News

National Life Group CISO expects more vulnerabilities in six months than in thirty years

National Life Group CISO expects more vulnerabilities in six months than in thirty years 2026-09-02 at 09:00 By Mirko Zorz In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot […]

National Life Group CISO expects more vulnerabilities in six months than in thirty years Read More »

Scareware ads keep running on Google’s transparency tool, even after they’re reported

Scareware ads keep running on Google’s transparency tool, even after they’re reported 2026-09-02 at 08:30 By Mirko Zorz A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to […]

Scareware ads keep running on Google’s transparency tool, even after they’re reported Read More »

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira 2026-09-02 at 08:00 By Mirko Zorz Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows file shares, an entire Active Directory domain, […]

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira Read More »

Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud

Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud 2026-09-02 at 07:30 By Anamarija Pogorelec Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, spent months working with Anthropic on a […]

Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud Read More »

CISA review makes the case for eliminating vulnerability classes

CISA review makes the case for eliminating vulnerability classes 2026-09-01 at 18:23 By Zeljka Zorz For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of […]

CISA review makes the case for eliminating vulnerability classes Read More »

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks 2026-09-01 at 17:07 By Sinisa Markovic A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ […]

Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks Read More »

Fake Claude Opus 5 app delivers malware and wipes its own tracks

Fake Claude Opus 5 app delivers malware and wipes its own tracks 2026-09-01 at 15:21 By Sinisa Markovic A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository README using […]

Fake Claude Opus 5 app delivers malware and wipes its own tracks Read More »

Berlin refuses to be blackmailed after network breach

Berlin refuses to be blackmailed after network breach 2026-09-01 at 12:07 By Sinisa Markovic Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior Senator Iris Spranger addressed the extortion attempt on Friday, following an emergency Senate session at the Rotes […]

Berlin refuses to be blackmailed after network breach Read More »

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers 2026-09-01 at 08:30 By Mirko Zorz Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The startup, […]

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers Read More »

Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes

Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes 2026-09-01 at 08:04 By Anamarija Pogorelec Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to […]

Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes Read More »

NIS2 compliance: Fixing IAM and access control before the 2026 audit

NIS2 compliance: Fixing IAM and access control before the 2026 audit 2026-09-01 at 08:00 By Help Net Security The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into […]

NIS2 compliance: Fixing IAM and access control before the 2026 audit Read More »

What your vendor says about PQC tells you if they are ready

What your vendor says about PQC tells you if they are ready 2026-09-01 at 07:30 By Mirko Zorz In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity […]

What your vendor says about PQC tells you if they are ready Read More »

Cybersecurity jobs available right now: September 1, 2026

Cybersecurity jobs available right now: September 1, 2026 2026-09-01 at 07:00 By Sinisa Markovic Security Engineer, PSO Google | USA | On-site – View job details As a Security Engineer, you will provide technical guidance to customers adopting Google Cloud Platform, helping them navigate their cloud journey with the Professional Services team. The role includes […]

Cybersecurity jobs available right now: September 1, 2026 Read More »

Attackers plant remote access tools on compromised PaperCut servers

Attackers plant remote access tools on compromised PaperCut servers 2026-08-31 at 17:54 By Zeljka Zorz The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most recent update on the ongoing attack campaign. PaperCut zero-days exploited to deploy remote access tools The vendor […]

Attackers plant remote access tools on compromised PaperCut servers Read More »

Threat actors are posing as AI crawlers to hunt for exposed credentials

Threat actors are posing as AI crawlers to hunt for exposed credentials 2026-08-31 at 17:54 By Sinisa Markovic Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: GreyNoise) “Every program that visits […]

Threat actors are posing as AI crawlers to hunt for exposed credentials Read More »

AWS Console Private Access can block sign-ins to personal accounts

AWS Console Private Access can block sign-ins to personal accounts 2026-08-31 at 14:57 By Anamarija Pogorelec The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private clouds, the isolated networks customers run inside AWS, that have no […]

AWS Console Private Access can block sign-ins to personal accounts Read More »

ShinyHunters claims it stole 284 million patient records from McKesson

ShinyHunters claims it stole 284 million patient records from McKesson 2026-08-31 at 14:57 By Sinisa Markovic Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company that distributes pharmaceuticals, medical supplies and other healthcare products to pharmacies, hospitals and clinics. According […]

ShinyHunters claims it stole 284 million patient records from McKesson Read More »

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails 2026-08-31 at 12:45 By Sinisa Markovic Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, named GuardBreaker by ESET, appeared in a malicious VBS script tied […]

Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails Read More »

Scroll to Top