Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
North Korea
Lazarus hackers pair fake job offers with Windows zero-day exploit

The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point …

deepfake
Split-second deepfake glitch blows digital certificate fraudster’s cover

Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital …

crypto scams
Ready-made $500 kit puts a crypto scam within anyone’s reach

A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and …

SIM
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G

Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, …

ransomware
Ransomware gangs don’t need control system access to disrupt industrial production

Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial …

OpenAI
GPT-5.6-Cyber refuses security researchers’ requests far less often

GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. …

Previously unseen entry vector used to breach Polish energy plant

The December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, …

Steam
Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began …

Microsoft Entra ID
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users

Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches …

Chainloop
Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what …

EU
How to report an AI Act violation in the EU

The EU’s fight to regulate AI models entered a new chapter on 2 August 2026, when the European Commission’s AI Office and national authorities began enforcing the …

SharePoint
200 accounts compromised in Swiss government’s Microsoft SharePoint breach

Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools