Help Net Security newsletters: Daily and weekly news, cybersecurity jobs, open source projects, breaking news – subscribe here!

Please turn on your JavaScript for this page to function normally.
AWS
AWS spent years rebuilding its routing control plane without taking the network down

Every AWS API call, CloudFront video stream, and Route 53 lookup crosses the same infrastructure, which AWS calls its border network. It now runs on a routing system rebuilt …

botnet
What breach and attack simulation needs to become in the AI era

Breach and attack simulation (BAS) has always had a supply chain. Somebody has to read the threat report, pull out the techniques, and turn them into something that will …

BleachBit
BleachBit 6.0.4 fixes secure wiping that skipped clusters on Windows

The open source cleaner BleachBit reached version 6.0.4 this week, erasing caches, browser traces, and files on Windows, Linux, and now macOS. If you shredded a sensitive file …

AI
Threat actors are giving AI agents a bigger role in cyberattacks

AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google …

WeChat WeWorm
“Zero-click” WeChat worm could hijack accounts and spread via a single call

Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create …

Trezor
Trezor customers hit with phishing calls and letters after shipping-partner breach

Roughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone …

Microsoft 365 phishing
IT help-desk vishing tricks executives into handing over Microsoft 365 access

IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and …

data breach
Mathspace breach exposes data on over a million students and parents

Mathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million …

Jellyfin
Jellyfin 12.0 security fixes arrive alongside the removal of legacy client logins

Jellyfin shipped version 12.0 of its media server. Several of the security fixes in it block requests built to reach files outside the folders the server is supposed to hand …

ransomware
Ransomware negotiation tactics have turned into a business process

In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware …

Doppler secrets management platform
Product showcase: Doppler secures secrets for humans, pipelines, and AI agents

Every engineering team has spent years trying to keep credentials out of source code. Then AI agents moved the problem. Coding agents review code, agents run workflows, and …

Microsoft
Microsoft’s Project Zenith puts large AI models directly on developer PCs

Microsoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without …

Don't miss

Cybersecurity news
Daily newsletter sent Monday-Friday
Weekly newsletter sent on Mondays
Editor's choice newsletter sent twice a month
Periodical newsletter released for important security events and breaking news
Weekly newsletter listing new cybersecurity job positions
Monthly newsletter focusing on open source cybersecurity tools