Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
USA
White House authorizes private US companies to hack foreign criminal networks

President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat …

SharePoint
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked …

LiteLLM
153GB of stolen credentials surface after LiteLLM supply chain attack

A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, …

Signal
Signal’s new security feature checks if your encrypted chats were tampered with

Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is …

North Korea
Lazarus hackers pair fake job offers with Windows zero-day exploit

The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point …

deepfake
Split-second deepfake glitch blows digital certificate fraudster’s cover

Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital …

crypto scams
Ready-made $500 kit puts a crypto scam within anyone’s reach

A seller on a cybercrime forum is offering a ready-made scam kit for $500, complete with an admin panel that tracks victims, checks their crypto wallets for value, and …

SIM
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G

Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, …

ransomware
Ransomware gangs don’t need control system access to disrupt industrial production

Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial …

OpenAI
GPT-5.6-Cyber refuses security researchers’ requests far less often

GPT-5.6-Cyber is a new OpenAI model built on GPT-5.6 Sol, trained to find zero-day vulnerabilities and build exploit chains, with fewer refusals on higher-risk, dual-use work. …

Previously unseen entry vector used to breach Polish energy plant

The December 29 cyberattack on a Polish combined heat and power (CHP) plant was the first observed case of attackers gaining access to an OT network through a private APN, …

Steam
Cyberattack on Steam hardware shipper leaks names, addresses, and order data

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools