Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
DuckDB AWS
DuckDB stays open source while the team behind it goes to work for Amazon

Hannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to …

Becky Palmer
National Life Group CISO expects more vulnerabilities in six months than in thirty years

In this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion …

Google
Scareware ads keep running on Google’s transparency tool, even after they’re reported

A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed …

Sift
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows …

Anthropic
Anthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloud

Eight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and …

puzzle
An AI CAPTCHA solver talked itself out of the right answer

You have probably spent a few seconds of your life turning a picture until it lines up. Some sites, instead of asking you to tick a box, show you a circular chunk of a photo …

software
CISA review makes the case for eliminating vulnerability classes

For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep …

Phishing
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks

A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting …

malware
Fake Claude Opus 5 app delivers malware and wipes its own tracks

A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that …

Berlin
Berlin refuses to be blackmailed after network breach

Berlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior …

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers

Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and …

CrowdSec
Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes

Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools