August 2026
Split-second deepfake glitch blows digital certificate fraudster’s cover
Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital …
Post-quantum migration gets harder when every user holds a key
In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords …
PentestGPT: Open-source automated penetration testing agentic framework
PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then …
338 million attack simulations reveal the state of enterprise defense
First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have …
Ready-made $500 kit puts a crypto scam within anyone’s reach
A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and …
AI deployments are stretching enterprise security to its limits
CISOs and CTOs expect AI deployments to increase their organizations’ attack surface by an average of 14% over the next year. Nearly all lack visibility into AI …
Arctera enhances Unified Platform for evidence-driven compliance workflows
Arctera has announced new capabilities to the Arctera Unified Platform enabling organizations to manage complex governance requirements by connecting signals, controls and …
Citrix expands Platform Flex with observability and secure developer services
Citrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work …
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, …
Ransomware gangs don’t need control system access to disrupt industrial production
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial …
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether …
GPT-5.6-Cyber refuses security researchers’ requests far less often
GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. …
Featured news
Resources
Don't miss
- A hollowed out data layer is making CISOs fly blind into AI attacks
- Hazmat: Open-source containment for AI agents
- Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
- Four corporate investigation mistakes organizations make under pressure
- A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months