Help Net Security

Help Net Security

Publication
0 followers

Established cybersecurity portal providing daily news and expert security advisories.

Firewalla Outlines a Zero Trust Approach to Fixing Flat Home Networks
NewsJan 26, 2026

Firewalla Outlines a Zero Trust Approach to Fixing Flat Home Networks

Firewalla introduced a zero‑trust, microsegmentation approach that lets homeowners modernize large, flat Wi‑Fi networks without renumbering IP addresses or reconfiguring devices. Using the AP7 and Orange appliances, users can keep existing SSIDs while automatically isolating legacy IoT, newer smart devices,...

By Help Net Security
Brakeman: Open-Source Vulnerability Scanner for Ruby on Rails Applications
NewsJan 26, 2026

Brakeman: Open-Source Vulnerability Scanner for Ruby on Rails Applications

Brakeman is an open‑source static analysis scanner that inspects Ruby on Rails codebases for security flaws without executing the application. It evaluates controllers, models, views, templates, and dependency versions, flagging injection, XSS, unsafe redirects, and authentication weaknesses. The tool integrates...

By Help Net Security
Incident Response Lessons Learned the Hard Way
NewsJan 26, 2026

Incident Response Lessons Learned the Hard Way

Ryan Seymour, VP of Consulting and Education at ConnectSecure, draws on over twenty years of incident‑response work to explain why many failures begin before an attack even starts. He shows that teams often hesitate when alerts appear, not because of...

By Help Net Security
AWS Releases Updated PCI PIN Compliance Report for Payment Cryptography
NewsJan 26, 2026

AWS Releases Updated PCI PIN Compliance Report for Payment Cryptography

Amazon Web Services has released an updated PCI PIN compliance package for its Payment Cryptography service, confirming a recent third‑party audit with zero findings. The package includes a PCI PIN Attestation of Compliance and a Responsibility Summary that outlines customer obligations. The...

By Help Net Security
Elastic Agent Builder Expands How Developers Build Production-Ready AI Agents
NewsJan 23, 2026

Elastic Agent Builder Expands How Developers Build Production-Ready AI Agents

Elastic has launched the general availability of Agent Builder, a platform that lets developers create secure, context‑driven AI agents in minutes by leveraging Elasticsearch’s unified search and analytics capabilities. The offering includes native data preparation, retrieval, ranking, custom tools, conversational...

By Help Net Security
Ring Now Lets Users Verify Whether Videos Have Been Altered
NewsJan 23, 2026

Ring Now Lets Users Verify Whether Videos Have Been Altered

Ring has launched Ring Verify, a built‑in authenticity feature that embeds a digital security seal in every video recorded after December 2025. The seal automatically breaks if the footage is trimmed, re‑encoded, or otherwise altered, and users can check verification status...

By Help Net Security
Iboss Unveils AI-Powered SSPM Capability to Reduce SaaS Risk
NewsJan 23, 2026

Iboss Unveils AI-Powered SSPM Capability to Reduce SaaS Risk

iboss introduced an AI‑powered SaaS Security Posture Management (SSPM) capability within its Zero Trust SASE platform. The solution connects to SaaS apps via native APIs, continuously scanning configurations, permissions and data exposure. AI analysis prioritizes misconfigurations and risky sharing, presenting...

By Help Net Security
Microsoft Introduces Winapp, an Open-Source CLI for Building Windows Apps
NewsJan 23, 2026

Microsoft Introduces Winapp, an Open-Source CLI for Building Windows Apps

Microsoft has launched winapp, an open‑source command‑line interface designed to simplify Windows application development. The tool consolidates SDK management, manifest editing, certificate generation, and packaging into unified commands, supporting project scaffolding, dependency handling, and build/run operations. Winapp integrates with Visual...

By Help Net Security
Energy Sector Orgs Targeted with AiTM Phishing Campaign
NewsJan 22, 2026

Energy Sector Orgs Targeted with AiTM Phishing Campaign

Microsoft has identified a sophisticated AiTM phishing campaign targeting energy‑sector organizations. Attackers use compromised trusted email accounts to send “NEW PROPOSAL – NDA” messages containing a malicious SharePoint link that leads to a fake login page. The page captures credentials...

By Help Net Security
Claroty Raises $150 Million to Advance Global CPS Protection Platform
NewsJan 22, 2026

Claroty Raises $150 Million to Advance Global CPS Protection Platform

Claroty announced a $150 million Series F round led by Golub Growth, with existing investors contributing up to an additional $50 million. The capital will fund both organic and inorganic expansion of its cyber‑physical systems (CPS) protection platform. Claroty positions the funding as...

By Help Net Security
OpenWrt One Gains Support for Running Debian
NewsJan 22, 2026

OpenWrt One Gains Support for Running Debian

Debian now runs on the OpenWrt One router hardware. Engineers added low‑level platform support, bootloader tweaks, and system initialization scripts to enable Debian to boot directly without abstraction layers. The OpenWrt One serves as a reference device for the OpenWrt...

By Help Net Security
EaseUS Disk Copy 7.0.0 Enables Backup, Restore, and Migration without Multiple Drives Connected
NewsJan 22, 2026

EaseUS Disk Copy 7.0.0 Enables Backup, Restore, and Migration without Multiple Drives Connected

EaseUS released Disk Copy 7.0.0, adding full disk‑imaging capabilities to its previously cloning‑only tool. Users can now create compressed image files, store them independently, and restore them to physical or virtual disks without needing both drives connected. The update also...

By Help Net Security
Unbounded AI Use Can Break Your Systems
NewsJan 22, 2026

Unbounded AI Use Can Break Your Systems

James Wickett, CEO of DryRun Security, warns that organizations are rapidly embedding large‑language‑model (LLM) features into live products without adequate safeguards. He highlights the danger of AI‑generated code being trusted for critical business logic and access control. The video stresses...

By Help Net Security
MacOS Tahoe Improves Privacy and Communication Safety
NewsJan 22, 2026

MacOS Tahoe Improves Privacy and Communication Safety

Apple’s macOS Tahoe introduces a suite of privacy‑focused features that screen unwanted calls, messages, and online tracking. Native Phone, Messages and FaceTime now offer system‑level unknown‑contact controls, while Safari extends Advanced Fingerprinting Protection to every browsing session. Parental tools let...

By Help Net Security
Microsoft Updates the Security Baseline for Microsoft 365 Apps for Enterprise
NewsJan 21, 2026

Microsoft Updates the Security Baseline for Microsoft 365 Apps for Enterprise

Microsoft has released security baseline version 2512 for Microsoft 365 Apps for enterprise, providing recommended policy settings across Word, Excel, PowerPoint, Outlook, and Access. The baseline addresses macros, add‑ins, ActiveX, Protected View, and update behavior, and is delivered as Group Policy objects...

By Help Net Security
Check Point Exposure Management Unifies Threat Intelligence, Context, and Remediation
NewsJan 21, 2026

Check Point Exposure Management Unifies Threat Intelligence, Context, and Remediation

Check Point unveiled Exposure Management, a platform that fuses threat intelligence, vulnerability prioritization, and automated remediation into a single workflow. The solution offers real‑time situational awareness by correlating dark‑web insights, exploitability context, and attack‑surface visibility. It integrates with more than...

By Help Net Security
Cohesity Enhances Identity Resilience with ITDR Capabilities
NewsJan 21, 2026

Cohesity Enhances Identity Resilience with ITDR Capabilities

Cohesity has introduced Identity Threat Detection and Response (ITDR) capabilities, extending its Identity Resilience suite to protect Active Directory and Microsoft Entra ID. The solution continuously monitors identity posture, flags risky changes, and detects attack patterns before an incident. During...

By Help Net Security
Vectra AI Helps Organizations Prevent AI-Powered Cyberattacks
NewsJan 21, 2026

Vectra AI Helps Organizations Prevent AI-Powered Cyberattacks

Vectra AI unveiled a next‑generation platform designed to safeguard the emerging AI enterprise, where machine‑speed workloads span on‑premises, multi‑cloud, SaaS, IoT and edge environments. The solution delivers unified observability, automatically discovers AI agents as first‑class identities, and uses behavior‑driven AI...

By Help Net Security
Rust Package Registry Adds Security Tools and Metrics to crates.io
NewsJan 21, 2026

Rust Package Registry Adds Security Tools and Metrics to crates.io

The Rust package registry crates.io has introduced a Security tab that surfaces RustSec advisories and flags vulnerable versions on each crate page. Publishing workflows were enhanced with Trusted Publishing support for GitLab CI/CD, enabling OIDC‑based authentication without long‑lived tokens. New...

By Help Net Security
Linux Users Targeted by Crypto Thieves via Hijacked Apps on Snap Store
NewsJan 21, 2026

Linux Users Targeted by Crypto Thieves via Hijacked Apps on Snap Store

Security researcher Alan Pope revealed that crypto thieves are hijacking expired domains linked to Snap Store publishers to gain Snapcraft account access and push malicious updates. The attackers replace benign snaps with crypto‑wallet malware that steals recovery phrases via automatic...

By Help Net Security
Cside Targets Hidden Website Privacy Violations with Privacy Watch
NewsJan 21, 2026

Cside Targets Hidden Website Privacy Violations with Privacy Watch

cside unveiled Privacy Watch, an AI‑driven platform that continuously monitors client‑side third‑party scripts for hidden data collection and privacy violations. The tool automatically generates evidence logs and regulation‑specific reports to help organizations meet GDPR, CPRA, HIPAA and emerging state‑level requirements. With...

By Help Net Security
Cybercriminals Speak the Language Young People Trust
NewsJan 21, 2026

Cybercriminals Speak the Language Young People Trust

Criminal networks are systematically recruiting minors through familiar platforms such as TikTok, Instagram, Snapchat and Discord, using encrypted messaging and crypto payments to mask their activities. They speak in coded, game‑like language that makes illegal tasks appear low‑risk and rewarding,...

By Help Net Security
Bandit: Open-Source Tool Designed to Find Security Issues in Python Code
NewsJan 21, 2026

Bandit: Open-Source Tool Designed to Find Security Issues in Python Code

Bandit is an open‑source Python security scanner maintained by the PyCQA community. It parses source files and flags risky patterns such as unsafe eval calls, weak cryptography, hard‑coded credentials, and insecure temporary file handling. Each finding is annotated with severity...

By Help Net Security
The 2026 State of Pentesting: Why Delivery and Follow-Through Matter More than Ever
NewsJan 21, 2026

The 2026 State of Pentesting: Why Delivery and Follow-Through Matter More than Ever

Penetration testing has shifted from static, point‑in‑time reports to continuous, outcome‑driven programs. Modern teams now demand real‑time delivery, automated routing of findings, and closed‑loop validation to reduce risk. Platforms like PlexTrac enable centralized visibility, integration with ticketing tools, and automated...

By Help Net Security
Security Leaders Push for Continuous Controls as Audits Stay Manual
NewsJan 21, 2026

Security Leaders Push for Continuous Controls as Audits Stay Manual

Security and risk teams still rely heavily on manual GRC processes, spending thousands of person‑hours each year collecting evidence and preparing audits. While organizations adopt automation for policy management and evidence gathering, deeper workflow automation and continuous controls monitoring remain...

By Help Net Security
Ping Identity Launches Universal Services for Ongoing Identity Assurance
NewsJan 20, 2026

Ping Identity Launches Universal Services for Ongoing Identity Assurance

Ping Identity introduced Universal Services, a continuous identity assurance suite that extends trust beyond the login event to every digital interaction. The offering integrates with any existing identity provider via standard APIs, allowing enterprises to validate, re‑verify, and adapt protections...

By Help Net Security
Endace Pushes Packet Capture Into Real-Time Security Workflows
NewsJan 20, 2026

Endace Pushes Packet Capture Into Real-Time Security Workflows

Endace released OSm 7.3, a major update that dramatically speeds packet‑capture search and adds a Vault REST API for automated forensic data access. The new search engine delivers up to 50‑fold performance gains, cutting typical query times from nearly a minute...

By Help Net Security
Radware Targets API Blind Spots with Real-Time Lifecycle Protection
NewsJan 20, 2026

Radware Targets API Blind Spots with Real-Time Lifecycle Protection

Radware announced its API Security Service, an end‑to‑end platform that safeguards APIs throughout their entire lifecycle using live production traffic. The solution tackles OWASP Top 10 API risks, including sophisticated Layer 7 DDoS attacks, by delivering continuous discovery, runtime posture management, and...

By Help Net Security
Confusion and Fear Send People to Reddit for Cybersecurity Advice
NewsJan 20, 2026

Confusion and Fear Send People to Reddit for Cybersecurity Advice

Researchers from Google and University College London examined 1.1 billion Reddit posts from 2021‑2024 to map how users seek cybersecurity help. Help‑seeking activity remained steady until a sharp 66 % jump in 2024, topping 100 000 questions per month by August. Scams, account‑access...

By Help Net Security
Keepnet Bets on Agentic AI Behavioral Training to Curb Security Mistakes
NewsJan 19, 2026

Keepnet Bets on Agentic AI Behavioral Training to Curb Security Mistakes

Keepnet introduced Agentic AI for Behavioral Microlearning, shifting training success metrics from completion rates to measurable behavior change and incident reduction. The autonomous platform plans, creates, delivers, and optimizes short, contextual lessons using real‑time risk data, cutting content‑creation time from...

By Help Net Security
British Army to Spend £279 Million on Permanent Cyber Regiment Base
NewsJan 19, 2026

British Army to Spend £279 Million on Permanent Cyber Regiment Base

The British Army will invest £279 million to build a permanent base for its 13 Signal Regiment at Duke of Gloucester Barracks in Gloucestershire. The new facility will house cyber training, operations, and the Army’s Cyber, Information and Security Operations Centre, enhancing...

By Help Net Security
SEON Identity Verification Combines KYC Checks with Real-Time Fraud Intelligence
NewsJan 19, 2026

SEON Identity Verification Combines KYC Checks with Real-Time Fraud Intelligence

SEON introduced an AI‑powered Identity Verification solution that combines document validation, biometric liveness detection, proof‑of‑address checks, and optional government database queries within its unified risk platform. The service draws on more than 900 real‑time fraud signals to evaluate both the...

By Help Net Security
Global Tensions Are Pushing Cyber Activity Toward Dangerous Territory
NewsJan 19, 2026

Global Tensions Are Pushing Cyber Activity Toward Dangerous Territory

Geopolitical rivalries are increasingly manifesting as cyber operations that target critical infrastructure, disinformation networks, and supply‑chain dependencies. Recent incidents—from the Ukrainian power‑grid outage to a Norwegian dam breach—illustrate how state actors can weaponize digital tools against civilian services. AI‑generated disinformation...

By Help Net Security
Rubrik Introduces Security Cloud Sovereign for Data Sovereignty and Regulatory Compliance
NewsJan 19, 2026

Rubrik Introduces Security Cloud Sovereign for Data Sovereignty and Regulatory Compliance

Rubrik unveiled Security Cloud Sovereign, a data‑protection platform that keeps all data, metadata, and control planes inside a customer‑chosen jurisdiction. The solution offers immutable safeguards that prevent encryption, deletion, or alteration even if attackers gain elevated access. Integrated threat‑detection analytics...

By Help Net Security
Review: AI Strategy and Security
NewsJan 19, 2026

Review: AI Strategy and Security

AI Strategy and Security, authored by Dr. Donnie W. Wendt, is a practical guide for technology leaders and security professionals designing enterprise AI programs. The book maps AI adoption to business objectives, outlines readiness assessments, and defines a comprehensive team...

By Help Net Security
Bytebase: Open-Source Database DevOps Tool
NewsJan 19, 2026

Bytebase: Open-Source Database DevOps Tool

Bytebase is an open‑source DevOps platform that streamlines database schema and data changes through a structured change‑request workflow. It lets teams submit SQL changes, run automated reviews, and track executions across development, staging, and production environments. The tool includes built‑in...

By Help Net Security
New Intelligence Is Moving Faster than Enterprise Controls
NewsJan 16, 2026

New Intelligence Is Moving Faster than Enterprise Controls

A new NTT global study finds AI integration outpaces enterprise security and governance. Companies expand AI deployments but many lack infrastructure readiness, data integrity controls, and mature governance. Only a small share can support AI at scale; performance drives design,...

By Help Net Security
Who’s on the Other End? Rented Accounts Are Stress-Testing Trust in Gig Platforms
NewsJan 16, 2026

Who’s on the Other End? Rented Accounts Are Stress-Testing Trust in Gig Platforms

A TransUnion study of U.S. gig workers reveals that 34% have been defrauded by customers, while nearly half admit to renting or selling their accounts. Victims demand stronger identity checks, yet confidence in existing safety tools remains low. The research...

By Help Net Security
Bitwarden Advances Passkeys and Credential Risk Controls
NewsJan 15, 2026

Bitwarden Advances Passkeys and Credential Risk Controls

Bitwarden unveiled Access Intelligence, delivering application‑level visibility into weak, reused or exposed credentials and guiding remediation, cutting average resolution time from nine days. The company also expanded passkey support, adding native Windows 11 integration, cross‑platform portability via the FIDO Credential Exchange...

By Help Net Security
F5 Targets AI Runtime Risk with New Guardrails and Adversarial Testing Tools
NewsJan 15, 2026

F5 Targets AI Runtime Risk with New Guardrails and Adversarial Testing Tools

F5 announced the general availability of two AI‑runtime security products—F5 AI Guardrails and F5 AI Red Team. The Guardrails solution provides model‑agnostic, real‑time protection for AI agents, while the Red Team offers automated adversarial testing using a continuously updated threat...

By Help Net Security
Asimily Extends Cisco ISE Integration to Turn Device Risk Into Segmentation Policy
NewsJan 15, 2026

Asimily Extends Cisco ISE Integration to Turn Device Risk Into Segmentation Policy

Asimily announced new microsegmentation capabilities that add Security Group Access Control List (SGACL) support to Cisco Identity Services Engine (ISE). The integration lets organizations automatically translate device classification, behavior analysis, and risk scores into enforceable segmentation policies. By extending its...

By Help Net Security
Microsoft Shuts Down RedVDS Cybercrime Subscription Service Tied to Millions in Fraud Losses
NewsJan 15, 2026

Microsoft Shuts Down RedVDS Cybercrime Subscription Service Tied to Millions in Fraud Losses

Microsoft announced a coordinated legal operation in the United States and United Kingdom, backed by Europol and German authorities, to dismantle RedVDS, a subscription‑based cybercrime platform. Since March 2025, RedVDS has enabled fraudsters to rent disposable virtual machines for $24...

By Help Net Security
LinkedIn Wants to Make Verification a Portable Trust Signal
NewsJan 15, 2026

LinkedIn Wants to Make Verification a Portable Trust Signal

LinkedIn is launching a self‑serve API that lets its Verified on LinkedIn badge be displayed on third‑party platforms, turning the verification badge into a portable trust signal. The company reports that 75 members verify each minute, now exceeding 100 million verified...

By Help Net Security
QR Codes Are Getting Colorful, Fancy, and Dangerous
NewsJan 15, 2026

QR Codes Are Getting Colorful, Fancy, and Dangerous

QR codes have evolved from plain black‑and‑white squares to colorful, logo‑embedded designs, making them a popular yet risky communication channel. Researchers at Deakin University identified a surge in "quishing" attacks that exploit these stylized codes to bypass traditional URL‑based security...

By Help Net Security
Cybersecurity Spending Keeps Rising, so Why Is Business Impact Still Hard to Explain?
NewsJan 15, 2026

Cybersecurity Spending Keeps Rising, so Why Is Business Impact Still Hard to Explain?

Cybersecurity budgets are set to increase again, yet security leaders still struggle to demonstrate clear business value. Finance executives express uneven trust in security teams’ ability to translate risk mitigation into financial outcomes, creating friction in budget approvals. Divergent definitions...

By Help Net Security
The NSA Lays Out the First Steps for Zero Trust Adoption
NewsJan 15, 2026

The NSA Lays Out the First Steps for Zero Trust Adoption

The National Security Agency has published the first two documents in its Zero Trust Implementation Guidelines series—a Primer and a Discovery Phase guide. The Primer explains the structure and principles of the series, while the Discovery Phase directs organizations to...

By Help Net Security
Webinar: Beyond the Quadrant: An Analyst’s Guide to Evaluating Email Security in 2026
NewsJan 14, 2026

Webinar: Beyond the Quadrant: An Analyst’s Guide to Evaluating Email Security in 2026

Former Gartner analyst Ravisha Chugh and Abnormal’s Director of Product Marketing Lane Billings will host a webinar on January 20 2026, revealing how email‑security vendors will be evaluated in 2026. The session outlines Gartner’s evaluation criteria, essential vendor questions, red‑flags, and a proven shortlisting...

By Help Net Security
Airia Adds AI Governance for Compliance, Accountability, and Control
NewsJan 14, 2026

Airia Adds AI Governance for Compliance, Accountability, and Control

Airia has launched an AI Governance product, completing its three‑pillar enterprise AI management ecosystem alongside AI Security and Agent Orchestration. The new suite offers a governance dashboard, model and agent registries, compliance automation, and risk assessment tools to provide end‑to‑end...

By Help Net Security
One Identity Manager 10.0 Introduces Risk-Based Governance and ITDR Capabilities
NewsJan 14, 2026

One Identity Manager 10.0 Introduces Risk-Based Governance and ITDR Capabilities

One Identity launched Manager 10.0, adding risk‑based governance, identity threat detection and response (ITDR) playbooks, and AI‑assisted natural‑language reporting. The upgrade integrates third‑party UEBA risk scores, automates remediation actions, and introduces a browser‑based admin console. Enhanced Syslog CEF formatting improves SIEM...

By Help Net Security