on cloned piracy sites: fake browser warnings

The Odyssey piracy scams surface hours after its theatrical debut Read More »

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel 2026-07-20 at 20:20 By Sinisa Markovic Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel Read More »

Paidwork breach exposes sensitive data of 23 million user

Paidwork breach exposes sensitive data of 23 million user 2026-07-20 at 17:52 By Sinisa Markovic Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads,

Paidwork breach exposes sensitive data of 23 million user Read More »

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875)

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) 2026-07-20 at 17:32 By Zeljka Zorz Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection

ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) Read More »

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches 2026-07-20 at 16:19 By Sinisa Markovic Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000

Italy fines WINDTRE €1.7 million over security flaws behind two data breaches Read More »

Hugging Face breached by autonomous AI agent

Hugging Face breached by autonomous AI agent 2026-07-20 at 13:52 By Zeljka Zorz Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16),

Hugging Face breached by autonomous AI agent Read More »

Scroll to Top