tips

Production data in testing is still common, and Tricentis’ CISO wants it gone

Production data in testing is still common, and Tricentis’ CISO wants it gone 2026-08-26 at 08:30 By Mirko Zorz In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught […]

Production data in testing is still common, and Tricentis’ CISO wants it gone Read More »

AI supply chain risk is showing up in developer workflows first

AI supply chain risk is showing up in developer workflows first 2026-08-25 at 09:00 By Mirko Zorz In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and

AI supply chain risk is showing up in developer workflows first Read More »

The cybercrime supply chain has five stages, each with a price

The cybercrime supply chain has five stages, each with a price 2026-08-25 at 08:00 By Help Net Security In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five

The cybercrime supply chain has five stages, each with a price Read More »

OpenAI tightens defenses after AI agents breach research environment

OpenAI tightens defenses after AI agents breach research environment 2026-08-18 at 12:41 By Anamarija Pogorelec Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included previously unknown vulnerabilities and credentials leaked

OpenAI tightens defenses after AI agents breach research environment Read More »

Four corporate investigation mistakes organizations make under pressure

Four corporate investigation mistakes organizations make under pressure 2026-08-13 at 08:00 By Help Net Security In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and

Four corporate investigation mistakes organizations make under pressure Read More »

Post-quantum migration gets harder when every user holds a key

Post-quantum migration gets harder when every user holds a key 2026-08-12 at 09:00 By Mirko Zorz In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break

Post-quantum migration gets harder when every user holds a key Read More »

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) 2026-08-03 at 14:42 By Zeljka Zorz A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) Read More »

Aviation cyber risk sits on the ground, the blindness sits in the air

Aviation cyber risk sits on the ground, the blindness sits in the air 2026-07-31 at 08:30 By Mirko Zorz In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in

Aviation cyber risk sits on the ground, the blindness sits in the air Read More »

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced 2026-07-29 at 08:30 By Mirko Zorz A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets

The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced Read More »

Shadow AI incident response begins with logs that may already be gone

Shadow AI incident response begins with logs that may already be gone 2026-07-28 at 09:00 By Mirko Zorz In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how quickly logs roll over, why firewall records of outbound

Shadow AI incident response begins with logs that may already be gone Read More »

Multi-patch vulnerability fixes can leave open source exposed

Multi-patch vulnerability fixes can leave open source exposed 2026-07-23 at 08:00 By Mirko Zorz Vulnerability management runs on a shorthand. A CVE shows a linked patch, someone applies it, and the ticket moves to closed. That shorthand covers most open source fixes. A share work in a different way, arriving as a run of two

Multi-patch vulnerability fixes can leave open source exposed Read More »

Building a defense in depth strategy for sensitive data

Building a defense in depth strategy for sensitive data 2026-07-23 at 07:00 By Help Net Security In this Help Net Security video, Venkata Pavan Kumar Gummadi, Professional Software Engineer at Broadridge, explains how to build a defense in depth strategy for protecting sensitive data. He argues that a single control, like encrypting a disk or

Building a defense in depth strategy for sensitive data Read More »

The air gap is a myth and other OT security truths

The air gap is a myth and other OT security truths 2026-07-21 at 09:00 By Mirko Zorz Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth.

The air gap is a myth and other OT security truths Read More »

More alerts are making your team slower, and an outcome-based SOC fixes that

More alerts are making your team slower, and an outcome-based SOC fixes that 2026-07-20 at 08:30 By Help Net Security In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like

More alerts are making your team slower, and an outcome-based SOC fixes that Read More »

The five step plan that cuts security budget waste

The five step plan that cuts security budget waste 2026-07-17 at 08:00 By Help Net Security In this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, and that mismatch is

The five step plan that cuts security budget waste Read More »

Reading between the lines of a cyber insurance policy

Reading between the lines of a cyber insurance policy 2026-07-16 at 09:00 By Mirko Zorz Enterprises in regulated industries often carry cyber insurance policies because contracts require it or boards ask for documented risk transfer. The global market for these policies reached about $16 billion in premiums in 2024. Coverage has become widespread. Payouts have

Reading between the lines of a cyber insurance policy Read More »

Turning software supply chain security into a daily habit

Turning software supply chain security into a daily habit 2026-07-10 at 08:30 By Help Net Security In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every

Turning software supply chain security into a daily habit Read More »

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure 2026-07-08 at 09:00 By Mirko Zorz In this interview with Help Net Security, Miranda Ritchie, CISO at Orbia, talks about protecting industrial systems where software runs water, chemical and manufacturing processes. She explains why a cyber incident in these settings can harm people, equipment and

Orbia CISO Miranda Ritchie on building security into sustainable infrastructure Read More »

Your company already adopted AI and nobody is governing access

Your company already adopted AI and nobody is governing access 2026-07-07 at 08:30 By Help Net Security In this Help Net Security video, Antoine Berton, CTO at Elba Security, breaks down the AI attack surface. Your company already adopted AI, and every adoption creates access that nobody governs. A quick click on a Friday afternoon

Your company already adopted AI and nobody is governing access Read More »

Securing the inbox: Where identity, brand and security meet

Securing the inbox: Where identity, brand and security meet 2026-07-06 at 09:00 By Mirko Zorz Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority

Securing the inbox: Where identity, brand and security meet Read More »

Scroll to Top