Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
SharePoint
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)

Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked …

Patch Tuesday
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and …

Microsoft Entra ID
Microsoft Entra ID is removing an extra MFA hurdle for Windows Hello and macOS PSSO users

Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches …

N-able N-central
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service …

SharePoint
200 accounts compromised in Swiss government’s Microsoft SharePoint breach

Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), …

Patch Tuesday
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?

July 2026 Patch Tuesday was record-setting in so many ways. The sheer volume of security patches for almost every product in the Microsoft portfolio was the highest ever and, …

Microsoft
Microsoft extends zero trust deeper into enterprise AI

Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security …

wireless
Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

Midnight Blizzard, the Russian threat actor tied to the country’s foreign intelligence service, has spent months targeting users of public Wi-Fi networks at places like …

Nuget
Microsoft shortens NuGet API key lifetime to improve supply chain security

Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for …

Microsoft
Microsoft unveils MAI-Cyber-1-Flash, promises cybersecurity AI at half the cost

Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. …

predictions
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)

Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate …

Windows Server
Microsoft tightens Windows enterprise activation security

Microsoft is making Trusted Platform Module (TPM)-backed attestation a requirement for Windows Key Management Service (KMS), the on-premises service used for Windows volume …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools