CISA lays out new guidance for using open-source software
The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies …
Mapping the malware blast radius a single alert won’t show you
In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far …
Anthropic’s Claude breached three companies during security tests
Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure …
Companies push AI, sysadmins keep it on a short leash
In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. …
AI agents are changing where cybersecurity seed funding lands
Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last …
AI takes on a bigger role in finding Chrome vulnerabilities
Google has expanded the use of AI in Chrome’s security workflow, using it to find vulnerabilities, triage bug reports, generate patches, and review code to shorten the …
CISA sets a new SBOM baseline
The US Cybersecurity and Infrastructure Security Agency (CISA), together with its co-authoring partners, has released the 2026 Minimum Elements for a Software Bill of …
Data breach cost 2026 averaged $4.99 million, AI attacks ran higher
More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran …
Your AI agents can reach data no one approved
A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the …
VERITAS project could change the way scientists secure AI
The AI models, datasets, and automated systems researchers depend on can be compromised in ways conventional cybersecurity tools aren’t designed to detect. A new project …
Shadow AI incident response begins with logs that may already be gone
In this Help Net Security interview, Brandy Wityak, VP of Complex Matters at LevelBlue, explains what happens in the hours after a shadow AI incident. She describes how …
AI took more than junior developer jobs and the bill comes later
A ticket comes in for a small bug fix. Hand it to the junior on your team and you wait a day, review something that half works, and sit down to explain what went wrong. …
Featured news
Resources
Don't miss
- Unpatched Zimbra servers are falling to CVE-2026-73570 attacks
- AI supply chain risk is showing up in developer workflows first
- HOL Guard: Open-source antivirus for AI agents
- The cybercrime supply chain has five stages, each with a price
- Suspected Iran-linked attack knocked UK power plant offline for days