Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
Aryon
ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility

Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization …

network
Cloudflare reveals what’s behind major internet outages

Storms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to …

Google Meta
Stolen Meta and Google ad accounts are worth more than the money they hold

Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy complete with tiered pricing, …

WhatsApp
WhatsApp brings end-to-end encrypted voice and video calls to the web

WhatsApp has launched support for voice and video calls on the web, allowing users to make and receive calls directly from their browser without installing the desktop app. …

lock
An AI agent can pass every safety check and still leak secrets

A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the …

critical infrastructure
The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced

A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to …

Specter
Specter: Open-source NFC reader bug sweep for Flipper Zero

Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The Flipper’s own …

LLM
Your AI agents can reach data no one approved

A credential expired. An AI agent kept using it anyway, and a mid-sized company’s systems went down for a quarter’s worth of trouble before anyone traced the …

Android
Android malware detection collapses when the context stage comes out

A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and …

AI
Hugging Face breach reignites open-weights debate, raises liability questions

The first publicly documented cyberattack run end-to-end by an autonomous AI was an OpenAI benchmark test that escaped its sandbox and breached Hugging Face. In an incident …

error
Exposed BMCs hand out password hashes before login

An attacker who reaches UDP port 623 on a server’s baseboard management controller can ask it for a password hash and receive one before logging in. The exchange is part …

TeamCity JetBrains
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)

JetBrains has fixed a critical vulnerability (CVE-2026-63077) affecting TeamCity On-Premises and is urging admins to upgrade self-hosted servers as soon as possible. …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools