Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
Python Package Index
PyPI hardens package security with new upload restrictions

The Python Package Index (PyPI) now rejects uploads of new files to releases older than 14 days to prevent attackers from poisoning long-stable releases if a project’s …

GitHub
GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. The changes will …

shadow AI
Shadow AI is becoming enterprise security’s biggest blind spot

Artificial intelligence has moved from experimentation to everyday business operations with remarkable speed. Employees are using it to summarize documents, draft …

code
The AI code vulnerabilities that grow with your app

Theori built 28 apps with AI coding agents and scanned each one through its pentesting platform. Five models did the building, split between Anthropic and OpenAI, across apps …

shield
Building a defense in depth strategy for sensitive data

In this Help Net Security video, Venkata Pavan Kumar Gummadi, a Professional Software Engineer, explains how to build a defense in depth strategy for protecting sensitive …

Hugging Face
OpenAI: Our models breached Hugging Face during a cyber capability test

The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging …

Robot
AI models cheat on cybersecurity evaluations, then fail to admit it

Frontier AI models will take just about any route to finish a task, cheating included, according to new cybersecurity evaluations from the UK government’s AI Security …

Google Gemini
Google’s Gemini 3.5 Flash Cyber becomes a vulnerability hunter

Google’s Gemini 3.5 Flash Cyber model finds, validates, and patches vulnerabilities before they can be exploited while helping mitigate broader misuse. It is part of a …

Snowpick
Snowpick: Open-source ServiceNow exposure scanner

An employee opens a company service portal, searches the knowledge base, and drops a file onto a ticket. Someone who never signed in can send a request to that same portal and …

vulnerability
Security teams keep finding critical flaws after scheduled testing ends

Enterprise environments change between scheduled security assessments, leaving organizations with periods where new vulnerabilities can go undetected. Synack’s State of …

AI
Cloud operations become the next big role for agentic AI

Companies are using agentic AI to manage growing application environments, automate routine tasks, and support decisions. Business and IT leaders increasingly see the …

AI
AI agents are still logging in as humans

Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools