Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
AI
Threat actors are posing as AI crawlers to hunt for exposed credentials

Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for …

PaperCut
Attackers plant remote access tools on compromised PaperCut servers

The threat actor targeting internet-facing PaperCut Application Servers is covertly installing legitimate remote access software on them, PaperCut Software shared in the most …

Amazon AWS
AWS Console Private Access can block sign-ins to personal accounts

The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for virtual private …

data breach
ShinyHunters claims it stole 284 million patient records from McKesson

Healthcare company McKesson disclosed a cybersecurity incident in which hackers got into third-party applications and stole data. McKesson is a major U.S. healthcare company …

Claude
Anthropic locks out Claude users after infostealers hijack login sessions

Anthropic has started locking users out of their Claude accounts due to their login sessions having been compromised through infostealer malware. “The malware identified …

AI
Russian hackers plant nuclear weapon prompt in malware to trip AI safety guardrails

Russian state hackers are trying to interfere with AI-assisted malware analysis in Ukraine by deliberately setting off AI safety mechanisms, ESET has found. The technique, …

Debian
Debian developers rejected an LLM ban and left disclosure voluntary

A maintainer reading a merge request can’t tell whether a person or a model wrote the diff, and nobody has to say. Debian developers voted on that through August 28, and …

OpenClaw
The OpenClaw 2.0 release moves your sessions into SQLite

OpenClaw is open source software that hands an AI model small standing jobs across your accounts, the kind of chore where it watches a mailbox for vendor advisories and pings …

Dr. Joye Purser
What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different …

Halo-record
Halo-record: Open-source audit trails for AI agents

Brian Kuan wrote halo-record, a small Python package that sits inside an AI agent and writes down the moves it makes: tool calls, model calls, data access, approvals. Each …

vulnerability
AI AppSec tools agree on just 5% of security findings

Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Top types of viable application …

ChatGPT
Free ChatGPT users get ads picked from whatever they just asked about

Say you’re on the free plan and you ask ChatGPT to help you pick a mattress. An ad may turn up next to the answer, and it got there because of what you just asked about, …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools