Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
OpenSSL
OpenSSL’s new alpha build speeds up post-quantum crypto

The OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and …

crypto scams
$245 million in stolen crypto funded racketeering crew’s lavish lifestyle

A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions. …

F5
Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory

A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides …

Google Chrome
Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)

Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for …

AI
Threat actors are giving AI agents a bigger role in cyberattacks

AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google …

Microsoft 365 phishing
IT help-desk vishing tricks executives into handing over Microsoft 365 access

IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and …

data breach
Mathspace breach exposes data on over a million students and parents

Mathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million …

Mikrotik
Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication

Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national …

N-able N-central
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular …

ConnectWise
Attackers use rogue ScreenConnect clients to spread malware

A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A CVE identifier …

AI write
18 ways to check whether data can be trusted for AI

ETSI has published TR 104 180, a technical report that defines 18 metrics for measuring data quality, giving companies a way to check whether their data is good enough for AI …

cybersecurity week in review
Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers hijack login sessions …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools