<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<title>Latest News on Technology, Cryptocurrency, AI, and Cyber Security &#45; : Cyber Security</title>
<link>https://block385.com/rss/category/cybernews</link>
<description>Latest News on Technology, Cryptocurrency, AI, and Cyber Security &#45; : Cyber Security</description>
<dc:language>en</dc:language>
<dc:rights>2026 Block385.com</dc:rights>

<item>
<title>Thieves can pull off keyless car theft in under a minute and here’s how to stop them</title>
<link>https://block385.com/thieves-can-pull-off-keyless-car-theft-in-under-a-minute-and-heres-how-to-stop-them</link>
<guid>https://block385.com/thieves-can-pull-off-keyless-car-theft-in-under-a-minute-and-heres-how-to-stop-them</guid>
<description><![CDATA[ A keyless car can be stolen in under a minute. Two people, a pair of cheap radio amplifiers, and a fob sitting on a hallway table inside the house. That is enough. No broken glass. No alarm. No sound. Most keyless cars remain vulnerable The vulnerability runs across the global market. Germany’s largest auto club, ADAC, runs ongoing tests of keyless models against relay attacks. The rolling series has now covered more than 800 vehicles, … More →
The post Thieves can pull off keyless car theft in under a minute and here’s how to stop them appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/01131358/car_key-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 09:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Thieves, can, pull, off, keyless, car, theft, under, minute, and, here’s, how, stop, them</media:keywords>
</item>

<item>
<title>AgentGG: Open&#45;source agentic SAST scanner</title>
<link>https://block385.com/agentgg-open-source-agentic-sast-scanner</link>
<guid>https://block385.com/agentgg-open-source-agentic-sast-scanner</guid>
<description><![CDATA[ Static analysis tools have spent years matching source code against known-bad patterns and handing engineers long lists of candidate issues to triage by hand. AgentGG approaches the same job with AI agents that read the code, follow imports, walk the call graph, and confirm a finding before they report it. The project is an open-source agentic SAST scanner released under the Apache 2.0 license. How the agents run Each agent is a self-contained markdown file … More →
The post AgentGG: Open-source agentic SAST scanner appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/03174032/agentgg-scanner-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 09:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>AgentGG:, Open-source, agentic, SAST, scanner</media:keywords>
</item>

<item>
<title>June 2026 Patch Tuesday forecast: Where are the CVEs?</title>
<link>https://block385.com/june-2026-patch-tuesday-forecast-where-are-the-cves</link>
<guid>https://block385.com/june-2026-patch-tuesday-forecast-where-are-the-cves</guid>
<description><![CDATA[ My forecast from last month was only partly right. After the Anthropic Mythos announcements and the deluge of newly discovered vulnerabilities from vendors like Mozilla, Microsoft’s updates were standard fare, 65 CVEs reported in Windows 11 and 58 in Windows 10. The Microsoft Office releases were a bit higher with 19 CVEs or so reported for the online versions. Apple did indeed release their OS security updates the day before Patch Tuesday, which garnered some … More →
The post June 2026 Patch Tuesday forecast: Where are the CVEs? appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/12193553/patch-tuesday-2-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 09:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>June, 2026, Patch, Tuesday, forecast:, Where, are, the, CVEs</media:keywords>
</item>

<item>
<title>Photos: Infosecurity Europe 2026</title>
<link>https://block385.com/photos-infosecurity-europe-2026</link>
<guid>https://block385.com/photos-infosecurity-europe-2026</guid>
<description><![CDATA[ Infosecurity Europe 2026 is a cybersecurity event that took place from June 2 to 4 in London. Help Net Security was on-site and here’s a closer look at the conference. The featured vendors are: Microsoft, JupiterOne, Menlo Security, Cato Networks, Falkin, Vivida, Pen Test Partners, Netskope, Qualys, Syteca, runZero, Vanta, OneTrust, Panaseer, Airia.
The post Photos: Infosecurity Europe 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2016/06/09112125/london.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 09:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Photos:, Infosecurity, Europe, 2026</media:keywords>
</item>

<item>
<title>PCPJack Hijacks 230 AWS, Google Cloud, and Azure Servers for Covert SMTP Relay Network</title>
<link>https://block385.com/pcpjack-hijacks-230-aws-google-cloud-and-azure-servers-for-covert-smtp-relay-network</link>
<guid>https://block385.com/pcpjack-hijacks-230-aws-google-cloud-and-azure-servers-for-covert-smtp-relay-network</guid>
<description><![CDATA[ The threat actor known as PCPJack has hijacked cloud servers associated with Amazon Web Services (AWS), Google Cloud, and Microsoft Azure to create a covert SMTP email relay network.

&quot;Compromised business servers across the U.S., Europe, and Asia were quietly converted into SMTP proxies, verified for mail relay capability, and synced to a downstream consumer every five minutes,&quot; Hunt.io said in ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibu0mX9Tusu3siXFJzPskfA1ZYZ2OdRJTegsJFkffBc9cBBPGWguTUAI3PPAaFy-WIjziA9PIrMrZNVuFVNmbFhOSPLv6mMBPvjWnR-WQGBD2fvGFTJT358yWFFTxeFSS87aQ_fj30G2VdsGlBjy2KJiby4CS-k3X9FjjpyTGxljOo373cUaZKhdBvWZ_a/s1600/cloud-emails.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 09:00:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>PCPJack, Hijacks, 230, AWS, Google, Cloud, and, Azure, Servers, for, Covert, SMTP, Relay, Network</media:keywords>
</item>

<item>
<title>New infosec products of the week: June 5, 2026</title>
<link>https://block385.com/new-infosec-products-of-the-week-june-5-2026</link>
<guid>https://block385.com/new-infosec-products-of-the-week-june-5-2026</guid>
<description><![CDATA[ Here’s a look at the most interesting products from the past week, featuring releases from Asimily, depthfirst, Diligent, Hyland, MazeBolt, and Noma. Asimily turns device risk into automated network policy Asimily has launched Segmentation Orchestration, enabling connected-device risk intelligence to flow directly into enforceable network policy without manual translation. No other platform combines full asset visibility, vulnerability prioritization, and segmentation orchestration in a single system. Hyland platform innovations focus on AI governance, context, and agent … More →
The post New infosec products of the week: June 5, 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/28091843/infosec-week-1200.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 07:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, infosec, products, the, week:, June, 2026</media:keywords>
</item>

<item>
<title>Most pros have seen AI hallucinations in IT operations</title>
<link>https://block385.com/most-pros-have-seen-ai-hallucinations-in-it-operations</link>
<guid>https://block385.com/most-pros-have-seen-ai-hallucinations-in-it-operations</guid>
<description><![CDATA[ Autonomous AI is taking action inside enterprise IT environments. Software is restarting services, isolating risky devices, and applying patches without waiting for a human to approve the step. The capability is spreading at the same time IT professionals are reporting frequent encounters with AI output errors that can carry operational impact. Ivanti’s 2026 AI Maturity Report, drawn from responses by 1,500 IT professionals across six countries, finds that 68% have personally seen AI produce hallucinations … More →
The post Most pros have seen AI hallucinations in IT operations appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/02135045/ai-1500-2.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 07:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Most, pros, have, seen, hallucinations, operations</media:keywords>
</item>

<item>
<title>AI agent governance gets harder when agents outnumber your people</title>
<link>https://block385.com/ai-agent-governance-gets-harder-when-agents-outnumber-your-people</link>
<guid>https://block385.com/ai-agent-governance-gets-harder-when-agents-outnumber-your-people</guid>
<description><![CDATA[ In this Help Net Security video, Amit Gautam, CTO at Abluva, explains the security risks that autonomous AI agents bring into enterprise environments. He opens with a real case: a reconciliation agent at a financial services firm had legitimate access to a customer database. A poison instruction from upstream changed its behavior, and it scanned the entire table, extracting six million records and posting them to a Slack webhook that sent them outside the company. … More →
The post AI agent governance gets harder when agents outnumber your people appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/30133724/bots-supply-chain.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 07:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>agent, governance, gets, harder, when, agents, outnumber, your, people</media:keywords>
</item>

<item>
<title>China&amp;apos;s TA4922 Expands Cybercrime Attacks Globally</title>
<link>https://block385.com/chinas-ta4922-expands-cybercrime-attacks-globally</link>
<guid>https://block385.com/chinas-ta4922-expands-cybercrime-attacks-globally</guid>
<description><![CDATA[ One of the world&#039;s most diverse, least-focused cybercrime groups is enlarging its footprint beyond East Asia. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt7a874a07e705cab8/6a21d83653660505464e0115/China-filo-Getty.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 01:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Chinas, TA4922, Expands, Cybercrime, Attacks, Globally</media:keywords>
</item>

<item>
<title>Rust&#45;Written IronWorm Hits NPM Supply Chain</title>
<link>https://block385.com/rust-written-ironworm-hits-npm-supply-chain</link>
<guid>https://block385.com/rust-written-ironworm-hits-npm-supply-chain</guid>
<description><![CDATA[ Like Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt705e8d4cc3766735/6a21e18d9f92ca732208c2ed/supplychain_Efkaysim_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 05 Jun 2026 01:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Rust-Written, IronWorm, Hits, NPM, Supply, Chain</media:keywords>
</item>

<item>
<title>4 Critical Threats Where Attackers Have the Advantage</title>
<link>https://block385.com/4-critical-threats-where-attackers-have-the-advantage</link>
<guid>https://block385.com/4-critical-threats-where-attackers-have-the-advantage</guid>
<description><![CDATA[ Gartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc676a0962a0ea8fe/6a21d849a5de42bca35b6335/promptinjections-tadamichi-Getty-2254128440.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 23:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Critical, Threats, Where, Attackers, Have, the, Advantage</media:keywords>
</item>

<item>
<title>Bugcrowd Launches EU Data Residency Option For Evolving Data Sovereignty Needs</title>
<link>https://block385.com/bugcrowd-launches-eu-data-residency-option-for-evolving-data-sovereignty-needs</link>
<guid>https://block385.com/bugcrowd-launches-eu-data-residency-option-for-evolving-data-sovereignty-needs</guid>
<description><![CDATA[ Organizations are growing serious about what nation’s rules apply to their data. Experts point to geopolitical tensions as a main contributing factor. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt54c8aa181780cfa7/6a2195015d57941c61b44ddd/GettyImages-2194925350.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 21:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Bugcrowd, Launches, Data, Residency, Option, For, Evolving, Data, Sovereignty, Needs</media:keywords>
</item>

<item>
<title>Cisco Patches CVE&#45;2026&#45;20230 in Unified CM as Exploit Code Goes Public</title>
<link>https://block385.com/cisco-patches-cve-2026-20230-in-unified-cm-as-exploit-code-goes-public</link>
<guid>https://block385.com/cisco-patches-cve-2026-20230-in-unified-cm-as-exploit-code-goes-public</guid>
<description><![CDATA[ Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root.

It is tracked as CVE-2026-20230, and proof-of-concept exploit code is already public. Cisco&#039;s PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway.

The flaw is a server-side request forgery. ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6_xkmI_c8KreZ4cr2oC9gHJERU9xWsLGDrCNCaB11IQVGmJ-r0MYUjqGllvOFc0IVwGYBqnzLJl96WBTSVXUr5Z8KRym9SsnoUlNN6oEditbTFqW3kTfOhujPEPN-KIzGJmxaJGh9mCvY1TadCVfJJfIBoTjbXn2TCcbQE8NHsKhe8ld53YHYsG5MTYg/s1600/cisco-flaw.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 21:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cisco, Patches, CVE-2026-20230, Unified, Exploit, Code, Goes, Public</media:keywords>
</item>

<item>
<title>Agentic AI Is Transforming Defense, But Only Secure IT Infrastructure Will Maximize It</title>
<link>https://block385.com/agentic-ai-is-transforming-defense-but-only-secure-it-infrastructure-will-maximize-it</link>
<guid>https://block385.com/agentic-ai-is-transforming-defense-but-only-secure-it-infrastructure-will-maximize-it</guid>
<description><![CDATA[ Over the past several weeks, the cybersecurity community has been reminded how quickly frontier and agentic AI in defense networks can challenge our assumptions. When Anthropic&#039;s Claude Mythos model was made available to a limited set of organizations as a technical preview, it was reported that an unauthorized group claimed that it had gained access within hours. The incident, if true, was ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi6i36LXqSESJrnuYOf6ULo2Hijp9l8i9UTGbRzCLuWImPpfPJ6cKQgBFGhS8yx3_qn8IoM0MgY0pmL4mZfzegatvhQWDKV5OQ3MfOWvPzYIokXaFDUvBM3EYsMOqtQoxx0AmeiakeocpBIlaNeCiBkPcnK1OW8abfIz0_8zuybqKQvWuriVC97Ir259Sw/s1600/agentic-ai.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 21:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Agentic, Transforming, Defense, But, Only, Secure, Infrastructure, Will, Maximize</media:keywords>
</item>

<item>
<title>China&#45;Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa</title>
<link>https://block385.com/china-linked-ta4922-expands-phishing-attacks-to-uk-germany-italy-and-south-africa-8665</link>
<guid>https://block385.com/china-linked-ta4922-expands-phishing-attacks-to-uk-germany-italy-and-south-africa-8665</guid>
<description><![CDATA[ A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa.

These efforts have been complemented by a &quot;rapid operational tempo&quot; and a continually evolving malware arsenal comprising known families like ValleyRAT (aka Winos 4.0) and Atlas RAT (aka AtlasCross RAT), as well as previously ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq_JkP80d1IA8rz-SoYEBmuGqK_K7OpGrqiki4vB1ShMW5mFBVSMvl8H5MnYylZMl3AWeqdAmp19oZIL_7amYErNxBGiUAJqrOqGO0zjHH2jxCKCNdiGH_nqjHlksD9dlu4QGCq9KzMRfnWAi7YnPQQ86pnCypNupFDn_h-hSJdfhWT0Y4s01w6Cw-s6Od/s1600/phishing-hook.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 21:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>China-Linked, TA4922, Expands, Phishing, Attacks, U.K., Germany, Italy, and, South, Africa</media:keywords>
</item>

<item>
<title>Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories</title>
<link>https://block385.com/claude-code-github-action-flaw-let-one-malicious-issue-hijack-repositories</link>
<guid>https://block385.com/claude-code-github-action-flaw-let-one-malicious-issue-hijack-repositories</guid>
<description><![CDATA[ A security researcher found a flaw in Anthropic&#039;s Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic&#039;s own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto the projects downstream that pull it.

RyotaK of GMO ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhiaBF9jAklPh1ncr_eVPGnV229BSTNgAjkScVm-yTXAn4IcBjjZoLIglasRdu1XEPafCxJhqVZrC3zkNWilyAhN-6Ox8z2HBRjNg2D4aqJsDiRDg02BgAy4zgwU2100ZLIO8yTOtarI0Vxa3AGUQk0GZq1_zKSFQOhNiNoyVsP2AldJZoW8ZJ1rY936ZI/s1600/claude-code-hack.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 19:00:18 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Claude, Code, GitHub, Action, Flaw, Let, One, Malicious, Issue, Hijack, Repositories</media:keywords>
</item>

<item>
<title>ThreatsDay Bulletin: AI Agents Gone Wrong, Sketchy C2 Tools, ClickFix Tricks, JS Backdoors &amp;amp; 20+ New Stories</title>
<link>https://block385.com/threatsday-bulletin-ai-agents-gone-wrong-sketchy-c2-tools-clickfix-tricks-js-backdoors-20-new-stories</link>
<guid>https://block385.com/threatsday-bulletin-ai-agents-gone-wrong-sketchy-c2-tools-clickfix-tricks-js-backdoors-20-new-stories</guid>
<description><![CDATA[ It got stupid again.

The internet still feels held together with tape. Bad plugins, old bugs, fake tools, trusted apps doing shady things. Same mess, new wrapper. And now the weird stuff is normal. Forums go down and come back worse. Cheap hackers get better toys. AI starts breaking real systems. Great.

Read the whole thing before it ruins your week anyway.








  
  
    Unauthenticated ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOsPH2SzhBWTxhXi2KCJw0YY29azn2hLkDQwQhyrjmwaRIXQfCAPNIjej3_TBd6VJm1JqWSs2EoI2jiWyVHENmhtd1alqSEqlJC8WxUk4b5zWUqszQ8akhGzRmCHf8OL7wMTZiWLYZDzHRXY8unPcsh2QMTfyTH0XeRszrwCunK2DazuZIF9oNKQUFxlqN/s1600/thh.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 17:00:22 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>ThreatsDay, Bulletin:, Agents, Gone, Wrong, Sketchy, Tools, ClickFix, Tricks, Backdoors, 20, New, Stories</media:keywords>
</item>

<item>
<title>OAuth marketplace apps keep access after publishers vanish</title>
<link>https://block385.com/oauth-marketplace-apps-keep-access-after-publishers-vanish</link>
<guid>https://block385.com/oauth-marketplace-apps-keep-access-after-publishers-vanish</guid>
<description><![CDATA[ Installing an app from the Google Workspace Marketplace or GitHub Marketplace can grant a third party access to company email, files, calendars, code repositories, CI workflows, organization settings, and secrets. Marketplace presence gives these apps the appearance of approval. The OAuth grants behind them often reach into business systems beyond the listed function. An audit by OhAuth, the OAuth research project from identity security company Offroad, covered 2,890 public OAuth app listings, with 1,595 on … More →
The post OAuth marketplace apps keep access after publishers vanish appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/03090853/eye-digital-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 15:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>OAuth, marketplace, apps, keep, access, after, publishers, vanish</media:keywords>
</item>

<item>
<title>China&#45;Linked TA4922 Expands Phishing Attacks to UK, Germany, Italy, and South Africa</title>
<link>https://block385.com/china-linked-ta4922-expands-phishing-attacks-to-uk-germany-italy-and-south-africa</link>
<guid>https://block385.com/china-linked-ta4922-expands-phishing-attacks-to-uk-germany-italy-and-south-africa</guid>
<description><![CDATA[ A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa.

These efforts have been complemented by a &quot;rapid operational tempo&quot; and a continually evolving malware arsenal comprising known families like ValleyRAT (aka Winos 4.0) and Atlas RAT (aka AtlasCross RAT), as well as previously ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhq_JkP80d1IA8rz-SoYEBmuGqK_K7OpGrqiki4vB1ShMW5mFBVSMvl8H5MnYylZMl3AWeqdAmp19oZIL_7amYErNxBGiUAJqrOqGO0zjHH2jxCKCNdiGH_nqjHlksD9dlu4QGCq9KzMRfnWAi7YnPQQ86pnCypNupFDn_h-hSJdfhWT0Y4s01w6Cw-s6Od/s1600/phishing-hook.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 15:00:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>China-Linked, TA4922, Expands, Phishing, Attacks, UK, Germany, Italy, and, South, Africa</media:keywords>
</item>

<item>
<title>FlutterShell Backdoor Spreads to macOS via Malicious Google and YouTube Ads</title>
<link>https://block385.com/fluttershell-backdoor-spreads-to-macos-via-malicious-google-and-youtube-ads</link>
<guid>https://block385.com/fluttershell-backdoor-spreads-to-macos-via-malicious-google-and-youtube-ads</guid>
<description><![CDATA[ Cybersecurity researchers have shed light on a macOS malvertising campaign codenamed Operation FlutterBridge that spreads a new backdoor called FlutterShell.

According to Palo Alto Networks Unit 42, the campaign is said to be the next stage of a previously reported activity cluster dubbed JSCoreRunner (aka FileRipple) in late August 2025. The cybercrime group behind the two attack chains is ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwFQkJElJQpI5ODTBzh1EzrxsRYamFN0ntC9V6vF4b4FfEJ0svPhI_1TnKm960eIsewSFT-DR1RtNk3M511OQK6I-k3UQNNLut1f_fjM9wB4NHxdvJzJQ3VvhIGO9ja0hNIzRAOZLVMngS4R8hQxXfV-_DO71x0CU0YSnxpclCnV0DGX6TdNmr32ongewk/s1600/macos.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 15:00:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>FlutterShell, Backdoor, Spreads, macOS, via, Malicious, Google, and, YouTube, Ads</media:keywords>
</item>

<item>
<title>Fake Sites Mimicking Open&#45;Source Tools Rank High on Google to Deliver Malware via TDS</title>
<link>https://block385.com/fake-sites-mimicking-open-source-tools-rank-high-on-google-to-deliver-malware-via-tds</link>
<guid>https://block385.com/fake-sites-mimicking-open-source-tools-rank-high-on-google-to-deliver-malware-via-tds</guid>
<description><![CDATA[ Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic Distribution System (TDS) and deliver malware families like Remus Stealer, AnimateClipper, and the SessionGate framework.

&quot;The sites are well-designed and often look like legitimate project portals at a glance, sometimes referencing ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiM7j9PG_c741so0RmX7eIB48xO-ndyZSF0pIU5j2anTqxJNj8A3XVstoIjq3iMnuQxhgyhl3LKP5laenFIj7IT0V8SOJ0lK7-Ywdsr5yBioNKF60SegkvR3SkfaSkPqZxN3rak0J-sZbvjxGDozCupAP3wraZjk0XU6-ZA590Q42cPaHXrdg7PJFGk1Ss/s1600/site.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 13:00:17 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Fake, Sites, Mimicking, Open-Source, Tools, Rank, High, Google, Deliver, Malware, via, TDS</media:keywords>
</item>

<item>
<title>Hackers Spied on a Stock Exchange Executive&amp;apos;s Outlook Mailbox for Five Months</title>
<link>https://block385.com/hackers-spied-on-a-stock-exchange-executives-outlook-mailbox-for-five-months</link>
<guid>https://block385.com/hackers-spied-on-a-stock-exchange-executives-outlook-mailbox-for-five-months</guid>
<description><![CDATA[ Unknown attackers spent at least five months inside the Outlook mailbox of a senior executive at a major global stock exchange, copying the inbox out in small, repeated batches and routing it through Dropbox and OneDrive so the traffic blended into normal cloud activity.

Symantec and Carbon Black&#039;s Threat Hunter Team reported the campaign this week. This points to espionage, not a money grab: ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpg8pBdHkENT_CKClsSR7f4Rb7BQpM27ynGrkRdJg-bbUfI2NIHQ_rFmkOVHjK8RggTD-XMvVdGGI_qrYyIx-Ml1sfwbRkbjaNo8Fz40cWg8wFWK8h5-f-FaB58HryMM5AYlUHI2uO7x12VFvAB6N3w1gobWmzGgp8xXqHfWMERFh7hVS9lBHxfdu71Xs/s1600/stock-emails.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 13:00:17 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Hackers, Spied, Stock, Exchange, Executives, Outlook, Mailbox, for, Five, Months</media:keywords>
</item>

<item>
<title>CISA Adds Exploited Magento RCE Flaw CVE&#45;2026&#45;45247 to KEV Catalog</title>
<link>https://block385.com/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog</link>
<guid>https://block385.com/cisa-adds-exploited-magento-rce-flaw-cve-2026-45247-to-kev-catalog</guid>
<description><![CDATA[ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

The vulnerability, tracked as CVE-2026-45247 (CVSS score: 9.8), is a case of deserialization of untrusted ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8P5o_wfJsxsTaxY4OONIm2y5N5x9heoFeLchfLU13YA36tGQGJtu00tOCQSKhCTBFobAAWfhXLtNGMu8ZCG7ozeLVggi1tnQVRK_1mJHd6eq1YSb5AlRZq5eDp3rGDL2Uli_b3aBPMBsLfMJ5QEm_XW1MF43_dcCf64rSbVrhsUakhaOAn5-GOmuLiq0s/s1600/mag.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 11:00:27 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CISA, Adds, Exploited, Magento, RCE, Flaw, CVE-2026-45247, KEV, Catalog</media:keywords>
</item>

<item>
<title>From critical to controlled: Cutting vulnerabilities in a live manufacturing environment</title>
<link>https://block385.com/from-critical-to-controlled-cutting-vulnerabilities-in-a-live-manufacturing-environment</link>
<guid>https://block385.com/from-critical-to-controlled-cutting-vulnerabilities-in-a-live-manufacturing-environment</guid>
<description><![CDATA[ A vulnerability scanner flags a critical CVSS 10 vulnerability on an industrial asset. The report lands in the boss’ inbox and now he wants to know why we’re sitting on a critical vulnerability. In a normal IT environment, you patch it then close the ticket and call it a day. If, however, you’re in OT or dealing with ICS in a live manufacturing facility, it’s rarely that simple. Here’s framework I use to answer the … More →
The post From critical to controlled: Cutting vulnerabilities in a live manufacturing environment appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/02/19165750/vulnerability-1400.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 09:30:12 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>From, critical, controlled:, Cutting, vulnerabilities, live, manufacturing, environment</media:keywords>
</item>

<item>
<title>The modern&#45;day business can learn a lot about risk from this year’s mega events</title>
<link>https://block385.com/the-modern-day-business-can-learn-a-lot-about-risk-from-this-years-mega-events</link>
<guid>https://block385.com/the-modern-day-business-can-learn-a-lot-about-risk-from-this-years-mega-events</guid>
<description><![CDATA[ Every year brings its share of global events, but 2026 is proving to be a banner year for mega-scale entertainment. The year got off to a roaring start with the Winter Olympics, and now anticipation is building for the fast-approaching FIFA World Cup. But amid the buzz, have you ever paused to consider the staggering level of risk inherent to such large-scale events? Or how impressive it is that organizers are able to manage that … More →
The post The modern-day business can learn a lot about risk from this year’s mega events appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/03/03162225/world-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 09:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, modern-day, business, can, learn, lot, about, risk, from, this, year’s, mega, events</media:keywords>
</item>

<item>
<title>Spotless compliance evidence can still hide a broken control</title>
<link>https://block385.com/spotless-compliance-evidence-can-still-hide-a-broken-control</link>
<guid>https://block385.com/spotless-compliance-evidence-can-still-hide-a-broken-control</guid>
<description><![CDATA[ In this interview with Help Net Security, Marc Rubbinaccio, Head of Cybersecurity and Compliance at Secureframe, explains where security teams go wrong when preparing for CMMC and FedRAMP 20x. The conversation covers how organizations check the 110 requirements but miss the 320 assessment objectives beneath them, why spotless SOC 2 evidence can hide a broken control, and how continuous monitoring is changing compliance work. It also includes advice for junior practitioners on AI and practical … More →
The post Spotless compliance evidence can still hide a broken control appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/01111422/marc_rubbinaccio-2-secureframe.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 09:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Spotless, compliance, evidence, can, still, hide, broken, control</media:keywords>
</item>

<item>
<title>DoJ Disrupts Southeast Asia Crypto Fraud Networks, Freezes $3.8 Million in Assets</title>
<link>https://block385.com/doj-disrupts-southeast-asia-crypto-fraud-networks-freezes-38-million-in-assets</link>
<guid>https://block385.com/doj-disrupts-southeast-asia-crypto-fraud-networks-freezes-38-million-in-assets</guid>
<description><![CDATA[ The U.S. Department of Justice (DoJ) on Wednesday announced the results of a sweeping action undertaken by government authorities and private sector companies to combat cyber-enabled and cryptocurrency fraud targeting Americans.

The &quot;Disruption Week&quot; operation began May 18, 2026, leading to the takedown of millions of social media, email, and internet access accounts used by transnational ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiTf5wAHnoXtVauiln2MwlVvLc4LxcL8SBTLuW648LfFhUd8QyuOUfjmg0Hd91QlksmWF2u-PQhxHDTDmseMIG64V4Fo2I2lXXGO1o0BncbL_UTeBrGztErg66yXAm0trYlWxqGbE-sKb5VjXjqeyNiCMkxbdcxwX1BDRGexhP-b0s3dZl0lNRpY9u6nsTQ/s1600/police-crypto.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 09:00:13 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>DoJ, Disrupts, Southeast, Asia, Crypto, Fraud, Networks, Freezes, 3.8, Million, Assets</media:keywords>
</item>

<item>
<title>ETSI sets security requirements for AI data centers and cloud platforms</title>
<link>https://block385.com/etsi-sets-security-requirements-for-ai-data-centers-and-cloud-platforms</link>
<guid>https://block385.com/etsi-sets-security-requirements-for-ai-data-centers-and-cloud-platforms</guid>
<description><![CDATA[ ETSI has published TS 104 033, a technical specification that defines security requirements for AI computing platforms. The specification establishes a security framework for platforms used to host AI applications in data center and edge computing environments, covering security functions, platform components, interfaces, and services designed to protect AI models, datasets, training processes, and inference workloads. “This work builds on the AI computing platform security framework we have previously developed and marks a significant step … More →
The post ETSI sets security requirements for AI data centers and cloud platforms appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/02135044/ai-1500-1.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 07:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>ETSI, sets, security, requirements, for, data, centers, and, cloud, platforms</media:keywords>
</item>

<item>
<title>Product showcase: Trend Micro Mobile Security detects scams in messages, QR codes, and websites</title>
<link>https://block385.com/product-showcase-trend-micro-mobile-security-detects-scams-in-messages-qr-codes-and-websites</link>
<guid>https://block385.com/product-showcase-trend-micro-mobile-security-detects-scams-in-messages-qr-codes-and-websites</guid>
<description><![CDATA[ Trend Micro Mobile Security for iOS protects devices from potentially harmful websites while browsing, blocks ads and personal information trackers, helps users avoid unsafe Wi-Fi networks, and monitors data usage. The app is available for both iOS and Android devices. Getting Started After installing the app from the App Store, I created an account to start using it. Account creation is handled through Trend Micro’s TrendLife platform. Once installed, the app automatically scanned the device … More →
The post Product showcase: Trend Micro Mobile Security detects scams in messages, QR codes, and websites appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/03134538/trend_micro_mobile_security.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 07:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Product, showcase:, Trend, Micro, Mobile, Security, detects, scams, messages, codes, and, websites</media:keywords>
</item>

<item>
<title>Attackers already know the secrets are on your developers’ machines. Do you?</title>
<link>https://block385.com/attackers-already-know-the-secrets-are-on-your-developers-machines-do-you</link>
<guid>https://block385.com/attackers-already-know-the-secrets-are-on-your-developers-machines-do-you</guid>
<description><![CDATA[ In a recent GitGuardian analysis, an average of 150 secrets were found on a sample of developer endpoints. Private keys accounted for 38% of unique secrets, while cloud, identity provider, and secret management credentials (AWS IAM, Hashicorp vault) added another 22%. Those figures should not be treated as a universal prevalence estimate for every developer machine, but they are directionally significant. They show how much credential material can accumulate outside the places security teams usually … More →
The post Attackers already know the secrets are on your developers’ machines. Do you? appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/03184906/gitguardian-secrets.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 07:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Attackers, already, know, the, secrets, are, your, developers’, machines., you</media:keywords>
</item>

<item>
<title>Pakistan Spies on Afghan Finance Ministry With Xeno RAT</title>
<link>https://block385.com/pakistan-spies-on-afghan-finance-ministry-with-xeno-rat</link>
<guid>https://block385.com/pakistan-spies-on-afghan-finance-ministry-with-xeno-rat</guid>
<description><![CDATA[ Despite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan&#039;s porous cybersecurity. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltb991e5256c40bcd1/6a205634289788f8c51207a1/Pakistan_Afghanistan-Oleksii_Liskonih-Getty.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 07:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Pakistan, Spies, Afghan, Finance, Ministry, With, Xeno, RAT</media:keywords>
</item>

<item>
<title>Attackers Use AI to Automate EDR Evasion Testing</title>
<link>https://block385.com/attackers-use-ai-to-automate-edr-evasion-testing</link>
<guid>https://block385.com/attackers-use-ai-to-automate-edr-evasion-testing</guid>
<description><![CDATA[ Python scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt016007dbff30c0e1/6a2085be38e0c7c4b455ca45/Sophos_offices-Sundry_Photography-getty-1200830219.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 04 Jun 2026 01:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Attackers, Use, Automate, EDR, Evasion, Testing</media:keywords>
</item>

<item>
<title>Tropical Blend: Cyber &amp;amp;amp; Politics Ramp Up Across Latin America</title>
<link>https://block385.com/tropical-blend-cyber-politics-ramp-up-across-latin-america</link>
<guid>https://block385.com/tropical-blend-cyber-politics-ramp-up-across-latin-america</guid>
<description><![CDATA[ China-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltaa97395bb0805f7f/6a1f49d4c6f2ac73df1ebf16/old-globe-showing-south-america-jhonny_marcell_oportus-shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 23:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Tropical, Blend:, Cyber, &amp;amp, Politics, Ramp, Across, Latin, America</media:keywords>
</item>

<item>
<title>Coding Gaffe Exposes Microsoft 365 Accounts to Widespread Takeover</title>
<link>https://block385.com/coding-gaffe-exposes-microsoft-365-accounts-to-widespread-takeover</link>
<guid>https://block385.com/coding-gaffe-exposes-microsoft-365-accounts-to-widespread-takeover</guid>
<description><![CDATA[ A disabled security setting meant to protect authentication across Android versions of key apps like Word, PowerPoint, and Excel paved the way for attackers to steal logins and data. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blta6d9216f2cd41b4b/6a2015f94a4fc7d0bb15144e/Authentication_Zoonar_GmbH_Alamy.png" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 23:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Coding, Gaffe, Exposes, Microsoft, 365, Accounts, Widespread, Takeover</media:keywords>
</item>

<item>
<title>WhatsApp, Slack Notifications Could Hijack Google Gemini on Android</title>
<link>https://block385.com/whatsapp-slack-notifications-could-hijack-google-gemini-on-android</link>
<guid>https://block385.com/whatsapp-slack-notifications-could-hijack-google-gemini-on-android</guid>
<description><![CDATA[ A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini&#039;s voice assistant on Android and made it open a victim&#039;s connected windows, fake a message from their boss, push the phone into a Zoom call, or quietly poison its long-term memory.

No malicious app on the phone is required. The assistant just had to treat a hostile ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCJpW9I-QTgQOkP7AV3rwUtEOEs96ek2ySR06Go-xq5AThZV84qY3mDN1Dkh0oQ-94jZHc7zB21ax9ljU0dW2LtsSW5p7xuuX9ARsvoIZQTGaMSkESGxTjl-PgTy8hrnsI8ucVZpENLEuMa9QzoUYVmfp4aug4OnEZq3XeL3ZELNZVELSegpS398l8vKg/s1600/gemini-prompt.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 23:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>WhatsApp, Slack, Notifications, Could, Hijack, Google, Gemini, Android</media:keywords>
</item>

<item>
<title>Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT</title>
<link>https://block385.com/google-doubleclick-abused-in-new-malspam-campaign-to-deliver-desckvb-rat</link>
<guid>https://block385.com/google-doubleclick-abused-in-new-malspam-campaign-to-deliver-desckvb-rat</guid>
<description><![CDATA[ Cybersecurity researchers have flagged a new malspam campaign that makes use of Google&#039;s DoubleClick domain as a way to evade detection and ultimately deliver a remote access trojan (RAT) named DesckVB RAT.

&quot;Before the victim ever reaches attacker-controlled infrastructure, the lure routes through DoubleClick, a legitimate Google-owned domain that many security tools are less likely to treat as ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpQ6QXxFH4zkfeHGdcm1WXVcNXMpyJm-1dlZLbFCdp6rKDRhuwICzYaKaR-rCpn61qod6A1F98PZejZbmYuxaUXPJLXQffoaniCkqgyqR1-p7gClpj4PYibjzIDHk8_Vw4ag00EYPCM3Nz1G0Hvzuf6wBV-HzDFoSiYDEEdjPU45Bk_rIlGk9dJ_MMVuue/s1600/ad-malware.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 23:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Google, DoubleClick, Abused, New, Malspam, Campaign, Deliver, DesckVB, RAT</media:keywords>
</item>

<item>
<title>Microsoft 365 Android Apps Let Any App Steal Account Tokens via Leftover Debug Flag</title>
<link>https://block385.com/microsoft-365-android-apps-let-any-app-steal-account-tokens-via-leftover-debug-flag</link>
<guid>https://block385.com/microsoft-365-android-apps-let-any-app-steal-account-tokens-via-leftover-debug-flag</guid>
<description><![CDATA[ A development flag left switched on in production builds of several Microsoft 365 Android apps disabled the check that limits account-token sharing to trusted Microsoft apps.

Any other app on the same phone could ask for the signed-in user&#039;s token and get it, then read email, open files, browse the calendar, and send messages as that user. No password, no login screen, no permission prompt. ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_pEYWDRVadGL0WYM3iSY6jqFgBez8snXgoyeyAzcXNmxiytv-FgiKoBJX3aPivuYhSJjXp4o_zO1dQSIPUfduaAlB-rvSti7pFhdDZSrAa-ennBdfdVpe1Xo0dMxKATB8te61pyJAf60x5CP6OJzjzmtpFIg_qHQqA7VP-rUnEpaT37Z0qBOmbZ52BfM/s1600/ms-android.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 23:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, 365, Android, Apps, Let, Any, App, Steal, Account, Tokens, via, Leftover, Debug, Flag</media:keywords>
</item>

<item>
<title>Autonomous AI Tool Finds 2&#45;Year&#45;Old RCE Flaw in Redis (CVE&#45;2026&#45;23479)</title>
<link>https://block385.com/autonomous-ai-tool-finds-2-year-old-rce-flaw-in-redis-cve-2026-23479</link>
<guid>https://block385.com/autonomous-ai-tool-finds-2-year-old-rce-flaw-in-redis-cve-2026-23479</guid>
<description><![CDATA[ Redis has  patched  a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases.
Tracked as CVE-2026-23479, the flaw was introduced in Redis 7.2.0 and remained in every stable branch until the May 5 fixes, unnoticed for over two years. ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjTV6zPqD9KC3Rc5Mz9c8XENLiJntboDT6LIoD3L2FXlTUVC3rsWZ_3YLfe_jmhhyphenhyphenjb5RCwkTsdoyypD9VXxYgj_2GYaAupNMlOyZkycm94qr7XiarmBCpYQdZDN_Gwq6KrOmomzx1dmbz4hpUkw4OZparqEbydJneNKaWQI0fcP5tctpKxsZ7kFP5FCv0/s1600/redis-db.png" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 23:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Autonomous, Tool, Finds, 2-Year-Old, RCE, Flaw, Redis, CVE-2026-23479</media:keywords>
</item>

<item>
<title>Cyber Insurance Rates Are Dropping, but Exclusions Widen</title>
<link>https://block385.com/cyber-insurance-rates-are-dropping-but-exclusions-widen</link>
<guid>https://block385.com/cyber-insurance-rates-are-dropping-but-exclusions-widen</guid>
<description><![CDATA[ Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltccb00eced4dc6fb5/6a204f532928e1ceac7b3c4c/cyberinsurance-Poca_Wander_Stock-getty-1470986827.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 21:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cyber, Insurance, Rates, Are, Dropping, but, Exclusions, Widen</media:keywords>
</item>

<item>
<title>Microsoft responds to security challenges facing code, AI agents, and models</title>
<link>https://block385.com/microsoft-responds-to-security-challenges-facing-code-ai-agents-and-models</link>
<guid>https://block385.com/microsoft-responds-to-security-challenges-facing-code-ai-agents-and-models</guid>
<description><![CDATA[ Microsoft has introduced a series of security tools and capabilities focused on AI-driven vulnerability discovery, AI agents, and AI models. The updates include a multi-agent vulnerability discovery system, new controls for managing and securing AI agents, data protection capabilities, and tools designed to identify potentially vulnerable or compromised AI models before deployment. MDASH targets exploitable vulnerabilities Microsoft expanded the preview of MDASH, a multi-model agentic vulnerability discovery system that now integrates with Microsoft Defender. The … More →
The post Microsoft responds to security challenges facing code, AI agents, and models appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/19154107/microsoft3.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 17:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, responds, security, challenges, facing, code, agents, and, models</media:keywords>
</item>

<item>
<title>One&#45;Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens</title>
<link>https://block385.com/one-click-github-dev-attack-lets-attackers-steal-full-github-oauth-tokens</link>
<guid>https://block385.com/one-click-github-dev-attack-lets-attackers-steal-full-github-oauth-tokens</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed a one-click attack via Microsoft Visual Studio Code (VS Code) that makes it possible to steal a user&#039;s GitHub token.

&quot;Just by clicking a link, it&#039;s possible for an attacker to steal a GitHub token that can read and write to your repos, including private ones,&quot; security researcher Ammar Askar said.

GitHub supports a feature called GitHub.dev that runs as ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgeHvqmNHvAhdxgoBLbfFWsFBMdvH5SbJovunxx8AYHRkq7HOQ2l6I_ZaJGi_PF5WHKOlHEQHK4HyPBhmzOpYNhPS4HJSna2uLVlEwUV9i2j5YuRqGOLUqgKIrhx2ndFm1OSME7usiLk_ohtIBYyR5Xpq5Pzc2eHAjCK0OA_89JwPNxVrrBVDbTDRVbRG6e/s1600/github.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 17:00:15 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>One-Click, GitHub, Dev, Attack, Lets, Attackers, Steal, Full, GitHub, OAuth, Tokens</media:keywords>
</item>

<item>
<title>Malware campaign targeting Minecraft users infects over 116,000 systems</title>
<link>https://block385.com/malware-campaign-targeting-minecraft-users-infects-over-116000-systems</link>
<guid>https://block385.com/malware-campaign-targeting-minecraft-users-infects-over-116000-systems</guid>
<description><![CDATA[ A Malware-as-a-Service (MaaS) operation named WeedHack is targeting Minecraft users and allows threat actors to gain remote access to victims’ screens, webcams, and files through a web-based dashboard, McAfee researchers found. Minecraft, developed by Mojang Studios and released in 2011, is one of the best-selling video games of all time, with more than 350 million copies sold worldwide. Since January 2026, the campaign has infected more than 116,000 systems and continues to add between 2,000 … More →
The post Malware campaign targeting Minecraft users infects over 116,000 systems appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2016/04/09112920/minecraft.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 15:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Malware, campaign, targeting, Minecraft, users, infects, over, 116, 000, systems</media:keywords>
</item>

<item>
<title>Autonomous AI&#45;driven worm can reason its way through corporate networks</title>
<link>https://block385.com/autonomous-ai-driven-worm-can-reason-its-way-through-corporate-networks</link>
<guid>https://block385.com/autonomous-ai-driven-worm-can-reason-its-way-through-corporate-networks</guid>
<description><![CDATA[ Researchers at the University of Toronto, the Vector Institute, and the University of Cambridge have built and tested a proof-of-concept AI-driven worm that does not operate on a fixed list of exploits. Instead, it analyzes each target it encounters, reasons about how to attack it, and creates a strategy on the fly, all with the help of a small, free large language model (LLM) running directly on machines it has already compromised. A worm that … More →
The post Autonomous AI-driven worm can reason its way through corporate networks appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18161426/key.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 15:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Autonomous, AI-driven, worm, can, reason, its, way, through, corporate, networks</media:keywords>
</item>

<item>
<title>Malicious Notifications Could Trick Google Gemini Users</title>
<link>https://block385.com/malicious-notifications-could-trick-google-gemini-users</link>
<guid>https://block385.com/malicious-notifications-could-trick-google-gemini-users</guid>
<description><![CDATA[ A prompt injection flaw in Google Gemini&#039;s voice assistant let attackers hide malicious commands in notifications, enabling social engineering and more. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt5b11efb4c67c9e8c/6a1f2620668c359305c948cc/AIappsphone-Nazar_Rybak-getty-2198117815.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 15:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Malicious, Notifications, Could, Trick, Google, Gemini, Users</media:keywords>
</item>

<item>
<title>Zoom CISO: AI as a Security Enabler, Not Role&#45;Replacer</title>
<link>https://block385.com/zoom-ciso-ai-as-a-security-enabler-not-role-replacer</link>
<guid>https://block385.com/zoom-ciso-ai-as-a-security-enabler-not-role-replacer</guid>
<description><![CDATA[ As Zoom&#039;s CISO, Sandra McLeod discusses the challenges of securing a global communication platform, the promise of AI-driven security workflows, and advice for aspiring cybersecurity leaders. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt29d6aa3a289232b2/6a18ab058bc1ea30bf4df571/zoom1800_M4OS_Photos_alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 15:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Zoom, CISO:, Security, Enabler, Not, Role-Replacer</media:keywords>
</item>

<item>
<title>Simplify security management with CIS SecureSuite Platform</title>
<link>https://block385.com/simplify-security-management-with-cis-securesuite-platform</link>
<guid>https://block385.com/simplify-security-management-with-cis-securesuite-platform</guid>
<description><![CDATA[ New operating systems prioritize usability, a reality which threat actors use to exploit security gaps. Every misconfiguration creates an opportunity for compromise, and lean teams struggle in their security management efforts to harden hundreds or thousands of endpoints. CIS SecureSuite Membership simplifies the process with tools, benefits, and resources for implementing the secure recommendations of the CIS Benchmarks. With the release of our CIS SecureSuite Platform, it’s now even easier for Members to harden their … More →
The post Simplify security management with CIS SecureSuite Platform appeared first on Help Net Security. ]]></description>
<enclosure url="https://www.cisecurity.org/-/jssmedia/project/cisecurity/cisecurity/data/media/img/insights_images/blog_post_img/2025/10/simplify-security-management-with-cis-securesuite-platform.png" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 15:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Simplify, security, management, with, CIS, SecureSuite, Platform</media:keywords>
</item>

<item>
<title>Beyond the Zero&#45;Day: See Your Network Like an Attacker | Webinar with HD Moore</title>
<link>https://block385.com/beyond-the-zero-day-see-your-network-like-an-attacker-webinar-with-hd-moore</link>
<guid>https://block385.com/beyond-the-zero-day-see-your-network-like-an-attacker-webinar-with-hd-moore</guid>
<description><![CDATA[ Assume the breach. Zero-days keep shipping, AI is writing exploits faster than anyone patches, and &quot;patch everything in time&quot; stopped working years ago. Stop betting the org on winning that race. You don&#039;t control which bug lands. You control what it can reach once it does.

That is a question about the shape of your network, and most teams have the shape wrong. HD Moore, creator of Metasploit ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzZPASJ7ymlBpeDWq_d-byWp58FpBR6tdX6QfLJFFoGRHK9xB5mTbx0guIcMFKFYV87inRtJyM-cKJXI0Td5fVtpC1ITBFmp2myS2wBynVSF3rZP2jZWH6uR-_14ZEalErJASiKWVDJ_TD551AC0pN5A3Mu8y-Z1zW5mKvFMOmdLzrdWnhYCif0FR1lOE/s1600/hd.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 15:00:17 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Beyond, the, Zero-Day:, See, Your, Network, Like, Attacker, Webinar, with, Moore</media:keywords>
</item>

<item>
<title>New Android feature promises to spot deepfake scam calls</title>
<link>https://block385.com/new-android-feature-promises-to-spot-deepfake-scam-calls</link>
<guid>https://block385.com/new-android-feature-promises-to-spot-deepfake-scam-calls</guid>
<description><![CDATA[ Android is introducing fake call detection to help protect users from impersonation scams. The feature can detect and flag suspected spoofed calls when both parties use Phone by Google on Android 12 or later. It will roll out globally this month, starting with Pixel devices. Story of two calls from “Mom” (Source: Google) “Fake call detection helps protect you, your family and friends by identifying when a caller isn’t who they claim to be, giving … More →
The post New Android feature promises to spot deepfake scam calls appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/02132603/android-security2.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 13:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, Android, feature, promises, spot, deepfake, scam, calls</media:keywords>
</item>

<item>
<title>Only 11% of production agents pass the AI agent security bar</title>
<link>https://block385.com/only-11-of-production-agents-pass-the-ai-agent-security-bar</link>
<guid>https://block385.com/only-11-of-production-agents-pass-the-ai-agent-security-bar</guid>
<description><![CDATA[ Enterprise teams are running AI agents that write code, drive browsers, answer customer calls, manage cloud infrastructure, and query data warehouses with standing credentials. A new independent assessment of 100 production agents finds that nearly all of them carry the conditions for a single hostile document to take them over. The AI Risk Quadrant (AIRQ) report, a 2026 Q2 edition produced by independent researchers, scores 100 commercial and publicly available AI agents across three dimensions: … More →
The post Only 11% of production agents pass the AI agent security bar appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/01115443/ai-robot-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 13:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Only, 11, production, agents, pass, the, agent, security, bar</media:keywords>
</item>

<item>
<title>Global Stock Exchange Hit by Monthslong Email Campaign</title>
<link>https://block385.com/global-stock-exchange-hit-by-monthslong-email-campaign</link>
<guid>https://block385.com/global-stock-exchange-hit-by-monthslong-email-campaign</guid>
<description><![CDATA[ A threat actor got a near-continuous view into an influential finance executive&#039;s email inbox, thanks to clever use of legitimate, native Windows tools. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt5908b752b625e143/6a1ef59f4a4fc7dbba150b40/Stocks_down-nagelestock.net-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 13:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Global, Stock, Exchange, Hit, Monthslong, Email, Campaign</media:keywords>
</item>

<item>
<title>New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy &amp;amp; Cloudflare</title>
<link>https://block385.com/new-http2-bomb-vulnerability-allows-remote-dos-on-nginx-apache-iis-envoy-cloudflare</link>
<guid>https://block385.com/new-http2-bomb-vulnerability-allows-remote-dos-on-nginx-apache-iis-envoy-cloudflare</guid>
<description><![CDATA[ Cybersecurity researchers have discovered a remote denial-of-service exploit that affects major web servers, including NGINX, Apache HTTPD, Microsoft IIS, Envoy, and Cloudflare Pingora.

The vulnerability has been codenamed HTTP/2 Bomb by Calif.

&quot;The vulnerable behavior exists in each server&#039;s default HTTP/2 configuration,&quot; the company said, adding it was discovered by OpenAI Codex by chaining ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhP07q0cgsa0a9VyTU6oPpxqvoZ5Gg2spx-ClmUIzn9LjYzDfuKNxnLXNuXMexiMB8GjKewhk7CnAL5HXgpCL_wq5eaU8VK2mTxxcKJHAZ9eLBskg516sBn4SV5XHWOuZIozDzBD_0MUCAMcVpGyqOEWITNKi2mQFxFLl9gqg_3UxPlwmXCkRfm2JERftyN/s1600/http2.gif" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 13:00:13 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, HTTP2, Bomb, Vulnerability, Allows, Remote, DoS, NGINX, Apache, IIS, Envoy, Cloudflare</media:keywords>
</item>

<item>
<title>Unpatched Windows Search URI Vulnerability Lets Attackers Steal NTLMv2 Hashes</title>
<link>https://block385.com/unpatched-windows-search-uri-vulnerability-lets-attackers-steal-ntlmv2-hashes</link>
<guid>https://block385.com/unpatched-windows-search-uri-vulnerability-lets-attackers-steal-ntlmv2-hashes</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed details of an unpatched issue that could be exploited to disclose a user&#039;s NTLMv2 hash to the attacker.

Like in the case of CVE-2026-33829, which impacted the Windows Snipping Tool&#039;s ms-screensketch: URI handler, the newly flagged issue resides in the search: URI handler, per Huntress.

CVE-2026-33829 refers to a spoofing vulnerability that could expose ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9Y4FY1kH_mrU4oH2X7TPrnmPdf9Ib4UZ4Xgud4Qgjie69on9qP9D1OU8i3ol3THTISUTy8OBJzPXzbUTyHwx1xF8cWuYvb9r-_7r_g-gFXyW62phdyaEAd41PI5cfduXxd084XQdwhxQ40Ti5n7SvkhIbZRktqP8G9bhufjlrxzxHYWpFTAXAfSSWstwc/s1600/NTLM.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 13:00:12 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Unpatched, Windows, Search, URI, Vulnerability, Lets, Attackers, Steal, NTLMv2, Hashes</media:keywords>
</item>

<item>
<title>Anthropic expands Project Glasswing to 150 organizations in more than 15 countries</title>
<link>https://block385.com/anthropic-expands-project-glasswing-to-150-organizations-in-more-than-15-countries</link>
<guid>https://block385.com/anthropic-expands-project-glasswing-to-150-organizations-in-more-than-15-countries</guid>
<description><![CDATA[ Anthropic is expanding Project Glasswing, its cybersecurity initiative built around the Claude Mythos Preview model, by adding about 150 organizations following several weeks of work with its initial group of partners, security firms, open-source maintainers, and government agencies. Organizations joining the program must meet security requirements before gaining access, Anthropic noted. The expansion brings the program to organizations in more than 15 countries and includes sectors such as healthcare, energy, communications, technology, and other infrastructure … More →
The post Anthropic expands Project Glasswing to 150 organizations in more than 15 countries appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/04/14132052/anthropic-red-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 11:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Anthropic, expands, Project, Glasswing, 150, organizations, more, than, countries</media:keywords>
</item>

<item>
<title>Microsoft Scout agent opens a new category of always&#45;on Autopilots</title>
<link>https://block385.com/microsoft-scout-agent-opens-a-new-category-of-always-on-autopilots</link>
<guid>https://block385.com/microsoft-scout-agent-opens-a-new-category-of-always-on-autopilots</guid>
<description><![CDATA[ Workplace AI assistants have mostly waited for a prompt before doing anything. A user asks, the tool answers, and the exchange ends there. Microsoft is putting a different kind of agent inside its Office applications, one designed to keep operating in the background once a person stops paying attention. The company introduced Microsoft Scout, calling it the first entry in a category it labels Autopilots. What an Autopilot does Autopilots are always-on agents that run … More →
The post Microsoft Scout agent opens a new category of always-on Autopilots appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/03102039/microsoft_copilot-autopilot.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 11:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Scout, agent, opens, new, category, always-on, Autopilots</media:keywords>
</item>

<item>
<title>Google adds a silent check to catch scammers posing as your contacts</title>
<link>https://block385.com/google-adds-a-silent-check-to-catch-scammers-posing-as-your-contacts</link>
<guid>https://block385.com/google-adds-a-silent-check-to-catch-scammers-posing-as-your-contacts</guid>
<description><![CDATA[ Android is introducing fake call detection to help protect users from impersonation scams. The feature can detect and flag suspected spoofed calls when both parties use Phone by Google on Android 12 or later. It will roll out globally this month, starting with Pixel devices. Story of two calls from “Mom” (Source: Google) “Fake call detection helps protect you, your family and friends by identifying when a caller isn’t who they claim to be, giving … More →
The post Google adds a silent check to catch scammers posing as your contacts appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/02132603/android-security2.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 11:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Google, adds, silent, check, catch, scammers, posing, your, contacts</media:keywords>
</item>

<item>
<title>A small Slovenian team handles 6,000 cyber incidents a year</title>
<link>https://block385.com/a-small-slovenian-team-handles-6000-cyber-incidents-a-year</link>
<guid>https://block385.com/a-small-slovenian-team-handles-6000-cyber-incidents-a-year</guid>
<description><![CDATA[ Online fraud complaints, ransomware cases, and phishing tips reach Slovenia’s national cyber response center in steady volume, and a team of around a dozen analysts sorts through them. Gorazd Božič, who manages SI-CERT at the public agency ARNES, described that work in an interview conducted in person at the Span Cyber Security Arena conference. He put the original proposal for a Slovenian CERT to ARNES leadership in 1994, and the center now records about 6,000 … More →
The post A small Slovenian team handles 6,000 cyber incidents a year appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/02112226/gorazd_bozic-2-arnes.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 09:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>small, Slovenian, team, handles, 6, 000, cyber, incidents, year</media:keywords>
</item>

<item>
<title>MazeBolt brings AI&#45;generated attack simulation to DDoS security testing</title>
<link>https://block385.com/mazebolt-brings-ai-generated-attack-simulation-to-ddos-security-testing</link>
<guid>https://block385.com/mazebolt-brings-ai-generated-attack-simulation-to-ddos-security-testing</guid>
<description><![CDATA[ MazeBolt has announced the launch of RADAR VectorAI, a new MazeBolt module that creates AI-generated DDoS attacks. As AI outpaces human response, enterprises need to have access to validated DDoS vulnerability data about both known and AI-generated attack vectors. Mythos has raised awareness of the cybersecurity risks created by AI. But while Mythos makes it faster and easier for attackers to identify exploitable gaps in software, it does not address DDoS vulnerabilities. VectorAI functions as … More →
The post MazeBolt brings AI-generated attack simulation to DDoS security testing appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 09:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>MazeBolt, brings, AI-generated, attack, simulation, DDoS, security, testing</media:keywords>
</item>

<item>
<title>Netskope adds AI asset discovery and AISecOps agent to AI security portfolio</title>
<link>https://block385.com/netskope-adds-ai-asset-discovery-and-aisecops-agent-to-ai-security-portfolio</link>
<guid>https://block385.com/netskope-adds-ai-asset-discovery-and-aisecops-agent-to-ai-security-portfolio</guid>
<description><![CDATA[ Netskope has announced Netskope One AI Command Center, bringing together AI discovery, risk intelligence, and autonomous response capabilities in a single platform. As the latest expansion of the Netskope One AI Security suite, it helps security teams understand what AI is running in their environments, determine which risks require action, and accelerate response efforts. Among enterprises tracked by Netskope Threat Labs, the average enterprise organization saw the number of AI applications in use grow fivefold … More →
The post Netskope adds AI asset discovery and AISecOps agent to AI security portfolio appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 09:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Netskope, adds, asset, discovery, and, AISecOps, agent, security, portfolio</media:keywords>
</item>

<item>
<title>Critical Start expands MDR capabilities with multi&#45;agent AI system</title>
<link>https://block385.com/critical-start-expands-mdr-capabilities-with-multi-agent-ai-system</link>
<guid>https://block385.com/critical-start-expands-mdr-capabilities-with-multi-agent-ai-system</guid>
<description><![CDATA[ Critical Start has released SOC AI, a production-proven multi-agent framework powering its AI-led Managed Detection and Response (MDR). SOC AI coordinates ten specialized agents across the full alert investigation and response lifecycle, covering detection, triage, response, threat hunting, and continuous improvement. Each agent operates with a discrete function, a defined scope, and a complete audit trail on every action taken. After implementation of SOC AI, Investigation Agent enhanced thousands of investigations, compressing analyst time-to-investigate to … More →
The post Critical Start expands MDR capabilities with multi-agent AI system appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 09:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Critical, Start, expands, MDR, capabilities, with, multi-agent, system</media:keywords>
</item>

<item>
<title>Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content</title>
<link>https://block385.com/weedhack-attacks-minecraft-users-countloader-hits-86k-miners-spread-via-pirated-content</link>
<guid>https://block385.com/weedhack-attacks-minecraft-users-countloader-hits-86k-miners-spread-via-pirated-content</guid>
<description><![CDATA[ Cybersecurity researchers have flagged a new campaign targeting Minecraft players via YouTube to spread malware capable of gaining control of victims&#039; systems.

The Minecraft-focused malware-as-a-service (MaaS) campaign has been codenamed Weedhack by McAfee Labs, stating the activity has been active since January 2026 and impersonates Minecraft clients and mods to infect users. In all, 3820 ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBhPg_oWS3s5XgNMW4vuwq3Pwrnsw3l3FyzGwoYkQ7AwCuU6VXH6sOv03o04S4jw-7pkVzAsccuFCxzMX1tg8JbB8D9k5onrVg0-D7HBQduN4pAHq2FOH9a-tSeokVqGIyJS-hStrL7fs5I9u67yp2gRKjOYuTYF_xUrsJnIWL3GdTZ7bLiU6u1vObezoD/s1600/hacker-pirate.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 09:00:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Weedhack, Attacks, Minecraft, Users, CountLoader, Hits, 86K, Miners, Spread, via, Pirated, Content</media:keywords>
</item>

<item>
<title>Known vulnerabilities behind most application security incidents</title>
<link>https://block385.com/known-vulnerabilities-behind-most-application-security-incidents</link>
<guid>https://block385.com/known-vulnerabilities-behind-most-application-security-incidents</guid>
<description><![CDATA[ Eight in ten organizations took an application security hit during the past year tied to a vulnerability their team had already cataloged, according to a survey of 902 IT and security professionals conducted by the Cloud Security Alliance. The pattern points to a structural condition across the industry, where the window between identifying a flaw and closing it in production stays open long enough for attackers to act. Which of the following best describes your … More →
The post Known vulnerabilities behind most application security incidents appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/29150033/vulnerability-danger.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 07:30:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Known, vulnerabilities, behind, most, application, security, incidents</media:keywords>
</item>

<item>
<title>What CISOs need to do about post&#45;quantum migration in the next 24 months</title>
<link>https://block385.com/what-cisos-need-to-do-about-post-quantum-migration-in-the-next-24-months</link>
<guid>https://block385.com/what-cisos-need-to-do-about-post-quantum-migration-in-the-next-24-months</guid>
<description><![CDATA[ In this Help Net Security video, Garfield Jones, SVP Global Strategy and Research, QuSecure, lays out what CISOs should do over the next 24 months. A recent Google paper moved the expected arrival of a cryptographically relevant quantum computer from 2035 to 2029, leaving organizations about two and a half years to prepare. Such a machine, paired with Shor’s algorithm, would break the public key encryption in use today. Jones explains the Harvest Now, Decrypt … More →
The post What CISOs need to do about post-quantum migration in the next 24 months appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/30133249/door-lock-encryption.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 07:30:12 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>What, CISOs, need, about, post-quantum, migration, the, next, months</media:keywords>
</item>

<item>
<title>Agent Threat Rules: Open detection rule format for AI agent security threats</title>
<link>https://block385.com/agent-threat-rules-open-detection-rule-format-for-ai-agent-security-threats</link>
<guid>https://block385.com/agent-threat-rules-open-detection-rule-format-for-ai-agent-security-threats</guid>
<description><![CDATA[ AI agents run inside coding assistants, MCP servers, and multi-agent frameworks, and the access that makes them useful also opens paths to prompt injection, tool poisoning, and credential theft. Public CVE feeds carry agent-execution flaws that reach production faster than the tooling built to catch them. Agent Threat Rules, or ATR, is an open detection format aimed at this category of attack. ATR rules are YAML documents that conform to a versioned schema. Each one … More →
The post Agent Threat Rules: Open detection rule format for AI agent security threats appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/28092756/agent_threat_rules-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 07:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Agent, Threat, Rules:, Open, detection, rule, format, for, agent, security, threats</media:keywords>
</item>

<item>
<title>Zoom CISO: AI as Security Enabler, Not Role&#45;Replacer</title>
<link>https://block385.com/zoom-ciso-ai-as-security-enabler-not-role-replacer</link>
<guid>https://block385.com/zoom-ciso-ai-as-security-enabler-not-role-replacer</guid>
<description><![CDATA[ As Zoom&#039;s CISO, Sandra McLeod, discusses the challenges of securing a global communication platform, the promise of AI-driven security workflows, and advice for aspiring cybersecurity leaders. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt29d6aa3a289232b2/6a18ab058bc1ea30bf4df571/zoom1800_M4OS_Photos_alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 01:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Zoom, CISO:, Security, Enabler, Not, Role-Replacer</media:keywords>
</item>

<item>
<title>FBI&#45;Flagged Phishing Kit Kali365 Expands Its Reach</title>
<link>https://block385.com/fbi-flagged-phishing-kit-kali365-expands-its-reach</link>
<guid>https://block385.com/fbi-flagged-phishing-kit-kali365-expands-its-reach</guid>
<description><![CDATA[ Once targeting just Microsoft 365, the phishing-as-a-service platform now aims at AWS, Okta, and Russian platforms, while relying on device code phishing. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blta4f731d1ead13c9d/6a1f3ff44bb1191264ce8b45/phishing_babar_ali_1233_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 03 Jun 2026 01:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>FBI-Flagged, Phishing, Kit, Kali365, Expands, Its, Reach</media:keywords>
</item>

<item>
<title>DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks</title>
<link>https://block385.com/drivesurge-hijacks-thousands-of-sites-for-clickfix-fakeupdate-attacks</link>
<guid>https://block385.com/drivesurge-hijacks-thousands-of-sites-for-clickfix-fakeupdate-attacks</guid>
<description><![CDATA[ A sneaky, wide-scale IAB operation uses a malicious traffic distribution system (TDS) to redirect visitors of trusted websites to ones that deliver malware. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltffc3f8961236e781/6a1ebc8da5c0c3c931d33c0f/browser_Tada_Images_shutterstock.png" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 23:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>DriveSurge, Hijacks, Thousands, Sites, for, ClickFix, FakeUpdate, Attacks</media:keywords>
</item>

<item>
<title>China Uses Dual&#45;Method Cyberattack on Czech Orgs</title>
<link>https://block385.com/china-uses-dual-method-cyberattack-on-czech-orgs</link>
<guid>https://block385.com/china-uses-dual-method-cyberattack-on-czech-orgs</guid>
<description><![CDATA[ China is stealing data from high-value targets via a sneaky, double-layer spear-phishing campaign that includes the Azureveil malware. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt39042307a404a226/6a1de2a14bb119d786ce85f4/charlesbridgeprague-GarySandyWales-getty-2198931158.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 23:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>China, Uses, Dual-Method, Cyberattack, Czech, Orgs</media:keywords>
</item>

<item>
<title>Securing AI Agents Before They Go Rogue Is Next to Impossible</title>
<link>https://block385.com/securing-ai-agents-before-they-go-rogue-is-next-to-impossible</link>
<guid>https://block385.com/securing-ai-agents-before-they-go-rogue-is-next-to-impossible</guid>
<description><![CDATA[ High-autonomy agents with broad permissions and unfettered access are a recipe for disaster, and enterprises need to act now before they become the next horror story. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltb353cb4eb8945ff6/6a1f007a2897886e9b11fcab/aiagents-Suchat_longthara-getty-2229177564.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 23:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Securing, Agents, Before, They, Rogue, Next, Impossible</media:keywords>
</item>

<item>
<title>Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited</title>
<link>https://block385.com/google-june-2026-android-update-patches-124-flaws-one-actively-exploited</link>
<guid>https://block385.com/google-june-2026-android-update-patches-124-flaws-one-actively-exploited</guid>
<description><![CDATA[ Google on Monday released patches for 124 security vulnerabilities impacting its Android operating system for the month of June 2026, including one high-severity flaw in the Framework component that has come under active exploitation.

Tracked as CVE-2025-48595 (CVSS score: 8.4), the security flaw has been described as a case of privilege escalation without requiring any user interaction. The ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgu6SfsDfrb_dr_5DP0MiwOMy86maTi3XyrtkQLw-sHAGlBZbhZ0uEfRkamwFqXGT4qNmVIqg6LQtaaRVLr_oGnxvKHiSuCU0Qts79fzGzWbeySgkpak_Cci73EHSyvr1qC1EqiciaI86XW4KtODuln9vUkYHvoH1p3bh_FTzW6scXui1REmWDv84cTxhoX/s1600/android.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 23:00:11 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Google, June, 2026, Android, Update, Patches, 124, Flaws, One, Actively, Exploited</media:keywords>
</item>

<item>
<title>Gamaredon Exploits WinRAR to Deliver GammaWorm and GammaSteel Against Ukraine</title>
<link>https://block385.com/gamaredon-exploits-winrar-to-deliver-gammaworm-and-gammasteel-against-ukraine</link>
<guid>https://block385.com/gamaredon-exploits-winrar-to-deliver-gammaworm-and-gammasteel-against-ukraine</guid>
<description><![CDATA[ The Russian hacking group known as Gamaredon has been attributed to the continued exploitation of a WinRAR vulnerability to deliver multiple malware families aimed at data theft and propagation.

Per Sekoia, the activity involves the weaponization of CVE-2025-8088, a path traversal flaw in WinRAR, to launch an HTML Application payload dubbed GammaPhish, which is then used to retrieve an ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiIWYqVAlf5o0isz1fGZ_KcAkqIAroOtFMRAvlOMseZrj7e5iLaZ47_92-zoFzN4rtQHJpmGHjMaOShanlb01qhHO5-_EFXskV2RdVtxShkQDFzCBGrgec2P-6IAFxMqRBkkbnLFyjl0n4ZkPbQBkEMl0OQqlj3CgThRwQ6Z6tQaYPbp1YhZy4wcxdmi5dy/s1600/russian-malware.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 21:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Gamaredon, Exploits, WinRAR, Deliver, GammaWorm, and, GammaSteel, Against, Ukraine</media:keywords>
</item>

<item>
<title>Oracle WebLogic CVE&#45;2024&#45;21182 Added to KEV Catalog After Active Exploitation</title>
<link>https://block385.com/oracle-weblogic-cve-2024-21182-added-to-kev-catalog-after-active-exploitation</link>
<guid>https://block385.com/oracle-weblogic-cve-2024-21182-added-to-kev-catalog-after-active-exploitation</guid>
<description><![CDATA[ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

The vulnerability, CVE-2024-21182 (CVSS score: 7.5), allows an unauthenticated attacker with network access to take control of susceptible servers. It was ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyTRAA7jrm-wO7d39ZhI2e75GnwqNE6t-CKpScXYfVikGGVRC4fYajbw5kn3aHqZc9rmbdjIqft5nwFLWAxCikfEMsfpt_h6dxGczVBeqAuujhbo01DpypfOJMqGqS0ohY7U1_L084pUvBxX8riiXrWssrwn76k7mMR-yR_3FMQV5fDjxIpRg-BPebCG_J/s1600/oracle.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 21:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Oracle, WebLogic, CVE-2024-21182, Added, KEV, Catalog, After, Active, Exploitation</media:keywords>
</item>

<item>
<title>Tuskira Quell identifies, mitigates, and validates zero&#45;day risk before breach</title>
<link>https://block385.com/tuskira-quell-identifies-mitigates-and-validates-zero-day-risk-before-breach</link>
<guid>https://block385.com/tuskira-quell-identifies-mitigates-and-validates-zero-day-risk-before-breach</guid>
<description><![CDATA[ Tuskira launched Quell, its exposure-led zero-day defense capability. Quell helps enterprises survive the window between a zero-day’s disclosure and a patch by determining which zero-days are reachable in their environment, whether existing controls would stop them, and which compensating control change would disrupt the exploit immediately. Organizations using Tuskira have cut breachable exposure by up to 99%. In one global financial services deployment, Tuskira reduced 12.3 million raw findings to 0.46% actionable risk within weeks, … More →
The post Tuskira Quell identifies, mitigates, and validates zero-day risk before breach appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 17:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Tuskira, Quell, identifies, mitigates, and, validates, zero-day, risk, before, breach</media:keywords>
</item>

<item>
<title>Noma brings visibility and access governance to AI agents and MCP servers</title>
<link>https://block385.com/noma-brings-visibility-and-access-governance-to-ai-agents-and-mcp-servers</link>
<guid>https://block385.com/noma-brings-visibility-and-access-governance-to-ai-agents-and-mcp-servers</guid>
<description><![CDATA[ Noma has announced the launch of Noma Agent Access Control, which helps security teams discover, govern, and enforce access policies for AI agents and Model Context Protocol (MCP) servers throughout the enterprise. AI agents and MCP servers have proliferated across developer environments faster than existing governance frameworks were designed to handle. In less than 12 months, organizations have gone from experimenting with a handful of agents to running dozens, or even hundreds of them, each … More →
The post Noma brings visibility and access governance to AI agents and MCP servers appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 17:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Noma, brings, visibility, and, access, governance, agents, and, MCP, servers</media:keywords>
</item>

<item>
<title>Codex knowledge work expands into research, reports, and spreadsheets</title>
<link>https://block385.com/codex-knowledge-work-expands-into-research-reports-and-spreadsheets</link>
<guid>https://block385.com/codex-knowledge-work-expands-into-research-reports-and-spreadsheets</guid>
<description><![CDATA[ Office workers in the United States lose hours each week to email triage and to searching for files spread across disconnected systems. Roughly 40 percent of US labor, about 72 million people, works primarily with information such as analysis, documents, designs, and communication. Research from the McKinsey Global Institute puts the average knowledge worker at 28 percent of the workweek on email and close to 20 percent on hunts for internal information or for colleagues … More →
The post Codex knowledge work expands into research, reports, and spreadsheets appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/02/05154533/openai-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 15:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Codex, knowledge, work, expands, into, research, reports, and, spreadsheets</media:keywords>
</item>

<item>
<title>Google fixes actively exploited Android vulnerability (CVE&#45;2025&#45;48595)</title>
<link>https://block385.com/google-fixes-actively-exploited-android-vulnerability-cve-2025-48595</link>
<guid>https://block385.com/google-fixes-actively-exploited-android-vulnerability-cve-2025-48595</guid>
<description><![CDATA[ Google has announced the June 2026 Android security updates, which fix a bucketload of vulnerabilities, including a high-severity vulnerability (CVE-2025-48595) in the Android Framework that “may be under limited, targeted exploitation.” About CVE-2025-48595 CVE-2025-48595 is an integer overflow vulnerability in the Android Framework, a set of APIs and system services that apps interact with directly. The flaw allows attackers to escalate privileges on a vulnerable device, and they may gain complete access to the device … More →
The post Google fixes actively exploited Android vulnerability (CVE-2025-48595) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/04/23101514/android-broken-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 15:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Google, fixes, actively, exploited, Android, vulnerability, CVE-2025-48595</media:keywords>
</item>

<item>
<title>Diligent automates cyber risk assessments and reporting</title>
<link>https://block385.com/diligent-automates-cyber-risk-assessments-and-reporting</link>
<guid>https://block385.com/diligent-automates-cyber-risk-assessments-and-reporting</guid>
<description><![CDATA[ Diligent has announced Diligent Cyber Risk Management, an agentic solution designed to help organizations manage cybersecurity risk in a business context. Available in summer 2026, the platform reduces cyber risk assessment work from weeks to hours and links cyber threats to strategic objectives, critical business processes, and board-level oversight, helping organizations prioritize security investments based on business impact. “Municipal security teams don’t have the luxury of piecing together risk from scattered scans and spreadsheets. We … More →
The post Diligent automates cyber risk assessments and reporting appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 15:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Diligent, automates, cyber, risk, assessments, and, reporting</media:keywords>
</item>

<item>
<title>64,000 accounts exposed in breach of GTA V cheat service Atlas Menu</title>
<link>https://block385.com/64000-accounts-exposed-in-breach-of-gta-v-cheat-service-atlas-menu</link>
<guid>https://block385.com/64000-accounts-exposed-in-breach-of-gta-v-cheat-service-atlas-menu</guid>
<description><![CDATA[ Atlas Menu, a cheat service for Grand Theft Auto V and Counter-Strike 2, has been added to the Have I Been Pwned database following a data breach that exposed tens of thousands of user records. The incident exposed approximately 64,000 accounts, including email addresses, usernames, IP addresses, support tickets, and passwords hashed with bcrypt. The attacker claimed to have compromised all Atlas systems before leaking the service’s database through a public GitHub repository. In a … More →
The post 64,000 accounts exposed in breach of GTA V cheat service Atlas Menu appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/02133747/atlas_menu-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 15:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>64, 000, accounts, exposed, breach, GTA, cheat, service, Atlas, Menu</media:keywords>
</item>

<item>
<title>Beyond Assume&#45;Breach: How AI&#45;Native Security Will Reshape Enterprise Defense</title>
<link>https://block385.com/beyond-assume-breach-how-ai-native-security-will-reshape-enterprise-defense</link>
<guid>https://block385.com/beyond-assume-breach-how-ai-native-security-will-reshape-enterprise-defense</guid>
<description><![CDATA[ Twenty years after Dark Reading launched, we&#039;re looking ahead at what&#039;s next for enterprise security. Spoiler: It&#039;s hyper-segmented, AI-orchestrated, and way more sophisticated than your dad&#039;s firewall. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt5c9210f3fa88fb2f/6a1ddb22a0b6da11e713e9c7/AIBrian-imaginima-GettyImages-2206927993.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 15:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Beyond, Assume-Breach:, How, AI-Native, Security, Will, Reshape, Enterprise, Defense</media:keywords>
</item>

<item>
<title>Meta adds stricter guardrails for teen feeds</title>
<link>https://block385.com/meta-adds-stricter-guardrails-for-teen-feeds</link>
<guid>https://block385.com/meta-adds-stricter-guardrails-for-teen-feeds</guid>
<description><![CDATA[ Meta has expanded its Teen Accounts 13+ content settings globally on Instagram, Facebook, and Messenger. The safeguards are designed to help young users see age-appropriate content by default. The company also introduced Limited Content on Instagram for parents seeking stricter restrictions. Meta plans to roll out the feature on Facebook and Messenger later this year. Content settings (Source: Meta) What the 13+ setting includes Facebook’s 13+ content setting hides content in Feed and Reels that … More →
The post Meta adds stricter guardrails for teen feeds appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/02/09135147/meta-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 15:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Meta, adds, stricter, guardrails, for, teen, feeds</media:keywords>
</item>

<item>
<title>AI&#45;Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.</title>
<link>https://block385.com/ai-driven-exploitation-is-destroying-vulnerability-management-heres-how-to-handle-it</link>
<guid>https://block385.com/ai-driven-exploitation-is-destroying-vulnerability-management-heres-how-to-handle-it</guid>
<description><![CDATA[ AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security. As a result, the window between a vulnerability being disclosed and indiscriminate exploitation observed across the internet is now measured in hours, not days.

The industry&#039;s ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgC5W9v8FZkEWo3lLXfVm96RBtE2mlXcUmv-T0KxRiUVUsBhQOMm8MG6G-IExq0SIu3KlkO309v-a63s4dCkLdR6CCZ3Mf-XK-qi3a7T-Lp_mJB2jio7dLxMAnvAqxlh4J0-F7fUr7uiSeWOk7ldmBLNki4ORg2A_Y5yJ-tk0b9V6iJjjf7U4CRwD9eAA/s1600/watch.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 15:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>AI-Driven, Exploitation, Destroying, Vulnerability, Management., Here’s, How, Handle, It.</media:keywords>
</item>

<item>
<title>How Leading Organizations Are Turning EDR Into Operational Resilience</title>
<link>https://block385.com/how-leading-organizations-are-turning-edr-into-operational-resilience</link>
<guid>https://block385.com/how-leading-organizations-are-turning-edr-into-operational-resilience</guid>
<description><![CDATA[ Most organizations now recognize that endpoint protection alone is no longer sufficient.

That&#039;s why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand that modern attacks move faster, evade traditional prevention controls, and require continuous visibility into suspicious activity across the environment.

But owning EDR ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhdciYseLWNtSuIlPrhxjKI4HId3_-g3E9nr2PmvF-sdPELDdug8zPHASf-hJwZKEUXi9n0pjN08mhpoe-BB_wi241-xBwfKPT8YeJdo41fnHHC9phaZR4TrLiGfTXS8X2SKdlKJMMcwbTuh0LYSbdsHJtNgTfVD5AZU9Y6XzCTqdTg8Vy8qSAVXq254AM/s1600/alert.png" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 15:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>How, Leading, Organizations, Are, Turning, EDR, Into, Operational, Resilience</media:keywords>
</item>

<item>
<title>Red Hat npm packages compromised in new Mini Shai&#45;Hulud malware wave</title>
<link>https://block385.com/red-hat-npm-packages-compromised-in-new-mini-shai-hulud-malware-wave</link>
<guid>https://block385.com/red-hat-npm-packages-compromised-in-new-mini-shai-hulud-malware-wave</guid>
<description><![CDATA[ Unknown attackers have compromised 30+ Red Hat Cloud Services npm packages with malware that goes after credentials stored in developers’ build environment. What the malware stole and how it can spread further The compromised packages were published in two different GitHub source repositories on June 1, 2026, between 10:53 and 10:53:33 UTC and 13:44 and 13:46:47 UTC. According to Wiz Security, a specific Red Hat employee GitHub account was compromised and “pushed malicious orphan commits … More →
The post Red Hat npm packages compromised in new Mini Shai-Hulud malware wave appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/10/02183423/redhat-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 13:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Red, Hat, npm, packages, compromised, new, Mini, Shai-Hulud, malware, wave</media:keywords>
</item>

<item>
<title>Microsoft Entra pushes passkeys, tightens identity security</title>
<link>https://block385.com/microsoft-entra-pushes-passkeys-tightens-identity-security</link>
<guid>https://block385.com/microsoft-entra-pushes-passkeys-tightens-identity-security</guid>
<description><![CDATA[ Microsoft has released multiple identity and network access capabilities for Entra, its family of identity and network access products that help organizations implement a zero trust security strategy, over the last 30 days. Features reaching general availability Identity and authentication updates Phishing-resistant MFA is now available on Linux desktops through the Microsoft identity broker. The feature supports Ubuntu 24.04 and 26.04, as well as RHEL 8, 9, and 10, bringing Linux support in line with … More →
The post Microsoft Entra pushes passkeys, tightens identity security appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/01/26083820/microsoft-entra_id-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 13:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Entra, pushes, passkeys, tightens, identity, security</media:keywords>
</item>

<item>
<title>Sophos uncovers AI&#45;powered malware lab built for EDR evasion</title>
<link>https://block385.com/sophos-uncovers-ai-powered-malware-lab-built-for-edr-evasion</link>
<guid>https://block385.com/sophos-uncovers-ai-powered-malware-lab-built-for-edr-evasion</guid>
<description><![CDATA[ A threat actor used AI technologies to build a malware-testing framework for developing and refining endpoint detection and response (EDR) evasion techniques, according to Sophos. The investigation began after an anomalous endpoint in a customer environment triggered alerts tied to malicious payloads originating from a testing directory. The files pointed to a broader framework focused on evading detection. The environment contained Cobalt Strike profiles designed to disguise beacon traffic as legitimate web requests, a Telegram-based … More →
The post Sophos uncovers AI-powered malware lab built for EDR evasion appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/08/28142151/agentic-ai-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 13:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Sophos, uncovers, AI-powered, malware, lab, built, for, EDR, evasion</media:keywords>
</item>

<item>
<title>Pakistan&#45;Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT</title>
<link>https://block385.com/pakistan-linked-sidecopy-targets-afghanistan-finance-ministry-with-xeno-rat</link>
<guid>https://block385.com/pakistan-linked-sidecopy-targets-afghanistan-finance-ministry-with-xeno-rat</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan&#039;s Ministry of Finance with an open-source remote access trojan called Xeno RAT.

&quot;The campaign opens with a spear phishing delivery - a ZIP archive containing a malicious LNK file bearing a carefully crafted Pashto-language filename,&quot; ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiilTEadDjLrLdKByKVP6n_zfNSbhTTutHu-9BbbIDTBotobmqmIOI7fDdGGHZQQB7wTo00L66NAKZBA3iRBLQpSf_NgH9hKe9Xd-WUoijt7y-CUbdZore_qSZpTmuBhExaAxeXn39EPCVPYugMnJ85c15e161ttOMRmbSAv7NcbUlYrqDV4NnbzHZvw0A5/s1600/paki.gif" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 13:00:14 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Pakistan-Linked, SideCopy, Targets, Afghanistan, Finance, Ministry, with, Xeno, RAT</media:keywords>
</item>

<item>
<title>Sensitive government personnel data posted online, Spanish police arrest suspect</title>
<link>https://block385.com/sensitive-government-personnel-data-posted-online-spanish-police-arrest-suspect</link>
<guid>https://block385.com/sensitive-government-personnel-data-posted-online-spanish-police-arrest-suspect</guid>
<description><![CDATA[ The Spanish National Police arrested a man in Granada for allegedly leaking personal data belonging to members of several sensitive state institutions. According to police, the suspect published the information on multiple online platforms, exposing personnel associated with organizations including the National Cybersecurity Institute (INCIBE), the National Security Council, the National Police, the Civil Guard, the State Attorney General’s Office, the Ministry of Finance, and the Tax Agency. “The investigation, led by Madrid’s Court of … More →
The post Sensitive government personnel data posted online, Spanish police arrest suspect appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/28094517/arrest-bw1-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 11:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Sensitive, government, personnel, data, posted, online, Spanish, police, arrest, suspect</media:keywords>
</item>

<item>
<title>OpenAI brings frontier AI to existing AWS environments</title>
<link>https://block385.com/openai-brings-frontier-ai-to-existing-aws-environments</link>
<guid>https://block385.com/openai-brings-frontier-ai-to-existing-aws-environments</guid>
<description><![CDATA[ OpenAI frontier models and Codex are now available on AWS, giving customers access to OpenAI capabilities within AWS environments and the controls needed to move more quickly from evaluation to deployment. OpenAI capabilities on Amazon Bedrock These capabilities are available through OpenAI models on Amazon Bedrock, a platform for building generative AI applications and agents at production scale. The platform enables teams to build AI applications using AWS-native security and governance controls. Amazon Bedrock Managed … More →
The post OpenAI brings frontier AI to existing AWS environments appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/03102604/openai-lock-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 11:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>OpenAI, brings, frontier, existing, AWS, environments</media:keywords>
</item>

<item>
<title>KDE Linux security audit cuts kernel modules and unused packages</title>
<link>https://block385.com/kde-linux-security-audit-cuts-kernel-modules-and-unused-packages</link>
<guid>https://block385.com/kde-linux-security-audit-cuts-kernel-modules-and-unused-packages</guid>
<description><![CDATA[ KDE Linux, the in-progress operating system from the KDE community, removed several kernel modules and software packages after a security audit of the components shipped with the system. The work followed the discovery of multiple security issues in the upstream Linux kernel during the prior month. Kernel and module changes Three contributors examined insecure and unused software included in KDE Linux. The audit led to a return to the vanilla Linux kernel. The Zen kernel … More →
The post KDE Linux security audit cuts kernel modules and unused packages appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/30140123/linux_tux_1.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 11:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>KDE, Linux, security, audit, cuts, kernel, modules, and, unused, packages</media:keywords>
</item>

<item>
<title>Cybanetix unveils Managed AI Service to secure users, models, and agents</title>
<link>https://block385.com/cybanetix-unveils-managed-ai-service-to-secure-users-models-and-agents</link>
<guid>https://block385.com/cybanetix-unveils-managed-ai-service-to-secure-users-models-and-agents</guid>
<description><![CDATA[ Cybanetix has announced the launch of its Managed AI Service to address all three aspects of AI use within the enterprise. Covering employee AI usage, AI governance, and embedded AI, the Managed AI Service combines technology from NOMA, SentinelOne, Microsoft, and Exabeam with Cybanetix consultancy, managed services, and 24/7 Security Operations Centre (SOC) monitoring. The result is a managed service for AI security within the enterprise, capable of responding to alerts in under 15 minutes. … More →
The post Cybanetix unveils Managed AI Service to secure users, models, and agents appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 11:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cybanetix, unveils, Managed, Service, secure, users, models, and, agents</media:keywords>
</item>

<item>
<title>RSA extends passwordless authentication to Linux environments</title>
<link>https://block385.com/rsa-extends-passwordless-authentication-to-linux-environments</link>
<guid>https://block385.com/rsa-extends-passwordless-authentication-to-linux-environments</guid>
<description><![CDATA[ RSA has expanded its passwordless authentication capabilities to Linux environments, advancing its goal of delivering secure, password-free access for every user in every environment. Linux is ubiquitous in enterprise infrastructure, powering servers, developer workstations, and critical operational environments across industries from financial services to government. Despite its reach, Linux users have historically been underserved by passwordless solutions, often left to rely on legacy credential-based access while users elsewhere deployed modern passwordless form factors. The Linux … More →
The post RSA extends passwordless authentication to Linux environments appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 09:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>RSA, extends, passwordless, authentication, Linux, environments</media:keywords>
</item>

<item>
<title>Zero trust physical security needs trust decisions at the edge</title>
<link>https://block385.com/zero-trust-physical-security-needs-trust-decisions-at-the-edge</link>
<guid>https://block385.com/zero-trust-physical-security-needs-trust-decisions-at-the-edge</guid>
<description><![CDATA[ In this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the edge without recreating old perimeter assumptions, why these devices should be treated as IT assets, and what the Mirai botnet taught the industry. Davis also covers posture assessment for devices that cannot run standard agents, and … More →
The post Zero trust physical security needs trust decisions at the edge appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/30071951/chuck_davis-2-hikvision.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 09:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Zero, trust, physical, security, needs, trust, decisions, the, edge</media:keywords>
</item>

<item>
<title>Dashlane Discloses Brute&#45;Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded</title>
<link>https://block385.com/dashlane-discloses-brute-force-attack-encrypted-vaults-of-fewer-than-20-users-downloaded</link>
<guid>https://block385.com/dashlane-discloses-brute-force-attack-encrypted-vaults-of-fewer-than-20-users-downloaded</guid>
<description><![CDATA[ Password manager Dashlane has disclosed that &quot;fewer than&quot; 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party.

On May 31, 2026, the company said an &quot;external&quot; threat actor launched a brute-force attack against certain Dashlane user accounts with the aim of breaking two-factor authentication (2FA) ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMY3oQNaqfV2_sMYMZJ_EbUA90VD_t0w342aOV-tTDXEui63NgSB0SPYPhGVW9e5i8ZcEk7P5uudw6PJOi5od9rdsq9GzG0npc8FiqXuQ33r-zg81AMHW53prz_ovs2YbKrjaNfOOAp1tpmjhE3ADsjVymKPDGf4TyikPb1z18MOWk2YH-BteUQ6EUqYFI/s1600/dashlane.png" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 09:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Dashlane, Discloses, Brute-Force, Attack, Encrypted, Vaults, Fewer, Than, Users, Downloaded</media:keywords>
</item>

<item>
<title>Cybersecurity jobs available right now: June 2, 2026</title>
<link>https://block385.com/cybersecurity-jobs-available-right-now-june-2-2026</link>
<guid>https://block385.com/cybersecurity-jobs-available-right-now-june-2-2026</guid>
<description><![CDATA[ Agentic Safety and Ecosystem Architect, Trust and Safety Google | USA | On-site – View job details As an Agentic Safety and Ecosystem Architect, Trust and Safety, you will define safety controls and permission models for autonomous agents on Android, helping ensure actions are reviewed before execution and access to sensitive data requires explicit consent. You will develop monitoring mechanisms to detect unsafe agent behavior and work with the developer community to promote secure agent … More →
The post Cybersecurity jobs available right now: June 2, 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/11140410/cybersecurity_jobs-4-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 07:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cybersecurity, jobs, available, right, now:, June, 2026</media:keywords>
</item>

<item>
<title>This AI model backdoor attack stays hidden until you customize the model</title>
<link>https://block385.com/this-ai-model-backdoor-attack-stays-hidden-until-you-customize-the-model</link>
<guid>https://block385.com/this-ai-model-backdoor-attack-stays-hidden-until-you-customize-the-model</guid>
<description><![CDATA[ Most teams that deploy AI start with a backbone model. They download a large pre-trained system, adapt it to a specific task, and put it into production. The download step carries a security question: the origin of the model. A research team built an attack called BadBone. It plants a backdoor inside a backbone model. Downstream tasks that adapt the model inherit the backdoor. The name points at the target. Corrupt the skeleton, and systems … More →
The post This AI model backdoor attack stays hidden until you customize the model appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/01091216/brain-backdoor.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 07:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>This, model, backdoor, attack, stays, hidden, until, you, customize, the, model</media:keywords>
</item>

<item>
<title>Why you need BAS and autonomous pentesting together</title>
<link>https://block385.com/why-you-need-bas-and-autonomous-pentesting-together</link>
<guid>https://block385.com/why-you-need-bas-and-autonomous-pentesting-together</guid>
<description><![CDATA[ Most security teams know the drill: A new autonomous penetration testing tool gets deployed, and the first run is genuinely impressive. The dashboard surfaces critical findings, maps lateral movement paths nobody had documented before, and exposes a legacy service account that has been sitting idle for years. Great. The red team feels like it’s found a force multiplier. The CISO feels like the “human element” of validation has finally been automated away. Then, troublingly, by … More →
The post Why you need BAS and autonomous pentesting together appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/26122920/connect-servers.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 07:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Why, you, need, BAS, and, autonomous, pentesting, together</media:keywords>
</item>

<item>
<title>Microsoft&amp;apos;s Zero&#45;Day Legal Threats Spark Backlash</title>
<link>https://block385.com/microsofts-zero-day-legal-threats-spark-backlash</link>
<guid>https://block385.com/microsofts-zero-day-legal-threats-spark-backlash</guid>
<description><![CDATA[ After a disgruntled security researcher published several zero-day exploits in recent weeks, Microsoft seemingly indicated criminal charges were in order. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt110b7f1326599f0b/6a1dd3554d48bfcf20ade268/RMmicrosoft-DrewAngerer-Getty-675949746.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 02 Jun 2026 01:30:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsofts, Zero-Day, Legal, Threats, Spark, Backlash</media:keywords>
</item>

<item>
<title>Anthropic to Open Mythos AI to EU&amp;apos;s ENISA</title>
<link>https://block385.com/anthropic-to-open-mythos-ai-to-eus-enisa</link>
<guid>https://block385.com/anthropic-to-open-mythos-ai-to-eus-enisa</guid>
<description><![CDATA[ The European security agency&#039;s entry to Project Glasswing is the result of &quot;strong bilateral cooperation&quot; between the European Commission and Anthropic. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt301abc846275d0a4/6a1de7c8479f3e4dd25cf448/enisa_ricochet64_shuttrstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 23:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Anthropic, Open, Mythos, EUs, ENISA</media:keywords>
</item>

<item>
<title>Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential&#45;Stealing Worm</title>
<link>https://block385.com/miasma-supply-chain-attack-compromises-red-hat-npm-packages-with-credential-stealing-worm</link>
<guid>https://block385.com/miasma-supply-chain-attack-compromises-red-hat-npm-packages-with-credential-stealing-worm</guid>
<description><![CDATA[ A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm.

&quot;This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOyc2NTiIl0XKOTZBsFh1bTPqNpVXfDhASWkCsYz17d-nbiWVKlxCzoq3WthMD8kMomrRPPOYLM-XRmSdtXNKAxtk1QLtmZH47y2RExMGohBaBDPkpFp2PteUgaA16VcCs7tK-ImqCiLnpqyLg8Pwp6cWE5d9QT2_v0-QBduT7ovYrs7WSZ9t1MnQJ4EuO/s1600/redhat.png" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 21:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Miasma, Supply, Chain, Attack, Compromises, Red, Hat, npm, Packages, with, Credential-Stealing, Worm</media:keywords>
</item>

<item>
<title>Meta tries to get ahead of scammers before the World Cup begins</title>
<link>https://block385.com/meta-tries-to-get-ahead-of-scammers-before-the-world-cup-begins</link>
<guid>https://block385.com/meta-tries-to-get-ahead-of-scammers-before-the-world-cup-begins</guid>
<description><![CDATA[ Football fans are counting down the days until the FIFA World Cup begins, and scammers are doing the same. Last week, the FBI warned that cybercriminals are spoofing FIFA websites to steal personal information, sell fake tickets, and promote fraudulent hospitality packages ahead of the tournament. With millions of supporters expected to travel to the United States, Canada, and Mexico for the 2026 World Cup, fraudsters are likely to target demand for tickets, accommodation, and … More →
The post Meta tries to get ahead of scammers before the World Cup begins appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/28100914/fifa_2026.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 19:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Meta, tries, get, ahead, scammers, before, the, World, Cup, begins</media:keywords>
</item>

<item>
<title>OpenAI requires stronger authentication for users of its most powerful AI models</title>
<link>https://block385.com/openai-requires-stronger-authentication-for-users-of-its-most-powerful-ai-models</link>
<guid>https://block385.com/openai-requires-stronger-authentication-for-users-of-its-most-powerful-ai-models</guid>
<description><![CDATA[ Yubico announced its significant role in securing the AI frontier as OpenAI mandates the use of passkeys for individuals that are part of their Trusted Access for Cyber (TAC) program. As a leading global AI research and development company, OpenAI is setting a precedent for empowering its users to take control of their own security posture with more secure authentication options. Starting June 1, 2026, individuals in TAC with access to OpenAI’s most powerful and … More →
The post OpenAI requires stronger authentication for users of its most powerful AI models appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 19:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>OpenAI, requires, stronger, authentication, for, users, its, most, powerful, models</media:keywords>
</item>

<item>
<title>depthfirst adds pre&#45;install protection against malicious dependencies</title>
<link>https://block385.com/depthfirst-adds-pre-install-protection-against-malicious-dependencies</link>
<guid>https://block385.com/depthfirst-adds-pre-install-protection-against-malicious-dependencies</guid>
<description><![CDATA[ depthfirst has introduced Dependency Firewall, a product that reviews every open-source package being downloaded anywhere in a company and blocks the malicious ones before they reach the person or system that requested them. Developers, AI agents, and any employee using Claude, Codex, or other AI tools keep installing exactly as they do today, and nothing dangerous makes it through. Security teams can ensure that AI is rolled out safely across the company. Modern software runs … More →
The post depthfirst adds pre-install protection against malicious dependencies appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>depthfirst, adds, pre-install, protection, against, malicious, dependencies</media:keywords>
</item>

<item>
<title>PathSolutions brings on&#45;premises AI troubleshooting to NetOps teams</title>
<link>https://block385.com/pathsolutions-brings-on-premises-ai-troubleshooting-to-netops-teams</link>
<guid>https://block385.com/pathsolutions-brings-on-premises-ai-troubleshooting-to-netops-teams</guid>
<description><![CDATA[ PathSolutions has announced the launch of TotalView AI, a new capability within its TotalView platform that provides AI-driven troubleshooting for NetOps teams using network data analyzed on-premises. As enterprise networks become more distributed and complex, NetOps teams face increasing pressure to resolve issues quickly, often without the benefit of deep domain expertise. At the same time, many AI-driven monitoring solutions rely on sending limited datasets to the cloud, introducing latency, increasing cost, and restricting visibility. … More →
The post PathSolutions brings on-premises AI troubleshooting to NetOps teams appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>PathSolutions, brings, on-premises, troubleshooting, NetOps, teams</media:keywords>
</item>

<item>
<title>Brute&#45;force attack triggers Dashlane account lockouts</title>
<link>https://block385.com/brute-force-attack-triggers-dashlane-account-lockouts</link>
<guid>https://block385.com/brute-force-attack-triggers-dashlane-account-lockouts</guid>
<description><![CDATA[ Password manager Dashlane has confirmed that a brute-force attack targeting user accounts triggered temporary account suspensions and authentication issues. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. “Your account has been temporarily suspended for security reasons as someone has attempted to register a new device and didn’t enter the correct token after several tries,” the emails stated, instructing affected users to contact customer … More →
The post Brute-force attack triggers Dashlane account lockouts appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/04/30124152/altert3.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Brute-force, attack, triggers, Dashlane, account, lockouts</media:keywords>
</item>

<item>
<title>Insight bundles exposure management, patch operations, and XDR into one service</title>
<link>https://block385.com/insight-bundles-exposure-management-patch-operations-and-xdr-into-one-service</link>
<guid>https://block385.com/insight-bundles-exposure-management-patch-operations-and-xdr-into-one-service</guid>
<description><![CDATA[ Insight has launched Insight Managed Exposure Defense, a managed security service designed to help organizations identify and address vulnerabilities. The service aims to help organizations reduce exposure and implement protections without lengthy procurement processes or reliance on multiple vendors. AI-assisted exploit development has compressed the weaponization window from days to hours, and most organizations lack the dedicated patch operations and infrastructure required to safely absorb updates at this extreme velocity. For mid-market organizations especially, the … More →
The post Insight bundles exposure management, patch operations, and XDR into one service appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Insight, bundles, exposure, management, patch, operations, and, XDR, into, one, service</media:keywords>
</item>

<item>
<title>NetQuest expands NetworkLens to detect threats hidden in network management traffic</title>
<link>https://block385.com/netquest-expands-networklens-to-detect-threats-hidden-in-network-management-traffic</link>
<guid>https://block385.com/netquest-expands-networklens-to-detect-threats-hidden-in-network-management-traffic</guid>
<description><![CDATA[ NetQuest announced an expansion of its NetworkLens enriched dataset portfolio. The new network telemetry datasets deliver detailed traffic characteristics of network management transactions, giving security teams the granular, AI-ready intelligence needed to detect threats hidden within the protocols used to manage critical network infrastructure. The effectiveness of AI-driven threat detection tools — including agentic security platforms — is only as strong as the data powering them. NetworkLens, powered by NetQuest’s Streaming Network Sensor (SNS) platform, … More →
The post NetQuest expands NetworkLens to detect threats hidden in network management traffic appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>NetQuest, expands, NetworkLens, detect, threats, hidden, network, management, traffic</media:keywords>
</item>

<item>
<title>Windows Netlogon RCE exploited, domain controllers at risk (CVE&#45;2026&#45;41089)</title>
<link>https://block385.com/windows-netlogon-rce-exploited-domain-controllers-at-risk-cve-2026-41089</link>
<guid>https://block385.com/windows-netlogon-rce-exploited-domain-controllers-at-risk-cve-2026-41089</guid>
<description><![CDATA[ CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB) warned on Friday. About CVE-2026-41089 CVE-2026-41089 is a stack-based buffer overflow vulnerability in Windows Netlogon, the service and protocol that handles authentication and security within a Windows domain environment. The flaw can be exploited by attackers by sending a specially crafted network request to a Windows server that is acting … More →
The post Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/10/24123541/windows_server-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Windows, Netlogon, RCE, exploited, domain, controllers, risk, CVE-2026-41089</media:keywords>
</item>

<item>
<title>Secure Code Warrior connects developer training to AI usage and code risks</title>
<link>https://block385.com/secure-code-warrior-connects-developer-training-to-ai-usage-and-code-risks</link>
<guid>https://block385.com/secure-code-warrior-connects-developer-training-to-ai-usage-and-code-risks</guid>
<description><![CDATA[ Secure Code Warrior has introduced Adaptive Learning, a capability designed to help organizations support AI software governance through targeted training based on identified risks. The feature delivers contextual microlearning and tracks outcomes at the code commit level. Software development is going through its biggest shift ever, from human-written code, to AI-assisted coding, to fully agentic systems with AI writing and revising everything autonomously. It is introducing code churn at an alarming rate. According to Faros’ … More →
The post Secure Code Warrior connects developer training to AI usage and code risks appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Secure, Code, Warrior, connects, developer, training, usage, and, code, risks</media:keywords>
</item>

<item>
<title>Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit</title>
<link>https://block385.com/patch-now-another-palo-alto-auth-bypass-bug-under-active-exploit</link>
<guid>https://block385.com/patch-now-another-palo-alto-auth-bypass-bug-under-active-exploit</guid>
<description><![CDATA[ Exploiting the PAN-OS GlobalProtect VPN vulnerability requires certain conditions, but adversaries have done so in two attack waves that started in mid-May. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt225868f85dab8e5a/6a1d6cdb688dd44956baf7b6/Vulnerability_(1800)_Sergey_Tarasov_Alamy.png" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Patch, Now:, Another, Palo, Alto, Auth, Bypass, Bug, Under, Active, Exploit</media:keywords>
</item>

<item>
<title>⚡ Weekly Recap: New Linux Flaw, PAN&#45;OS Exploit, AI&#45;Powered Attacks, OAuth Phishing and More</title>
<link>https://block385.com/weekly-recap-new-linux-flaw-pan-os-exploit-ai-powered-attacks-oauth-phishing-and-more</link>
<guid>https://block385.com/weekly-recap-new-linux-flaw-pan-os-exploit-ai-powered-attacks-oauth-phishing-and-more</guid>
<description><![CDATA[ Monday hit like a cron job with anger issues.

A busted auth path here, a repo-side faceplant there, some &quot;patched-ish&quot; thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought &#039;curl | sh&#039; had a personality.

The vibe is simple: old ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiV-leTG-MQremNN5Ju342L6LQMn36xeD4jiS4YWT7EdYluHOtFDqIN8y3bQuV-A0D0wtsO5sRpG3Bpy5xdHhMs_sO_w3WoiiJzCd7o-7Hxw736ERxQs4WDd71EQEBIHLzT_UNFMwCDvC8Nij-gDNpMhsRnpsqoDHkuxUWLUEZSSTfDc4aXpx2qlpsaqlgH/s1600/cyberrecap.png" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:00:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>⚡, Weekly, Recap:, New, Linux, Flaw, PAN-OS, Exploit, AI-Powered, Attacks, OAuth, Phishing, and, More</media:keywords>
</item>

<item>
<title>China&#45;Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic &amp;amp; Taiwan</title>
<link>https://block385.com/china-aligned-groups-ramp-up-attacks-dragon-weave-hits-czech-republic-taiwan</link>
<guid>https://block385.com/china-aligned-groups-ramp-up-attacks-dragon-weave-hits-czech-republic-taiwan</guid>
<description><![CDATA[ A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent.

According to Seqrite Labs, targets of the campaign include government, research, academic, technology, and financial services sectors. The activity entails distributing spear-phishing emails containing ZIP attachments ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUhiw46hdnhoY05E-0EyhOX5AxQrqJeNM0WDEWiYHAi5pPt4kIFPbvqGZhyAK4NxlAF7KJKxPfWlbGLbZUJJD9PgGmazvyhzaSgBXokM_6eYQfWXQ1HDv2heSDTnps4EGhjKqwCbuQOl0d9QN25tmn85xLujp-htCwLhhywI4A6BKJxkOOKb9FSu02AMjX/s1600/china.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 17:00:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>China-Aligned, Groups, Ramp, Attacks:, Dragon, Weave, Hits, Czech, Republic, Taiwan</media:keywords>
</item>

<item>
<title>Horizon3.ai introduces Rapid Response to prioritize and verify vulnerability remediation</title>
<link>https://block385.com/horizon3ai-introduces-rapid-response-to-prioritize-and-verify-vulnerability-remediation</link>
<guid>https://block385.com/horizon3ai-introduces-rapid-response-to-prioritize-and-verify-vulnerability-remediation</guid>
<description><![CDATA[ Horizon3.ai has introduced Rapid Response, a capability that helps organizations assess exposure to newly disclosed threats, prioritize remediation, and verify that vulnerabilities have been addressed. Security teams are inundated with vulnerability disclosures, threat intelligence feeds, exploit chatter, and vendor advisories, all demanding immediate attention. While tens of thousands of new vulnerabilities are disclosed each year, only a small fraction are actively exploited. Across more than 250,000 NodeZero security assessments, Horizon3.ai has consistently found that exploitability, … More →
The post Horizon3.ai introduces Rapid Response to prioritize and verify vulnerability remediation appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 15:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Horizon3.ai, introduces, Rapid, Response, prioritize, and, verify, vulnerability, remediation</media:keywords>
</item>

<item>
<title>How NIST fumbled management of the National Vulnerability Database</title>
<link>https://block385.com/how-nist-fumbled-management-of-the-national-vulnerability-database</link>
<guid>https://block385.com/how-nist-fumbled-management-of-the-national-vulnerability-database</guid>
<description><![CDATA[ A US federal watchdog has outlined how the National Institute of Standards and Technology (NIST) failed to effectively manage the growing backlog of unprocessed cybersecurity vulnerabilities in the National Vulnerability Database (NVD). How the NVD crisis unfolded The NVD was established in 2005 and serves as a central repository for cybersecurity vulnerability data. When security researchers or software vendors discover a flaw in a piece of software or hardware, they submit a report through the … More →
The post How NIST fumbled management of the National Vulnerability Database appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/04/03121316/nist_nvd-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 15:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>How, NIST, fumbled, management, the, National, Vulnerability, Database</media:keywords>
</item>

<item>
<title>Hyland platform innovations focus on AI governance, context, and agent oversight</title>
<link>https://block385.com/hyland-platform-innovations-focus-on-ai-governance-context-and-agent-oversight</link>
<guid>https://block385.com/hyland-platform-innovations-focus-on-ai-governance-context-and-agent-oversight</guid>
<description><![CDATA[ Hyland has unveiled platform innovations designed to move AI from experimentation to enterprise-wide adoption. Powered by the Content Innovation Cloud, these advancements transform governed enterprise content into trusted, actionable intelligence that accelerates business outcomes. To meet the demands of global organizations, Hyland announced the general availability of the Enterprise Context Engine and introduced industry-specific ontologies that enrich organizational context for more accurate, domain-aware AI performance. Additionally, the company delivered Enterprise Agent Mesh, enabling governed orchestration … More →
The post Hyland platform innovations focus on AI governance, context, and agent oversight appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 15:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Hyland, platform, innovations, focus, governance, context, and, agent, oversight</media:keywords>
</item>

<item>
<title>Microsoft Defender Vulnerability Management gets a smarter exposure score</title>
<link>https://block385.com/microsoft-defender-vulnerability-management-gets-a-smarter-exposure-score</link>
<guid>https://block385.com/microsoft-defender-vulnerability-management-gets-a-smarter-exposure-score</guid>
<description><![CDATA[ Microsoft Defender Vulnerability Management’s updated exposure score model adds vulnerability risk signals and asset context to help teams understand where risk is concentrated and which remediation actions are likely to have the greatest impact. The model is available in public preview. “The updated model addresses these customer pain points by combining vulnerability risk, exploitability signals, and asset context into a more representative exposure score. The goal is to help security teams move from a score … More →
The post Microsoft Defender Vulnerability Management gets a smarter exposure score appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/19154102/microsoft2.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 15:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Defender, Vulnerability, Management, gets, smarter, exposure, score</media:keywords>
</item>

<item>
<title>Cato cuts vulnerability protection time to 45 minutes with agentic threat research</title>
<link>https://block385.com/cato-cuts-vulnerability-protection-time-to-45-minutes-with-agentic-threat-research</link>
<guid>https://block385.com/cato-cuts-vulnerability-protection-time-to-45-minutes-with-agentic-threat-research</guid>
<description><![CDATA[ Cato Networks announced a new capability that reduces time-to-protect for newly disclosed vulnerabilities to 45 minutes. The company attributes this reduction to the use of agentic threat research designed to accelerate protection against emerging exploits. Traditional appliance-based security depends on a slow customer-operated patching cycle: vendors develop protections, customers receive updates, teams test them, and thousands of distributed appliances must be upgraded or configured. In the AI era, that model cannot keep pace with exploit … More →
The post Cato cuts vulnerability protection time to 45 minutes with agentic threat research appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 15:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cato, cuts, vulnerability, protection, time, minutes, with, agentic, threat, research</media:keywords>
</item>

<item>
<title>The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools</title>
<link>https://block385.com/the-security-growth-platform-why-msps-are-moving-beyond-vciso-tools</link>
<guid>https://block385.com/the-security-growth-platform-why-msps-are-moving-beyond-vciso-tools</guid>
<description><![CDATA[ Three years ago, the practical question for an MSP building a cybersecurity practice was which &quot;vCISO platform&quot; to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has since outgrown the descriptor.

A Security Growth Platform is the more precise name for what MSPs and MSSPs need from the software ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOvm8XaHJ9FBjwjKyTkm_2pt81tT-4sHdK9UDWm7_hCk4rA95U0peF3Zi7kO_fmJioaGKKloqru4yC-AwrSOdZ17v7m8K2K-t4lyYOGfC66J8r3cSi_v09IPRAfknHSeRBv13kjrk6XBzqpCvKS6ujugm4cR6Xrt1LK40bC091c0k_SgptQnGYIznwWwQ/s1600/cynomi.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 15:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, Security, Growth, Platform:, Why, MSPs, Are, Moving, Beyond, vCISO, Tools</media:keywords>
</item>

<item>
<title>OpenAI Codex Authentication Tokens Stolen in codexui&#45;android npm Supply Chain Attack</title>
<link>https://block385.com/openai-codex-authentication-tokens-stolen-in-codexui-android-npm-supply-chain-attack</link>
<guid>https://block385.com/openai-codex-authentication-tokens-stolen-in-codexui-android-npm-supply-chain-attack</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that&#039;s targeting developers using OpenAI Codex through a legitimate-looking remote web UI.

The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository.

What ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4veBAmEJHF2nXN_nIgXeWxVSxlTDBc6uWiLwVCYNUqGMF9ZtPre3zF_CXmGnAxX2rbqfwgm_Au0tXvYwv1oTGim1STiGCeVOyMXglUTd-3LeJEN3q718Fdlck9mbQ6aUUYP0NM9S7bakZ4_XF5HHYH-cz2QmKBlge6xNMxbbEjDjZQ4wd1maPKnjgKrsu/s1600/codex.png" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 15:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>OpenAI, Codex, Authentication, Tokens, Stolen, codexui-android, npm, Supply, Chain, Attack</media:keywords>
</item>

<item>
<title>Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE&#45;2026&#45;0257)</title>
<link>https://block385.com/hackers-are-exploiting-palo-alto-globalprotect-vpn-authentication-bypass-cve-2026-0257</link>
<guid>https://block385.com/hackers-are-exploiting-palo-alto-globalprotect-vpn-authentication-bypass-cve-2026-0257</guid>
<description><![CDATA[ Authentication bypass vulnerabilities (CVE-2026-0257) in Palo Alto Networks’ firewalls that the company disclosed on May 13 have been targeted in “limited exploit attempts”. “Across multiple customers, Rapid7 observed successful exploitation via authentication probes using forged cookies, but the appliance accepted the cookie without a full VPN session being established in 8 out of 10 impacted [Managed Detection Response] customers.” The good news, though, is that the company hasn’t observed any indication of successful lateral movement … More →
The post Hackers are exploiting Palo Alto GlobalProtect VPN authentication bypass (CVE-2026-0257) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/04/17164810/palo_alto_networks-2-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 13:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Hackers, are, exploiting, Palo, Alto, GlobalProtect, VPN, authentication, bypass, CVE-2026-0257</media:keywords>
</item>

<item>
<title>Dragos acquires Phosphorus to secure extended operational technology</title>
<link>https://block385.com/dragos-acquires-phosphorus-to-secure-extended-operational-technology</link>
<guid>https://block385.com/dragos-acquires-phosphorus-to-secure-extended-operational-technology</guid>
<description><![CDATA[ Dragos has acquired Phosphorus, extending the Dragos Platform to protect billions of connected devices embedded across critical infrastructure and other operational networks. Operational environments have outgrown traditional OT boundaries. Power grids, pipelines, manufacturing facilities, and data centers now depend on an increasingly diverse mix of connected devices and digital systems. Traditional and non-traditional assets alike are woven throughout their operational environments. This expanded environment, OT systems and the billions of connected devices that have reshaped … More →
The post Dragos acquires Phosphorus to secure extended operational technology appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 13:30:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Dragos, acquires, Phosphorus, secure, extended, operational, technology</media:keywords>
</item>

<item>
<title>Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts</title>
<link>https://block385.com/critical-wp-maps-pro-flaw-actively-exploited-to-create-admin-accounts</link>
<guid>https://block385.com/critical-wp-maps-pro-flaw-actively-exploited-to-create-admin-accounts</guid>
<description><![CDATA[ Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites.

WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, listings, and advanced location features on WordPress sites. It is ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhR5AZVDVlhPdPOYO4FsyfLsBmtohzgdjmh688BLU6VRpwi-MaKq4XYgE5-ygnQtcUDMKcR8R4-f9IrfiSFpCodN01gveAWlDpu4Jg4AI9DMKQG50zMr5M1QhqjVAjyuYJQ-vF849bn3jkkDJuBRahpyUwAz8libDqBIwh08wgQNsfmchLwqRUqiYKRDkMT/s1600/wordpress-2.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 13:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Critical, Maps, Pro, Flaw, Actively, Exploited, Create, Admin, Accounts</media:keywords>
</item>

<item>
<title>Asimily turns device risk into automated network policy</title>
<link>https://block385.com/asimily-turns-device-risk-into-automated-network-policy</link>
<guid>https://block385.com/asimily-turns-device-risk-into-automated-network-policy</guid>
<description><![CDATA[ Asimily has launched Segmentation Orchestration, enabling connected-device risk intelligence to flow directly into enforceable network policy without manual translation. No other platform combines full asset visibility, vulnerability prioritization, and segmentation orchestration in a single system. “AI has exploded the volume and sophistication of network attacks against connected devices, and security teams are discovering that visibility tools and manual policies cannot keep pace,” said Shankar Somasundaram, CEO, Asimily. “Attackers are exploiting the space between what organizations … More →
The post Asimily turns device risk into automated network policy appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 11:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Asimily, turns, device, risk, into, automated, network, policy</media:keywords>
</item>

<item>
<title>DNS&#45;AID lets AI agents find and verify each other through DNS</title>
<link>https://block385.com/dns-aid-lets-ai-agents-find-and-verify-each-other-through-dns</link>
<guid>https://block385.com/dns-aid-lets-ai-agents-find-and-verify-each-other-through-dns</guid>
<description><![CDATA[ AI agents run across many platforms, and each one needs a way to locate and confirm the identity of the others it works with. The Linux Foundation’s DNS-AID project gives them that capability through the Domain Name System, the same address lookup system that has directed internet traffic for decades. The project lets AI agents and Model Context Protocol (MCP) servers use DNS as a global, vendor-neutral directory for publishing, discovering, and verifying one another. … More →
The post DNS-AID lets AI agents find and verify each other through DNS appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/09/12093307/brain-ai-intelligence-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 11:30:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>DNS-AID, lets, agents, find, and, verify, each, other, through, DNS</media:keywords>
</item>

<item>
<title>NVIDIA goes open source with a big batch of physical AI agent tools</title>
<link>https://block385.com/nvidia-goes-open-source-with-a-big-batch-of-physical-ai-agent-tools</link>
<guid>https://block385.com/nvidia-goes-open-source-with-a-big-batch-of-physical-ai-agent-tools</guid>
<description><![CDATA[ NVIDIA just dropped a big batch of open-source “physical AI” skills and tools, and they’re designed to make a roboticist’s life a whole lot easier. The idea? Take the messy, complicated work behind robots, self-driving cars, vision AI, and industrial digital twins, and break it into bite-sized tasks that AI agents can actually run themselves. These skills ship as part of the NVIDIA Agent Toolkit, and here’s what makes them handy: they let AI agents … More →
The post NVIDIA goes open source with a big batch of physical AI agent tools appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/01104031/nvidia-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 11:30:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>NVIDIA, goes, open, source, with, big, batch, physical, agent, tools</media:keywords>
</item>

<item>
<title>Data discovery gaps that catch enterprises off guard</title>
<link>https://block385.com/data-discovery-gaps-that-catch-enterprises-off-guard</link>
<guid>https://block385.com/data-discovery-gaps-that-catch-enterprises-off-guard</guid>
<description><![CDATA[ In this interview with Help Net Security, Avani Desai, CEO at Schellman, talks about the gap between what organizations think they know about their data and what discovery scans turn up. She shares stories of shadow data in abandoned cloud storage, post-merger surprises where duplicated datasets slowed integration, and why synthetic data is overmarketed while confidential computing stays underappreciated. Desai also explains why smaller companies often beat large enterprises on compliance, and the one question … More →
The post Data discovery gaps that catch enterprises off guard appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/06/27165431/avani_desai-2-schellman.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 09:30:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Data, discovery, gaps, that, catch, enterprises, off, guard</media:keywords>
</item>

<item>
<title>145 AI laws passed in 2025 and privacy teams aren’t catching a break</title>
<link>https://block385.com/145-ai-laws-passed-in-2025-and-privacy-teams-arent-catching-a-break</link>
<guid>https://block385.com/145-ai-laws-passed-in-2025-and-privacy-teams-arent-catching-a-break</guid>
<description><![CDATA[ 145 AI-related laws were enacted by state legislatures in 2025, and more than 1,000 additional bills were introduced or revised, according to DataGrail’s Privacy and AI Trends Report 2026. Average cost of manual data subject request management (Source: DataGrail) Shadow AI risks Of the 2,400 popular business software providers that advertised AI capabilities, 63.6% did not disclose third-party AI subprocessors in their legal documentation, exposing businesses to shadow AI risks they may not be aware … More →
The post 145 AI laws passed in 2025 and privacy teams aren’t catching a break appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/10/08112913/privacy-eye-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 07:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>145, laws, passed, 2025, and, privacy, teams, aren’t, catching, break</media:keywords>
</item>

<item>
<title>Governing shadow AI without killing innovation</title>
<link>https://block385.com/governing-shadow-ai-without-killing-innovation</link>
<guid>https://block385.com/governing-shadow-ai-without-killing-innovation</guid>
<description><![CDATA[ In this Help Net Security video, Alan Snyder, CEO at NowSecure, talks about governing shadow AI without stopping innovation. He frames the problem as two opposing forces. Companies need to adopt AI fast because attackers and competitors will outpace them otherwise, but they also need to do it safely. Snyder argues the pressure to move quickly will win, so leaders must work hard to manage AI risk along the way. He references the first 8-K … More →
The post Governing shadow AI without killing innovation appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/10/31083710/shadow-ai.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 07:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Governing, shadow, without, killing, innovation</media:keywords>
</item>

<item>
<title>EU organizations buckle under rising compliance pressure</title>
<link>https://block385.com/eu-organizations-buckle-under-rising-compliance-pressure</link>
<guid>https://block385.com/eu-organizations-buckle-under-rising-compliance-pressure</guid>
<description><![CDATA[ Cybersecurity governance in the EU is shifting under expanding frameworks such as NIS2 and DORA, while AI raises new questions for security teams. What the future brings is hard to predict, and organizations must find a way to cope. Antonija Vojnović, Governance, Risk and Compliance Department Manager at Span, spoke with Help Net Security at the Span Cyber Security Arena conference about how these regulatory frameworks are shaping compliance priorities and day-to-day decision-making. Compliance overload … More →
The post EU organizations buckle under rising compliance pressure appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/29133117/antonija_vojnovic-2-span.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 07:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>organizations, buckle, under, rising, compliance, pressure</media:keywords>
</item>

<item>
<title>OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory</title>
<link>https://block385.com/owasp-agent-memory-guard-stop-ai-agents-from-being-weaponized-through-their-own-memory</link>
<guid>https://block385.com/owasp-agent-memory-guard-stop-ai-agents-from-being-weaponized-through-their-own-memory</guid>
<description><![CDATA[ AI agents keep memory across sessions. Conversation history, vector stores, scratchpads, and RAG indexes persist between runs, and anything written into that store becomes a privileged input the agent reads back later. An attacker who plants text in the wrong field can override an agent’s instructions, pull out user data, or steer future tool calls, and the effect survives across sessions because the memory does. Agent Memory Guard is an open-source runtime defense layer that … More →
The post OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/29103649/owasp-agent-memory-guard-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 01 Jun 2026 07:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>OWASP, Agent, Memory, Guard:, Stop, agents, from, being, weaponized, through, their, own, memory</media:keywords>
</item>

<item>
<title>Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices</title>
<link>https://block385.com/dutch-authorities-dismantle-botnet-linked-to-17-million-infected-devices</link>
<guid>https://block385.com/dutch-authorities-dismantle-botnet-linked-to-17-million-infected-devices</guid>
<description><![CDATA[ Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks.

The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), consisted of at least 17 million infected devices. More than 200 servers located in the Netherlands acted as the ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiU44Ejz__EFKfpIrEypTxhK3KW7XV3oiEIJEWAC-_PyhbhUvOZzmv3SCAmiuGZdFNdzYIDR2GLwOAhX9nIaAoOD4iFXucpEpB4Ym2vMAqvayyi1JkYyqj2uEYAXPGbXe5dzYNw5a__5KnXvrnJsEVtwnJJs6v_zBlfl3sKo0J83QwylgCL1A2Vck1HktJ8/s1600/botnet.png" length="49398" type="image/jpeg"/>
<pubDate>Sun, 31 May 2026 15:00:13 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Dutch, Authorities, Dismantle, Botnet, Linked, Million, Infected, Devices</media:keywords>
</item>

<item>
<title>Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw</title>
<link>https://block385.com/week-in-review-infostealer-dropped-via-forticlient-ems-flaw-exploited-trend-micro-apex-one-flaw</link>
<guid>https://block385.com/week-in-review-infostealer-dropped-via-forticlient-ems-flaw-exploited-trend-micro-apex-one-flaw</guid>
<description><![CDATA[ Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Coinflow CISO on crypto payments security under AI pressure Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs the company’s security program from Malta. Coinflow is headquartered in the United States and operates across multiple jurisdictions. Portelli sat … More →
The post Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2023/12/01112506/cybersecurity_week_in_review2.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sun, 31 May 2026 11:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Week, review:, Infostealer, dropped, via, FortiClient, EMS, flaw, exploited, Trend, Micro, Apex, One, flaw</media:keywords>
</item>

<item>
<title>PAN&#45;OS GlobalProtect Authentication Bypass (CVE&#45;2026&#45;0257) Under Active Exploitation</title>
<link>https://block385.com/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitation</link>
<guid>https://block385.com/pan-os-globalprotect-authentication-bypass-cve-2026-0257-under-active-exploitation</guid>
<description><![CDATA[ Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections.

&quot;Authentication bypass vulnerabilities in the ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkaW0i4ALAlpWQ_cOjfhoqUlNgMlZysJA6ay0qPViGI_KxEEG-Hh0KdtWLqBXDH42ZBGSONs0ZJuzOqdRF7vbx6Xa9J8HlP60lY45JHy0ivdRQs0exe4wZT2lI3TW4oDO-XXPVz2pek2M3izLqT3ONwq2iuHPN31ZZvK3jl0zIDq_h5XF1CTRk7fUPzjEQ/s1600/panos.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sat, 30 May 2026 11:00:11 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>PAN-OS, GlobalProtect, Authentication, Bypass, CVE-2026-0257, Under, Active, Exploitation</media:keywords>
</item>

<item>
<title>New Russia&#45;Linked GREYVIBE Targets Ukraine with AI&#45;Powered Cyberattacks</title>
<link>https://block385.com/new-russia-linked-greyvibe-targets-ukraine-with-ai-powered-cyberattacks</link>
<guid>https://block385.com/new-russia-linked-greyvibe-targets-ukraine-with-ai-powered-cyberattacks</guid>
<description><![CDATA[ A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025.

GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzJ8u1-LKZwf1FFeVF2K2D2pupLFnsW_zsTumbLXt6eRSNY5NYPuBVxyacqbH-WZRBmTpGmnB0pulEcGex16O8u6812DC7RjtV5fBtVmRG55MdKOdmX2B5m1AtcgfZLCGnH_wNVxrdpfvRR70-MjsT7fzuS8wasEGhnDKmavU02xE6HjMg6FLpv3dvSFi7/s1600/russia-ai-cyberattacks.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sat, 30 May 2026 09:00:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, Russia-Linked, GREYVIBE, Targets, Ukraine, with, AI-Powered, Cyberattacks</media:keywords>
</item>

<item>
<title>Name That Toon: Mark of (Cybersecurity) Progress</title>
<link>https://block385.com/name-that-toon-mark-of-cybersecurity-progress</link>
<guid>https://block385.com/name-that-toon-mark-of-cybersecurity-progress</guid>
<description><![CDATA[ As part of Dark Reading&#039;s 20th anniversary package, we asked readers for a cybersecurity-related caption that captures their thoughts about the industry&#039;s last two decades. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltcecddc9a9b77560b/6a19f878719ad34f2440c903/dr20-toon-may26-final.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 23:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Name, That, Toon:, Mark, Cybersecurity, Progress</media:keywords>
</item>

<item>
<title>ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface</title>
<link>https://block385.com/chatgphish-vulnerability-turns-chatgpt-web-summaries-into-a-phishing-surface</link>
<guid>https://block385.com/chatgphish-vulnerability-turns-chatgpt-web-summaries-into-a-phishing-surface</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant&#039;s implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks.

The technique has been codenamed ChatGPhish by Permiso Security.

&quot;The chatgpt.com response renderer trusts Markdown links and Markdown ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikkk-MbHPjc5UpAORUC9pUfe-LntIu7A2tsg3EBFPXh3b6WXoiv8HtxvSakdqICfwN1YGSY452zIdjuyafscYfbf7yKnzbE_SxWxmPeX9uBLkTWY7aNyzLK903ts83ThlQGKOPYKNCW6UHg2c7ia4O7cVIwV5p24c-POfHYTJak6tRmL03rbjOWxCfpPYb/s1600/chatgpt-phishing.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 20:30:11 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>ChatGPhish, Vulnerability, Turns, ChatGPT, Web, Summaries, Into, Phishing, Surface</media:keywords>
</item>

<item>
<title>As Global Powers Explore Humanoid Robots, Cyber&#45;Risk Looms</title>
<link>https://block385.com/as-global-powers-explore-humanoid-robots-cyber-risk-looms</link>
<guid>https://block385.com/as-global-powers-explore-humanoid-robots-cyber-risk-looms</guid>
<description><![CDATA[ The future of cybersecurity is germinating, as nation states vie for dominance in the embodied AI market and its supply chain. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltd919de1e6eb08bb9/6a18cae74c25b5264e1e240f/Terminator-Over_There_Pics-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 19:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Global, Powers, Explore, Humanoid, Robots, Cyber-Risk, Looms</media:keywords>
</item>

<item>
<title>Attackers Use LLM Agent for Post&#45;Exploitation After Marimo CVE&#45;2026&#45;39987 Exploit</title>
<link>https://block385.com/attackers-use-llm-agent-for-post-exploitation-after-marimo-cve-2026-39987-exploit</link>
<guid>https://block385.com/attackers-use-llm-agent-for-post-exploitation-after-marimo-cve-2026-39987-exploit</guid>
<description><![CDATA[ An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability.

&quot;The attacker compromised an internet-reachable Marimo notebook via CVE-2026-39987, extracted two cloud credentials from the compromised ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi20dgnD8cZh6NCcPM9Xa3fzLgNygU4O6AmBUmN1w6KwsDMJ8_jkpZPk77r8phf3MX-cXOlVxke-ypIuj2xh3AB3dy1HSuIa4YYFlgH8Odm1jCRVESBGqxgiDoRbQEG4L_QrKOoH8TSvLLKZxnBfPEemz4kaqWto4t_3cZCmWW44NX-Q1aWakBWVDhAza7T/s1600/marimo.png" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 18:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Attackers, Use, LLM, Agent, for, Post-Exploitation, After, Marimo, CVE-2026-39987, Exploit</media:keywords>
</item>

<item>
<title>Asia&amp;apos;s Cyber Insurance Market Shows Signs of Life</title>
<link>https://block385.com/asias-cyber-insurance-market-shows-signs-of-life</link>
<guid>https://block385.com/asias-cyber-insurance-market-shows-signs-of-life</guid>
<description><![CDATA[ The cyber insurance industry has made relatively weak inroads into Asia due to a a variety of factors, but that could be changing. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltb9e3fbe8c75eb597/6a19745b69143b73c43502c5/Blue_globe_Asia_Jimmie_Tolliver_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Asias, Cyber, Insurance, Market, Shows, Signs, Life</media:keywords>
</item>

<item>
<title>Dutch police disrupts botnet composed of 17 million devices</title>
<link>https://block385.com/dutch-police-disrupts-botnet-composed-of-17-million-devices</link>
<guid>https://block385.com/dutch-police-disrupts-botnet-composed-of-17-million-devices</guid>
<description><![CDATA[ The Dutch National Police and the country’s National Cyber Security Center (NCSC) have taken offline 200 servers controlling a botnet of 17 million devices, the law enforcement agency announced on Thursday. The investigation was launched after the NCSC received a report by a security researcher, and showed that the botnet consisted of at least 17 million infected devices – computers, mobile phones, IoT devices, routers, etc. – and that the 200 servers used to host … More →
The post Dutch police disrupts botnet composed of 17 million devices appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/06/10110030/botnet.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Dutch, police, disrupts, botnet, composed, million, devices</media:keywords>
</item>

<item>
<title>New infostealer reaches enterprise devices through FortiClient EMS vulnerability</title>
<link>https://block385.com/new-infostealer-reaches-enterprise-devices-through-forticlient-ems-vulnerability</link>
<guid>https://block385.com/new-infostealer-reaches-enterprise-devices-through-forticlient-ems-vulnerability</guid>
<description><![CDATA[ Attackers are delivering a broad-spectrum infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS). “The [malicious] payload was presented as a Fortinet endpoint update and executed through FortiClient-managed VPN scripting workflows,” Arctic Wold researchers noted. About CVE-2026-35616 CVE-2026-35616 is an improper access control vulnerability vulnerability in FortiClient EMS, a centralized management platform through which IT admins deploy, configure, and monitor FortiClient endpoint security software across all devices in … More →
The post New infostealer reaches enterprise devices through FortiClient EMS vulnerability appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/01/21163939/fortinet-computer-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 15:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, infostealer, reaches, enterprise, devices, through, FortiClient, EMS, vulnerability</media:keywords>
</item>

<item>
<title>With Complex Cloud Integrations, Small Errors Lead to Major Compromises</title>
<link>https://block385.com/with-complex-cloud-integrations-small-errors-lead-to-major-compromises</link>
<guid>https://block385.com/with-complex-cloud-integrations-small-errors-lead-to-major-compromises</guid>
<description><![CDATA[ Researchers discover an exploit chain combining over-permissioned roles, secrets discovery, and non-human identities that could have compromised a popular automation service. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt33ea1925a9f97ba7/6a18a8b047696a7d03d6ca07/rube-goldberg-machine-complexity-T_N_Sursock-shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 15:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>With, Complex, Cloud, Integrations, Small, Errors, Lead, Major, Compromises</media:keywords>
</item>

<item>
<title>&amp;apos;The Com&amp;apos; Cyberattacks Support Violence &amp;amp;amp; Sexploitation</title>
<link>https://block385.com/the-com-cyberattacks-support-violence-sexploitation</link>
<guid>https://block385.com/the-com-cyberattacks-support-violence-sexploitation</guid>
<description><![CDATA[ Your organization&#039;s security failures have consequences for everyone else too, since this neo-Nazi-infested criminal gang uses its cyber winnings to support more violent and widespread crimes. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltdf36383b6981cdfc/6a189af651a3babba50e026a/Hooded_crowd-John_Williams_RF-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 15:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, Com, Cyberattacks, Support, Violence, &amp;amp, Sexploitation</media:keywords>
</item>

<item>
<title>New Russian&#45;Linked GREYVIBE Targets Ukraine with AI&#45;Powered Cyberattacks</title>
<link>https://block385.com/new-russian-linked-greyvibe-targets-ukraine-with-ai-powered-cyberattacks</link>
<guid>https://block385.com/new-russian-linked-greyvibe-targets-ukraine-with-ai-powered-cyberattacks</guid>
<description><![CDATA[ A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025.

GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzJ8u1-LKZwf1FFeVF2K2D2pupLFnsW_zsTumbLXt6eRSNY5NYPuBVxyacqbH-WZRBmTpGmnB0pulEcGex16O8u6812DC7RjtV5fBtVmRG55MdKOdmX2B5m1AtcgfZLCGnH_wNVxrdpfvRR70-MjsT7fzuS8wasEGhnDKmavU02xE6HjMg6FLpv3dvSFi7/s1600/russia-ai-cyberattacks.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 14:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, Russian-Linked, GREYVIBE, Targets, Ukraine, with, AI-Powered, Cyberattacks</media:keywords>
</item>

<item>
<title>What 2,000 Exposed Vibe&#45;Coded Apps Reveal About the Limits of Most Security Stacks</title>
<link>https://block385.com/what-2000-exposed-vibe-coded-apps-reveal-about-the-limits-of-most-security-stacks</link>
<guid>https://block385.com/what-2000-exposed-vibe-coded-apps-reveal-about-the-limits-of-most-security-stacks</guid>
<description><![CDATA[ Shadow AI used to mean employees pasting things they shouldn&#039;t into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or IT in the loop.

The artifact moved from a prompt to a product. The risk surface moved with it.

In The Shadow Builders report (get it here), a ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9_WTd_LhWXwvu2jTcVVVgE_IpLISA8vfn0awG8fVwVv_vxx1LvLU7XOxFCtSLMbiP6JKPQfFMdpA7cRJy0Phlu-RWtKH8m57ZMUwRI-tz0C-cAiASKIFS2Fytms6DnCCEif9l-CYN0drhFUEbrt71isM3LmzuA8Guqmhn6iiRqrTROcX-9tniNTQsglc/s1600/red.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 14:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>What, 2, 000, Exposed, Vibe-Coded, Apps, Reveal, About, the, Limits, Most, Security, Stacks</media:keywords>
</item>

<item>
<title>Microsoft 365 Copilot redesign brings context and actions into one workspace</title>
<link>https://block385.com/microsoft-365-copilot-redesign-brings-context-and-actions-into-one-workspace</link>
<guid>https://block385.com/microsoft-365-copilot-redesign-brings-context-and-actions-into-one-workspace</guid>
<description><![CDATA[ Microsoft 365 Copilot, an AI assistant that helps people write, summarize, analyze information, and complete work tasks, has been redesigned. It now serves as a single, flexible entry point to Copilot across Microsoft 365 apps, suggesting relevant actions based on the user’s work. A redesigned interface built around user intent Microsoft applied the design principle of progressive disclosure, allowing users to start with a focused interface that reveals additional capabilities as needed. The left side … More →
The post Microsoft 365 Copilot redesign brings context and actions into one workspace appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/29110716/copilot-1.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 13:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, 365, Copilot, redesign, brings, context, and, actions, into, one, workspace</media:keywords>
</item>

<item>
<title>LinkedIn&#45;themed phishing abuses Adobe’s A/B testing platform</title>
<link>https://block385.com/linkedin-themed-phishing-abuses-adobes-ab-testing-platform</link>
<guid>https://block385.com/linkedin-themed-phishing-abuses-adobes-ab-testing-platform</guid>
<description><![CDATA[ A newly documented phishing campaign is targeting professionals with fake LinkedIn business emails and abusing a trusted service operated by Adobe. The attack from the victim’s perspective The attack starts with an email that looks, at first glance, like a routine business inquiry: someone wants to do business with you through LinkedIn and has attached a signed contract for your review. The phishing email (Source: Malwarebytes) The message is short and professional and the sender … More →
The post LinkedIn-themed phishing abuses Adobe’s A/B testing platform appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/05094658/linkedin-red-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 13:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>LinkedIn-themed, phishing, abuses, Adobe’s, AB, testing, platform</media:keywords>
</item>

<item>
<title>Websites can spy on user activity by analyzing SSD behavior</title>
<link>https://block385.com/websites-can-spy-on-user-activity-by-analyzing-ssd-behavior</link>
<guid>https://block385.com/websites-can-spy-on-user-activity-by-analyzing-ssd-behavior</guid>
<description><![CDATA[ Websites have spent years collecting information about visitors through browser fingerprinting, tracking scripts, and other techniques designed to identify devices and monitor behavior. Researchers have demonstrated another method that relies on something most users would never expect a website to observe: activity on their SSD (Solid-State Drive), the storage device where applications and files are stored. Dubbed FROST, short for Fingerprinting Remotely using OPFS-based SSD Timing, the technique allows a website to infer information about … More →
The post Websites can spy on user activity by analyzing SSD behavior appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/12/14144300/eye-privacy-internet-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 13:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Websites, can, spy, user, activity, analyzing, SSD, behavior</media:keywords>
</item>

<item>
<title>Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets</title>
<link>https://block385.com/malicious-sicoob-nuget-steals-banking-credentials-as-npm-packages-target-cloud-secrets</link>
<guid>https://block385.com/malicious-sicoob-nuget-steals-banking-credentials-as-npm-packages-target-cloud-secrets</guid>
<description><![CDATA[ Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil&#039;s largest cooperative financial systems, to siphon client IDs and PFX certificates.

According to Socket, versions 2.0.0 through 2.0.4 of &quot;Sicoob.Sdk&quot; contain functionality to exfiltrate sensitive information, including PFX certificates that are used to ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUbmZyAOVZRXrWddG8PMuXbVyex9s5HPD2cH8rDjYP6EHuVadkyj72NdN9PreAnGX9iOCVGxWI2YmSLu818VmdLGEcPkb60qPIUgBYh5oBHsA4KKYufsHbFGhAQDD7SjpZU0In0TPiHN4TxCR4THBwmKa4Bus98vBgx5mO3QTQRpTM5RERk8bFWi4psF7d/s1600/sdk.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 12:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Malicious, Sicoob, NuGet, Steals, Banking, Credentials, npm, Packages, Target, Cloud, Secrets</media:keywords>
</item>

<item>
<title>Humanix expands detection to identify live violations of security procedures</title>
<link>https://block385.com/humanix-expands-detection-to-identify-live-violations-of-security-procedures</link>
<guid>https://block385.com/humanix-expands-detection-to-identify-live-violations-of-security-procedures</guid>
<description><![CDATA[ Humanix has announced a capability to identify live violations of organization-defined procedures governing IT support workflows. Designed to prevent unauthorized access, these procedures typically require help desk and service desk agents to follow identity verification steps before fulfilling sensitive requests, such as credential resets. Attackers have learned that pressuring agents to bypass these safeguards is among the fastest paths to a breach. “People staffing help desks and service desks are placed in an impossible position. … More →
The post Humanix expands detection to identify live violations of security procedures appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 11:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Humanix, expands, detection, identify, live, violations, security, procedures</media:keywords>
</item>

<item>
<title>Netskope extends data localization capabilities with NewEdge updates</title>
<link>https://block385.com/netskope-extends-data-localization-capabilities-with-newedge-updates</link>
<guid>https://block385.com/netskope-extends-data-localization-capabilities-with-newedge-updates</guid>
<description><![CDATA[ Netskope has enhanced its NewEdge Network infrastructure, expanding data sovereignty capabilities to more regions than any other SASE cloud provider. The NewEdge Network architecture provides national data localization features that address requirements for network transport, data processing, and metadata governance in major regions worldwide, while enabling Netskope to extend this coverage to additional countries. The solution will also offer third-party validation to help customers meet compliance and data localization requirements. A comprehensive approach to data … More →
The post Netskope extends data localization capabilities with NewEdge updates appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 11:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Netskope, extends, data, localization, capabilities, with, NewEdge, updates</media:keywords>
</item>

<item>
<title>Claroty targets cyber&#45;physical system risks with AI&#45;powered security agent</title>
<link>https://block385.com/claroty-targets-cyber-physical-system-risks-with-ai-powered-security-agent</link>
<guid>https://block385.com/claroty-targets-cyber-physical-system-risks-with-ai-powered-security-agent</guid>
<description><![CDATA[ Claroty has launched Claroty Claire, a CPS-native AI security agent designed to help organizations defend mission-critical infrastructure. Claire is powered by a CPS language model trained on more than a decade of industry expertise and CPS-related data. The launch expands organizations’ capabilities for supporting the safety, uptime, and availability of cyber-physical systems. Defending a rapidly expanding attack surface from supercharged threats The rate at which AI is expanding the CPS attack surface requires proactive steps … More →
The post Claroty targets cyber-physical system risks with AI-powered security agent appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 11:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Claroty, targets, cyber-physical, system, risks, with, AI-powered, security, agent</media:keywords>
</item>

<item>
<title>Anthropic launches Claude Opus 4.8, prepares Mythos&#45;class models for all customers</title>
<link>https://block385.com/anthropic-launches-claude-opus-48-prepares-mythos-class-models-for-all-customers</link>
<guid>https://block385.com/anthropic-launches-claude-opus-48-prepares-mythos-class-models-for-all-customers</guid>
<description><![CDATA[ Anthropic has released Claude Opus 4.8 and outlined plans for broader access to its Mythos-class models, which the company expects to make available to all customers in the coming weeks. Claude Opus 4.8 (Source: Anthropic) Claude Opus 4.8 is available to all users, with pricing unchanged from Opus 4.7. Anthropic highlighted improvements in model honesty, noting that Opus 4.8 is more likely to acknowledge when it lacks sufficient information and less likely to make unsupported … More →
The post Anthropic launches Claude Opus 4.8, prepares Mythos-class models for all customers appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/27125835/claude-vortex.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 11:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Anthropic, launches, Claude, Opus, 4.8, prepares, Mythos-class, models, for, all, customers</media:keywords>
</item>

<item>
<title>Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels</title>
<link>https://block385.com/kimsuky-deploys-httpspy-expands-arsenal-with-hellodoor-and-vs-code-tunnels</link>
<guid>https://block385.com/kimsuky-deploys-httpspy-expands-arsenal-with-hellodoor-and-vs-code-tunnels</guid>
<description><![CDATA[ The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026.

&quot;Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex meeting page that leveraged ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJfUl1K-os1XyLN-SBt6PgMia_jFG03ArRa3H0FI2hsiUqNa3lqSWY2NJcvOhY33TArSKJxeookUpkATdERUpEwKw-IUi6iv9ZVuUq4c1A99mLwgQB4ibCxBx4MBR1XXmM98zH7v-QWDO7bhh1AONQ8Op0htvwHhuivwI1Cch9rgLPO-zSGCjjQbvXdDte/s1600/north-korea.png" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 10:30:11 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Kimsuky, Deploys, HTTPSpy, Expands, Arsenal, with, HelloDoor, and, Code, Tunnels</media:keywords>
</item>

<item>
<title>Product showcase: TotalAV helps iOS users clean up their digital mess</title>
<link>https://block385.com/product-showcase-totalav-helps-ios-users-clean-up-their-digital-mess</link>
<guid>https://block385.com/product-showcase-totalav-helps-ios-users-clean-up-their-digital-mess</guid>
<description><![CDATA[ TotalAV Mobile Security helps protect devices from malicious websites, SMS scams, unsafe public Wi-Fi networks, and exposed credentials. The app is available for Windows, Android, macOS, and iOS devices. After downloading the app from the App Store, users provide an email address, select what they want to scan, and start a Smart Scan. The scan reviews device settings, browser protections, breach exposure, and other security-related areas before presenting a summary of the device’s status. The … More →
The post Product showcase: TotalAV helps iOS users clean up their digital mess appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/28120402/totalav.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 09:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Product, showcase:, TotalAV, helps, iOS, users, clean, their, digital, mess</media:keywords>
</item>

<item>
<title>The behavioral signals that sharpen Trojan malware detection</title>
<link>https://block385.com/the-behavioral-signals-that-sharpen-trojan-malware-detection</link>
<guid>https://block385.com/the-behavioral-signals-that-sharpen-trojan-malware-detection</guid>
<description><![CDATA[ Malware analysts spend a lot of time deciding which signals from a sandbox run are worth keeping. A sample executed in a controlled environment can generate hundreds of measurable attributes covering file structure, registry edits, process behavior, and network traffic. Most of those attributes add noise. A recent study works through this problem in detail, and the part that earns attention from working defenders is the feature selection, not the deep learning model attached to … More →
The post The behavioral signals that sharpen Trojan malware detection appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/28105926/trojan-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, behavioral, signals, that, sharpen, Trojan, malware, detection</media:keywords>
</item>

<item>
<title>New infosec products of the month: May 2026</title>
<link>https://block385.com/new-infosec-products-of-the-month-may-2026</link>
<guid>https://block385.com/new-infosec-products-of-the-month-may-2026</guid>
<description><![CDATA[ Here’s a look at the most interesting products from the past month, featuring releases from Alation, AppOmni, Apricorn, ASAPP, Babel Street, Checksum, Cogent, CTERA, Forward, LastPass, Operant AI, Riverbed, Sysdig, Trust3 AI, TrustCloud, VIAVI, Versa Networks, and XM Cyber. Operant AI Endpoint Protector secures AI agents and MCP tools Operant AI has launched Operant Endpoint Protector, a new addition to its AI Defense Platform that enables enterprise IT and security teams to discover, detect, and … More →
The post New infosec products of the month: May 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/28092100/infosec-month-1200.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, infosec, products, the, month:, May, 2026</media:keywords>
</item>

<item>
<title>Building a risk&#45;based vulnerability management program that scales</title>
<link>https://block385.com/building-a-risk-based-vulnerability-management-program-that-scales</link>
<guid>https://block385.com/building-a-risk-based-vulnerability-management-program-that-scales</guid>
<description><![CDATA[ In this Help Net Security video, Shankar Somasundaram, CEO at Asimily, explains how to build a risk-based vulnerability program. He notes that vulnerabilities are exploding by an order of magnitude in the age of AI-driven attacks, with one customer finding a thousand vulnerabilities for every one they knew about. Patching everything is not workable, and relying on CVSS scores fails because two-thirds of published CVEs are marked high risk. Shankar walks through a better approach. … More →
The post Building a risk-based vulnerability management program that scales appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/27143607/magnify-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 29 May 2026 07:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Building, risk-based, vulnerability, management, program, that, scales</media:keywords>
</item>

<item>
<title>Name That Toon Contest</title>
<link>https://block385.com/name-that-toon-contest</link>
<guid>https://block385.com/name-that-toon-contest</guid>
<description><![CDATA[  ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt638feb7893167b94/6a186a557f1d278d580dc037/Remove_InformationWeek_Logo_from_Header_(1).png" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 23:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Name, That, Toon, Contest</media:keywords>
</item>

<item>
<title>Dutch Raid Fails to Dent Russian Bulletproof Host</title>
<link>https://block385.com/dutch-raid-fails-to-dent-russian-bulletproof-host</link>
<guid>https://block385.com/dutch-raid-fails-to-dent-russian-bulletproof-host</guid>
<description><![CDATA[ Dutch law enforcement seized 800 servers and arrested two operators of THE.Hosting but left the hosting provider&#039;s core IP address space intact. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt75939e9e57fa1b91/6a1777b27e488fa22d7404ec/bulletproof_Viktollio_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 23:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Dutch, Raid, Fails, Dent, Russian, Bulletproof, Host</media:keywords>
</item>

<item>
<title>Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code</title>
<link>https://block385.com/critical-gogs-rce-vulnerability-lets-any-authenticated-user-execute-arbitrary-code</link>
<guid>https://block385.com/critical-gogs-rce-vulnerability-lets-any-authenticated-user-execute-arbitrary-code</guid>
<description><![CDATA[ A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions.

The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifier.

&quot;The vulnerability allows any authenticated user to achieve remote code execution (RCE) on ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaqRd_3DDSSASg_YzvuUEqv3elhvFWSjk56bXPoqJeNIWVo-K0giuJ3TNEXV-aYpnuVfOv00_VM428vIFVaMiuZzfL0dQdQvz0_xMNFq4CtrppgTZu5dupV0asq1wZjPW3FoMgUnyGMR_RgBpWT2oTnJFuhaldo3Cd3eNP-MOlDNhP9Uu2KDRiDpYHdoeq/s1600/exploit-meta.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Critical, Gogs, RCE, Vulnerability, Lets, Any, Authenticated, User, Execute, Arbitrary, Code</media:keywords>
</item>

<item>
<title>[An RX Global Event] Infosecurity Europe</title>
<link>https://block385.com/an-rx-global-event-infosecurity-europe</link>
<guid>https://block385.com/an-rx-global-event-infosecurity-europe</guid>
<description><![CDATA[  ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blta212ce7bfdb601e7/6a0dbacd3c21f6a4c08ba686/Infosecurity_Europe_2026.png" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>An, Global, Event, Infosecurity, Europe</media:keywords>
</item>

<item>
<title>Agentic AI Isn&amp;apos;t Risky; the Way Orgs Deploy It Is</title>
<link>https://block385.com/agentic-ai-isnt-risky-the-way-orgs-deploy-it-is</link>
<guid>https://block385.com/agentic-ai-isnt-risky-the-way-orgs-deploy-it-is</guid>
<description><![CDATA[ AI agents aren&#039;t black boxes — they&#039;re models interacting with software tools. The risk lies in their overlap. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt0dbefeb02aa6a89d/6a184e146efe0009ef849df5/Black_box-Rawf8-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Agentic, Isnt, Risky, the, Way, Orgs, Deploy</media:keywords>
</item>

<item>
<title>BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model</title>
<link>https://block385.com/btmob-rat-spreads-across-brazil-latam-via-maas-model</link>
<guid>https://block385.com/btmob-rat-spreads-across-brazil-latam-via-maas-model</guid>
<description><![CDATA[ An advanced remote access Trojan is propagating online. Notably, it&#039;s delivered via an operator licensing model and features a no-code malware-development interface. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt50056046e2acf85d/6a1805a808b87d2f6a04c317/androidmalware_rafapress_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>BTMOB, RAT, Spreads, Across, Brazil, LatAm, via, MaaS, Model</media:keywords>
</item>

<item>
<title>Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer</title>
<link>https://block385.com/threat-actors-exploit-critical-forticlient-ems-flaw-to-deploy-credential-stealer</link>
<guid>https://block385.com/threat-actors-exploit-critical-forticlient-ems-flaw-to-deploy-credential-stealer</guid>
<description><![CDATA[ Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware.

&quot;The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints,&quot; Arctic Wolf said. &quot;Threat actors disguised the credential stealer payload as a Fortinet endpoint ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLo8Mb8UwcN2lkMlnUi-l3a8DXNNL2_dW0VcATt8d34xxXX-kQN8HMolrIuw8ty0WZmpURI7hyphenhyphenDrvCAiKAarvJU1__tzxaKMxX3U4ZJbuwydE2zGoyFmutxDtid410NLBq_wi7fv_QFMdmkHGqRPwVcLY8xfeJ1PSb46o0RpCA4ubLLl8_LlLg-Id7ceU8/s1600/fort.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 18:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Threat, Actors, Exploit, Critical, FortiClient, EMS, Flaw, Deploy, Credential, Stealer</media:keywords>
</item>

<item>
<title>Zapier exploit chain shows how known anti&#45;patterns compose into critical risk</title>
<link>https://block385.com/zapier-exploit-chain-shows-how-known-anti-patterns-compose-into-critical-risk</link>
<guid>https://block385.com/zapier-exploit-chain-shows-how-known-anti-patterns-compose-into-critical-risk</guid>
<description><![CDATA[ A five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier’s public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in the chain was a known anti-pattern. The composition across five systems was the finding. Zapier triaged the report within four days of submission on February 12, 2026, revoked the leaked NPM token, and tightened the underlying AWS role … More →
The post Zapier exploit chain shows how known anti-patterns compose into critical risk appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/22171738/zepier-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 17:00:13 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Zapier, exploit, chain, shows, how, known, anti-patterns, compose, into, critical, risk</media:keywords>
</item>

<item>
<title>Microsoft’s Copilot trust test: Zero findings, more models, wider oversight</title>
<link>https://block385.com/microsofts-copilot-trust-test-zero-findings-more-models-wider-oversight</link>
<guid>https://block385.com/microsofts-copilot-trust-test-zero-findings-more-models-wider-oversight</guid>
<description><![CDATA[ Microsoft 365 Copilot and Copilot Chat (Copilot) have been recertified under ISO/IEC 42001:2023 by an independent auditor for the second consecutive year. Copilot first received ISO 42001 certification in March 2025. This year’s recertification recorded zero non-conformities and zero improvement observations, resulting in a second audit in a row. The certification evaluates the AI management system in areas including governance, risk assessment, data management, transparency, human oversight, and supplier management. Microsoft 365 Copilot is an … More →
The post Microsoft’s Copilot trust test: Zero findings, more models, wider oversight appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/06/07135928/varonis-copilot-365.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 17:00:12 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft’s, Copilot, trust, test:, Zero, findings, more, models, wider, oversight</media:keywords>
</item>

<item>
<title>Cybercriminals sail away with data from 6 million Carnival customers</title>
<link>https://block385.com/cybercriminals-sail-away-with-data-from-6-million-carnival-customers</link>
<guid>https://block385.com/cybercriminals-sail-away-with-data-from-6-million-carnival-customers</guid>
<description><![CDATA[ Carnival Corporation, one of the world’s largest cruise operators, confirmed a data breach weeks after the ShinyHunters hacking group claimed it had stolen millions of customer records. Carnival acknowledged a phishing incident involving a single employee account and stated that it was investigating the scope of the unauthorized activity. “On April 14, 2026, the company’s IT security team identified unauthorized activity involving an employee’s account. An unauthorized actor used social engineering to deceive an employee … More →
The post Cybercriminals sail away with data from 6 million Carnival customers appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/28101246/data-breach-red.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 17:00:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cybercriminals, sail, away, with, data, from, million, Carnival, customers</media:keywords>
</item>

<item>
<title>Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security</title>
<link>https://block385.com/focus-on-cyber-insurance-how-quantifying-risk-is-reshaping-security</link>
<guid>https://block385.com/focus-on-cyber-insurance-how-quantifying-risk-is-reshaping-security</guid>
<description><![CDATA[ In this latest installment of the Reporters&#039; Notebook video series, we discuss how cyber insurance is forcing organizations to quantify risk, what&#039;s covered (and what&#039;s not), and why this could be the best thing to happen to cybersecurity. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltf9514fbeb5a1fa18/6a168d897e488f337374002f/insuranceload-Bordeianu_Andrei-alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 17:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Focus, Cyber, Insurance:, How, Quantifying, Risk, Reshaping, Security</media:keywords>
</item>

<item>
<title>IBM and Red Hat are betting $5 billion that open source needs a security guard</title>
<link>https://block385.com/ibm-and-red-hat-are-betting-5-billion-that-open-source-needs-a-security-guard</link>
<guid>https://block385.com/ibm-and-red-hat-are-betting-5-billion-that-open-source-needs-a-security-guard</guid>
<description><![CDATA[ IBM and Red Hat announced Project Lightwell, a $5 billion commitment backed by new frontier AI capabilities and a global force of more than 20,000 engineers to help enterprises secure open source software. Together, these investments establish a new model for enterprise use of open source software, from upstream development through production environments. Project Lightwell will establish a trusted enterprise clearinghouse combined with a global force of engineers to identify and fix vulnerabilities at scale. … More →
The post IBM and Red Hat are betting $5 billion that open source needs a security guard appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/10/02183423/redhat-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 17:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>IBM, and, Red, Hat, are, betting, billion, that, open, source, needs, security, guard</media:keywords>
</item>

<item>
<title>Microsoft Slams Public Zero&#45;Day Disclosures Amid GitHub Researcher Account Removal</title>
<link>https://block385.com/microsoft-slams-public-zero-day-disclosures-amid-github-researcher-account-removal</link>
<guid>https://block385.com/microsoft-slams-public-zero-day-disclosures-amid-github-researcher-account-removal</guid>
<description><![CDATA[ Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed.

The development comes after a researcher named Chaotic Eclipse (aka Nightmare-Eclipse) disclosed details of multiple zero-day ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhIMDR_KVt17sFMXeEhMvDYHLwBX_Aix1bz3y0izMs7PsVIuGSQhOLX_khN3Ckl_eRm9OEMAlVmBxPHhQvCGDJB5wXJ2rtOT8uQAiWCWCZwc7dvOfbWyuZ0BpNFAKohIpLUq9KR76XvZ3eT0TpltWDHUWQY-nUJzJflA1y5l7q_UXsjVtAMPhwVAULZZScp/s1600/github-ms.png" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 16:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Slams, Public, Zero-Day, Disclosures, Amid, GitHub, Researcher, Account, Removal</media:keywords>
</item>

<item>
<title>ThreatsDay Bulletin: Claude Security Plugin, Azure Priv&#45;Esc, Kali365 MFA Bypass, FIFA Scams +15 More</title>
<link>https://block385.com/threatsday-bulletin-claude-security-plugin-azure-priv-esc-kali365-mfa-bypass-fifa-scams-15-more</link>
<guid>https://block385.com/threatsday-bulletin-claude-security-plugin-azure-priv-esc-kali365-mfa-bypass-fifa-scams-15-more</guid>
<description><![CDATA[ Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now - meanwhile some researcher casually drops a technique that turns a &quot;minor&quot; foothold into total account ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBnLTRREuP8t8AoMRlakMDVRNoOYCA18IuBTWxA_nms12GdQaSfaU1kgpLSrgUvFFH1goJ_-NOIerDAnZxlD86Oafg_b6QdecLrT4UJdb3_qfmgtxdjrhF8GioeuEZbyZBTVL4cXUcpWqZujpLoI4zBm9y7XvFUjYR5cjF0GmmU_TXlmX0W7zsxlcvV9mW/s1600/tbb.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 16:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>ThreatsDay, Bulletin:, Claude, Security, Plugin, Azure, Priv-Esc, Kali365, MFA, Bypass, FIFA, Scams, 15, More</media:keywords>
</item>

<item>
<title>Qevlar’s new AI agents correlate CVEs, incident data, and active exploitation signals</title>
<link>https://block385.com/qevlars-new-ai-agents-correlate-cves-incident-data-and-active-exploitation-signals</link>
<guid>https://block385.com/qevlars-new-ai-agents-correlate-cves-incident-data-and-active-exploitation-signals</guid>
<description><![CDATA[ Qevlar has announced a new set of AI agents designed to bridge the disconnect between Security Operations Centers (SOCs) and vulnerability management teams. The new capabilities help security teams correlate CVEs with live incident data for real-time risk prioritization, automatically identify asset owners to speed remediation, and autonomously hunt for active CVE exploitation. General availability is scheduled for Fall 2026. Finding and exploiting zero-day vulnerabilities has never been faster or easier than in 2026. According … More →
The post Qevlar’s new AI agents correlate CVEs, incident data, and active exploitation signals appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 15:00:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Qevlar’s, new, agents, correlate, CVEs, incident, data, and, active, exploitation, signals</media:keywords>
</item>

<item>
<title>Qumulo NeuralProtect uses AI to detect and stop ransomware before encryption</title>
<link>https://block385.com/qumulo-neuralprotect-uses-ai-to-detect-and-stop-ransomware-before-encryption</link>
<guid>https://block385.com/qumulo-neuralprotect-uses-ai-to-detect-and-stop-ransomware-before-encryption</guid>
<description><![CDATA[ Qumulo has unveiled Qumulo NeuralProtect, a ransomware resilience solution built to protect data at the storage layer by detecting and stopping threats before data is encrypted, corrupted, or lost. Integrated directly into the Qumulo Data Platform, NeuralProtect inspects every file at the precise point-of-write using a series of AI-driven analysis models to detect both known and zero-day threats, instantly isolating malicious activity and enabling rapid recovery. NeuralProtect shifts ransomware protection from reactive recovery to proactive … More →
The post Qumulo NeuralProtect uses AI to detect and stop ransomware before encryption appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 15:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Qumulo, NeuralProtect, uses, detect, and, stop, ransomware, before, encryption</media:keywords>
</item>

<item>
<title>Digimarc adds provenance, audit, and verification controls for AI agent workflows</title>
<link>https://block385.com/digimarc-adds-provenance-audit-and-verification-controls-for-ai-agent-workflows</link>
<guid>https://block385.com/digimarc-adds-provenance-audit-and-verification-controls-for-ai-agent-workflows</guid>
<description><![CDATA[ Digimarc has announced new provenance and verification infrastructure designed to secure autonomous and AI-enabled workflows. As enterprises increasingly adopt AI systems capable of generating content, orchestrating workflows, and taking action with minimal human intervention, establishing trusted provenance and verifiable authenticity is becoming mission critical. Digimarc’s new capabilities are designed to help organizations determine whether digital content and artifacts produced or consumed by autonomous AI agents can be trusted before downstream action occurs. The OWASP Top … More →
The post Digimarc adds provenance, audit, and verification controls for AI agent workflows appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 15:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Digimarc, adds, provenance, audit, and, verification, controls, for, agent, workflows</media:keywords>
</item>

<item>
<title>OpenAI prepares ChatGPT for the election misinformation wave</title>
<link>https://block385.com/openai-prepares-chatgpt-for-the-election-misinformation-wave</link>
<guid>https://block385.com/openai-prepares-chatgpt-for-the-election-misinformation-wave</guid>
<description><![CDATA[ AI-generated election misinformation could shape public opinion and influence the lives of millions of people. To address those risks, OpenAI outlined a series of safeguards ahead of the 2026 election cycle. The company said its efforts will focus on helping users access voting information, supporting cybersecurity defenders, and improving transparency around AI-generated content. “People already use ChatGPT to ask practical questions in their preferred languages about civic events: how to register, where to vote, what … More →
The post OpenAI prepares ChatGPT for the election misinformation wave appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/09/09074651/deepfake_geopolitics-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 15:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>OpenAI, prepares, ChatGPT, for, the, election, misinformation, wave</media:keywords>
</item>

<item>
<title>New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI &amp;quot;Power users&amp;quot;</title>
<link>https://block385.com/new-ai-usage-report-enterprise-ai-risk-is-heavily-concentrated-among-a-small-group-of-ai-power-users</link>
<guid>https://block385.com/new-ai-usage-report-enterprise-ai-risk-is-heavily-concentrated-among-a-small-group-of-ai-power-users</guid>
<description><![CDATA[ State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don&#039;t understand where their AI exposure is actually coming from. The research shows that enterprise AI risk is not distributed evenly across users or platforms. Instead, it is heavily concentrated among a small group of AI power users and a ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXxB1vzDMiskZRwzcQojV8rDdalRXWpzXieLES5nUD0bXfnbXrUwsV00RsMmRFdd-Zd3up_9wAGsvfzTDmWi4MLp70XlajlgakXsuCfdWmOe0uQuy0yIwxC4-fevqlb0Rs3AR_eqInGT1scQfa5oiGqY-TRmswOwkY4Zg2ikCYxlsBF2FQTEGA216b_NF8/s1600/apples.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 14:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, Usage, Report:, Enterprise, Risk, Heavily, Concentrated, Among, Small, Group, Power, users</media:keywords>
</item>

<item>
<title>Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaigns</title>
<link>https://block385.com/oil-shipments-drone-makers-and-a-poisoned-code-library-targeted-in-recent-apt-campaigns</link>
<guid>https://block385.com/oil-shipments-drone-makers-and-a-poisoned-code-library-targeted-in-recent-apt-campaigns</guid>
<description><![CDATA[ Geopolitical pressure drove much of the state-sponsored cyber activity recorded between October 2025 and March 2026, according to ESET’s latest APT Activity Report. Espionage groups aligned with China, North Korea, Russia, and Iran adjusted their targets to match the economic and security concerns of their governments. Attack sources (Source: ESET) “In Asia, the campaigns primarily focused on governmental organizations, strategic industries, and advanced technology sectors. In the Middle East, Israel remained the principal focus of … More →
The post Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaigns appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/28073755/chess-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 13:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Oil, shipments, drone, makers, and, poisoned, code, library, targeted, recent, APT, campaigns</media:keywords>
</item>

<item>
<title>A single typo could derail your World Cup plans</title>
<link>https://block385.com/a-single-typo-could-derail-your-world-cup-plans</link>
<guid>https://block385.com/a-single-typo-could-derail-your-world-cup-plans</guid>
<description><![CDATA[ Cybercriminals are spoofing Fédération Internationale de Football Association (FIFA) websites ahead of the 2026 FIFA World Cup, the FBI warns. The attackers are registering lookalike domains with small spelling changes or different domain endings to impersonate FIFA websites and services. The tactic, known as typosquatting, relies on users making small typing mistakes when entering website addresses. People who land on the fake sites may hand over names, addresses, phone numbers, email addresses, banking details, or … More →
The post A single typo could derail your World Cup plans appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/28100914/fifa_2026.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 13:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>single, typo, could, derail, your, World, Cup, plans</media:keywords>
</item>

<item>
<title>Microsoft’s new cloud PCs place AI agents under enterprise controls</title>
<link>https://block385.com/microsofts-new-cloud-pcs-place-ai-agents-under-enterprise-controls</link>
<guid>https://block385.com/microsofts-new-cloud-pcs-place-ai-agents-under-enterprise-controls</guid>
<description><![CDATA[ Microsoft’s Windows 365 for Agents, a cloud PC platform for agentic workloads, runs AI agents in secure environments. Organizations can direct agents with natural language to interact with applications, browsers, files, and enterprise systems. The platform is available in public preview. A conceptual computer-using agent architecture. (Source: Microsoft) Users will be able to automate workflows that rely on applications and systems without APIs, including legacy and UI-based environments, without giving up enterprise security or control. … More →
The post Microsoft’s new cloud PCs place AI agents under enterprise controls appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/02/11132343/windows-1500-1.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 13:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft’s, new, cloud, PCs, place, agents, under, enterprise, controls</media:keywords>
</item>

<item>
<title>JINX&#45;0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware</title>
<link>https://block385.com/jinx-0164-targets-cryptocurrency-firms-with-fake-recruiter-lures-and-macos-malware</link>
<guid>https://block385.com/jinx-0164-targets-cryptocurrency-firms-with-fake-recruiter-lures-and-macos-malware</guid>
<description><![CDATA[ A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft using recruitment-themed social engineering and bespoke macOS malware.

&quot;These campaigns leveraged sophisticated social engineering techniques, custom macOS malware, and deep targeting of CI/CD infrastructure,&quot; Wiz researchers Shira Ayal, ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyRUE7TEns58pfRrpwegQH6tBvGORrdclhPKKI7B7l9eNy5bMA1_ra6HAyGPUC_NKD8ZTnpVt7z88AII1Sd8QpA-sqZ7ONKZGwEVFB0u8gNvsBVRtfJuTsvWM4q6V_9MXVj7fX4ug_7mel-x1i2l7qm1GY94gVA1AbyCrvRQA8JcaDmhF1i_tM22NF_RPX/s1600/crypto-hacks.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 12:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>JINX-0164, Targets, Cryptocurrency, Firms, with, Fake, Recruiter, Lures, and, macOS, Malware</media:keywords>
</item>

<item>
<title>Police arrest suspect in Ajax football club hack that exposed 300,000 fan records</title>
<link>https://block385.com/police-arrest-suspect-in-ajax-football-club-hack-that-exposed-300000-fan-records</link>
<guid>https://block385.com/police-arrest-suspect-in-ajax-football-club-hack-that-exposed-300000-fan-records</guid>
<description><![CDATA[ The Dutch National Police arrested a man suspected of hacking into the computer systems of AFC Ajax, a football club from Amsterdam. “On the morning of Tuesday, May 26, detectives arrested a 35-year-old man from the municipality of Buren for computer intrusion at the Amsterdam football club Ajax. The man is suspected of intentionally and unlawfully entering Ajax’s computer systems multiple times ,” the police said. The investigation began after AFC Ajax discovered unauthorized access … More →
The post Police arrest suspect in Ajax football club hack that exposed 300,000 fan records appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/01/20132222/arrest-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 11:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Police, arrest, suspect, Ajax, football, club, hack, that, exposed, 300, 000, fan, records</media:keywords>
</item>

<item>
<title>Checksum introduces Continuous Quality Agent for automated test generation and healing</title>
<link>https://block385.com/checksum-introduces-continuous-quality-agent-for-automated-test-generation-and-healing</link>
<guid>https://block385.com/checksum-introduces-continuous-quality-agent-for-automated-test-generation-and-healing</guid>
<description><![CDATA[ Checksum has launched its Continuous Quality Agent, an autonomous system that runs nightly against deployed applications and automatically heals broken tests without waiting for an engineer to open a dashboard or write a prompt. AI coding has changed the constraint in software development. Teams can now ship far more code than before, but every PR still needs to be tested, validated, and trusted before it reaches production. Even tests written by AI require human maintenance … More →
The post Checksum introduces Continuous Quality Agent for automated test generation and healing appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 11:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Checksum, introduces, Continuous, Quality, Agent, for, automated, test, generation, and, healing</media:keywords>
</item>

<item>
<title>XM Cyber enhances identity risk visibility with continuous exposure management capabilities</title>
<link>https://block385.com/xm-cyber-enhances-identity-risk-visibility-with-continuous-exposure-management-capabilities</link>
<guid>https://block385.com/xm-cyber-enhances-identity-risk-visibility-with-continuous-exposure-management-capabilities</guid>
<description><![CDATA[ XM Cyber has announced platform enhancements aimed at helping organizations reduce identity risk, compounded by AI-enabled attackers. According to Gartner, “By 2028, 70% of CISOs will use identity visibility and intelligence capabilities to shrink the IAM attack surface, reducing the risks of credential compromise.” Excessive permissions are a leading technique used in breaches and a common path for lateral movement across hybrid-cloud environments. The new capabilities help teams identify where access can be right-sized in … More →
The post XM Cyber enhances identity risk visibility with continuous exposure management capabilities appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 11:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cyber, enhances, identity, risk, visibility, with, continuous, exposure, management, capabilities</media:keywords>
</item>

<item>
<title>Ketch brings multi&#45;agent AI orchestration to enterprise privacy programs</title>
<link>https://block385.com/ketch-brings-multi-agent-ai-orchestration-to-enterprise-privacy-programs</link>
<guid>https://block385.com/ketch-brings-multi-agent-ai-orchestration-to-enterprise-privacy-programs</guid>
<description><![CDATA[ Ketch has unveiled its vision for agentic privacy with the Ketch Agent Network, a multi-agent orchestration layer for enterprise privacy programs. The platform is designed to continuously reason across legal obligations, internal policies, and operational realities within a unified AI-driven system. Privacy teams today are accountable for more than ever: global regulations, AI governance mandates, accelerating enforcement, and a wave of demand letters that punish the unprepared. Keeping up requires continuous analysis across a staggering … More →
The post Ketch brings multi-agent AI orchestration to enterprise privacy programs appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 11:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Ketch, brings, multi-agent, orchestration, enterprise, privacy, programs</media:keywords>
</item>

<item>
<title>Nordic CISOs Handle Rising Cyber Threats Remarkably Well</title>
<link>https://block385.com/nordic-cisos-handle-rising-cyber-threats-remarkably-well</link>
<guid>https://block385.com/nordic-cisos-handle-rising-cyber-threats-remarkably-well</guid>
<description><![CDATA[ Artificial intelligence notwithstanding, the vast majority of CISOs in northern Europe say they&#039;re facing no more serious cyberattacks than they did two years ago. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt70c6acdf0ad722a2/6a17391e011a18831c6e30bd/Nordic_flags-Eric_D_ricochet69-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 11:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Nordic, CISOs, Handle, Rising, Cyber, Threats, Remarkably, Well</media:keywords>
</item>

<item>
<title>Hottest cybersecurity open&#45;source tools of the month: May 2026</title>
<link>https://block385.com/hottest-cybersecurity-open-source-tools-of-the-month-may-2026</link>
<guid>https://block385.com/hottest-cybersecurity-open-source-tools-of-the-month-may-2026</guid>
<description><![CDATA[ Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. Pipelock: Open-source AI agent firewall AI coding agents run with shell access, environment variables containing API keys, and unrestricted internet connectivity, creating a single point of failure where one compromised tool call can leak credentials to an attacker-controlled domain. Pipelock, an open-source security harness developed by Joshua Waldrep under the … More →
The post Hottest cybersecurity open-source tools of the month: May 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/09/09085108/open-source_cybersec_tools-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 09:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Hottest, cybersecurity, open-source, tools, the, month:, May, 2026</media:keywords>
</item>

<item>
<title>Frontier AI models collapse under multi&#45;turn AI attacks, Cisco finds</title>
<link>https://block385.com/frontier-ai-models-collapse-under-multi-turn-ai-attacks-cisco-finds</link>
<guid>https://block385.com/frontier-ai-models-collapse-under-multi-turn-ai-attacks-cisco-finds</guid>
<description><![CDATA[ Attackers who probe large language models rarely give up after one refusal. They reframe, build context across turns, adopt personas, and escalate gradually. New research from Cisco’s AI threat intelligence team finds that the safety benchmarks used across the industry miss almost all of this behavior, and the gap between published scores and observed resilience runs wide enough to misrank leading models. Single-turn versus multi-turn ASR by model, with approximate 95% confidence half-widths on single-turn … More →
The post Frontier AI models collapse under multi-turn AI attacks, Cisco finds appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18161426/key.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 09:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Frontier, models, collapse, under, multi-turn, attacks, Cisco, finds</media:keywords>
</item>

<item>
<title>Nudge Security adds browser&#45;based discovery for shadow AI agents</title>
<link>https://block385.com/nudge-security-adds-browser-based-discovery-for-shadow-ai-agents</link>
<guid>https://block385.com/nudge-security-adds-browser-based-discovery-for-shadow-ai-agents</guid>
<description><![CDATA[ Nudge Security announced that its AI security platform offers discovery of shadow AI agents via the browser, extending its agent discovery capabilities to cover platforms that do not provide a public API for agent identity and inventory. The new browser-based agentic AI discovery closes a fundamental gap, where other solutions depend solely on platform APIs that many agent-building tools simply don’t offer yet. The new browser-based discovery finds AI agents built in Airbyte, Atlassian Rovo, … More →
The post Nudge Security adds browser-based discovery for shadow AI agents appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Nudge, Security, adds, browser-based, discovery, for, shadow, agents</media:keywords>
</item>

<item>
<title>The CISO selling confidence in a market full of breach headlines</title>
<link>https://block385.com/the-ciso-selling-confidence-in-a-market-full-of-breach-headlines</link>
<guid>https://block385.com/the-ciso-selling-confidence-in-a-market-full-of-breach-headlines</guid>
<description><![CDATA[ Engineering teams across enterprise IT are writing their own software with AI coding assistants, spinning up agents that act on their behalf, and assigning those agents the same access privileges their human creators hold. The shift has pulled the role of the chief information security officer into territory that did not exist two years ago. Speaking at the Span Cyber Security Arena conference, Hrvoje Englman, CISO at Span, said it is changing what defenders worry … More →
The post The CISO selling confidence in a market full of breach headlines appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/26162842/hrvoje_englman-2-span.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 09:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, CISO, selling, confidence, market, full, breach, headlines</media:keywords>
</item>

<item>
<title>Canonical releases Workshop for one&#45;command sandboxed dev environments on Ubuntu</title>
<link>https://block385.com/canonical-releases-workshop-for-one-command-sandboxed-dev-environments-on-ubuntu</link>
<guid>https://block385.com/canonical-releases-workshop-for-one-command-sandboxed-dev-environments-on-ubuntu</guid>
<description><![CDATA[ Canonical released Workshop, a tool that launches sandboxed development environments on Ubuntu with a single command. Environments are configured once and reproduced on different machines, giving teams consistent setups across development workstations and deployment pipelines. A terminal showing the output of the workshop launch and list commands (Source: Canonical) How Workshop defines environments Workshop environments are described in YAML files, which can be version-controlled and shared among contributors to a project. A single command creates, … More →
The post Canonical releases Workshop for one-command sandboxed dev environments on Ubuntu appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/11144606/linux-tux.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 07:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Canonical, releases, Workshop, for, one-command, sandboxed, dev, environments, Ubuntu</media:keywords>
</item>

<item>
<title>Companies built AI into core systems before figuring out how to govern it</title>
<link>https://block385.com/companies-built-ai-into-core-systems-before-figuring-out-how-to-govern-it</link>
<guid>https://block385.com/companies-built-ai-into-core-systems-before-figuring-out-how-to-govern-it</guid>
<description><![CDATA[ 70% of organizations use GenAI in live environments, and 64% have AI agents in pilot or production deployments. Some of those agents have privileged access to core systems, according to Check Point’s 2026 Cloud Security Report. Confirmed and suspected AI incidents (Source: Check Point) Production AI expands the enterprise attack surface Security architectures built around human users and predictable application behavior are struggling with AI systems that rely on APIs, automation, and autonomous actions. More … More →
The post Companies built AI into core systems before figuring out how to govern it appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/06/12155822/cloud-security.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 28 May 2026 07:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Companies, built, into, core, systems, before, figuring, out, how, govern</media:keywords>
</item>

<item>
<title>Ransomware Actors Show Up In Person to Steal Law Firm Data</title>
<link>https://block385.com/ransomware-actors-show-up-in-person-to-steal-law-firm-data</link>
<guid>https://block385.com/ransomware-actors-show-up-in-person-to-steal-law-firm-data</guid>
<description><![CDATA[ The FBI warned that the extortion gang Silent Ransom Group is targeting law firms and socially engineering its way into servers and databases. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt8feb125a519f8c9d/6a1745ffd8e1c3494b5e2e18/angry_businessman_Liubomyr_Vorona_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 23:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Ransomware, Actors, Show, Person, Steal, Law, Firm, Data</media:keywords>
</item>

<item>
<title>AI chatbot recommendations lure users to cryptojacking malware sites</title>
<link>https://block385.com/ai-chatbot-recommendations-lure-users-to-cryptojacking-malware-sites</link>
<guid>https://block385.com/ai-chatbot-recommendations-lure-users-to-cryptojacking-malware-sites</guid>
<description><![CDATA[ Cybercriminals are using AI chatbot interactions alongside poisoned search results to direct users to malicious download sites in an active cryptojacking campaign, Microsoft has warned. The campaign impersonates legitimate software tools such as CrystalDiskInfo, HWMonitor, Display Driver Uninstaller (DDU), FurMark, K-Lite Codec Pack, and PDFgear. Screenshot of search engine results showing a malicious source of hwmonitor (Source: Microsoft) “The selection of these brands is deliberate. Each application is favored by PC enthusiasts and hardware-focused users, … More →
The post AI chatbot recommendations lure users to cryptojacking malware sites appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/03/26092845/hand-monitor-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 23:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>chatbot, recommendations, lure, users, cryptojacking, malware, sites</media:keywords>
</item>

<item>
<title>Hackers are knocking on office doors pretending to be IT staff</title>
<link>https://block385.com/hackers-are-knocking-on-office-doors-pretending-to-be-it-staff</link>
<guid>https://block385.com/hackers-are-knocking-on-office-doors-pretending-to-be-it-staff</guid>
<description><![CDATA[ The Silent Ransom Group (SRG) is targeting law firms using social engineering techniques and an unusual tactic for cybercriminals: showing up at victims’ offices in person while posing as IT staff, the FBI warns. The group, also known as Luna Moth, Chatty Spider, and UNC3753, has been active since at least 2022 and has targeted companies in several sectors, including insurance, finance, and healthcare, though law firms remain its primary target. The FBI said SRG … More →
The post Hackers are knocking on office doors pretending to be IT staff appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/05/31195930/social-engineering_1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 19:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Hackers, are, knocking, office, doors, pretending, staff</media:keywords>
</item>

<item>
<title>Latin American Cybercriminals Hoover Up Government Data</title>
<link>https://block385.com/latin-american-cybercriminals-hoover-up-government-data</link>
<guid>https://block385.com/latin-american-cybercriminals-hoover-up-government-data</guid>
<description><![CDATA[ A  purported leak exposing 5.8 million records of Uruguayan citizens is the latest incident where cybercriminals targeted government agencies to monetize citizen data. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt69dc4075068a4990/6a1614614c25b5ccb71e1af2/globe-latin-america-caribbean-jhonny_marcell_oportus-shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Latin, American, Cybercriminals, Hoover, Government, Data</media:keywords>
</item>

<item>
<title>AI&#45;Assisted Exploit Development Outpaces Scanner Detection</title>
<link>https://block385.com/ai-assisted-exploit-development-outpaces-scanner-detection</link>
<guid>https://block385.com/ai-assisted-exploit-development-outpaces-scanner-detection</guid>
<description><![CDATA[ Attackers are using AI to dramatically reduce the time they need to develop a working exploit for a CVE, according to new research. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt657ae2e1d33745d1/6a16e2326f59863042093c62/Exploit_Tiny_Ivan_Alamy.png" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>AI-Assisted, Exploit, Development, Outpaces, Scanner, Detection</media:keywords>
</item>

<item>
<title>Shai&#45;Hulud Hackers TeamPCP: Lucky or Skilled?</title>
<link>https://block385.com/shai-hulud-hackers-teampcp-lucky-or-skilled</link>
<guid>https://block385.com/shai-hulud-hackers-teampcp-lucky-or-skilled</guid>
<description><![CDATA[ TeamPCP, the cybercrime group behind later waves of the Shai-Hulud worm, has done significant damage to the open source ecosystem. But it&#039;s not necessarily due to skill alone. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc7db7c7edbff4dd8/6a15d1131d874963b59c1439/bullseye_Oleksandr_Perepelytsia_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Shai-Hulud, Hackers, TeamPCP:, Lucky, Skilled</media:keywords>
</item>

<item>
<title>Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users</title>
<link>https://block385.com/grandoreiro-malware-and-btmob-rat-campaigns-target-windows-and-android-users</link>
<guid>https://block385.com/grandoreiro-malware-and-btmob-rat-campaigns-target-windows-and-android-users</guid>
<description><![CDATA[ Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively.

That&#039;s according to new findings from WatchGuard and ESET, which have observed the two malware families being used to single out companies in Spain, Portugal, and Mexico, as well as mobile users in Brazil.

The ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhLrxY3dAls7M9XrbkVjdGZELLj2DQ4eGof0qKdWXJLGqQgVgcbszD-mSmcUi6ljJEPyuM5qbIzFD2CAkjQMkwdznWW5nXnJpPUOxuLP87xIATaxqvIKByQr0ddq8GnYTJy_O6VX5Z0cv_S9AYbwVUzzMeKM3UoPGGJ3Bzei5FluxHchhuekfAiKxUnBmaa/s1600/android-malware.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 18:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Grandoreiro, Malware, and, BTMOB, RAT, Campaigns, Target, Windows, and, Android, Users</media:keywords>
</item>

<item>
<title>Malicious npm Package Stole Files From Claude AI User Directory via GitHub</title>
<link>https://block385.com/malicious-npm-package-stole-files-from-claude-ai-user-directory-via-github</link>
<guid>https://block385.com/malicious-npm-package-stole-files-from-claude-ai-user-directory-via-github</guid>
<description><![CDATA[ Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities.

According to OX Security, the package, named &quot;mouse5212-super-formatter,&quot; is designed to upload files from &quot;/mnt/user-data,&quot; a dedicated directory used by Anthropic&#039;s Claude artificial intelligence (AI) tool to handle uploads and outputs in the background. The ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjlezHawmKBTFBZSgR52vL_EBxfwIlMa0i4LdDK2xC_c8nw704KQHbRNSHYAy8TY4ShZMFwAJoZKUBSDJBCVnwbORTlz7iE0JI9f9ORbQQ-RB5lA_b9VbUzAsjpVeW2oJ94hdfzOeCWN3zd5Li7zWanNx3s07cF8IRlWuVrLqBNaY0sobbJww1Pa_o2t4JN/s1600/npm-ai.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 18:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Malicious, npm, Package, Stole, Files, From, Claude, User, Directory, via, GitHub</media:keywords>
</item>

<item>
<title>Ping Identity advances agentic security with AI governance and trusted access</title>
<link>https://block385.com/ping-identity-advances-agentic-security-with-ai-governance-and-trusted-access</link>
<guid>https://block385.com/ping-identity-advances-agentic-security-with-ai-governance-and-trusted-access</guid>
<description><![CDATA[ Ping Identity announced new capabilities that extend the Ping Identity Platform for the agentic enterprise, where AI agents, automation, and developers increasingly shape how access is managed, governed, and secured across organizations. AI agents are changing both sides of the identity equation. They are new actors that need to be discovered, governed, and managed across their lifecycle, and they are also new operators that can help builders administer and secure identity environments through machine-native interfaces. … More →
The post Ping Identity advances agentic security with AI governance and trusted access appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 17:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Ping, Identity, advances, agentic, security, with, governance, and, trusted, access</media:keywords>
</item>

<item>
<title>eSentire launches new Atlas AI Operatives for autonomous threat detection and response</title>
<link>https://block385.com/esentire-launches-new-atlas-ai-operatives-for-autonomous-threat-detection-and-response</link>
<guid>https://block385.com/esentire-launches-new-atlas-ai-operatives-for-autonomous-threat-detection-and-response</guid>
<description><![CDATA[ eSentire has unveiled new preempt, detect, and respond capabilities within the Atlas Platform, a unified agentic AI platform with purpose-built AI Operatives that work together in a continuous security lifecycle. Controlled autonomy SecOps The Atlas Platform delivers purpose-built and adaptive AI operative infrastructure in a continuous closed loop across autonomous AI offensive security, exposure management, and Managed Detection and Response (MDR) services. It executes hundreds of thousands of autonomous investigations and responses across 2,000+ customer … More →
The post eSentire launches new Atlas AI Operatives for autonomous threat detection and response appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 17:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>eSentire, launches, new, Atlas, Operatives, for, autonomous, threat, detection, and, response</media:keywords>
</item>

<item>
<title>Cogent targets exploit&#45;to&#45;remediation gap with new AI&#45;powered security capabilities</title>
<link>https://block385.com/cogent-targets-exploit-to-remediation-gap-with-new-ai-powered-security-capabilities</link>
<guid>https://block385.com/cogent-targets-exploit-to-remediation-gap-with-new-ai-powered-security-capabilities</guid>
<description><![CDATA[ Cogent has launched two new platform capabilities designed to reduce the time between vulnerability disclosure and confirmed remediation. Zero Day Response identifies exposure within minutes of public disclosure, without waiting for scanner signatures. Autonomous Remediation determines the right fix, assesses business impact before execution, and confirms that the vulnerability has been resolved. The releases arrive as AI-assisted exploit development compresses attacker timelines faster than most security programs can keep pace. Time to exploit has collapsed … More →
The post Cogent targets exploit-to-remediation gap with new AI-powered security capabilities appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cogent, targets, exploit-to-remediation, gap, with, new, AI-powered, security, capabilities</media:keywords>
</item>

<item>
<title>Claude now reviews and fixes vulnerabilities as you write code</title>
<link>https://block385.com/claude-now-reviews-and-fixes-vulnerabilities-as-you-write-code</link>
<guid>https://block385.com/claude-now-reviews-and-fixes-vulnerabilities-as-you-write-code</guid>
<description><![CDATA[ Anthropic introduced a security-guidance plugin for Claude Code that reviews code changes for common vulnerabilities and helps Claude identify and fix issues during the same development session. The company says the plugin is designed to catch issues such as injection flaws, unsafe deserialization, and insecure DOM APIs before code reaches pull requests, reducing the amount of manual security review later in the development process. Once installed, the plugin runs automatically during development sessions, without requiring … More →
The post Claude now reviews and fixes vulnerabilities as you write code appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/27125837/claude-city.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 17:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Claude, now, reviews, and, fixes, vulnerabilities, you, write, code</media:keywords>
</item>

<item>
<title>Google AI Threat Defense targets attackers using AI to find flaws faster</title>
<link>https://block385.com/google-ai-threat-defense-targets-attackers-using-ai-to-find-flaws-faster</link>
<guid>https://block385.com/google-ai-threat-defense-targets-attackers-using-ai-to-find-flaws-faster</guid>
<description><![CDATA[ Google Cloud introduced AI Threat Defense, an automated cybersecurity platform that combines several of the company’s security assets to find, prioritize, and patch software vulnerabilities at machine speed. The product is aimed at enterprises contending with attackers who use AI to discover and exploit flaws in hours or days, compressing windows that once stretched into weeks. The platform fuses the Gemini family of models, the cloud security firm Wiz, the AI code-fixing agent CodeMender, and … More →
The post Google AI Threat Defense targets attackers using AI to find flaws faster appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/10114613/google-lock-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 17:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Google, Threat, Defense, targets, attackers, using, find, flaws, faster</media:keywords>
</item>

<item>
<title>GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure</title>
<link>https://block385.com/glassworm-malware-takedown-disrupts-developer-supply-chain-attack-infrastructure</link>
<guid>https://block385.com/glassworm-malware-takedown-disrupts-developer-supply-chain-attack-infrastructure</guid>
<description><![CDATA[ CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm, a persistent software chain campaign targeting software developers through malicious packages and extensions.

&quot;Since at least early 2025, GlassWorm operators have systematically targeted software developers, a ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZssmt_sAQM7Hi8SpkOQnmc9tKVqlTyjMclO_ptRmn45_cDzz3KANdtBi4xzzuf7neoeylx39D4BZN_Wys34O8lCM9KP8qytxEq_QT4tQ_FTHBeRV75qVTNfzQg7UGa0IJGO3tuJBZGiDjNfB401rG6hPvu78_5H_Sp8UeYk9c74KlCr-CaVX1rg-Slxc6/s1600/botnet-down.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 16:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>GlassWorm, Malware, Takedown, Disrupts, Developer, Supply, Chain, Attack, Infrastructure</media:keywords>
</item>

<item>
<title>3 SOC Steps that Shut Down Incident Risks Early</title>
<link>https://block385.com/3-soc-steps-that-shut-down-incident-risks-early</link>
<guid>https://block385.com/3-soc-steps-that-shut-down-incident-risks-early</guid>
<description><![CDATA[ Most organizations still picture cyber defense as a fortress problem: build stronger walls, add more guards, buy another detection engine. But modern incidents rarely crash through the front gate. They drift in disguised as routine activity, hide inside legitimate processes, and quietly accumulate risk long before anyone labels them an &quot;incident.&quot;

That changes the role of the SOC entirely.

The ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5SbPsI2Ip_2s2JkLJSNNO05Qfn3zFQTpOSmRmqTreVUxDWTgZXSUgEtIwEvu5bQ8wGM24s68ikCnVLdKujVhF8j-TxTM5lr38lAdKkEummRkZxVnB5P1CQWNYqY-Oswvf6FHz4gWhFSAbrokC_3bnFksFvzGSC-0Fh5YUUJSNS2jlKrOJt4RCRJlYoJ4/s1600/iocc.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 16:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>SOC, Steps, that, Shut, Down, Incident, Risks, Early</media:keywords>
</item>

<item>
<title>Apple makes its quantum&#45;resistant encryption open source</title>
<link>https://block385.com/apple-makes-its-quantum-resistant-encryption-open-source</link>
<guid>https://block385.com/apple-makes-its-quantum-resistant-encryption-open-source</guid>
<description><![CDATA[ Apple has published its post-quantum cryptography implementations in corecrypto, together with mathematical proofs and verification tools for independent expert evaluation, allowing external researchers to review the work and reproduce the company’s analysis. Post-quantum cryptography is designed to protect encrypted data from future quantum computers that could break widely used public-key encryption algorithms. A new approach to formal verification of Apple corecrypto (Source: Apple) Corecrypto, the cryptography library used throughout Apple operating systems and services, provides … More →
The post Apple makes its quantum-resistant encryption open source appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/04/23105508/apple-chip.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 15:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Apple, makes, its, quantum-resistant, encryption, open, source</media:keywords>
</item>

<item>
<title>Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware</title>
<link>https://block385.com/fake-chatgpt-and-claude-installers-on-github-are-dropping-deno-rat-malware</link>
<guid>https://block385.com/fake-chatgpt-and-claude-installers-on-github-are-dropping-deno-rat-malware</guid>
<description><![CDATA[ Attackers are hosting counterfeit installers and plugins on GitHub and SourceForge that pose as widely used software, including ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY. The downloads deliver a backdoor called DinDoor, which then loads a remote access Trojan built on the Deno JavaScript runtime, according to Malwarebytes. Compromised YouTube channels push victims toward the malicious repositories. The videos promoting the fake tools have accumulated more than 50,000 views. The attackers rotate through GitHub … More →
The post Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/04/24114249/trojan-1-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Fake, ChatGPT, and, Claude, installers, GitHub, are, dropping, Deno, RAT, malware</media:keywords>
</item>

<item>
<title>Cybersecurity Evolution: How We Went From Perimeter Defense to AI&#45;Native Security</title>
<link>https://block385.com/cybersecurity-evolution-how-we-went-from-perimeter-defense-to-ai-native-security</link>
<guid>https://block385.com/cybersecurity-evolution-how-we-went-from-perimeter-defense-to-ai-native-security</guid>
<description><![CDATA[ The cybersecurity industry of 2006 barely resembled today&#039;s billion-dollar behemoth. As part of Dark Reading&#039;s 20th anniversary celebration, we trace the industry&#039;s evolution through a technology lens. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltfb21a70a1a635754/6a16e65fac4efe6d73c7ca76/Transformation_Aleksey_Funtap_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 15:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cybersecurity, Evolution:, How, Went, From, Perimeter, Defense, AI-Native, Security</media:keywords>
</item>

<item>
<title>State Cyber Leaders Beg Congress for More Funding, Support</title>
<link>https://block385.com/state-cyber-leaders-beg-congress-for-more-funding-support</link>
<guid>https://block385.com/state-cyber-leaders-beg-congress-for-more-funding-support</guid>
<description><![CDATA[ A recent congressional hearing highlighted how states are reeling from federal cutbacks to important cyber grants and information sharing initiatives amid damaging attacks to critical infrastructure. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt12b0781abe98a796/6824a51351025e2a07815d92/Congress_(1800)_Gang_Liu_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 15:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>State, Cyber, Leaders, Beg, Congress, for, More, Funding, Support</media:keywords>
</item>

<item>
<title>For Enterprises, Security Remains Agentic AI&amp;apos;s Biggest Challenge</title>
<link>https://block385.com/for-enterprises-security-remains-agentic-ais-biggest-challenge</link>
<guid>https://block385.com/for-enterprises-security-remains-agentic-ais-biggest-challenge</guid>
<description><![CDATA[ Every company needs an agentic AI strategy, but the tools to allow agentic AI frameworks be safely and securely adopted are just starting to appear. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt8b4a90dc0f0b5b75/69a60296c1c8e5611b80bbeb/openclaw_Koshiro_K_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 15:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>For, Enterprises, Security, Remains, Agentic, AIs, Biggest, Challenge</media:keywords>
</item>

<item>
<title>5 Steps to Managing Shadow AI Tools Without Slowing Down Employees</title>
<link>https://block385.com/5-steps-to-managing-shadow-ai-tools-without-slowing-down-employees</link>
<guid>https://block385.com/5-steps-to-managing-shadow-ai-tools-without-slowing-down-employees</guid>
<description><![CDATA[ When an employee installs an AI writing assistant, connects a coding copilot to their IDE, or starts summarizing meetings with a new browser tool, they are doing exactly what a productive employee should do: finding faster ways to work.

Across most organizations today, employees are running three to five AI tools on any given day. Most were never reviewed by IT. A significant portion connects ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6kyKLwKpVhYgitj4fm1vRuvXJPKSpYpf_WcR-b0_8CVkNeFLtcxO158cmOS_GAVNi7G1xTrDOLVcVqBXKW-rI31rDAVXhN-A3Q1g11l_17bAKuedJx_meh5Pf4hoRVLwx55EECim9EGrI0xRCsq2Dx-8nBNlNwIVqEApy16ZBm48DuqDq2Q7BtRKm3AA/s1600/shadow.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 14:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Steps, Managing, Shadow, Tools, Without, Slowing, Down, Employees</media:keywords>
</item>

<item>
<title>Gitea Vulnerability Exposes Private Container Images without Authentication</title>
<link>https://block385.com/gitea-vulnerability-exposes-private-container-images-without-authentication</link>
<guid>https://block385.com/gitea-vulnerability-exposes-private-container-images-without-authentication</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials.

The vulnerability, tracked as CVE-2026-27771 (CVSS score: N/A), affects all versions of Gitea prior to 1.26.2 ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtYSLWixSGb7jW2drND6NlHzXB4eHO0QyZNOovK9iVyaHGS6fSN4eqhWkijIhevhInH56hv03c29ziWCZiH58kY5EBbfuZloLfMP9yGJuFVtIaoJqj31KVFNeImMNVnLGrRHbhcGw7IMVZ8FEH2tK-Bit50KzXfe0F9jEQAO9iy5PNprbqJzgRB2WkI-0i/s1600/gitea-main.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 14:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Gitea, Vulnerability, Exposes, Private, Container, Images, without, Authentication</media:keywords>
</item>

<item>
<title>AppOmni’s Marlin AI automates SaaS threat analysis, triage, and remediation at scale</title>
<link>https://block385.com/appomnis-marlin-ai-automates-saas-threat-analysis-triage-and-remediation-at-scale</link>
<guid>https://block385.com/appomnis-marlin-ai-automates-saas-threat-analysis-triage-and-remediation-at-scale</guid>
<description><![CDATA[ AppOmni has launched Marlin AI to transform how enterprise organizations defend complex SaaS applications. Marlin AI delivers autonomous AI-powered SaaS security that leverages AppOmni’s deep SaaS application observability. It actively correlates SaaS security indicators, performs deep investigations, and guides security teams to immediate solutions. By reducing the massive hours wasted on investigating threats, alerts and warnings across the security tech stack, security teams can now move beyond manual event and indicator correlation to autonomous triaging … More →
The post AppOmni’s Marlin AI automates SaaS threat analysis, triage, and remediation at scale appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 11:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>AppOmni’s, Marlin, automates, SaaS, threat, analysis, triage, and, remediation, scale</media:keywords>
</item>

<item>
<title>Jetico expands BestCrypt Data Shelter with zero&#45;trust file access controls</title>
<link>https://block385.com/jetico-expands-bestcrypt-data-shelter-with-zero-trust-file-access-controls</link>
<guid>https://block385.com/jetico-expands-bestcrypt-data-shelter-with-zero-trust-file-access-controls</guid>
<description><![CDATA[ Jetico has announced the extension of BestCrypt Data Shelter to include centrally managed enterprise data access control for sensitive files. The solution allows security teams to define and enforce policies governing which applications, processes and users can access protected files. This default-deny model aligns with zero-trust security principles. “Organizations have made significant progress in encrypting data and securing the perimeter, but broad access inside trusted environments often remains uncontrolled,” explains Jetico CEO Hannaleena Pojanluoma. “BestCrypt … More →
The post Jetico expands BestCrypt Data Shelter with zero-trust file access controls appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 11:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Jetico, expands, BestCrypt, Data, Shelter, with, zero-trust, file, access, controls</media:keywords>
</item>

<item>
<title>Franklin Access adds three&#45;layer security system to Wi&#45;Fi routers</title>
<link>https://block385.com/franklin-access-adds-three-layer-security-system-to-wi-fi-routers</link>
<guid>https://block385.com/franklin-access-adds-three-layer-security-system-to-wi-fi-routers</guid>
<description><![CDATA[ Franklin Access has launched a three-layer security system integrated into its Wi-Fi routers, delivering enterprise-grade protection for consumers and small businesses. The system runs automatically in the background, blocking millions of malicious websites in real time to protect families, children, seniors, and businesses from online threats. Franklin’s Wi-Fi routers include advanced security protocols and privacy features designed to safeguard connected devices and user data. Layer 1: Foundation Franklin’s DNS filters block and redirect outgoing traffic … More →
The post Franklin Access adds three-layer security system to Wi-Fi routers appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 11:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Franklin, Access, adds, three-layer, security, system, Wi-Fi, routers</media:keywords>
</item>

<item>
<title>AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites</title>
<link>https://block385.com/ai-chatbot-recommendations-redirect-users-to-cryptojacking-malware-sites</link>
<guid>https://block385.com/ai-chatbot-recommendations-redirect-users-to-cryptojacking-malware-sites</guid>
<description><![CDATA[ Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing malicious download sites.

&quot;This emerging delivery technique extends social engineering beyond conventional search results and increases the visibility of malicious software recommendations,&quot; Microsoft Defender Experts and the Microsoft ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhqt5LC8yrEqRzxRxEUTh3yZSnXovvZU0R11suWWfP1FEKvC5ZOpPnLHpdDjAzUADZarX1C3XucsG5OOXN3Zj4-esPhUnz4DBnAdDxkZw3aEqdH_HHPn4N5Eu03Y-tG_kEmPOxKyMH14wpiOYs9w8jh7U6MlHjHqiS4nNxLH_NpS47oR-mRW5GfuDvX9VFo/s1600/ai-tools.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 10:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Chatbot, Recommendations, Redirect, Users, Cryptojacking, Malware, Sites</media:keywords>
</item>

<item>
<title>Coinflow CISO on crypto payments security under AI pressure</title>
<link>https://block385.com/coinflow-ciso-on-crypto-payments-security-under-ai-pressure</link>
<guid>https://block385.com/coinflow-ciso-on-crypto-payments-security-under-ai-pressure</guid>
<description><![CDATA[ Crypto payment firms sit near the top of the target list for advanced persistent threat groups, and the workload on their security leaders keeps growing. Malcolm Portelli, CISO at Coinflow, runs the company’s security program from Malta. Coinflow is headquartered in the United States and operates across multiple jurisdictions. Portelli sat down for this interview at the Span Cyber Security Arena conference. Portelli says the sector drives his threat model more than the location. “It’s … More →
The post Coinflow CISO on crypto payments security under AI pressure appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/26121932/malcolm_portelli-2-coinflow.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 09:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Coinflow, CISO, crypto, payments, security, under, pressure</media:keywords>
</item>

<item>
<title>Vigolium: Open&#45;source vulnerability scanner</title>
<link>https://block385.com/vigolium-open-source-vulnerability-scanner</link>
<guid>https://block385.com/vigolium-open-source-vulnerability-scanner</guid>
<description><![CDATA[ Vigolium, an open-source vulnerability scanner that combines deterministic scanning with AI-driven auditing, launched its initial open-source release this month. The project ships 235+ scanner modules and an in-process agent runtime called olium that handles autonomous endpoint discovery, attack planning, and finding triage. The tool exposes two scanning paths. vigolium scan runs a multi-phase deterministic pipeline covering content discovery, browser-based spidering, and active and passive auditing. vigolium agent hands control to an LLM-driven harness that selects … More →
The post Vigolium: Open-source vulnerability scanner appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/26063643/vigolium-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 09:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Vigolium:, Open-source, vulnerability, scanner</media:keywords>
</item>

<item>
<title>Novee’s Agentic Fix turns validated exploits into fixes through AI coding agents</title>
<link>https://block385.com/novees-agentic-fix-turns-validated-exploits-into-fixes-through-ai-coding-agents</link>
<guid>https://block385.com/novees-agentic-fix-turns-validated-exploits-into-fixes-through-ai-coding-agents</guid>
<description><![CDATA[ Novee has announced Agentic Fix, an enhancement to its AI penetration testing platform that helps teams move from validating security findings to deploying fixes in a single step. Agentic Fix extends Novee’s platform by generating remediation guidance from the same exploit context used to uncover an issue, then routing that guidance to the AI coding agents developers already use. Autonomous pentesting has compressed vulnerability discovery timelines from quarters to hours, but the rest of the … More →
The post Novee’s Agentic Fix turns validated exploits into fixes through AI coding agents appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 09:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Novee’s, Agentic, Fix, turns, validated, exploits, into, fixes, through, coding, agents</media:keywords>
</item>

<item>
<title>European AI adoption hits 99% with regulated data driving most policy violations</title>
<link>https://block385.com/european-ai-adoption-hits-99-with-regulated-data-driving-most-policy-violations</link>
<guid>https://block385.com/european-ai-adoption-hits-99-with-regulated-data-driving-most-policy-violations</guid>
<description><![CDATA[ Generative AI tools operate inside nearly every European workplace, embedded in meeting transcription services, writing assistants, coding copilots, and search features. Workers in the region pull these tools into daily routines that involve customer records, financial information, and proprietary code, and that volume of activity has produced a measurable pattern in where data exposure occurs. The Netskope Threat Labs Report: Europe 2026 documents this pattern across organizations in Europe over the past year. Source: Netskope … More →
The post European AI adoption hits 99% with regulated data driving most policy violations appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/06/27095654/eu-ai.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>European, adoption, hits, 99, with, regulated, data, driving, most, policy, violations</media:keywords>
</item>

<item>
<title>The alert economy is driving security analyst burnout</title>
<link>https://block385.com/the-alert-economy-is-driving-security-analyst-burnout</link>
<guid>https://block385.com/the-alert-economy-is-driving-security-analyst-burnout</guid>
<description><![CDATA[ In this Help Net Security video, Ido Livneh, CEO of Jazz, explains why security analysts burn out and what leaders can do about it. The cause, he argues, is not long hours but meaningless work. Analysts spend their days closing repetitive tickets while the institutional knowledge of senior staff walks out the door when they quit, taking organizational context with them and driving up false positives. Livneh points to an “alert economy” where detection tools … More →
The post The alert economy is driving security analyst burnout appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/21193943/burnout-3.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 27 May 2026 07:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, alert, economy, driving, security, analyst, burnout</media:keywords>
</item>

<item>
<title>Microsoft Issues Out&#45;of&#45;Band SharePoint Patch</title>
<link>https://block385.com/microsoft-issues-out-of-band-sharepoint-patch</link>
<guid>https://block385.com/microsoft-issues-out-of-band-sharepoint-patch</guid>
<description><![CDATA[ SharePoint access often means access to the keys of the kingdom, something attackers and defenders understand all too well. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt199e46ed0481cbe5/6a15e5f1011a1838a66e2c61/sharepoint_Tada_Images_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 23:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Issues, Out-of-Band, SharePoint, Patch</media:keywords>
</item>

<item>
<title>Feeding Frenzy: &amp;apos;Megalodon&amp;apos; Malware Infects Thousands of GitHub Repos</title>
<link>https://block385.com/feeding-frenzy-megalodon-malware-infects-thousands-of-github-repos</link>
<guid>https://block385.com/feeding-frenzy-megalodon-malware-infects-thousands-of-github-repos</guid>
<description><![CDATA[ In just six hours, the campaign quietly pushed thousands of malicious commits to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc325e59502521a65/6a15e639ac735951357db6b9/megalodon_FlixPix_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 23:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Feeding, Frenzy:, Megalodon, Malware, Infects, Thousands, GitHub, Repos</media:keywords>
</item>

<item>
<title>The Hackers Behind Shai&#45;Hulud: Lucky or Skilled?</title>
<link>https://block385.com/the-hackers-behind-shai-hulud-lucky-or-skilled</link>
<guid>https://block385.com/the-hackers-behind-shai-hulud-lucky-or-skilled</guid>
<description><![CDATA[ TeamPCP, the hackers behind the Shai-Hulud worm, has done significant damage to the open source ecosystem. But it&#039;s not necessarily due to skill alone. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc7db7c7edbff4dd8/6a15d1131d874963b59c1439/bullseye_Oleksandr_Perepelytsia_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 23:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, Hackers, Behind, Shai-Hulud:, Lucky, Skilled</media:keywords>
</item>

<item>
<title>MuddyWater Uses DLL Side&#45;Loading in Espionage Campaign Targeting 9 Countries</title>
<link>https://block385.com/muddywater-uses-dll-side-loading-in-espionage-campaign-targeting-9-countries</link>
<guid>https://block385.com/muddywater-uses-dll-side-loading-in-espionage-campaign-targeting-9-countries</guid>
<description><![CDATA[ The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026.

The activity targeted industrial and electronics manufacturing, education and public-sector bodies, financial services, and professional services, per the Threat Hunter Team from Symantec and Carbon Black. ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkb692n4xA8jDUKZCkwPSIXqiyTaEk_bQhrNaZj33tRhusSP40-iwlk5x7iblb9M63WKWVbj8Gm6oPJZY3bm602-qFyLLnRXuCKsl40iAZG_5-ehqlQ4CYaO442hgo4FBKrspLCO4r_ET1U4U3fPCKCYOc7DFuDn_mv7ZzbzH_IC0NAt2HVVSxwIBNOruk/s1600/cyber-espionage.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 20:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>MuddyWater, Uses, DLL, Side-Loading, Espionage, Campaign, Targeting, Countries</media:keywords>
</item>

<item>
<title>Conifers rolls out AI&#45;powered SOC for unified security operations and automated response</title>
<link>https://block385.com/conifers-rolls-out-ai-powered-soc-for-unified-security-operations-and-automated-response</link>
<guid>https://block385.com/conifers-rolls-out-ai-powered-soc-for-unified-security-operations-and-automated-response</guid>
<description><![CDATA[ Conifers has announced the launch of its agentic SOC, a unified AI platform designed to help security operations centers defend against cyber adversaries operating at machine speed. Built on the company’s CognitiveSOC platform, the new system connects threat intelligence, threat hunting, detection engineering, investigation, and remediation into a single operating framework grounded in each customer’s institutional knowledge and governed with transparency and control. The launch comes as the cybersecurity industry confronts a fundamental shift in … More →
The post Conifers rolls out AI-powered SOC for unified security operations and automated response appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 17:00:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Conifers, rolls, out, AI-powered, SOC, for, unified, security, operations, and, automated, response</media:keywords>
</item>

<item>
<title>Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE&#45;2026&#45;34926)</title>
<link>https://block385.com/actively-exploited-trend-micro-apex-one-flaw-gets-cisa-warning-cve-2026-34926</link>
<guid>https://block385.com/actively-exploited-trend-micro-apex-one-flaw-gets-cisa-warning-cve-2026-34926</guid>
<description><![CDATA[ A relative directory path traversal vulnerability (CVE-2026-34926) in Trend Micro’s Apex One platform has been exploited in zero-day attacks, the company confirmed. “TrendAI has observed at least one attempt to exploit this vulnerability in the wild,” Trend Micro noted, and credited the incident response team of its TrendAI enterprise cybersecurity business for reporting it. About Trend Micro Apex One Trend Micro Apex One is a security platform that protects all the devices in an organization … More →
The post Actively exploited Trend Micro Apex One flaw gets CISA warning (CVE-2026-34926) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/01/08123728/trendmicro-1-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 17:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Actively, exploited, Trend, Micro, Apex, One, flaw, gets, CISA, warning, CVE-2026-34926</media:keywords>
</item>

<item>
<title>Detectify brings AppSec automation to AI agents with MCP Server and continuous testing</title>
<link>https://block385.com/detectify-brings-appsec-automation-to-ai-agents-with-mcp-server-and-continuous-testing</link>
<guid>https://block385.com/detectify-brings-appsec-automation-to-ai-agents-with-mcp-server-and-continuous-testing</guid>
<description><![CDATA[ Detectify has unveiled the Detectify MCP (Model Context Protocol) Server, a new integration layer that brings Detectify’s security testing engines directly into AI-driven development workflows, helping coding agents find and validate exploitable vulnerabilities and interpret attack surface data with greater precision. As organizations increasingly rely on AI agents to write, refactor, and modernize code, software production is accelerating faster than many security teams can realistically review or govern. While AI-assisted development can eliminate common coding … More →
The post Detectify brings AppSec automation to AI agents with MCP Server and continuous testing appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 17:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Detectify, brings, AppSec, automation, agents, with, MCP, Server, and, continuous, testing</media:keywords>
</item>

<item>
<title>Chinese phishing gangs grow into a force to be reckoned with</title>
<link>https://block385.com/chinese-phishing-gangs-grow-into-a-force-to-be-reckoned-with</link>
<guid>https://block385.com/chinese-phishing-gangs-grow-into-a-force-to-be-reckoned-with</guid>
<description><![CDATA[ Chinese-language phishing-as-a-service (PhaaS) communities are expanding in an area historically dominated by Russian-speaking cybercriminal groups. The Google Threat Intelligence Group (GTIG) analyzed a dozen active PhaaS offerings operating in Chinese-language underground communities and found mature services, with several likely linked to broader criminal activity in the region. Nearly all legitimate organizations mimicked by these phishing services were non-Chinese entities, suggesting that activity rarely targets China itself. Researchers noted that Telegram serves as a common channel … More →
The post Chinese phishing gangs grow into a force to be reckoned with appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/05/18153305/phishing-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 17:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Chinese, phishing, gangs, grow, into, force, reckoned, with</media:keywords>
</item>

<item>
<title>Anthropic: Claude Mythos identified 10,000+ software flaws</title>
<link>https://block385.com/anthropic-claude-mythos-identified-10000-software-flaws</link>
<guid>https://block385.com/anthropic-claude-mythos-identified-10000-software-flaws</guid>
<description><![CDATA[ Anthropic and its Project Glasswing partners have identified more than 10,000 high- or critical-severity vulnerabilities in critical software systems, the company announced in an update on the project’s progress. Mythos identifies thousands of high-severity vulnerabilities In April 2026, Anthropic introduced Claude Mythos Preview, a new large language model that can autonomously find zero-day vulnerabilities and create exploits for them. The company also launched Project Glasswing and gave Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, … More →
The post Anthropic: Claude Mythos identified 10,000+ software flaws appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/03/11120918/anthropic-2-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 17:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Anthropic:, Claude, Mythos, identified, 10, 000, software, flaws</media:keywords>
</item>

<item>
<title>[THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back</title>
<link>https://block385.com/thn-webinar-new-ai-ddos-attacks-are-smarter-learn-how-to-fight-back</link>
<guid>https://block385.com/thn-webinar-new-ai-ddos-attacks-are-smarter-learn-how-to-fight-back</guid>
<description><![CDATA[ Every single day, hackers are finding new ways to crash websites and steal data.

But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and much harder to stop.

According to recent updates from The Hacker News, bad actors are using AI to find weak spots in systems and ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiphaRoHMD4mkIzApkJZumEOEdIR0c_RxQrvmjv5qM6Kgo8MBnKrIAxicsojC-CdXhcOfRR9t0DxQeyEMXjXtER-bkSqe97zvFr7mfz3HjwA-79JjLWg0IwhZFTulr__kB02fXgX09tOpLWUjqy-fFmQbfvCZG-2uLLAhJpFAFrPo5d9H0PVZHEaSvmZKFE/s1600/ddossss.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 16:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>THN, Webinar, New, DDoS, Attacks, Are, Smarter., Learn, How, Fight, Back</media:keywords>
</item>

<item>
<title>CERT&#45;In Recommends 12&#45;Hour Patching for Internet&#45;Facing Flaws Amid AI&#45;Assisted Attacks</title>
<link>https://block385.com/cert-in-recommends-12-hour-patching-for-internet-facing-flaws-amid-ai-assisted-attacks</link>
<guid>https://block385.com/cert-in-recommends-12-hour-patching-for-internet-facing-flaws-amid-ai-assisted-attacks</guid>
<description><![CDATA[ The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where &quot;feasible&quot; to safeguard against potential threats stemming from threat actors&#039; abuse of artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerability ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9yN2AliOVdy0oCCMNYXnnrLjE6yWRz_eXVGFhiIw9vxnia2BMUxqhMrI8Q23Y2hHcF-hjqbw4aIqJTvO4zDD1k_WlKzEqx_FZ7P45mn8RiQ1UEqNUgqXv4DqrkzyyjjjgjKcPnNjzKHTTX8NIelTf4L_Cbx4XyYK6piDr1oPFfSmtk-59NCbU3cGCQEcQ/s1600/indian-cert.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 16:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CERT-In, Recommends, 12-Hour, Patching, for, Internet-Facing, Flaws, Amid, AI-Assisted, Attacks</media:keywords>
</item>

<item>
<title>Personal information of 185,000 people exposed after cyberattack on 7&#45;Eleven</title>
<link>https://block385.com/personal-information-of-185000-people-exposed-after-cyberattack-on-7-eleven</link>
<guid>https://block385.com/personal-information-of-185000-people-exposed-after-cyberattack-on-7-eleven</guid>
<description><![CDATA[ Data belonging to about 185,000 people was exposed following a cyberattack on convenience store chain 7-Eleven that was later claimed by the ShinyHunters extortion gang, according to Have I Been Pwned. The exposed information includes email addresses, names, physical addresses, dates of birth, and phone numbers, while a small number of records also contained additional data fields. 7-Eleven is a convenience store chain with more than 86,000 stores in 19 countries. On April 8, 2026, … More →
The post Personal information of 185,000 people exposed after cyberattack on 7-Eleven appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/02/25185231/data_breach-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 15:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Personal, information, 185, 000, people, exposed, after, cyberattack, 7-Eleven</media:keywords>
</item>

<item>
<title>Tamnoon introduces skill&#45;based AI orchestration for autonomous cloud defense</title>
<link>https://block385.com/tamnoon-introduces-skill-based-ai-orchestration-for-autonomous-cloud-defense</link>
<guid>https://block385.com/tamnoon-introduces-skill-based-ai-orchestration-for-autonomous-cloud-defense</guid>
<description><![CDATA[ Tamnoon has expanded its AI engine, Tami, into a skill-based orchestrator that generates customer-specific remediation skills tailored to each enterprise environment. Trained on more than 6 million real cloud fixes across 800+ accounts, Tami coordinates specialized AI skills to safely and autonomously address every class of cloud risk. Two new skills are available, Remediation Confidence Score and Safe Vulnerability Patching Simulator. Frontier AI is reshaping the cloud attack surface exponentially. AI ships vulnerable code 24/7, … More →
The post Tamnoon introduces skill-based AI orchestration for autonomous cloud defense appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 15:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Tamnoon, introduces, skill-based, orchestration, for, autonomous, cloud, defense</media:keywords>
</item>

<item>
<title>Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading</title>
<link>https://block385.com/remembering-tim-wilson-whose-legacy-lives-on-at-dark-reading</link>
<guid>https://block385.com/remembering-tim-wilson-whose-legacy-lives-on-at-dark-reading</guid>
<description><![CDATA[ The co-founder and former editor-in-chief passed away five years ago in November. As Dark Reading enters is third decade, we pause to celebrate and honor Wilson&#039;s instrumental role in building and elevating the media site. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltca0b99a2b1a5609d/6a0e204172bcb64834c99c46/timwine.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Remembering, Tim, Wilson, Whose, Legacy, Lives, Dark, Reading</media:keywords>
</item>

<item>
<title>New AI DDoS Attacks Are Smarter. Learn How to Fight Back in This Webinar</title>
<link>https://block385.com/new-ai-ddos-attacks-are-smarter-learn-how-to-fight-back-in-this-webinar</link>
<guid>https://block385.com/new-ai-ddos-attacks-are-smarter-learn-how-to-fight-back-in-this-webinar</guid>
<description><![CDATA[ Every single day, hackers are finding new ways to crash websites and steal data.

But right now, something has changed. Hackers are no longer working alone. They are now using powerful Artificial Intelligence (AI) tools to make their attacks faster, stronger, and much harder to stop.

According to recent updates from The Hacker News, bad actors are using AI to find weak spots in systems and ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg-Jzce1sDI3eaFwGE2RPtOHh63Itg1gN7ay6XupD8AzHxmOlIY4BCsjavyHIHk9DsFNbFBtFn8sGxY5pIQ9zA0vsTz-BfoJZsSND0sZHCx09DNvj_m2Ik4v-lXpcyLPKUrDyYO7T1pSYPpOB2CdBogBXKkWbzx97I26hxNNtrFBhLRBaj0xc-yNq89mC1d/s1600/ddoss.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 14:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, DDoS, Attacks, Are, Smarter., Learn, How, Fight, Back, This, Webinar</media:keywords>
</item>

<item>
<title>Microsoft Patches SharePoint RCE Flaw CVE&#45;2026&#45;45659 Across Server Versions</title>
<link>https://block385.com/microsoft-patches-sharepoint-rce-flaw-cve-2026-45659-across-server-versions</link>
<guid>https://block385.com/microsoft-patches-sharepoint-rce-flaw-cve-2026-45659-across-server-versions</guid>
<description><![CDATA[ Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met.

The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity.

&quot;Deserialization of untrusted data in Microsoft Office SharePoint allows ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi34meakbjhvY3-jNVG7Q8tPJ5Xk1a-vtGSeKgfVDApX6pn88G7gYhK2oz34my6QeWHsldmSJuV4o8tlBOmw-9Ul32EJYhC-aFmExZvn6ibinw10_4DhBf6pHmIum2Ha_HggakezqS_uKiOPJzrIdwioMru5Oj74p87z_ZbQt_c-bH8kQl6jEXYycod7Vrw/s1600/sharepoint.png" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 14:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Patches, SharePoint, RCE, Flaw, CVE-2026-45659, Across, Server, Versions</media:keywords>
</item>

<item>
<title>MFA Prompt Bombing: Why Your Second Factor Isn&amp;apos;t Saving You</title>
<link>https://block385.com/mfa-prompt-bombing-why-your-second-factor-isnt-saving-you</link>
<guid>https://block385.com/mfa-prompt-bombing-why-your-second-factor-isnt-saving-you</guid>
<description><![CDATA[ Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn&#039;t log in without the second factor. While that logic was sound, attackers have now figured out that they don&#039;t need to steal the second factor: they just need the user to hand it over.

If your workforce authenticates with ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtums9LZoPXx5AzbNIYmdrNPI6vAAWAnYGfW6NzZ4DkICva0wX2GjMPvmYoq4EVuhvWUc6FyLrgJJ0Hvh8w0TBJ4MLkQplbffUwg89oiQxoJhV-93mboD0D2rdkrrhsblZ2tLJv-auc2GBNjIMsg8wGUCYOkZHNDHaQoqhDbLXrFC3-rD3cz0pI12U7rR2/s1600/prompt-1.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 14:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>MFA, Prompt, Bombing:, Why, Your, Second, Factor, Isnt, Saving, You</media:keywords>
</item>

<item>
<title>High&#45;severity SharePoint RCE bug patched by Microsoft (CVE&#45;2026&#45;45659)</title>
<link>https://block385.com/high-severity-sharepoint-rce-bug-patched-by-microsoft-cve-2026-45659</link>
<guid>https://block385.com/high-severity-sharepoint-rce-bug-patched-by-microsoft-cve-2026-45659</guid>
<description><![CDATA[ Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. About CVE-2026-45659 CVE-2026-45659 stems from Shareoint deserializing untrusted data, and may be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance – no user interaction required. “The attack complexity is Low (AC:L) because … More →
The post High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/07/20231158/microsoft_sharepoint.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 13:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>High-severity, SharePoint, RCE, bug, patched, Microsoft, CVE-2026-45659</media:keywords>
</item>

<item>
<title>What happens when security teams inherit identity</title>
<link>https://block385.com/what-happens-when-security-teams-inherit-identity</link>
<guid>https://block385.com/what-happens-when-security-teams-inherit-identity</guid>
<description><![CDATA[ At the Span Cyber Security Arena conference, I sat down with Eric Woodruff, Chief Identity Architect at Semperis, to talk about how organizations perceive identity and the challenges those perceptions create for security. He shared his perspective on where organizations struggle with identity, why identity platforms can become difficult to manage, how phishing-resistant authentication is viewed in practice, and what non-human identities and AI could mean for security. Most boards still treat identity as an … More →
The post What happens when security teams inherit identity appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/26065906/eric_woodruff-2-semperis.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 13:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>What, happens, when, security, teams, inherit, identity</media:keywords>
</item>

<item>
<title>CERT&#45;In Mandates 12&#45;Hour Patching for Internet&#45;Facing Flaws Amid AI&#45;Assisted Attacks</title>
<link>https://block385.com/cert-in-mandates-12-hour-patching-for-internet-facing-flaws-amid-ai-assisted-attacks</link>
<guid>https://block385.com/cert-in-mandates-12-hour-patching-for-internet-facing-flaws-amid-ai-assisted-attacks</guid>
<description><![CDATA[ The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where &quot;feasible&quot; to safeguard against potential threats stemming from threat actors&#039; abuse of artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerability ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9yN2AliOVdy0oCCMNYXnnrLjE6yWRz_eXVGFhiIw9vxnia2BMUxqhMrI8Q23Y2hHcF-hjqbw4aIqJTvO4zDD1k_WlKzEqx_FZ7P45mn8RiQ1UEqNUgqXv4DqrkzyyjjjgjKcPnNjzKHTTX8NIelTf4L_Cbx4XyYK6piDr1oPFfSmtk-59NCbU3cGCQEcQ/s1600/indian-cert.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 12:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CERT-In, Mandates, 12-Hour, Patching, for, Internet-Facing, Flaws, Amid, AI-Assisted, Attacks</media:keywords>
</item>

<item>
<title>Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning</title>
<link>https://block385.com/iranian-hackers-deploy-minifast-and-minijunk-v2-via-phishing-and-seo-poisoning</link>
<guid>https://block385.com/iranian-hackers-deploy-minifast-and-minijunk-v2-via-phishing-and-seo-poisoning</guid>
<description><![CDATA[ The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizations in the aviation and software sectors across the U.S., Europe, and the Middle East following the joint U.S.-Israeli military campaign against the country in late February 2026.

The activity, besides embracing ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhL7Xqq7FlHxai3-wKrWcUujSg4cXnMJ_0LiXDaZHaZosFt3sPF1_PwcaqufOoM7q66vakQyKX5-odysTHOhtIG7ESj52Kna0i3OxaOA0sTONuH3NhkmautF8CTeiLBDzHFWjEvIT286ZnhERvK2VsvzxTdqjlEpXsbSELeqVHyr18JodeQZC-qudm2yblS/s1600/iran-hackers.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 12:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Iranian, Hackers, Deploy, MiniFast, and, MiniJunk, via, Phishing, and, SEO, Poisoning</media:keywords>
</item>

<item>
<title>Product showcase: F&#45;Secure Internet Security blocks phishing sites, fake stores, and SMS scams</title>
<link>https://block385.com/product-showcase-f-secure-internet-security-blocks-phishing-sites-fake-stores-and-sms-scams</link>
<guid>https://block385.com/product-showcase-f-secure-internet-security-blocks-phishing-sites-fake-stores-and-sms-scams</guid>
<description><![CDATA[ F-Secure Internet Security protects against viruses, ransomware, spyware, infected email attachments, and other cyber threats. It focuses on securing devices and online activity through malware protection, scam prevention, safe browsing, and banking safeguards. The platform supports Windows, macOS, Android, and iOS devices under a single subscription. After downloading the Android app from the Play Store, I created an account and started using it. The setup process included enabling Device Protection, VPN, Scam Protection, and ID … More →
The post Product showcase: F-Secure Internet Security blocks phishing sites, fake stores, and SMS scams appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/25135732/f-secure-internet-security.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Product, showcase:, F-Secure, Internet, Security, blocks, phishing, sites, fake, stores, and, SMS, scams</media:keywords>
</item>

<item>
<title>KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike</title>
<link>https://block385.com/knowledgedeliver-lms-flaw-exploited-to-deploy-godzilla-and-cobalt-strike</link>
<guid>https://block385.com/knowledgedeliver-lms-flaw-exploited-to-deploy-godzilla-and-cobalt-strike</guid>
<description><![CDATA[ A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon.

The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), stems from the use of hard-coded ASP.NET machine keys, leading to ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZKxsveHlyTguEODsRiYVuCPiOkIgyd3imCYdnpwwV2NQ0pw9oPEQoVw-2T98HW0KgZvRqQ_zeZIT-4E3b6WH6hE-fxJeZ9YN2S9T5769SS11QP-Pf8E1kf8kk0mbwyX_sjXTgrqKDzbDivmQRRmB_qGQmTKkB673oTFD-gWDet_ptXihujQMioqvryplT/s1600/KnowledgeDeliver.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 08:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>KnowledgeDeliver, LMS, Flaw, Exploited, Deploy, Godzilla, and, Cobalt, Strike</media:keywords>
</item>

<item>
<title>Cybersecurity jobs available right now: May 26, 2026</title>
<link>https://block385.com/cybersecurity-jobs-available-right-now-may-26-2026</link>
<guid>https://block385.com/cybersecurity-jobs-available-right-now-may-26-2026</guid>
<description><![CDATA[ Application Security Engineer IG Group | India | Hybrid – View job details As an Application Security Engineer, you will assess the security of web, mobile, and cloud applications through penetration testing, secure code reviews, threat modeling, and architecture reviews. Responsibilities also include integrating security into CI/CD pipelines, managing vulnerability remediation, supporting purple team activities, training developers on secure coding practices, and assisting with application security incident response. CISO LianLian | Austria | Hybrid – … More →
The post Cybersecurity jobs available right now: May 26, 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/11140410/cybersecurity_jobs-4-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 07:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cybersecurity, jobs, available, right, now:, May, 26, 2026</media:keywords>
</item>

<item>
<title>Manage machine identities: The hidden privileged access layer you need to manage</title>
<link>https://block385.com/manage-machine-identities-the-hidden-privileged-access-layer-you-need-to-manage</link>
<guid>https://block385.com/manage-machine-identities-the-hidden-privileged-access-layer-you-need-to-manage</guid>
<description><![CDATA[ Why are machine identities becoming the majority of “things with access”? Every automation, integration, and workload needs a way to authenticate and the right permissions to act. That quiet requirement has created a massive population of machine identities, also called non-human identities (NHIs): service accounts, service principals, workload roles, OAuth apps, AI agents, and IAM roles. Machine identities authenticate using credentials like access keys, secrets, and tokens. Many of these identities hold privileges equal to … More →
The post Manage machine identities: The hidden privileged access layer you need to manage appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/25092139/delinea-managing_machine_identities.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 26 May 2026 07:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Manage, machine, identities:, The, hidden, privileged, access, layer, you, need, manage</media:keywords>
</item>

<item>
<title>Cisco refines its risk&#45;based vulnerability disclosure for the AI era</title>
<link>https://block385.com/cisco-refines-its-risk-based-vulnerability-disclosure-for-the-ai-era</link>
<guid>https://block385.com/cisco-refines-its-risk-based-vulnerability-disclosure-for-the-ai-era</guid>
<description><![CDATA[ Security teams already struggle with long lists of vulnerabilities and limited time to patch them. Cisco believes AI could increase that pressure by accelerating vulnerability discovery and increasing the number of findings security teams need to review. The company said it is moving further toward a risk-based disclosure approach, placing greater attention on issues under active exploitation or those considered more likely to be used in attacks. “Cisco is actively leveraging advanced AI Models to … More →
The post Cisco refines its risk-based vulnerability disclosure for the AI era appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/15100810/cisco-lines-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 19:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cisco, refines, its, risk-based, vulnerability, disclosure, for, the, era</media:keywords>
</item>

<item>
<title>Anthropic adds 28 security and compliance integrations for Claude</title>
<link>https://block385.com/anthropic-adds-28-security-and-compliance-integrations-for-claude</link>
<guid>https://block385.com/anthropic-adds-28-security-and-compliance-integrations-for-claude</guid>
<description><![CDATA[ AI tools are becoming part of everyday work in organizations, creating new security and oversight requirements as usage grows. To address that, Anthropic introduced 28 integrations with security and compliance tools that allow IT and security teams to manage Claude in the same way they manage other applications in their environments. The integrations are powered by the Claude Compliance API, which gives enterprise teams programmatic access to two types of data. The first category involves … More →
The post Anthropic adds 28 security and compliance integrations for Claude appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/04/14132052/anthropic-red-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Anthropic, adds, security, and, compliance, integrations, for, Claude</media:keywords>
</item>

<item>
<title>⚡ Weekly Recap: Linux Flaws, Defender 0&#45;Days, Router Botnets, and Supply Chain Chaos</title>
<link>https://block385.com/weekly-recap-linux-flaws-defender-0-days-router-botnets-and-supply-chain-chaos</link>
<guid>https://block385.com/weekly-recap-linux-flaws-defender-0-days-router-botnets-and-supply-chain-chaos</guid>
<description><![CDATA[ Monday recap. Same mess, new week.

A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should&#039;ve patched years ago. Good times.

Phishing crews are getting smarter too - less obvious scam junk, more targeted stuff that actually ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8B3KNTIZROmtfiYkIEINzg34cq_-I4prGGMjQ8F8oHbOcrNNB0FyCuQq-bb9ChCEtkO5TxGqm_5YRrG7r3IJAkcsX_eC3vmpR1Va-b3NOfEQynjPDmOm2A_uJ15IZk5VPnrmZzOKKjzA6_kjUFNbUkFHKsEk_Ts92DfPZXa3x4r8o8UQkOpMmNUfBwGxx/s1600/rere.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 18:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>⚡, Weekly, Recap:, Linux, Flaws, Defender, 0-Days, Router, Botnets, and, Supply, Chain, Chaos</media:keywords>
</item>

<item>
<title>Authorities seize 800 servers used for cyberattacks and disinformation</title>
<link>https://block385.com/authorities-seize-800-servers-used-for-cyberattacks-and-disinformation</link>
<guid>https://block385.com/authorities-seize-800-servers-used-for-cyberattacks-and-disinformation</guid>
<description><![CDATA[ Dutch authorities arrested two men and seized 800 servers linked to a hosting provider that investigators say supported Russian activities aimed at undermining democracy and security through cyberattacks, disinformation, and disruption of public and economic systems. Servers seized by Dutch authorities (Source: FIOD) The Dutch Fiscal Information and Investigation Service (FIOD) arrested a 57-year-old man from Amsterdam and a 39-year-old man from The Hague on suspicion of violating Dutch sanctions laws. The two men allegedly … More →
The post Authorities seize 800 servers used for cyberattacks and disinformation appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/04/28154436/sentence-court5-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Authorities, seize, 800, servers, used, for, cyberattacks, and, disinformation</media:keywords>
</item>

<item>
<title>US states step up cyber defenses to protect local communities</title>
<link>https://block385.com/us-states-step-up-cyber-defenses-to-protect-local-communities</link>
<guid>https://block385.com/us-states-step-up-cyber-defenses-to-protect-local-communities</guid>
<description><![CDATA[ U.S. state governments are taking on a larger role in cybersecurity to help protect local communities and essential services. Many states are building state-led cyber defense programs, including cybersecurity clinics, regional security operations centers (RSOCs), and state cyber corps programs to reduce costs, strengthen the local workforce, and improve cyber resilience. Cyber defense programs in the U.S. as of April 2026 (Source: UC Berkley, CLTC) Some states are expanding shared services, centralized procurement, cyber risk … More →
The post US states step up cyber defenses to protect local communities appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/02/24150622/lock-red-people-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 15:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>states, step, cyber, defenses, protect, local, communities</media:keywords>
</item>

<item>
<title>Ghost CMS CVE&#45;2026&#45;26980 Exploited to Hijack 700+ Sites for ClickFix Attacks</title>
<link>https://block385.com/ghost-cms-cve-2026-26980-exploited-to-hijack-700-sites-for-clickfix-attacks</link>
<guid>https://block385.com/ghost-cms-cve-2026-26980-exploited-to-hijack-700-sites-for-clickfix-attacks</guid>
<description><![CDATA[ Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks.

According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in Ghost&#039;s Content API that could allow an unauthenticated attacker to read arbitrary data from the ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5bYCvN_MmCGXVH5raR8wqJQv52CST3mK7UBfLXVnqRRL_rHkhJpSOBjdPyR5oXmPsSB-X3-Sib6-eVToqi4UXB218ESR2uFdczESGAM5i4ZkxQyE7AkQteCFCasknPz262ceUOFccS3xcUbaQdvUGoRw0kJE7QQMSbeP2OAQVfY9lFYTj7ZhzCL_GdkuM/s1600/check-cf.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 14:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Ghost, CMS, CVE-2026-26980, Exploited, Hijack, 700, Sites, for, ClickFix, Attacks</media:keywords>
</item>

<item>
<title>The Alert Firehose Finally Meets Its Match</title>
<link>https://block385.com/the-alert-firehose-finally-meets-its-match</link>
<guid>https://block385.com/the-alert-firehose-finally-meets-its-match</guid>
<description><![CDATA[ Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear &quot;Noisy,&quot; &quot;Too much data.&quot; But ask the teams running NDR that includes agentic AI capabilities and you&#039;ll hear they&#039;re actually using it to catch threats earlier, triage faster, and chase fewer false positives. The old complaint lingers in part because reputations are sticky, and because NDR has evolved ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhULc1VvUr1LQ1qZPTiw_sPmN3JbNIk0OSlxHRT0MFdY2kM5Z7psdZtrctiSOybvu8i1sCwcMeSUtXxHb0xBkQ2lCUt2l_kKmhp93ydvN4-E-qObRkmiFK2s-jOPqipBTGfBnv4o-d9nLuPIL2JMGO6FhCFsFV2NkBlARzWW9ScqccGvAVHzM9o-6MDwn4/s1600/corelight-main.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 14:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, Alert, Firehose, Finally, Meets, Its, Match</media:keywords>
</item>

<item>
<title>Lazarus Deploys RemotePE Memory&#45;Only RAT Against Financial and Crypto Firms</title>
<link>https://block385.com/lazarus-deploys-remotepe-memory-only-rat-against-financial-and-crypto-firms</link>
<guid>https://block385.com/lazarus-deploys-remotepe-memory-only-rat-against-financial-and-crypto-firms</guid>
<description><![CDATA[ Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations.

RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain that involves two loaders tracked as DPAPILoader and RemotePELoader.

&quot;DPAPILoader decrypts and ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEinuOeS1qVC0UHhPnJ0jlSdfScsZDRtkI6VU366iePjKdNTqLiqHcqjRcGL-sNBdUkShUH71YDDVwavzXM1cIu2UU9zE8VYgbJYsRUQeWRZAO75JC2vQHYs4saWOM3rQZKFPqNvlL8ASBocRiZXdO1jLgqLuCCeLHX0bAA1EQEhiBAq3i3Os97qHt_xF5ub/s1600/crypto-firms.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 14:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Lazarus, Deploys, RemotePE, Memory-Only, RAT, Against, Financial, and, Crypto, Firms</media:keywords>
</item>

<item>
<title>TrapDoor Supply Chain Attack Spreads Credential&#45;Stealing Malware via npm, PyPI, and CratesIO</title>
<link>https://block385.com/trapdoor-supply-chain-attack-spreads-credential-stealing-malware-via-npm-pypi-and-cratesio</link>
<guid>https://block385.com/trapdoor-supply-chain-attack-spreads-credential-stealing-malware-via-npm-pypi-and-cratesio</guid>
<description><![CDATA[ A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware.

The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, 2026, at 8:20 p.m. UTC, with new packages published to the ecosystems in waves from a cluster of ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOb58wXNPgRDazHcSLTObawPnMVsCDUEAoFclGVn3CC8qe6Pr_0-Gce-SxCO7FJ5HzU23WE_soU5iTc0zvLL0zzbXPcO8MqVgHIIAKXJo4ExcujDPV9yiIdN1X1jV63ACBN66_ktTeQ0FVmYsCTJC3tpyxpUBrvxLh_xqF-mKOZy8uaqz3QKyf6XpJHC4z/s1600/npm-python-rust.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 10:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>TrapDoor, Supply, Chain, Attack, Spreads, Credential-Stealing, Malware, via, npm, PyPI, and, CratesIO</media:keywords>
</item>

<item>
<title>OpenHack: Open&#45;source AI&#45;powered vulnerability research</title>
<link>https://block385.com/openhack-open-source-ai-powered-vulnerability-research</link>
<guid>https://block385.com/openhack-open-source-ai-powered-vulnerability-research</guid>
<description><![CDATA[ Source-guided vulnerability research increasingly leans on coding harnesses such as Claude Code, Codex, and Cursor to drive agent-based reviews of application code. A new MIT-licensed project from the Dutch security firm Hadrian, called OpenHack, packages that approach into a file-based workspace that any of those harnesses can run. OpenHack is a set of agents and tools that mimics how Hadrian’s research team performs automated vulnerability research. The workflow runs inside a coding harness or a … More →
The post OpenHack: Open-source AI-powered vulnerability research appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/22103105/openhack-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 09:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>OpenHack:, Open-source, AI-powered, vulnerability, research</media:keywords>
</item>

<item>
<title>Lessons for organizations from the Verizon 2026 Data Breach Investigations Report</title>
<link>https://block385.com/lessons-for-organizations-from-the-verizon-2026-data-breach-investigations-report</link>
<guid>https://block385.com/lessons-for-organizations-from-the-verizon-2026-data-breach-investigations-report</guid>
<description><![CDATA[ This is my favourite time of the year, not just because spring is here and the promise of summer is on the way. But also, because one of my must reads each year gets published. There are a few must read reports that I have on my reading list for each year and the Verizon Data Breach Investigations Report is on top of that list. The latest Verizon 2026 Data Breach Investigations Report (DBIR) once … More →
The post Lessons for organizations from the Verizon 2026 Data Breach Investigations Report appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/29222743/world-map-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Lessons, for, organizations, from, the, Verizon, 2026, Data, Breach, Investigations, Report</media:keywords>
</item>

<item>
<title>Turns out the C&#45;suite loves shadow AI</title>
<link>https://block385.com/turns-out-the-c-suite-loves-shadow-ai</link>
<guid>https://block385.com/turns-out-the-c-suite-loves-shadow-ai</guid>
<description><![CDATA[ Senior decision-makers are the heaviest users of unapproved AI tools, and they continue using them despite being aware of the security and privacy risks linked to shadow AI, according to TrustedTech’s Shadow AI in the Workplace report. The study found that 65% of decision-makers use shadow AI, compared with 31% of employees below decision-maker level. Net Shadow AI use (Source: TrustedTech) The data suggests that shadow AI is not mainly driven by junior employees experimenting … More →
The post Turns out the C-suite loves shadow AI appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/10/31095821/shadow-ai-3d.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 07:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Turns, out, the, C-suite, loves, shadow</media:keywords>
</item>

<item>
<title>Boards want cyber risk in dollars, not CVE counts</title>
<link>https://block385.com/boards-want-cyber-risk-in-dollars-not-cve-counts</link>
<guid>https://block385.com/boards-want-cyber-risk-in-dollars-not-cve-counts</guid>
<description><![CDATA[ In this Help Net Security video, Ziv Levi, SVP of Technology at CYE, explains why translating cyber risk into dollars is one of the most pressing tasks for security leaders. Boards and executives want cyber exposure described in business terms, not technical jargon. Levi walks through a three-step financial translation framework. First, identify business exposure by mapping attack paths to the assets that matter most, such as intellectual property and customer data. Second, focus on … More →
The post Boards want cyber risk in dollars, not CVE counts appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/22084337/money.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 25 May 2026 07:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Boards, want, cyber, risk, dollars, not, CVE, counts</media:keywords>
</item>

<item>
<title>Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited</title>
<link>https://block385.com/week-in-review-github-breached-via-poisoned-vs-code-extension-critical-nginx-flaw-exploited</link>
<guid>https://block385.com/week-in-review-github-breached-via-poisoned-vs-code-extension-critical-nginx-flaw-exploited</guid>
<description><![CDATA[ Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension Following TeamPCP’s claim that they’ve breached GitHub’s own private code repositories, the Microsoft-owned company launched an investigation and confirmed the compromise. Earbud sensors can authenticate users by their heartbeat, study finds Researchers built a continuous authentication system called AccLock that identifies a wearer by the tiny vibrations a heartbeat makes … More →
The post Week in review: GitHub breached via poisoned VS Code extension, critical NGINX flaw exploited appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/25124832/cybersecurity-week-review-2-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Sun, 24 May 2026 11:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Week, review:, GitHub, breached, via, poisoned, Code, extension, critical, NGINX, flaw, exploited</media:keywords>
</item>

<item>
<title>npm Adds 2FA&#45;Gated Publishing and Package Install Controls Against Supply Chain Attacks</title>
<link>https://block385.com/npm-adds-2fa-gated-publishing-and-package-install-controls-against-supply-chain-attacks</link>
<guid>https://block385.com/npm-adds-2fa-gated-publishing-and-package-install-controls-against-supply-chain-attacks</guid>
<description><![CDATA[ GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation.

Called staged publishing, the feature is now generally available on npm. It mandates that a human maintainer pass a two-factor authentication (2FA) challenge to approve ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4rnMZgOYbsYr65UN9AZ3oFzcAwqXSYqgRfjUGpeaQeyP-0OAaqJ9aceXPAiujRKwyGQMa_4ShcSvtOWPb9T3qpqF2LATAw2U4iA7IkU9ok0alDbzN_WYJeaZ1SrF0-vyRrEHGedMEcCeP2otYYqplHmqEBda1R_MePbWgEpt-b-GB_RhxJLDC1pJFV0S0/s1600/npm-security.png" length="49398" type="image/jpeg"/>
<pubDate>Sat, 23 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>npm, Adds, 2FA-Gated, Publishing, and, Package, Install, Controls, Against, Supply, Chain, Attacks</media:keywords>
</item>

<item>
<title>Packagist Supply Chain Attack Infects 8 Packages Using GitHub&#45;Hosted Linux Malware</title>
<link>https://block385.com/packagist-supply-chain-attack-infects-8-packages-using-github-hosted-linux-malware</link>
<guid>https://block385.com/packagist-supply-chain-attack-infects-8-packages-using-github-hosted-linux-malware</guid>
<description><![CDATA[ A new &quot;coordinated&quot; supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL.

&quot;Although the affected packages were all Composer packages, the malicious code was not added to composer.json,&quot; Socket said. &quot;Instead, it was inserted into package.json, targeting projects that ship JavaScript ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiQ5LyRYJIkEVUSrrBV-_qvrXIKC-B4h0JAxyV4IalzuiEzXi6KeCnZNTUWIIld3oeC5kDx85xppqYm9tG_UB3_Sss9WqH2bYsOVxkB3PhjUk_cQrdyvr6JKsYgn35_sESYYsLC_OuKN9_2korX__RfHwkecLX_BGk7aajnm3sfNqbpV4Pl55B1fpSBpbOA/s1600/packagist.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sat, 23 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Packagist, Supply, Chain, Attack, Infects, Packages, Using, GitHub-Hosted, Linux, Malware</media:keywords>
</item>

<item>
<title>Claude Mythos AI Finds 10,000 High&#45;Severity Flaws in Widely Used Software</title>
<link>https://block385.com/claude-mythos-ai-finds-10000-high-severity-flaws-in-widely-used-software</link>
<guid>https://block385.com/claude-mythos-ai-finds-10000-high-severity-flaws-in-widely-used-software</guid>
<description><![CDATA[ Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most &quot;systemically&quot; important software across the world since the cybersecurity initiative went live last month.

Project Glasswing is an effort led by the artificial intelligence (AI) company, as part of which a small set of about 50 partners ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOPcHXcMRS-BJNvy9aeoCz5H2Mmdh6mO6Kl3kM-l216B-3Wc0Iy5wayPkxJ79KtkHx2CGBwDVPMMeuB9E3jQlPXsa-vKqALoAuTwmEwsbH5sK0xs9xb_XWgk4uaGazYAcswrLxdX0QL74k7e85WXfL03rHFQStuxqpJFsJBcAQLOvNXSuX2YNBAScQStvj/s1600/claude-mythos-flaws.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sat, 23 May 2026 14:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Claude, Mythos, Finds, 10, 000, High-Severity, Flaws, Widely, Used, Software</media:keywords>
</item>

<item>
<title>Laravel&#45;Lang PHP Packages Compromised to Deliver Cross&#45;Platform Credential Stealer</title>
<link>https://block385.com/laravel-lang-php-packages-compromised-to-deliver-cross-platform-credential-stealer</link>
<guid>https://block385.com/laravel-lang-php-packages-compromised-to-deliver-cross-platform-credential-stealer</guid>
<description><![CDATA[ Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to  Laravel-Lang to deliver a comprehensive credential-stealing framework.

The affected packages include -


  laravel-lang/lang
  laravel-lang/http-statuses
  laravel-lang/attributes
  laravel-lang/actions

&quot;The timing and pattern of the newly published tags ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkqwlAgmL-HrE2pSx8xqfY4-AyYZ59wK4x5AWtnCXSHRoBO1wcYTpWw42Fe6VRoAT77e914MSqZW56fKX95IueHTCrk10XNn2Yxh7CU8iCdX5lzFowGeVkolW-4E3po81w9pFMsaLR_r85abtUv3bwvQMa6pP1BAiSj4DrmapTiYr1twfV61tvGdWJRgs8/s1600/lang-hack.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sat, 23 May 2026 12:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Laravel-Lang, PHP, Packages, Compromised, Deliver, Cross-Platform, Credential, Stealer</media:keywords>
</item>

<item>
<title>LiteSpeed cPanel Plugin CVE&#45;2026&#45;48172 Exploited to Run Scripts as Root</title>
<link>https://block385.com/litespeed-cpanel-plugin-cve-2026-48172-exploited-to-run-scripts-as-root</link>
<guid>https://block385.com/litespeed-cpanel-plugin-cve-2026-48172-exploited-to-run-scripts-as-root</guid>
<description><![CDATA[ A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild.

The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions.

&quot;Any cPanel user (including an attacker or a compromised account) may ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjM0W1UqsbcZ-8IV_n8ov3V24MQ74VaKe3auGFWNunDUfubEBeKEGREuFjC9-i7H_fLfSwFQQ5wqe8bhVWvAUVC_8U5AQg1c1Qbe-M7bSjuWCwcjTRrc2Du7L0Tm-NKO7ErhPUTR7YS6b1vkpmbYS1VaClWUGOvGe4cxv-jHkQFZMXbSDLfBiF7FFwd7Nfe/s1600/lightspeed.png" length="49398" type="image/jpeg"/>
<pubDate>Sat, 23 May 2026 10:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>LiteSpeed, cPanel, Plugin, CVE-2026-48172, Exploited, Run, Scripts, Root</media:keywords>
</item>

<item>
<title>Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV</title>
<link>https://block385.com/drupal-core-sql-injection-bug-actively-exploited-added-to-cisa-kev</link>
<guid>https://block385.com/drupal-core-sql-injection-bug-actively-exploited-added-to-cisa-kev</guid>
<description><![CDATA[ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core.

&quot;Drupal Core ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKqQ4Uk8lGWwF7f6lrmP6dRHkEmQTJsqFs8xvJ5256xUcHTeWMNVMkPguALNqLPpJWneU9XWIEzi4jSUVTiS2In1QMSl7NEjNDB99yHlGeCjw4OAQ3Lx8jhE5l9RUGMmth_ecUC1GcgierrFk8XKREHXC73mQn3w3jFcqjvJL1UZpPJPP62Uv-IpfBafRI/s1600/cisa-drupal.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sat, 23 May 2026 10:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Drupal, Core, SQL, Injection, Bug, Actively, Exploited, Added, CISA, KEV</media:keywords>
</item>

<item>
<title>First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups</title>
<link>https://block385.com/first-vpn-dismantled-in-global-takedown-over-use-by-25-ransomware-groups</link>
<guid>https://block385.com/first-vpn-dismantled-in-global-takedown-over-use-by-25-ransomware-groups</guid>
<description><![CDATA[ Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks.

The disruption of First VPN Service was led by France and the Netherlands, with several other nations supporting the investigation since December ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8yN-yeHodasj_piRqdUbE1MGyOfiyAzo-x6KZ_V9oilxP_v_kFNoyLVU7oNmG05F5g49pLeMY_jgJtU0mFk9ft_0qi4oLFgTxm0KWBncWw9lq0lVJFdkzshBzjul-2ODkaGNoLbgFUqKXbwKJJiF8nm0E6u7q6hnK_Vzb07XT-iygxE6Ct3bxW7A6s6f8/s1600/firstvpn.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>First, VPN, Dismantled, Global, Takedown, Over, Use, Ransomware, Groups</media:keywords>
</item>

<item>
<title>Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware</title>
<link>https://block385.com/ghostwriter-targets-ukraine-government-entities-with-prometheus-phishing-malware</link>
<guid>https://block385.com/ghostwriter-targets-ukraine-government-entities-with-prometheus-phishing-malware</guid>
<description><![CDATA[ The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine&#039;s National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country.

The activity, per the Computer Emergency Response Team of Ukraine (CERT-UA), involves sending phishing emails to government ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhNDmjcnVzVIqFFB-CQU7L6G8XVTifkZGmIMcPrui1EoffwwvtPXCrjKhRtIfxYsfPb5OUON4KQ1MVRosbP1BgCeFpqIIWRbgv34naUxEUTzyGRsPB6fY2gJJa5AXgT085SLFuc8ykNinXhnnpQzGAT2Kw1YwNe05vxSxlb6EVTu8_CoDws3QwR_SCk7dXm/s1600/ukuk.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Ghostwriter, Targets, Ukraine, Government, Entities, with, Prometheus, Phishing, Malware</media:keywords>
</item>

<item>
<title>Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers</title>
<link>https://block385.com/akamai-joins-growing-chorus-of-vendors-betting-big-on-secure-enterprise-browsers</link>
<guid>https://block385.com/akamai-joins-growing-chorus-of-vendors-betting-big-on-secure-enterprise-browsers</guid>
<description><![CDATA[ When Akamai announced its LayerX acquisition, the company joined a growing list of vendors adding secure enterprise browsers to their product portfolios. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltf459c9ff5d345e58/686d20d8a502a804ecf992c7/browser-security-Robert_Avgustin-shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 19:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Akamai, Joins, Growing, Chorus, Vendors, Betting, Big, Secure, Enterprise, Browsers</media:keywords>
</item>

<item>
<title>$20 per zero&#45;day is already the WordPress plugin reality</title>
<link>https://block385.com/20-per-zero-day-is-already-the-wordpress-plugin-reality</link>
<guid>https://block385.com/20-per-zero-day-is-already-the-wordpress-plugin-reality</guid>
<description><![CDATA[ Vulnerability researchers have spent the past year arguing about whether AI agents can find real bugs at scale or whether they mostly generate noise. A pipeline built in three days by researchers from TrendAI and CHT Security supplies an answer, along with a price tag that the security industry will have to reckon with. The system, presented at Ekoparty Miami, pairs AI-driven static analysis with automated Docker provisioning and dynamic verification through Chrome DevTools MCP. … More →
The post $20 per zero-day is already the WordPress plugin reality appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18093519/wordpress-explode.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 17:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>20, per, zero-day, already, the, WordPress, plugin, reality</media:keywords>
</item>

<item>
<title>Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks</title>
<link>https://block385.com/verizon-dbir-healthcare-fends-off-increased-social-engineering-attacks</link>
<guid>https://block385.com/verizon-dbir-healthcare-fends-off-increased-social-engineering-attacks</guid>
<description><![CDATA[ Ransomware and vendor breaches persist, but the 2026 Data Breach Investigations Report (DBIR) highlights how evolving social engineering tactics make the sector more vulnerable. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt239496a9d5a17a58/6a105fcb611161e1e7c5239b/patterns-healthcare-2026dbir.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 17:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Verizon, DBIR:, Healthcare, Fends, Off, Increased, Social, Engineering, Attacks</media:keywords>
</item>

<item>
<title>Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows</title>
<link>https://block385.com/megalodon-github-attack-targets-5561-repos-with-malicious-cicd-workflows</link>
<guid>https://block385.com/megalodon-github-attack-targets-5561-repos-with-malicious-cicd-workflows</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window.

&quot;Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjC_sjVeLejyyBZJ0DWW2y9-Z2Jvmrzz9h-5XEIKPFTcJvDj49Jlt-z1FNbSp51K9XcQ8FqC9MBDFPPPdZuzRfjqtYvKNaqT0Qzd61oCHVhNq59IcAVcWV3LvDmKCsX5pHn4nU3LclQPEozMp3XsgYZnVHCZEj89AGkWJpqL1EjCjiqMLnvggZLsgb08MYp/s1600/github-worm.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 16:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Megalodon, GitHub, Attack, Targets, 5, 561, Repos, with, Malicious, CICD, Workflows</media:keywords>
</item>

<item>
<title>Making Vulnerable Drivers Exploitable Without Hardware &#45; The BYOVD Perspective</title>
<link>https://block385.com/making-vulnerable-drivers-exploitable-without-hardware-the-byovd-perspective</link>
<guid>https://block385.com/making-vulnerable-drivers-exploitable-without-hardware-the-byovd-perspective</guid>
<description><![CDATA[ 1 Introduction

This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed for. This work was motivated by driver-oriented vulnerability research and the need to evaluate the exploitability of individual findings, which frequently affect code whose reachability is hardware-gated. The ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiUdjbDFZeTbwpdUFibGsmuDSgX_NHbFfTYroqcGYEGB6yvuKR3eUBSHo9XaphMTYmXC3cqmICDOGUjlsBrwwyJOxzkj1Cdh2xZcYxLz1WpHrV9QmloScYivp7jfyynDTiB51MTpsgGffJ9bZgYJeV3VhY6OA32tot8mC08F-g6KpU47zR513SkVqk-hIim/s1600/driver.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 16:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Making, Vulnerable, Drivers, Exploitable, Without, Hardware, The, BYOVD, Perspective</media:keywords>
</item>

<item>
<title>Deleted Google API keys keep working for up to 23 minutes, researchers warn</title>
<link>https://block385.com/deleted-google-api-keys-keep-working-for-up-to-23-minutes-researchers-warn</link>
<guid>https://block385.com/deleted-google-api-keys-keep-working-for-up-to-23-minutes-researchers-warn</guid>
<description><![CDATA[ Google API keys are credentials that let applications access Google services, from Maps to the Gemini AI. If a key is leaked, an attacker can use it to make API calls, rack up charges, and, if Gemini is enabled, access uploaded files and cached conversations. The assumed fix is simple: delete the key. But Aikido Security has found that deletion doesn’t actually work right away. The testing The researcherd found successful authentications up to 23 … More →
The post Deleted Google API keys keep working for up to 23 minutes, researchers warn appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/02/09085513/keys2-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 15:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Deleted, Google, API, keys, keep, working, for, minutes, researchers, warn</media:keywords>
</item>

<item>
<title>Kore.ai unveils AI&#45;native platform for enterprise multiagent systems</title>
<link>https://block385.com/koreai-unveils-ai-native-platform-for-enterprise-multiagent-systems</link>
<guid>https://block385.com/koreai-unveils-ai-native-platform-for-enterprise-multiagent-systems</guid>
<description><![CDATA[ Kore.ai has launched the new-generation Kore.ai Agent Platform Artemis edition, the AI-programmable, AI-native foundation that builds, governs, and optimizes the agents, systems, and workflows running across the enterprise. The platform launches initially on Microsoft Azure, with broader cloud availability to follow. The new-generation Kore.ai Agent Platform enables enterprises to deploy production-ready multiagent AI systems in days instead of months, with governance, observability, and operational control enforced before any agent goes live. Three core innovations make … More →
The post Kore.ai unveils AI-native platform for enterprise multiagent systems appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 15:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Kore.ai, unveils, AI-native, platform, for, enterprise, multiagent, systems</media:keywords>
</item>

<item>
<title>China&amp;apos;s Webworm Uses Discord, Microsoft Graphs to Hack EU Governments</title>
<link>https://block385.com/chinas-webworm-uses-discord-microsoft-graphs-to-hack-eu-governments</link>
<guid>https://block385.com/chinas-webworm-uses-discord-microsoft-graphs-to-hack-eu-governments</guid>
<description><![CDATA[ The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt9bbd9e9f246990ad/6a0f5eeab6882cd3afc7c328/Discord_app_iPhone_True_Images_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Chinas, Webworm, Uses, Discord, Microsoft, Graphs, Hack, Governments</media:keywords>
</item>

<item>
<title>Meet Fractal, an OS made for microarchitecture reverse engineering</title>
<link>https://block385.com/meet-fractal-an-os-made-for-microarchitecture-reverse-engineering</link>
<guid>https://block385.com/meet-fractal-an-os-made-for-microarchitecture-reverse-engineering</guid>
<description><![CDATA[ Probing how a CPU isolates user code from kernel code is messy work. Researchers patch kernels, write drivers, or boot stripped-down bare-metal programs, and any of those choices change variables they were trying to hold still. Fractal, a new operating system from MIT CSAIL, was built to take that mess out of the loop, and its authors used it to surface previously undocumented behavior in the Apple M1 branch predictor. Joseph Ravichandran and Mengjia Yan … More →
The post Meet Fractal, an OS made for microarchitecture reverse engineering appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/22105406/fractal-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 13:00:16 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Meet, Fractal, made, for, microarchitecture, reverse, engineering</media:keywords>
</item>

<item>
<title>Microsoft 365 users targeted by new phishing threat that bypasses MFA</title>
<link>https://block385.com/microsoft-365-users-targeted-by-new-phishing-threat-that-bypasses-mfa</link>
<guid>https://block385.com/microsoft-365-users-targeted-by-new-phishing-threat-that-bypasses-mfa</guid>
<description><![CDATA[ Microsoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is warning. First observed in April 2026, Kali365 has been distributed through Telegram, allowing cybercriminals to obtain Microsoft 365 access tokens and bypass MFA without stealing user credentials. “Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities,” the FBI said. … More →
The post Microsoft 365 users targeted by new phishing threat that bypasses MFA appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/08/08143621/microsoft-365-phishing.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 13:00:12 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, 365, users, targeted, new, phishing, threat, that, bypasses, MFA</media:keywords>
</item>

<item>
<title>CISA’s new KEV nomination form opens reporting to vendors and researchers</title>
<link>https://block385.com/cisas-new-kev-nomination-form-opens-reporting-to-vendors-and-researchers</link>
<guid>https://block385.com/cisas-new-kev-nomination-form-opens-reporting-to-vendors-and-researchers</guid>
<description><![CDATA[ The Cybersecurity and Infrastructure Security Agency launched a new nomination form that lets researchers, vendors, and industry partners report known exploited vulnerabilities for possible inclusion in its KEV catalog. The form gives outside contributors a direct way to submit vulnerabilities to CISA. Email submissions remain available at vulnerability@cisa.dhs.gov for organizations and individuals who prefer that route. “Every day, CISA collaborates with security researchers and industry partners that identify and report exploited vulnerabilities. This new reporting … More →
The post CISA’s new KEV nomination form opens reporting to vendors and researchers appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/02/13095016/cisa-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 13:00:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CISA’s, new, KEV, nomination, form, opens, reporting, vendors, and, researchers</media:keywords>
</item>

<item>
<title>Keepnet contributes voice and SMS phishing data to the 2026 Verizon DBIR</title>
<link>https://block385.com/keepnet-contributes-voice-and-sms-phishing-data-to-the-2026-verizon-dbir</link>
<guid>https://block385.com/keepnet-contributes-voice-and-sms-phishing-data-to-the-2026-verizon-dbir</guid>
<description><![CDATA[ Keepnet, an Extended Human Risk Management (xHRM) platform, today announced that its voice and SMS phishing simulation data contributed to the 2026 Verizon Data Breach Investigations Report (DBIR). The 2026 edition is the first to include voice and SMS phishing simulation data at this scale. The DBIR records this as “an increase of 40% in the median click rate” between phone-centric and email-based simulations (Verizon 2026 DBIR, p. 50). According to the report, phone-centric phishing … More →
The post Keepnet contributes voice and SMS phishing data to the 2026 Verizon DBIR appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 13:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Keepnet, contributes, voice, and, SMS, phishing, data, the, 2026, Verizon, DBIR</media:keywords>
</item>

<item>
<title>Proton Pass adds monitored credential sharing for AI agents</title>
<link>https://block385.com/proton-pass-adds-monitored-credential-sharing-for-ai-agents</link>
<guid>https://block385.com/proton-pass-adds-monitored-credential-sharing-for-ai-agents</guid>
<description><![CDATA[ Proton Pass, a secure, end-to-end encrypted password manager, added credential sharing through AI access tokens, allowing users to give AI agents access to selected items and monitor activity. To gain access, an agent must provide a reason for the request so users can see what actions are being performed. Access tokens are available with Pass Plus (included in Proton Unlimited), Pass Family, Pass Professional, and Proton Workspace plans. “AI access tokens are easy to set … More →
The post Proton Pass adds monitored credential sharing for AI agents appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/22122131/proton-pass-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 13:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Proton, Pass, adds, monitored, credential, sharing, for, agents</media:keywords>
</item>

<item>
<title>GitLab 19.0 adds AI workflows, secrets management, and self&#45;hosted model support</title>
<link>https://block385.com/gitlab-190-adds-ai-workflows-secrets-management-and-self-hosted-model-support</link>
<guid>https://block385.com/gitlab-190-adds-ai-workflows-secrets-management-and-self-hosted-model-support</guid>
<description><![CDATA[ GitLab released GitLab 19.0 with expanded secrets management, agentic merge request workflows, improved CI pipeline visibility, support for self-hosted open-source models, and supply chain visibility enhancements. Engineering organizations shipping more code than ever are confronting the AI Paradox firsthand, as the surrounding workflows for securing credentials, reviewing and merging changes, enforcing pipeline standards, and running AI in regulated environments have not kept pace. GitLab 19.0 advances the platform’s agentic core by embedding those capabilities where … More →
The post GitLab 19.0 adds AI workflows, secrets management, and self-hosted model support appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 13:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>GitLab, 19.0, adds, workflows, secrets, management, and, self-hosted, model, support</media:keywords>
</item>

<item>
<title>Versa extends zero trust principles to AI agents and MCP workflows</title>
<link>https://block385.com/versa-extends-zero-trust-principles-to-ai-agents-and-mcp-workflows</link>
<guid>https://block385.com/versa-extends-zero-trust-principles-to-ai-agents-and-mcp-workflows</guid>
<description><![CDATA[ Versa has introduced a patent-pending zero trust architecture for the Model Context Protocol (MCP), applying zero trust principles to AI execution. The company said every AI-generated action is validated against user identity, role-based access controls, and system policies before execution, with human approval required when defined by administrators. The launch addresses a growing challenge as enterprises deploy agentic AI systems. A single prompt can trigger multiple actions across network and security environments, reducing visibility into … More →
The post Versa extends zero trust principles to AI agents and MCP workflows appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 13:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Versa, extends, zero, trust, principles, agents, and, MCP, workflows</media:keywords>
</item>

<item>
<title>Suspected KimWolf botnet admin arrested over DDoS&#45;for&#45;hire operation</title>
<link>https://block385.com/suspected-kimwolf-botnet-admin-arrested-over-ddos-for-hire-operation</link>
<guid>https://block385.com/suspected-kimwolf-botnet-admin-arrested-over-ddos-for-hire-operation</guid>
<description><![CDATA[ U.S. and Canadian authorities arrested and charged a Canadian man accused of operating the KimWolf DDoS botnet, a service linked to attacks that infected more than one million devices worldwide. Jacob Butler, 23, of Ottawa, Canada, also known online as “Dort,” was arrested in Canada under an extradition warrant after U.S. prosecutors charged him with offenses related to the alleged development and operation of the KimWolf botnet. According to court documents, KimWolf targeted internet-connected devices … More →
The post Suspected KimWolf botnet admin arrested over DDoS-for-hire operation appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/06/10110030/botnet.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 13:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Suspected, KimWolf, botnet, admin, arrested, over, DDoS-for-hire, operation</media:keywords>
</item>

<item>
<title>Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS&#45;for&#45;Hire Attacks</title>
<link>https://block385.com/kimwolf-ddos-botnet-operator-arrested-in-canada-over-ddos-for-hire-attacks</link>
<guid>https://block385.com/kimwolf-ddos-botnet-operator-arrested-in-canada-over-ddos-for-hire-attacks</guid>
<description><![CDATA[ The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf.

In tandem, Jacob Butler (aka Dort), 23, Ottawa, Canada, has been charged with offenses related to the development and operation of the botnet. Kimwolf is assessed to be a variant of AISURU.

&quot;Kimwolf ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5VYMnsK-UMv3L8TZp1KhZ4PQti0VtUXkbDREtK-R9Hbtj6bdYrPRwwn8VItL49asZcHEMSOFJyfV25Da96CerBXrPRnHZHncrTuo7Mj7dxEkNGNR4jZZs19Y2pep2dl7KZ0IK1CkexVOQhr14e5MIP5oe5vglQ2StuxG6xv2ataqy8jvD9T1fXLToZHc5/s1600/ddos-canada.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 12:30:12 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Kimwolf, DDoS, Botnet, Operator, Arrested, Canada, Over, DDoS-for-Hire, Attacks</media:keywords>
</item>

<item>
<title>Downtime has become a $600 billion business problem</title>
<link>https://block385.com/downtime-has-become-a-600-billion-business-problem</link>
<guid>https://block385.com/downtime-has-become-a-600-billion-business-problem</guid>
<description><![CDATA[ The average cost of downtime has reached $600 billion for the Global 2000, a 50% increase in two years. According to Splunk’s The Hidden Costs of Downtime report, unplanned outages and service degradation cost each company an average of $300 million. Percentage of technology executives who consider a direct cost very or prohibitively disruptive (2024 versus 2026) (Source: Splunk) The consequences of an outage Delayed product launches, brand damage, and stock declines continue to affect … More →
The post Downtime has become a $600 billion business problem appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/03/24081916/downtime-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 11:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Downtime, has, become, 600, billion, business, problem</media:keywords>
</item>

<item>
<title>China&amp;apos;s Webworm Uses Discord, Microsoft Graphs to Hack EU Govts.</title>
<link>https://block385.com/chinas-webworm-uses-discord-microsoft-graphs-to-hack-eu-govts</link>
<guid>https://block385.com/chinas-webworm-uses-discord-microsoft-graphs-to-hack-eu-govts</guid>
<description><![CDATA[ The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt9bbd9e9f246990ad/6a0f5eeab6882cd3afc7c328/Discord_app_iPhone_True_Images_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 11:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Chinas, Webworm, Uses, Discord, Microsoft, Graphs, Hack, Govts.</media:keywords>
</item>

<item>
<title>CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV</title>
<link>https://block385.com/cisa-adds-exploited-langflow-and-trend-micro-apex-one-vulnerabilities-to-kev</link>
<guid>https://block385.com/cisa-adds-exploited-langflow-and-trend-micro-apex-one-vulnerabilities-to-kev</guid>
<description><![CDATA[ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerabilities in question are listed below -


  CVE-2025-34291 (CVSS score: 9.4) - An origin validation error vulnerability in Langflow that could ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi04a_rowIzNPvHHvDTUE34d3bZlOhBeQXtC0UdXyjlf988G4zVE89QKWqSWASKd2LD0T8O2XhkDVgG7UGFIxlpvQWHPx-o_X7vfMK5fH4uSDg3eSUDAaWKtgresEyD9JpINkxtdELWn-qiv6usoLgwSlYNi89xJeVBwYYsCF2y-KKNz0x04KS0PeDPL57J/s1600/cisa-kev-flaws.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 10:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CISA, Adds, Exploited, Langflow, and, Trend, Micro, Apex, One, Vulnerabilities, KEV</media:keywords>
</item>

<item>
<title>Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access</title>
<link>https://block385.com/cisco-patches-cvss-100-secure-workload-rest-api-flaw-enabling-data-access</link>
<guid>https://block385.com/cisco-patches-cvss-100-secure-workload-rest-api-flaw-enabling-data-access</guid>
<description><![CDATA[ Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data.

Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints.

&quot;An attacker could exploit this vulnerability if they are able to send ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLweJvl8B70zomibdr4U6WvYgbmZn4gKKOG9F7xDPXzgeENKK0kg2kgK1yvZDS7AJFkY9De2rG2EQzCLvN1FmjrXXDIm-CkmU88QcexbMkr60gKVKexF-d1qtGHusrr6_j5yrtMv31PSUEygioHJikBsifQ0VHW18IU7lu_oItTzQXugwHPLoO_DYNdnYx/s1600/cisco-workload.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 08:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cisco, Patches, CVSS, 10.0, Secure, Workload, REST, API, Flaw, Enabling, Data, Access</media:keywords>
</item>

<item>
<title>New infosec products of the week: May 22, 2026</title>
<link>https://block385.com/new-infosec-products-of-the-week-may-22-2026</link>
<guid>https://block385.com/new-infosec-products-of-the-week-may-22-2026</guid>
<description><![CDATA[ Here’s a look at the most interesting products from the past week, featuring releases from ASAPP, Babel Street, CTERA, Forward, Riverbed, and Trust3 AI. Babel Street targets AI-driven threats with new agentic investigation capabilities Babel Street has launched Insights Investigator, a new agentic capability that puts tradecraft-trained AI agents at the front edge of investigative work while ensuring analysts remain in control of scope, logic, and outcomes of their missions. As part of the Babel … More →
The post New infosec products of the week: May 22, 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/28091843/infosec-week-1200.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, infosec, products, the, week:, May, 22, 2026</media:keywords>
</item>

<item>
<title>The new economics of fraud: Cheaper, faster, more convincing</title>
<link>https://block385.com/the-new-economics-of-fraud-cheaper-faster-more-convincing</link>
<guid>https://block385.com/the-new-economics-of-fraud-cheaper-faster-more-convincing</guid>
<description><![CDATA[ Scams have become one of the fastest-growing consumer risks, driven by AI-enabled impersonation, social engineering, and sophisticated attack methods, according to Visa’s Spring 2026 Biannual Threats Report. Criminals redirect efforts toward trust and third parties Fraud involves behavioral manipulation, fragmented ecosystems, and faster attack cycles that use AI to pressure people into authorizing payments themselves. The payments ecosystem continues to strengthen core defenses. Token fraud declined 9.6% and enumeration losses fell 16% from July through … More →
The post The new economics of fraud: Cheaper, faster, more convincing appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/04/21081700/nfc-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 07:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, new, economics, fraud:, Cheaper, faster, more, convincing</media:keywords>
</item>

<item>
<title>How CISOs Should Prep for Agentic&#45;Ready AI BOMs</title>
<link>https://block385.com/how-cisos-should-prep-for-agentic-ready-ai-boms</link>
<guid>https://block385.com/how-cisos-should-prep-for-agentic-ready-ai-boms</guid>
<description><![CDATA[ Finding ways to document both component and execution attributes for AI bill of materials (AI BOM). ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc910f7f1381f9cc0/6a0c51d37e010876184b0788/robot-book-KittipongJirasukhanont-alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 22 May 2026 01:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>How, CISOs, Should, Prep, for, Agentic-Ready, BOMs</media:keywords>
</item>

<item>
<title>Google API Keys Remain Active After Deletion</title>
<link>https://block385.com/google-api-keys-remain-active-after-deletion</link>
<guid>https://block385.com/google-api-keys-remain-active-after-deletion</guid>
<description><![CDATA[ A security researcher discovered the API keys can still be used for 23 minutes after deletion, even though the cloud provider claims deletion is immediate. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltefc0db2ad802a547/6a0f5ac8f89ee59a84380e8a/apis_Sandwish_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 23:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Google, API, Keys, Remain, Active, After, Deletion</media:keywords>
</item>

<item>
<title>Microsoft open&#45;sources tools for designing and testing AI agents</title>
<link>https://block385.com/microsoft-open-sources-tools-for-designing-and-testing-ai-agents</link>
<guid>https://block385.com/microsoft-open-sources-tools-for-designing-and-testing-ai-agents</guid>
<description><![CDATA[ Microsoft has open-sourced two tools aimed at bringing security discipline to AI agent development: Clarity, a structured design review tool, and RAMPART, a continuous testing framework. The release comes from Microsoft’s AI Red Team, the company’s internal unit that stress-tests its own AI systems, and both tools have been used internally before being open-sourced. RAMPART: A test harness RAMPART is built on top of PyRIT, Microsoft’s existing open-source red-teaming library, and is designed to slot … More →
The post Microsoft open-sources tools for designing and testing AI agents appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/10/27095223/ai_agents-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, open-sources, tools, for, designing, and, testing, agents</media:keywords>
</item>

<item>
<title>AI Agents Are Shifting Identity Security Budget Dynamics</title>
<link>https://block385.com/ai-agents-are-shifting-identity-security-budget-dynamics</link>
<guid>https://block385.com/ai-agents-are-shifting-identity-security-budget-dynamics</guid>
<description><![CDATA[ AI agent projects are proliferating throughout the enterprise, and those AI agent identities require management, security, and governance. New Omdia research shows the AI agent identity budget dynamics are very different than traditional IAM projects. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltd00712c4fd23579b/6a0e0281107a585c56c6d09e/AI_ID_card_Edgars_Sermulis_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 19:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Agents, Are, Shifting, Identity, Security, Budget, Dynamics</media:keywords>
</item>

<item>
<title>Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor</title>
<link>https://block385.com/showboat-linux-malware-hits-middle-east-telecom-with-socks5-proxy-backdoor</link>
<guid>https://block385.com/showboat-linux-malware-hits-middle-east-telecom-with-socks5-proxy-backdoor</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022.

&quot;Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files, and functioning as a SOCKS5 proxy,&quot; Lumen ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYTZEcd3s0q7NssZnOYvAFrMtE1fTJQtdNoUDwBZKG1DkQWYL4uY6gExiUwuNcMnZG-J8dM8iTJIm6nD2Bv80qI2xMubYmnGScqUNQfeI6kF49vFkU0wKpi7iaVvbl1MX1zPleKP2iOShCd9u4S-EpLA-cBKf5lNlW7OXLu0NmiUlw35Qr0GzXmpylPcXz/s1600/telecom-linux.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 18:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Showboat, Linux, Malware, Hits, Middle, East, Telecom, with, SOCKS5, Proxy, Backdoor</media:keywords>
</item>

<item>
<title>GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise</title>
<link>https://block385.com/github-grafana-labs-breaches-traced-back-to-tanstack-supply-chain-compromise</link>
<guid>https://block385.com/github-grafana-labs-breaches-traced-back-to-tanstack-supply-chain-compromise</guid>
<description><![CDATA[ GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. A malicious version of the otherwise benign extension was used to steal secrets and developer credentials, which were then used to move through CI/CD pipelines and exfiltrate around 3,800 of GitHub’s private code repositories. One missed token, many victims The company … More →
The post GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/11/06180224/digital-supply-chain-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 17:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>GitHub, Grafana, Labs, breaches, traced, back, TanStack, supply, chain, compromise</media:keywords>
</item>

<item>
<title>Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks</title>
<link>https://block385.com/chinese-apts-share-linux-backdoor-in-central-asia-telco-attacks</link>
<guid>https://block385.com/chinese-apts-share-linux-backdoor-in-central-asia-telco-attacks</guid>
<description><![CDATA[ &quot;Showboat&quot; doesn&#039;t show off, but clearly it doesn&#039;t need to, as it&#039;s long helped China spy on small market communications providers. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt4ed651e9b0fd01c3/6a0c7dba3c21f60b728ba42d/Showboat-Mark_Summerfield-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Chinese, APTs, Share, Linux, Backdoor, Central, Asia, Telco, Attacks</media:keywords>
</item>

<item>
<title>Content Delivery Exploit Opens Websites to Brand Hijacking</title>
<link>https://block385.com/content-delivery-exploit-opens-websites-to-brand-hijacking</link>
<guid>https://block385.com/content-delivery-exploit-opens-websites-to-brand-hijacking</guid>
<description><![CDATA[ The Underminr domain-fronting attack allows threat actors to modify Web requests and leverage trusted websites to cloak malicious activity. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blta4e69c10af67b9ac/6a0b28b90c15634015ba260b/Landmine-hernandez_jose_maria-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Content, Delivery, Exploit, Opens, Websites, Brand, Hijacking</media:keywords>
</item>

<item>
<title>Authorities dismantle First VPN, used by ransomware actors</title>
<link>https://block385.com/authorities-dismantle-first-vpn-used-by-ransomware-actors</link>
<guid>https://block385.com/authorities-dismantle-first-vpn-used-by-ransomware-actors</guid>
<description><![CDATA[ First VPN, a virtual private network service marketed to cybercriminals, promising anonymity for its users, was taken offline on May 19 and 20 as part of Operation Saffron. During the operation, French and Dutch authorities, with support from Europol and Eurojust, dismantled 33 servers linked to the service and interviewed the operator in Ukraine. The targeted domain names were shut down through international cooperation between law enforcement and judicial authorities. The seized domains included 1vpns.com, … More →
The post Authorities dismantle First VPN, used by ransomware actors appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/06/05105923/europe-1500-2.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Authorities, dismantle, First, VPN, used, ransomware, actors</media:keywords>
</item>

<item>
<title>ThreatsDay Bulletin: Linux Rootkits, Router 0&#45;Day, AI Intrusions, Scam Kits and 25 New Stories</title>
<link>https://block385.com/threatsday-bulletin-linux-rootkits-router-0-day-ai-intrusions-scam-kits-and-25-new-stories</link>
<guid>https://block385.com/threatsday-bulletin-linux-rootkits-router-0-day-ai-intrusions-scam-kits-and-25-new-stories</guid>
<description><![CDATA[ This week starts small.

A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we already trust.

That is what makes it worrying. The danger is in normal things now - updates, apps, cloud buttons, support chats, trusted accounts. AI ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifIiAs3r9mSWAyNYngQby6QllKy0gx1dGJB4MNtgMjRQLUIkp7-fr851xuTEe6-izLAtNHux1PgdVBiWmEQctN2QM1bzV_CP0bcR7_ReqHg-lXrDa-EqUsZAUgC8da72h6tdbZU6H8nWMzAfZEItMY49Big4dpxtSHr5r7sgm7W01mhA31E274dUfWBHMi/s1600/tday.png" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 16:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>ThreatsDay, Bulletin:, Linux, Rootkits, Router, 0-Day, Intrusions, Scam, Kits, and, New, Stories</media:keywords>
</item>

<item>
<title>Microsoft Defender vulnerabilities exploited in the wild (CVE&#45;2026&#45;41091, CVE&#45;2026&#45;45498)</title>
<link>https://block385.com/microsoft-defender-vulnerabilities-exploited-in-the-wild-cve-2026-41091-cve-2026-45498</link>
<guid>https://block385.com/microsoft-defender-vulnerabilities-exploited-in-the-wild-cve-2026-41091-cve-2026-45498</guid>
<description><![CDATA[ Attackers are exploiting two Microsoft Defender vulnerabilities (CVE-2026-41091 and CVE-2026-45498), Microsoft acknowledged and CISA confirmed by adding them to its Known Exploited Vulnerabilities catalog. The vulnerabilities CVE-2026-41091 allows for local privilege elevation (LPE), and is caused by the Microsoft Malware Protection Engine improperly resolving links before accessing files. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft noted. CVE-2026-45498 can cause a denial-of-service (DoS) state, i.e., it can be used to prevent … More →
The post Microsoft Defender vulnerabilities exploited in the wild (CVE-2026-41091, CVE-2026-45498) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/19154102/microsoft2.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 15:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Defender, vulnerabilities, exploited, the, wild, CVE-2026-41091, CVE-2026-45498</media:keywords>
</item>

<item>
<title>Fake Android Apps Commit Carrier Billing Fraud for Premium Services</title>
<link>https://block385.com/fake-android-apps-commit-carrier-billing-fraud-for-premium-services</link>
<guid>https://block385.com/fake-android-apps-commit-carrier-billing-fraud-for-premium-services</guid>
<description><![CDATA[ The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt3de65670685255f7/6a0e1b5c27e92be2fabee02d/android_Stockinq_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Fake, Android, Apps, Commit, Carrier, Billing, Fraud, for, Premium, Services</media:keywords>
</item>

<item>
<title>Microsoft Warns of Two Actively Exploited Defender Vulnerabilities</title>
<link>https://block385.com/microsoft-warns-of-two-actively-exploited-defender-vulnerabilities</link>
<guid>https://block385.com/microsoft-warns-of-two-actively-exploited-defender-vulnerabilities</guid>
<description><![CDATA[ Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild.

The former, tracked as CVE-2026-41091, is rated 7.8 on the CVSS scoring system. Successful exploitation of the flaw could allow an attacker to gain SYSTEM privileges.

&quot;Improper link resolution before file access (&#039;link following&#039;) in Microsoft Defender ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNxp-fCwFOYcXoyRTmhjpwfvFCjfE36YoU8z-7es2XrOajnfSfpttiB9KMfwqCNbwzHQ85kILhlUwo4DeQFWXFq29J8p_oVAIe-gKCCegmTid4YW_22sK6CQO_TwELXa7Z-RZmvDvHx7N3Vg7y-xm78iSGjzCg2AU3FnHo1Hp7v80JJkBruCc05JVvVwnx/s1600/windows-defender.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 14:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Warns, Two, Actively, Exploited, Defender, Vulnerabilities</media:keywords>
</item>

<item>
<title>When Identity is the Attack Path</title>
<link>https://block385.com/when-identity-is-the-attack-path</link>
<guid>https://block385.com/when-identity-is-the-attack-path</guid>
<description><![CDATA[ Consider a cached access key on a single Windows machine. It got there the way most cached credentials do - a user logged in, and the key stored itself automatically. Standard AWS behavior. No one misconfigured anything or violated a policy. Yet that single key, which was easily accessible to a minor-league attacker, could have opened a path to some 98% of entities in the company&#039;s cloud ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgv9W2lSuCdHjvqeLUN5WtqUOgCwe2FAyP1Y_z4oUr1LgM1MdOE5A83gkzSOfGjIosfdlfB4SuLbeVbydeuParENW4MH2aWYuWqnB-DeOd7gC3RJnp7wFucmuinh9kiMBI99337kQYcBrlIX-WH3u204eu7FTy5b_gpkXC6ZHupWD3P60yFk4-2DUrTuuc/s1600/xmxm.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 14:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>When, Identity, the, Attack, Path</media:keywords>
</item>

<item>
<title>Terra adds continuous network exploitation validation to its platform</title>
<link>https://block385.com/terra-adds-continuous-network-exploitation-validation-to-its-platform</link>
<guid>https://block385.com/terra-adds-continuous-network-exploitation-validation-to-its-platform</guid>
<description><![CDATA[ Terra Security has announced the public preview of continuous exploitation validation for network infrastructure, now available to all customers through the Terra Platform. The launch expands Terra’s offensive security capabilities from web applications to network infrastructure and extends coverage across three areas: web applications, AI, and network environments. Terra said the update expands its continuous offensive security capabilities across web applications, AI, and network infrastructure within a single platform. The new capability brings Terra’s swarms … More →
The post Terra adds continuous network exploitation validation to its platform appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 11:00:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Terra, adds, continuous, network, exploitation, validation, its, platform</media:keywords>
</item>

<item>
<title>Forward launches Predict to test network changes before deployment</title>
<link>https://block385.com/forward-launches-predict-to-test-network-changes-before-deployment</link>
<guid>https://block385.com/forward-launches-predict-to-test-network-changes-before-deployment</guid>
<description><![CDATA[ Forward has unveiled Forward Predict, a new capability that allows organizations to evaluate the impact of network changes before deployment. By testing proposed changes against a digital twin of the production network, Forward Predict helps identify potential issues before they reach live environments and supports safer network operations at scale. “When we founded Forward more than a decade ago, we set our sights on the future of autonomous networking,” said David Erickson, CEO of Forward. … More →
The post Forward launches Predict to test network changes before deployment appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 11:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Forward, launches, Predict, test, network, changes, before, deployment</media:keywords>
</item>

<item>
<title>CTERA brings AI insights and automation for unstructured data</title>
<link>https://block385.com/ctera-brings-ai-insights-and-automation-for-unstructured-data</link>
<guid>https://block385.com/ctera-brings-ai-insights-and-automation-for-unstructured-data</guid>
<description><![CDATA[ CTERA has announced the launch of CTERA InsightAI, an agentic AI intelligence layer for the CTERA Intelligent Data Platform. The new capability is designed to help enterprises understand, manage, secure, and optimize unstructured data environments. CTERA InsightAI adds AI-driven insights and automation to data operations, expanding traditional data observability capabilities. CTERA InsightAI continuously analyzes enterprise data activity to surface emerging risks, unusual behavior, operational inefficiencies, and shifting storage consumption patterns in real time. Instead of … More →
The post CTERA brings AI insights and automation for unstructured data appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 11:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CTERA, brings, insights, and, automation, for, unstructured, data</media:keywords>
</item>

<item>
<title>Riverbed introduces new Aternity tools for autonomous IT operations</title>
<link>https://block385.com/riverbed-introduces-new-aternity-tools-for-autonomous-it-operations</link>
<guid>https://block385.com/riverbed-introduces-new-aternity-tools-for-autonomous-it-operations</guid>
<description><![CDATA[ Riverbed has announced new capabilities for Aternity designed to support autonomous IT operations for digital experience management. The updates help digital workplace teams move toward prevention-focused operations through broader visibility, context-aware intelligence, and governance controls that support automated workflows. Organizations are measured by their ability to deliver frictionless digital experiences that keep employees productive and business workflows operating without interruption. While many IT initiatives focus on improving reactive operations, Riverbed is focused on enabling organizations … More →
The post Riverbed introduces new Aternity tools for autonomous IT operations appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 11:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Riverbed, introduces, new, Aternity, tools, for, autonomous, operations</media:keywords>
</item>

<item>
<title>ASAPP expands adversarial testing for enterprise AI systems</title>
<link>https://block385.com/asapp-expands-adversarial-testing-for-enterprise-ai-systems</link>
<guid>https://block385.com/asapp-expands-adversarial-testing-for-enterprise-ai-systems</guid>
<description><![CDATA[ ASAPP has launched Continuous Red Teaming, a new capability that integrates adversarial AI testing directly into ASAPP’s model evaluation framework. The new capability is built on Promptfoo, an AI security platform that helps enterprises detect and address vulnerabilities in AI systems during development. Promptfoo continuously runs automated tests across ASAPP’s AI systems, screening for more than 50 vulnerability types to give enterprise customers the real-time data they need to trust their AI in production. As … More →
The post ASAPP expands adversarial testing for enterprise AI systems appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 11:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>ASAPP, expands, adversarial, testing, for, enterprise, systems</media:keywords>
</item>

<item>
<title>Tenable Hexa AI automates remediation across attack surfaces</title>
<link>https://block385.com/tenable-hexa-ai-automates-remediation-across-attack-surfaces</link>
<guid>https://block385.com/tenable-hexa-ai-automates-remediation-across-attack-surfaces</guid>
<description><![CDATA[ Tenable has announced the general availability of Tenable Hexa AI, the agentic AI engine of the Tenable One Exposure Management Platform. Tenable Hexa AI is an advanced agentic AI for cybersecurity solution, equipped with advanced multi-step reasoning and Model Context Protocol (MCP) support, enabling custom agent building and workflows that accelerate risk reduction at machine speed. LLMs and AI frontier models, such as Anthropic’s Mythos Preview, are accelerating the discovery of previously unknown vulnerabilities at … More →
The post Tenable Hexa AI automates remediation across attack surfaces appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 11:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Tenable, Hexa, automates, remediation, across, attack, surfaces</media:keywords>
</item>

<item>
<title>Virtru centers file collaboration around data&#45;level protection</title>
<link>https://block385.com/virtru-centers-file-collaboration-around-data-level-protection</link>
<guid>https://block385.com/virtru-centers-file-collaboration-around-data-level-protection</guid>
<description><![CDATA[ Virtru unveiled Virtru Collaborate, a new offering that eliminates that tradeoff, a FedRAMP authorized space where sensitive files are encrypted and protected by the Trusted Data Format (TDF), and where that protection travels seamlessly with the data as teams work together across organizational boundaries. Virtru Collaborate is the first solution built on the new Virtru Platform, a next-generation architecture powered by TDF, the open standard for data-centric protection. The platform embeds policy, encryption, and access … More →
The post Virtru centers file collaboration around data-level protection appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 11:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Virtru, centers, file, collaboration, around, data-level, protection</media:keywords>
</item>

<item>
<title>9&#45;Year&#45;Old Linux Kernel Flaw Enables Root Command Execution on Major Distros</title>
<link>https://block385.com/9-year-old-linux-kernel-flaw-enables-root-command-execution-on-major-distros</link>
<guid>https://block385.com/9-year-old-linux-kernel-flaw-enables-root-command-execution-on-major-distros</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years.

The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCjgJwva2lZrAwxHWPZFiphHAhxBdWRyU4gUiAZIStkUP4JU6yej3Z1xVhUtrhaIYVu4IL5KpvOomBDHU_aLtvgHV-R9_41nUSrngG0BGBlCv2pByfkVZNKxmwA3Nf6NR7pi6XgwdUjkwFw27lm_vNR_w2Cr1An46yOM8kfIEphrSCq2aRcaKNNj9D-PiN/s1600/linux-exploit.gif" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 10:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>9-Year-Old, Linux, Kernel, Flaw, Enables, Root, Command, Execution, Major, Distros</media:keywords>
</item>

<item>
<title>AI red teaming agents change how LLMs get tested</title>
<link>https://block385.com/ai-red-teaming-agents-change-how-llms-get-tested</link>
<guid>https://block385.com/ai-red-teaming-agents-change-how-llms-get-tested</guid>
<description><![CDATA[ Adversarial probing of LLMs has piled up a sprawling toolkit over the past three years. Attack techniques with names like Tree of Attacks with Pruning, Crescendo, and Skeleton Key sit alongside hundreds of prompt transforms and scoring methods across open-source frameworks including Microsoft’s PyRIT, NVIDIA’s Garak, and Promptfoo. The catalog has grown faster than any operator can fluently navigate it, and that mismatch is changing how AI red teaming gets done. A wave of recent … More →
The post AI red teaming agents change how LLMs get tested appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18084539/ai-robot-llm-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>red, teaming, agents, change, how, LLMs, get, tested</media:keywords>
</item>

<item>
<title>Most dark web activity revolves around a handful of topics</title>
<link>https://block385.com/most-dark-web-activity-revolves-around-a-handful-of-topics</link>
<guid>https://block385.com/most-dark-web-activity-revolves-around-a-handful-of-topics</guid>
<description><![CDATA[ Dark web activity often becomes visible during marketplace seizures, major data leaks, or sudden spikes in criminal activity. Those events can create an impression of an ecosystem where attention shifts quickly and new trends regularly replace old ones. A six-year dataset covering more than 25,000 dark web sites tracked what people discussed in underground forums and marketplaces and how those discussions changed over time. The work drew from more than 11 million archived snapshots collected … More →
The post Most dark web activity revolves around a handful of topics appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/03/19124947/dark_web-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 09:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Most, dark, web, activity, revolves, around, handful, topics</media:keywords>
</item>

<item>
<title>Why AI changed the threat model for travel technology</title>
<link>https://block385.com/why-ai-changed-the-threat-model-for-travel-technology</link>
<guid>https://block385.com/why-ai-changed-the-threat-model-for-travel-technology</guid>
<description><![CDATA[ In this Help Net Security interview, Devon Bryan, SVP, Global CSO at Booking Holdings, reflects on his path from Air Force network security engineer to global CSO across financial services, hospitality, and travel technology. He discusses why the travel industry’s interconnected ecosystem of identity, payments, loyalty programs, and third-party integrations creates compounding risk, and how AI has expanded threat modeling beyond traditional infrastructure to include prompt injection, model access, and shadow AI adoption. Bryan also … More →
The post Why AI changed the threat model for travel technology appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18193748/devon_bryan-2-booking_holdings.webp.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 09:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Why, changed, the, threat, model, for, travel, technology</media:keywords>
</item>

<item>
<title>GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension</title>
<link>https://block385.com/github-internal-repositories-breached-via-malicious-nx-console-vs-code-extension</link>
<guid>https://block385.com/github-internal-repositories-breached-via-malicious-nx-console-vs-code-extension</guid>
<description><![CDATA[ GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension. 

The development comes as the Nx team revealed that the extension, nrwl.angular-console, was breached after one of its developers&#039; systems was hacked in the ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJ64wgVqZTQx208NgY0sBvUUQcR5mb-G4ENkfw4PEX9KlJJxEI_uUKQvPG0rReXB4chZ3wXrvNSR1QsrK525DDHkzY9X3nQYduh36qKTyC-k4EfixFeOU7YR1mRIw8ZJL-oYN8k_wwBid2GU8NYJtCqEFLOSzomuu-Xx7yA3Djim0nq79RyoZJs6HGga_H/s1600/github-hacked.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 08:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>GitHub, Internal, Repositories, Breached, via, Malicious, Console, Code, Extension</media:keywords>
</item>

<item>
<title>Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks</title>
<link>https://block385.com/highly-critical-drupal-core-flaw-exposes-postgresql-sites-to-rce-attacks</link>
<guid>https://block385.com/highly-critical-drupal-core-flaw-exposes-postgresql-sites-to-rce-attacks</guid>
<description><![CDATA[ Drupal has released security updates for a &quot;highly critical&quot; security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure.
The vulnerability, now tracked as CVE-2026-9082, carries a CVSS score of 6.5 out of 10.0, per CVE.org. Drupal said the vulnerability resides in a database abstraction API that is ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyhKX1WKEWbBPd4sElCP9BB26eorxZX1Lo25Mcu-A5bfBUuWT63SQ-Hyycv1YPSlvVeZPfLSEbb8mQnuPvf0KEDm8mYTtCLoYZuMG6A8maidLefE12_3Plum0keZ-mbAS4dGN-x7Oj0NWOmoeqp6_PEK0fqpnZwz8ZFV-NhyFl78WS4Nck76yAbfgWRpK7/s1600/drupal-flaw.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 08:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Highly, Critical, Drupal, Core, Flaw, Exposes, PostgreSQL, Sites, RCE, Attacks</media:keywords>
</item>

<item>
<title>Cyber threats push SMBs to spend more on security</title>
<link>https://block385.com/cyber-threats-push-smbs-to-spend-more-on-security</link>
<guid>https://block385.com/cyber-threats-push-smbs-to-spend-more-on-security</guid>
<description><![CDATA[ Cybersecurity has become a key priority for small and medium-sized businesses due to growing threats and wider AI adoption. An IDC survey of 2,200 SMBs in eight markets examined how organizations manage cyber risks, prepare for AI-related threats, and handle third-party vendor security. Top business priorities for the year (Source: IDC) 60% of SMBs expect to increase cybersecurity spending over the next 12 months. The findings show that businesses continue to rely on reactive approaches … More →
The post Cyber threats push SMBs to spend more on security appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/09/23124652/attack-ddos-threat-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cyber, threats, push, SMBs, spend, more, security</media:keywords>
</item>

<item>
<title>Product showcase: Bitdefender Mobile Security for iOS protects privacy where scams begin</title>
<link>https://block385.com/product-showcase-bitdefender-mobile-security-for-ios-protects-privacy-where-scams-begin</link>
<guid>https://block385.com/product-showcase-bitdefender-mobile-security-for-ios-protects-privacy-where-scams-begin</guid>
<description><![CDATA[ Bitdefender Mobile Security for iOS is a security and privacy application for iPhone and iPad that helps protect against phishing attempts, online scams, unsafe websites, and account exposure. I have used Bitdefender Mobile Security for iOS for the last two years. It was easy to install, easy to use, and I have not noticed any impact on device performance. The app combines web protection, scam detection, privacy tools, account monitoring, and VPN capabilities. Dashboard and … More →
The post Product showcase: Bitdefender Mobile Security for iOS protects privacy where scams begin appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/19143513/bitdefender-1200.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 07:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Product, showcase:, Bitdefender, Mobile, Security, for, iOS, protects, privacy, where, scams, begin</media:keywords>
</item>

<item>
<title>Cyber Pros Can&amp;apos;t Decide If AI Is a Good or a Bad Thing</title>
<link>https://block385.com/cyber-pros-cant-decide-if-ai-is-a-good-or-a-bad-thing</link>
<guid>https://block385.com/cyber-pros-cant-decide-if-ai-is-a-good-or-a-bad-thing</guid>
<description><![CDATA[ There is nothing cybersecurity professionals are more excited about, and nothing they fear more, than AI. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt2c0354b9fcf6985f/6a0e106f7896f1466e6adf8e/Star_Wars-John_Bingham-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 01:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cyber, Pros, Cant, Decide, Good, Bad, Thing</media:keywords>
</item>

<item>
<title>Fake Android Apps Commit Carrier Billing Fraud for Premium Svcs.</title>
<link>https://block385.com/fake-android-apps-commit-carrier-billing-fraud-for-premium-svcs</link>
<guid>https://block385.com/fake-android-apps-commit-carrier-billing-fraud-for-premium-svcs</guid>
<description><![CDATA[ The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt3de65670685255f7/6a0e1b5c27e92be2fabee02d/android_Stockinq_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 21 May 2026 01:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Fake, Android, Apps, Commit, Carrier, Billing, Fraud, for, Premium, Svcs.</media:keywords>
</item>

<item>
<title>GitHub Confirms Breach, 4K Internal Repos Stolen</title>
<link>https://block385.com/github-confirms-breach-4k-internal-repos-stolen</link>
<guid>https://block385.com/github-confirms-breach-4k-internal-repos-stolen</guid>
<description><![CDATA[ Open source software giant GitHub confirmed a data breach this week involving the theft of thousands of repos. One threat actor — TeamPCP — took credit. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt14b264d36a8b1972/6a0e0edae87cf56bc17d8b98/GitHub_Octocat_logo_Sundry_Photography_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 23:00:12 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>GitHub, Confirms, Breach, Internal, Repos, Stolen</media:keywords>
</item>

<item>
<title>Processes and Culture Top Reasons Behind Data Breaches</title>
<link>https://block385.com/processes-and-culture-top-reasons-behind-data-breaches</link>
<guid>https://block385.com/processes-and-culture-top-reasons-behind-data-breaches</guid>
<description><![CDATA[ Government leaders revealed that, in spite of state laws meant to improve cyber hygiene, an analysis of incidents showed issues persist and visibility falls short. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt15c2853fa69a58ba/673f45b5df958859a25544ab/Breach_(1800)_Brain_light_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 23:00:12 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Processes, and, Culture, Top, Reasons, Behind, Data, Breaches</media:keywords>
</item>

<item>
<title>Microsoft Open&#45;Sources RAMPART and Clarity to Secure AI Agents During Development</title>
<link>https://block385.com/microsoft-open-sources-rampart-and-clarity-to-secure-ai-agents-during-development</link>
<guid>https://block385.com/microsoft-open-sources-rampart-and-clarity-to-secure-ai-agents-during-development</guid>
<description><![CDATA[ Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents.

RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and security testing framework for writing and running safety and security tests for AI agents, covering ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjPuhFp_KGzG3yZEzqIYh-at7Dm3vg4_QX97ilaSXDjsUbfhU7KCmRS-uQ2UrV9D855Nvy8HcBDKe25VMT63dfyzh-B2bzSx649SJQSQhL3bfm4Eitv4KLW4PhzRfE1HvoFOFDu2bB4alNLTFzvr6_IkKWjqxShcuWytNgDR4b3wR1xGE6z06xSyWo6NVg3/s1600/ms-tools.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Open-Sources, RAMPART, and, Clarity, Secure, Agents, During, Development</media:keywords>
</item>

<item>
<title>Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control</title>
<link>https://block385.com/patch-now-critical-flaw-in-ot-robot-os-gives-attackers-control</link>
<guid>https://block385.com/patch-now-critical-flaw-in-ot-robot-os-gives-attackers-control</guid>
<description><![CDATA[ An unauthenticated attacker can exploit the command injection vulnerability to gain remote access to robotic systems, causing significant disruption to the environment. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt7b8562594e40786d/6a0d83f54c91d13579cb3c25/robot-safety-cage-gen_A-AdobeStock.png" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Patch, Now:, Critical, Flaw, Robot, Gives, Attackers, Control</media:keywords>
</item>

<item>
<title>Microsoft Takes Down Malware&#45;Signing Service Behind Ransomware Attacks</title>
<link>https://block385.com/microsoft-takes-down-malware-signing-service-behind-ransomware-attacks</link>
<guid>https://block385.com/microsoft-takes-down-malware-signing-service-behind-ransomware-attacks</guid>
<description><![CDATA[ Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company&#039;s Artifact Signing system to deliver malicious code and conduct ransomware and other attacks, compromising thousands of machines and networks across the world.

The tech giant attributed the activity to a threat actor it calls Fox Tempest, which it said offered the MSaaS scheme ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgiypJnCUStqk0SRgnT6bFPLXM9F10uUBgEZgGScKH8lNthkNnD4zP2-CBNIvo2eukKJzGKOs7RFjIq1KmR-pIGFT3pFS1wgz8ySDW7O9OaMkAHXSaZvHSP_Y2JxqGgkdbCLXcn-VZOYwirKa9gU7FqEZXDafHhgxupVx6cuJam1wsnjq3qjz7q36GlvirT/s1600/windows-ransomware.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 18:30:11 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Takes, Down, Malware-Signing, Service, Behind, Ransomware, Attacks</media:keywords>
</item>

<item>
<title>NanoCo lands $12 million seed funding, launches enterprise assistant built on NanoClaw</title>
<link>https://block385.com/nanoco-lands-12-million-seed-funding-launches-enterprise-assistant-built-on-nanoclaw</link>
<guid>https://block385.com/nanoco-lands-12-million-seed-funding-launches-enterprise-assistant-built-on-nanoclaw</guid>
<description><![CDATA[ NanoCo announced a $12 million seed round, alongside the commercial launch of a professional assistant built on its open-source agent framework NanoClaw. Valley Capital Partners led the round. Docker, Vercel, monday.com, Slow Ventures, Clutch Capital, Factorial Capital, and Hugging Face CEO Clem Delangue participated. NanoCo founders (Photo by Ran Bergman) From open source traction to enterprise product NanoClaw launched as an open source project in February 2026. It has since collected nearly 29,000 GitHub stars … More →
The post NanoCo lands $12 million seed funding, launches enterprise assistant built on NanoClaw appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18154538/nanoclaw-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 17:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>NanoCo, lands, 12, million, seed, funding, launches, enterprise, assistant, built, NanoClaw</media:keywords>
</item>

<item>
<title>Verizon DBIR: Vulnerability exploitation is the dominant initial access vector</title>
<link>https://block385.com/verizon-dbir-vulnerability-exploitation-is-the-dominant-initial-access-vector</link>
<guid>https://block385.com/verizon-dbir-vulnerability-exploitation-is-the-dominant-initial-access-vector</guid>
<description><![CDATA[ Vulnerability exploitation has overtaken stolen credentials as the most common way attackers gain initial access to target networks, according to the 2026 Verizon Data Breach Investigations Report. This is the first time credential theft has been knocked off the top spot in the report’s 19-year history, the company noted. Known initial access vectors over time (Source: Verizon 2026 DBIR) What is Verizon DBIR? Published annually, Verizon’s DBIR is based on the analysis of real-world data … More →
The post Verizon DBIR: Vulnerability exploitation is the dominant initial access vector appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/19182742/verizon-dbir-2026.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 17:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Verizon, DBIR:, Vulnerability, exploitation, the, dominant, initial, access, vector</media:keywords>
</item>

<item>
<title>Infosecurity Europe</title>
<link>https://block385.com/infosecurity-europe</link>
<guid>https://block385.com/infosecurity-europe</guid>
<description><![CDATA[  ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blta212ce7bfdb601e7/6a0dbacd3c21f6a4c08ba686/Infosecurity_Europe_2026.png" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 17:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Infosecurity, Europe</media:keywords>
</item>

<item>
<title>Webworm APT targets European government organizations with new backdoors</title>
<link>https://block385.com/webworm-apt-targets-european-government-organizations-with-new-backdoors</link>
<guid>https://block385.com/webworm-apt-targets-european-government-organizations-with-new-backdoors</guid>
<description><![CDATA[ ESET has released an analysis of the 2025 activity of Webworm, a China-aligned APT group tracked as Space Pirates and UAT-8302. Active since at least 2022, the group initially focused on targets in Asia, but has recently expanded its operations into Europe. ESET observed Webworm targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. The group also expanded its activity into South Africa, where researchers identified activity involving a local university. Discord … More →
The post Webworm APT targets European government organizations with new backdoors appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/06144700/door-red-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 17:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Webworm, APT, targets, European, government, organizations, with, new, backdoors</media:keywords>
</item>

<item>
<title>Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API</title>
<link>https://block385.com/webworm-deploys-echocreep-and-graphworm-backdoors-using-discord-and-ms-graph-api</link>
<guid>https://block385.com/webworm-deploys-echocreep-and-graphworm-backdoors-using-discord-and-ms-graph-api</guid>
<description><![CDATA[ Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&amp;C) communications.

Webworm, first publicly documented by Broadcom-owned Symantec in September 2022, is assessed to be active since at least 2022, targeting government agencies ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjt4cD52DtnzH5FM8ZMrW9KyPrD1ysrJURSmqalrw9f6siP8XxYqClsqV6ofHpM8ir7gBnmmvehj5HB1k0aSHdPmLtKKwtLLvjSi4ELa9eMq12maW7p56a2yBdl7xzdfv6893fvQxLIH0kKGYKnzYM_7-3XysWIGsSNiEYXBjmiWFqe0Pe8uq-TkWlQjjv4/s1600/cyberattack-paki.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 16:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Webworm, Deploys, EchoCreep, and, GraphWorm, Backdoors, Using, Discord, and, Graph, API</media:keywords>
</item>

<item>
<title>Agent AI is Coming. Are You Ready?</title>
<link>https://block385.com/agent-ai-is-coming-are-you-ready</link>
<guid>https://block385.com/agent-ai-is-coming-are-you-ready</guid>
<description><![CDATA[ New Industry Data Just Released Suggests Not.

On May 19th, 2026, Orchid Security released the results of our Identity Gap: Snapshot 2026. Among the findings, &quot;identity dark matter&quot; (the unseen, unmanaged elements of identity) now overshadows the visible elements 57% vs. 43%. And it couldn&#039;t have occurred at a worse time, with enterprises embracing Agent AI with both arms (and unfortunately, as ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjYQaF0euKIc86WLed9RLojSVHUNrnpx7_OeZHvmaPtnFPmL3WrhC-DU-7asOtrYx8fBGP-UCdxI1QljVgaT_wYA6uIye4yHpzpk-uSQb934K7NDSPn-jFJR63cEeUZ8SsDevlcvX-O62_-C8HZeVreeg2aB5stt6z9kluLUvIUgXAGVpAMccDc19lrsmK/s1600/agentai.gif" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 16:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Agent, Coming., Are, You, Ready</media:keywords>
</item>

<item>
<title>ArmorCode gives security teams AI workers for exposure and remediation</title>
<link>https://block385.com/armorcode-gives-security-teams-ai-workers-for-exposure-and-remediation</link>
<guid>https://block385.com/armorcode-gives-security-teams-ai-workers-for-exposure-and-remediation</guid>
<description><![CDATA[ ArmorCode has announced Anya Agents, a new agentic AI framework delivered on the patented ArmorCode Agentic AI Platform that enables organizations to operationalize AI-driven security workflows at enterprise scale. Built on ArmorCode’s Context Risk Graph, Anya Agents help security teams move beyond generic AI assistants by turning unified security and business context into purpose-built AI workers for triage, exposure analysis, remediation, validation, and compliance. Traditional vulnerability management is no longer valid. The tsunami of high … More →
The post ArmorCode gives security teams AI workers for exposure and remediation appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 15:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>ArmorCode, gives, security, teams, workers, for, exposure, and, remediation</media:keywords>
</item>

<item>
<title>Novata uses AI to map risk across portfolios and supply chains</title>
<link>https://block385.com/novata-uses-ai-to-map-risk-across-portfolios-and-supply-chains</link>
<guid>https://block385.com/novata-uses-ai-to-map-risk-across-portfolios-and-supply-chains</guid>
<description><![CDATA[ Novata has announced the launch of Risk Atlas, a new AI-powered risk monitoring tool designed to help organizations identify, compare, and prioritize risks across portfolios and supply chains. Framework for comparative risk visibility Risk Atlas provides a single, customizable framework for comparing risk across entities, normalizing diverse risk signals into a comparable view across portfolios and supply chains. It enables organizations to: Gain insight across multiple categories to identify where risk is concentrated or emerging … More →
The post Novata uses AI to map risk across portfolios and supply chains appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 15:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Novata, uses, map, risk, across, portfolios, and, supply, chains</media:keywords>
</item>

<item>
<title>FBI: $388 million lost in crypto ATM scams in 2026</title>
<link>https://block385.com/fbi-388-million-lost-in-crypto-atm-scams-in-2026</link>
<guid>https://block385.com/fbi-388-million-lost-in-crypto-atm-scams-in-2026</guid>
<description><![CDATA[ Americans lost more than $388 million to crypto kiosk scams in 2025, with the FBI warning that criminals are increasingly directing victims to transfer funds through these machines. Cryptocurrency kiosks, popularly known as Bitcoin ATMs, are physical automated teller machines that allow users to buy cryptocurrencies with cash or card, and some also let users sell digital assets for cash. Like regular ATMs, they are commonly located in public places with high foot traffic. “In … More →
The post FBI: $388 million lost in crypto ATM scams in 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/09/16112525/crypto_scams.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 15:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>FBI:, 388, million, lost, crypto, ATM, scams, 2026</media:keywords>
</item>

<item>
<title>What It&amp;apos;ll Take to Make AI BOMs Usable in a Modern Security Program</title>
<link>https://block385.com/what-itll-take-to-make-ai-boms-usable-in-a-modern-security-program</link>
<guid>https://block385.com/what-itll-take-to-make-ai-boms-usable-in-a-modern-security-program</guid>
<description><![CDATA[ Five ways CISOs can prepare for consuming AI Bill of Materials and influence the direction of how they&#039;re generated. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt430d36ffa6e389ff/6a0dabba72bcb6d3b2c99b01/robotwork-_nastassia-AdobeStock_195826507.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>What, Itll, Take, Make, BOMs, Usable, Modern, Security, Program</media:keywords>
</item>

<item>
<title>Typosquatting Is No Longer a User Problem. It&amp;apos;s a Supply Chain Problem</title>
<link>https://block385.com/typosquatting-is-no-longer-a-user-problem-its-a-supply-chain-problem</link>
<guid>https://block385.com/typosquatting-is-no-longer-a-user-problem-its-a-supply-chain-problem</guid>
<description><![CDATA[ AI-generated lookalike domains are now embedded inside the third-party scripts running on your web properties. Here&#039;s why your current stack can&#039;t see them, and what detection actually requires.
Download the CISO Expert Guide to Typosquatting in the AI Era →


TL;DR 


  Typosquatting is no longer a user problem. Attackers now embed lookalike domains inside legitimate third-party scripts. ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLWPxY_gRwc5keQNREyoTXSadlwpCLyUdAq4v1fQA5_lA2tJ0Ia6xOk-FaLuNHwJjV_xaF7M0xzPvqHk4e7aym6R7J2aaGCGm7Bnv8OXh7GScZ-G7ic5pdEgK-0E0_y_yLz16V2A2GL5uTmU7tRPUyoDl5LfzTzQnuMlI1QV7SEhRC9Cli7zci_no9pyk/s1600/ref.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 14:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Typosquatting, Longer, User, Problem., Its, Supply, Chain, Problem</media:keywords>
</item>

<item>
<title>Darwinium updates mobile SDKs to detect remote access scam activity</title>
<link>https://block385.com/darwinium-updates-mobile-sdks-to-detect-remote-access-scam-activity</link>
<guid>https://block385.com/darwinium-updates-mobile-sdks-to-detect-remote-access-scam-activity</guid>
<description><![CDATA[ Darwinium has announced updates to its Android and iOS mobile SDKs. It enables banks, payment providers, and digital businesses to tackle the proliferation of remote access scams, including those that manipulate live sessions and account farming operations that run mule networks. “Most fraud platforms validate trust at a single moment, typically at login or payment, through device binding, authentication, or a step-up challenge,” said Alisdair Faulkner, CEO of Darwinium. “But agentic-fueled mobile fraud doesn’t happen … More →
The post Darwinium updates mobile SDKs to detect remote access scam activity appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 13:00:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Darwinium, updates, mobile, SDKs, detect, remote, access, scam, activity</media:keywords>
</item>

<item>
<title>Encryption Consulting launches CertSecure Manager v3.3 with zero&#45;touch certificate renewals</title>
<link>https://block385.com/encryption-consulting-launches-certsecure-manager-v33-with-zero-touch-certificate-renewals</link>
<guid>https://block385.com/encryption-consulting-launches-certsecure-manager-v33-with-zero-touch-certificate-renewals</guid>
<description><![CDATA[ Encryption Consulting has released CertSecure Manager v3.3, which automates zero-touch certificate renewal across all major enterprise server platforms and extends CA support to 11 providers, including Google Public CA and AWS. Certificate-related outages can cost enterprises millions in unplanned downtime, and expired or misconfigured certificates often cause serious security incidents. CertSecure Manager v3.3 closes both gaps, removing the manual steps that introduce costly renewal errors. “With v3.3, we have made zero-touch certificate renewal a reality … More →
The post Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 13:00:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Encryption, Consulting, launches, CertSecure, Manager, v3.3, with, zero-touch, certificate, renewals</media:keywords>
</item>

<item>
<title>Trust3 AI focuses on AI agent risks with MCP Security layer</title>
<link>https://block385.com/trust3-ai-focuses-on-ai-agent-risks-with-mcp-security-layer</link>
<guid>https://block385.com/trust3-ai-focuses-on-ai-agent-risks-with-mcp-security-layer</guid>
<description><![CDATA[ Trust3 AI has announced the launch of Model Context Protocol (MCP) Security, establishing a new standard for safeguarding enterprise agentic AI workloads. This solution forms a key capability within Trust3 AI’s enterprise agent control plane, empowering security and governance teams with a unified trust layer to seamlessly and safely connect AI agents with vital business data, applications, and systems. As organizations increasingly adopt autonomous AI architectures, internal IT teams face significant risks. MCP servers are … More →
The post Trust3 AI focuses on AI agent risks with MCP Security layer appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 13:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Trust3, focuses, agent, risks, with, MCP, Security, layer</media:keywords>
</item>

<item>
<title>TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension</title>
<link>https://block385.com/teampcp-breached-githubs-internal-codebase-via-poisoned-vs-code-extension</link>
<guid>https://block385.com/teampcp-breached-githubs-internal-codebase-via-poisoned-vs-code-extension</guid>
<description><![CDATA[ Following TeamPCP’s claim that they’ve breached GitHub’s own private code repositories, the Microsoft-owned company launched an investigation and confirmed the compromise. “Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far,” GitHub stated. The source of the breach The company previously said that they have no evidence that customer information stored outside of GitHub’s internal repositories was … More →
The post TeamPCP breached GitHub’s internal codebase via poisoned VS Code extension appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/11/06102419/github-danger.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 13:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>TeamPCP, breached, GitHub’s, internal, codebase, via, poisoned, Code, extension</media:keywords>
</item>

<item>
<title>Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE&#45;2026&#45;45585 Exploit</title>
<link>https://block385.com/microsoft-releases-mitigation-for-yellowkey-bitlocker-bypass-cve-2026-45585-exploit</link>
<guid>https://block385.com/microsoft-releases-mitigation-for-yellowkey-bitlocker-bypass-cve-2026-45585-exploit</guid>
<description><![CDATA[ Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week.

The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass.

&quot;Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as &#039;YellowKey,&#039;&quot; the ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8DmW5nAG63-9iR2RmnP7i3GVJ9EBtLznscnnjROZ-DWRALYo0zsPNjUm2J6khkqSDJiX5Gmwb8sxPh4jHRcsJWFhKSdxZzz4D2f5bOahbfcnmQrUdvhyphenhyphenNVrE-LFMUhhf6rvSyxG2CoVhEFxbZSpEc0y52PM-qxwn02cDP3K3hEzf1nqcRNZEG1wOTjAiQ/s1600/bitlocker-exploit.png" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 12:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Releases, Mitigation, for, YellowKey, BitLocker, Bypass, CVE-2026-45585, Exploit</media:keywords>
</item>

<item>
<title>GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos</title>
<link>https://block385.com/github-breached-employee-device-hack-led-to-exfiltration-of-3800-internal-repos</link>
<guid>https://block385.com/github-breached-employee-device-hack-led-to-exfiltration-of-3800-internal-repos</guid>
<description><![CDATA[ GitHub on Tuesday said it&#039;s investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform&#039;s source code and internal organizations for sale on a cybercrime forum.

&quot;While we currently have no evidence of impact to customer information stored outside of GitHub&#039;s internal repositories (such as our customers&#039; enterprises, ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoDiyeJZY33dxAsa8qElLYXNILLDT4NhloINZiuzcx3La2JvDK_d54kM8qsx_obt8vQ3FpTJr2ZVoMYiEcqHN0sbt-1A_MHlS7mSavlbDiEDg42HN1d4wCffs7ytuZhDvmMjuej5oljVIqIuRezyZCLmafRclN3wNBKcboV-19F0VMMBkVsQZckV5UaiiH/s1600/github.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 12:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>GitHub, Breached, —, Employee, Device, Hack, Led, Exfiltration, 3, 800, Internal, Repos</media:keywords>
</item>

<item>
<title>Interpol&amp;apos;s &amp;apos;Operation Ramz&amp;apos; Pioneers Cross&#45;Region Collabs in Middle East</title>
<link>https://block385.com/interpols-operation-ramz-pioneers-cross-region-collabs-in-middle-east</link>
<guid>https://block385.com/interpols-operation-ramz-pioneers-cross-region-collabs-in-middle-east</guid>
<description><![CDATA[ While the numbers are modest, the crackdown on cybercrime involved 13 countries in the MENA region, the largest law enforcement collaboration to date. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt0be6af563749ef53/6a0cb6c6fc6d781d0eb34f55/rams-at-luxor-in-Egypt-Yuliia24-shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 11:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Interpols, Operation, Ramz, Pioneers, Cross-Region, Collabs, Middle, East</media:keywords>
</item>

<item>
<title>Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE&#45;2026&#45;45585)</title>
<link>https://block385.com/microsoft-provides-mitigation-for-yellowkey-bitlocker-bypass-flaw-cve-2026-45585</link>
<guid>https://block385.com/microsoft-provides-mitigation-for-yellowkey-bitlocker-bypass-flaw-cve-2026-45585</guid>
<description><![CDATA[ Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the full-disk encryption feature built into Windows, and access users’ data. In the meantime, the company has provided step-by-step mitigation advice to protect affected Windows devices from exploitation. CVE-2026-45585 and the YellowKey exploit CVE-2026-45585 is a security feature bypass vulnerability that can only be exploited if the attacker has physical access … More →
The post Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/29223248/access.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 11:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, provides, mitigation, for, “YellowKey”, BitLocker, bypass, flaw, CVE-2026-45585</media:keywords>
</item>

<item>
<title>7 hard truths security pros should know: 2026 DevOps Threats Report</title>
<link>https://block385.com/7-hard-truths-security-pros-should-know-2026-devops-threats-report</link>
<guid>https://block385.com/7-hard-truths-security-pros-should-know-2026-devops-threats-report</guid>
<description><![CDATA[ In 2025, trusted Git hosting platforms became a playground for cyber criminals. This is the main conclusion from the latest “DevOps Threat Unwrapped Report 2026” by GitProtect. If you want to effectively counter attacks targeted at your code (and business), you need security measures, good practices, and knowledge. Strengthen your organization’s security posture. Learn about 7 hard truths from the report to discover the latest threats and ways to fight them off. #1 AI assistants … More →
The post 7 hard truths security pros should know: 2026 DevOps Threats Report appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/19100537/gitprotect-2026_devsecops_threat_landscape.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 09:00:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>hard, truths, security, pros, should, know:, 2026, DevOps, Threats, Report</media:keywords>
</item>

<item>
<title>When your AI assistant has the keys to production</title>
<link>https://block385.com/when-your-ai-assistant-has-the-keys-to-production</link>
<guid>https://block385.com/when-your-ai-assistant-has-the-keys-to-production</guid>
<description><![CDATA[ Large language models in operational roles query telemetry, propose configuration changes, and in some deployments execute those changes against live infrastructure. Ticket drafting and alert summarization were the starting point. Vendors describe this work as autonomous remediation or self-healing infrastructure. A recent survey on agentic AI in network and IT operations gives it a more useful name: a confused-deputy problem waiting to happen. The confused-deputy problem in agentic AI security The classic confused-deputy attack tricks … More →
The post When your AI assistant has the keys to production appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/15085505/lock-lines-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 09:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>When, your, assistant, has, the, keys, production</media:keywords>
</item>

<item>
<title>CVE Lite CLI: Open&#45;source dependency vulnerability scanner</title>
<link>https://block385.com/cve-lite-cli-open-source-dependency-vulnerability-scanner</link>
<guid>https://block385.com/cve-lite-cli-open-source-dependency-vulnerability-scanner</guid>
<description><![CDATA[ Dependency vulnerability scanning in JavaScript and TypeScript projects has long sat at the end of the development pipeline. Pull requests get opened, continuous integration runs, and a security scanner returns a list of CVE identifiers that developers then have to triage hours or days after writing the code. CVE Lite CLI, now an officially recognized OWASP Incubator Project, moves that check to the developer’s terminal. The open-source tool, maintained by Sonu Kapoor, reads a project’s … More →
The post CVE Lite CLI: Open-source dependency vulnerability scanner appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/14134803/cve-lite-cli-1600.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 09:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CVE, Lite, CLI:, Open-source, dependency, vulnerability, scanner</media:keywords>
</item>

<item>
<title>Communicating cyber risk in dollars boards understand</title>
<link>https://block385.com/communicating-cyber-risk-in-dollars-boards-understand</link>
<guid>https://block385.com/communicating-cyber-risk-in-dollars-boards-understand</guid>
<description><![CDATA[ In this Help Net Security interview, Nick Nieuwenhuis, Cybersecurity Architect at Nedscaper, explains why cybersecurity has not delivered the resilience that decades of investment have promised. He argues that spending has leaned too heavily on technical controls while neglecting people, processes, and organizational dynamics. He unpacks the gap between security teams and boards, pointing to weak risk communication and a reliance on qualitative heatmaps over hard evidence. He pushes back on root cause analysis as … More →
The post Communicating cyber risk in dollars boards understand appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18105720/nick_nieuwenhuis-2-nedscaper.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Communicating, cyber, risk, dollars, boards, understand</media:keywords>
</item>

<item>
<title>Grafana GitHub Breach Exposes Source Code via TanStack npm Attack</title>
<link>https://block385.com/grafana-github-breach-exposes-source-code-via-tanstack-npm-attack</link>
<guid>https://block385.com/grafana-github-breach-exposes-source-code-via-tanstack-npm-attack</guid>
<description><![CDATA[ Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised.

It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private source code along with internal GitHub repositories.

&quot;After the initial assessment, we found that in addition to source ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1N3gjAFZQ-1hptUuKwQmHMjlZwIMDn6H6mKc9UuDELAKWl_3Kow6EcD72IkWpBf8ZB2Db8wrZW86zVxKaEgQZ7_sVrWoDokD1LoLPUqhhCw2lLDl9ODqq2ZkfBrK6SUTrbROBuFNXN16HPtMWtS9EMIFsO3yQsISWCK0JrlwiUWineb9sxIq-un41smHG/s1600/grafana-breach.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 08:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Grafana, GitHub, Breach, Exposes, Source, Code, via, TanStack, npm, Attack</media:keywords>
</item>

<item>
<title>What Will Make AI BOMs Real?</title>
<link>https://block385.com/what-will-make-ai-boms-real</link>
<guid>https://block385.com/what-will-make-ai-boms-real</guid>
<description><![CDATA[ A brief overview of the forces at play that will get more organizations on board with creating and consuming AI bill of materials (BOMs). ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt82d57f92a103d9df/6a0d147edc31f80b8cc3c3a0/robot-Pluto-alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>What, Will, Make, BOMs, Real</media:keywords>
</item>

<item>
<title>What happens when your identity provider becomes the kill chain</title>
<link>https://block385.com/what-happens-when-your-identity-provider-becomes-the-kill-chain</link>
<guid>https://block385.com/what-happens-when-your-identity-provider-becomes-the-kill-chain</guid>
<description><![CDATA[ In this Help Net Security video, Colin Constable, CTO at Atsign, explains why your identity provider (IdP) has become the kill chain in cyberattacks. Attackers steal session cookies, tokens, or consent grants you’ve already issued and walk in behind you. Constable breaks down how passwords, session cookies, and OAuth grants all rely on shared secrets between browser and server. Even with TLS encryption, intermediaries like CDNs, load balancers, and WAFs can see these credentials in … More →
The post What happens when your identity provider becomes the kill chain appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/14074133/identity-face-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>What, happens, when, your, identity, provider, becomes, the, kill, chain</media:keywords>
</item>

<item>
<title>GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories</title>
<link>https://block385.com/github-investigating-teampcp-claimed-breach-of-4000-internal-repositories</link>
<guid>https://block385.com/github-investigating-teampcp-claimed-breach-of-4000-internal-repositories</guid>
<description><![CDATA[ GitHub on Tuesday said it&#039;s investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform&#039;s source code and internal organizations for sale on a cybercrime forum.

&quot;While we currently have no evidence of impact to customer information stored outside of GitHub&#039;s internal repositories (such as our customers&#039; enterprises, ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgoDiyeJZY33dxAsa8qElLYXNILLDT4NhloINZiuzcx3La2JvDK_d54kM8qsx_obt8vQ3FpTJr2ZVoMYiEcqHN0sbt-1A_MHlS7mSavlbDiEDg42HN1d4wCffs7ytuZhDvmMjuej5oljVIqIuRezyZCLmafRclN3wNBKcboV-19F0VMMBkVsQZckV5UaiiH/s1600/github.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 06:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>GitHub, Investigating, TeamPCP, Claimed, Breach, 4, 000, Internal, Repositories</media:keywords>
</item>

<item>
<title>Verizon DBIR: Enterprises Face a Dangerous Vulnerability Glut</title>
<link>https://block385.com/verizon-dbir-enterprises-face-a-dangerous-vulnerability-glut</link>
<guid>https://block385.com/verizon-dbir-enterprises-face-a-dangerous-vulnerability-glut</guid>
<description><![CDATA[ Verizon&#039;s &quot;2026 Data Breach Investigations Report&quot; (&quot;DBIR&quot;) finds that exploits are now involved in 31% of initial access for breaches, while patching lags too far behind the bad guys. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltdf277665f3314cb9/6a0cc97e3c21f6422d8ba496/risk_blocks_Cagkan_Sayin_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 01:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Verizon, DBIR:, Enterprises, Face, Dangerous, Vulnerability, Glut</media:keywords>
</item>

<item>
<title>Windows Zero&#45;Day Barrage Continues After Patch Tuesday</title>
<link>https://block385.com/windows-zero-day-barrage-continues-after-patch-tuesday</link>
<guid>https://block385.com/windows-zero-day-barrage-continues-after-patch-tuesday</guid>
<description><![CDATA[ YellowKey, GreenPlasma, and MiniPlasma add to the growing list of vulnerabilities a security researcher disclosed over the past six weeks. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt94e5c85a811ff21b/6a0cc864ccb12f62a67122e5/zeroday_JLStock_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 20 May 2026 01:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Windows, Zero-Day, Barrage, Continues, After, Patch, Tuesday</media:keywords>
</item>

<item>
<title>CISA Exposes Secrets, Credentials in &amp;apos;Private&amp;apos; Repo</title>
<link>https://block385.com/cisa-exposes-secrets-credentials-in-private-repo</link>
<guid>https://block385.com/cisa-exposes-secrets-credentials-in-private-repo</guid>
<description><![CDATA[ The agency&#039;s GitHub repository, publicly available since November 2025, was ironically named &quot;Private-CISA.&quot; ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt188d6215ae555513/6a0cb49ac7403d88c6336bf7/github_PJ_McDonnell_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 23:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CISA, Exposes, Secrets, Credentials, Private, Repo</media:keywords>
</item>

<item>
<title>Stealer Spoofs Google, Microsoft &amp;amp;amp; Apple, Then Backdoors macOS</title>
<link>https://block385.com/stealer-spoofs-google-microsoft-apple-then-backdoors-macos</link>
<guid>https://block385.com/stealer-spoofs-google-microsoft-apple-then-backdoors-macos</guid>
<description><![CDATA[ The SHub Reaper stealer, which hides behind fake WeChat and Miro installers, marks a shift from ClickFix social engineering to Apple script-based execution. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt92862d21865d67ee/6a0c49b0d929ba87161f7f33/macOS_AfricaStudio_AlamyStockPhoto.png" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 23:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Stealer, Spoofs, Google, Microsoft, &amp;amp, Apple, Then, Backdoors, macOS</media:keywords>
</item>

<item>
<title>[Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You</title>
<link>https://block385.com/virtual-event-anatomy-of-a-data-breach-what-to-do-if-it-happens-to-you</link>
<guid>https://block385.com/virtual-event-anatomy-of-a-data-breach-what-to-do-if-it-happens-to-you</guid>
<description><![CDATA[  ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt947fd68cd895a80d/6a060e70239afa534b9406ac/DR_Anatomy_of_a_Data_Breach_Virtual_Event_2026.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 21:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Virtual, Event, Anatomy, Data, Breach:, What, Happens, You</media:keywords>
</item>

<item>
<title>Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps</title>
<link>https://block385.com/trapdoor-android-ad-fraud-scheme-hit-659-million-daily-bid-requests-using-455-apps</link>
<guid>https://block385.com/trapdoor-android-ad-fraud-scheme-hit-659-million-daily-bid-requests-using-455-apps</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users.

The activity, per HUMAN&#039;s Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control (C2) domains, turning the infrastructure into a pipeline for multi-stage fraud.

&quot;Users ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4-ldAXS8Yw3BhdSS9xeJFNzwDm-mrNDxHr28zcknAKH8knTU_WleHEhmJ-vgNokgVbm9y8vRH18v9Oxz6F7twmnBoJfIQ2fVeuhEErRAF31F9MES02sZMhYG-i7F9Ty-C-yD64U4cmgq3CD7nuEnD9OZpxWCTKAPCXfIDKycUeZEfJIBBagPPW72JgWZO/s1600/android-ad-fraud.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 20:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Trapdoor, Android, Fraud, Scheme, Hit, 659, Million, Daily, Bid, Requests, Using, 455, Apps</media:keywords>
</item>

<item>
<title>DirtyDecrypt PoC Released for Linux Kernel CVE&#45;2026&#45;31635 LPE Vulnerability</title>
<link>https://block385.com/dirtydecrypt-poc-released-for-linux-kernel-cve-2026-31635-lpe-vulnerability</link>
<guid>https://block385.com/dirtydecrypt-poc-released-for-linux-kernel-cve-2026-31635-lpe-vulnerability</guid>
<description><![CDATA[ Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE).
Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security team on May 9, 2026, only to be informed by the maintainers that it was a duplicate of a vulnerability that had ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgecVdZ_vIxfMWdiQkn7dC_SCueSRLBHaU01aHrtW1lUsx3_5gwbM6fG5NyV-VUhnDxvolk_tzMNWgINg06cwjKL1xIeDIFMiFH56IUO_zwZwJqiLnMp-VJcIWFjhulk1AHnlZ_ETgH3vg6Q6SHS4Ae-teRmaLDY4XZhONjoz4MeKvQLyzJ_YdckL8lk3fe/s1600/linux-poc.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 18:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>DirtyDecrypt, PoC, Released, for, Linux, Kernel, CVE-2026-31635, LPE, Vulnerability</media:keywords>
</item>

<item>
<title>Selector extends AI&#45;driven observability into multi&#45;cloud environments</title>
<link>https://block385.com/selector-extends-ai-driven-observability-into-multi-cloud-environments</link>
<guid>https://block385.com/selector-extends-ai-driven-observability-into-multi-cloud-environments</guid>
<description><![CDATA[ Selector has announced the expansion of its platform with AI-powered multi-cloud observability capabilities. The extension of Selector’s AI-driven observability approach into multi-cloud environments enables organizations to correlate signals across the full hybrid path. By unifying rich telemetry data from cloud, network, and infrastructure into a shared intelligence layer, Selector gives teams a more complete, actionable view of incidents and true root cause. As cloud adoption and hybrid infrastructure expansion have become the operational norm, teams … More →
The post Selector extends AI-driven observability into multi-cloud environments appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 17:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Selector, extends, AI-driven, observability, into, multi-cloud, environments</media:keywords>
</item>

<item>
<title>PureLogs infostealer is stealing credentials worldwide</title>
<link>https://block385.com/purelogs-infostealer-is-stealing-credentials-worldwide</link>
<guid>https://block385.com/purelogs-infostealer-is-stealing-credentials-worldwide</guid>
<description><![CDATA[ A phishing campaign is smuggling the powerful PureLogs information stealer onto targets’ Windows machines by hiding encrypted malicious payloads inside cat photos, Fortinet researchers discovered. The attack The attack starts with a phishing email containing a TXZ archive and using an invoice-themed lure to pressure the victim into opening it quickly: The phishing email carrying the malicious TXZ archive (Source: Fortinet) The extracted JavaScript stores malicious commands in process environment variables (which are also filled … More →
The post PureLogs infostealer is stealing credentials worldwide appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/25121802/malware-computer-2-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>PureLogs, infostealer, stealing, credentials, worldwide</media:keywords>
</item>

<item>
<title>Looking Back, Looking Forward: Digesting a Dynamic Bouillabaisse of Cyber Evolution</title>
<link>https://block385.com/looking-back-looking-forward-digesting-a-dynamic-bouillabaisse-of-cyber-evolution</link>
<guid>https://block385.com/looking-back-looking-forward-digesting-a-dynamic-bouillabaisse-of-cyber-evolution</guid>
<description><![CDATA[ Dark Reading editors reflect on two decades of dramatic change — from perimeter defense to assume-breach strategies — and warn that while AI, cloud, and COVID-19 have transformed the threat landscape, organizations are still failing at fundamental security hygiene that could stop sophisticated attacks in their tracks. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltff02a5783ecdf09b/6a0c6774e492c85df1966d2d/stew-Zoonar_GmbH-alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 17:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Looking, Back, Looking, Forward:, Digesting, Dynamic, Bouillabaisse, Cyber, Evolution</media:keywords>
</item>

<item>
<title>The New Phishing Click: How OAuth Consent Bypasses MFA</title>
<link>https://block385.com/the-new-phishing-click-how-oauth-consent-bypasses-mfa</link>
<guid>https://block385.com/the-new-phishing-click-how-oauth-consent-bypasses-mfa</guid>
<description><![CDATA[ In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries. 

The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelogin and complete their normal MFA challenge, then walked away believing they had verified a ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLnnvBvl0Gs5pfpUcrlJ_Ni62CyGs5UpoGCmpUAjReyBpExj5FzhuxSwuUcfQiyxDqeeoy6jSAHq4tA2KUnO5CRfbpfd_jN1ndeXgC0MiG0TrAfAyW67eybZeHMY-t6_kICQdPPKqK-1n9Ngkrj7UJrZZa1KQWqN9WjaTaDuHA_t6RW9Stul6tb82OS_4/s1600/reco1.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 16:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, New, Phishing, Click:, How, OAuth, Consent, Bypasses, MFA</media:keywords>
</item>

<item>
<title>Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare</title>
<link>https://block385.com/drupal-to-release-urgent-core-security-updates-on-may-20-sites-told-to-prepare</link>
<guid>https://block385.com/drupal-to-release-urgent-core-security-updates-on-may-20-sites-told-to-prepare</guid>
<description><![CDATA[ Drupal has issued an alert stating that it intends to release a &quot;core security release&quot; for all supported branches on May 20, 2026, from 5-9 p.m. UTC.

&quot;The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hours or days,&quot; the maintainers of the PHP-based content management system (CMS) said.

&quot;Not all configurations are ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjdm6ntsTvJJXoF1Bvx2Qm11faosxt-w7g0VzPCnsORnDN-q79t1wnbzqTFxbkRw5DF1DjhdDUgZ1H_0O4h35tZcEvlsM7dEUkbPyvaQdkEhhyGhpF90Bug4O1aai-0dXi1DdnnOpH2SmC8GoQD0TAd742-StQ4Pva_IVXNUcRpy9V96B7dwBnOc41xScyj/s1600/drupal-update.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 16:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Drupal, Release, Urgent, Core, Security, Updates, May, 20, Sites, Told, Prepare</media:keywords>
</item>

<item>
<title>The end of unencrypted Discord calls is here</title>
<link>https://block385.com/the-end-of-unencrypted-discord-calls-is-here</link>
<guid>https://block385.com/the-end-of-unencrypted-discord-calls-is-here</guid>
<description><![CDATA[ Discord has protected voice and video calls in DMs, group DMs, voice channels, and Go Live streams with end-to-end encryption (E2EE) by default. The company began experimenting with E2EE for voice and video in 2023, starting a long-term effort. End-to-end encryption allows only participants in a call to access its content, while Discord does not have access to media encryption keys. Since then, the company introduced DAVE, an open and audited E2EE protocol developed for … More →
The post The end of unencrypted Discord calls is here appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/02/10070641/discord-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 15:00:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, end, unencrypted, Discord, calls, here</media:keywords>
</item>

<item>
<title>New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain</title>
<link>https://block385.com/new-macos-infostealer-impersonates-apple-microsoft-and-google-in-a-single-attack-chain</link>
<guid>https://block385.com/new-macos-infostealer-impersonates-apple-microsoft-and-google-in-a-single-attack-chain</guid>
<description><![CDATA[ A SHub macOS infostealer variant called Reaper impersonates Apple, Microsoft, and Google to trick users into executing malicious code, then targets browser data, password managers, and cryptocurrency wallets while establishing persistence for continued access, SentinelOne found. ClickFix gives way to a new delivery method Consistent with earlier SHub versions, Reaper uses a multi-stage execution chain. Researchers said this variant shifts away from standard ClickFix social engineering techniques, where victims are tricked into pasting commands into … More →
The post New macOS infostealer impersonates Apple, Microsoft, and Google in a single attack chain appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/02/09085518/infostealers2-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 15:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, macOS, infostealer, impersonates, Apple, Microsoft, and, Google, single, attack, chain</media:keywords>
</item>

<item>
<title>Canonical ships Ubuntu Core 26 with 15 years of security maintenance</title>
<link>https://block385.com/canonical-ships-ubuntu-core-26-with-15-years-of-security-maintenance</link>
<guid>https://block385.com/canonical-ships-ubuntu-core-26-with-15-years-of-security-maintenance</guid>
<description><![CDATA[ Operators of industrial sensors, edge AI controllers, and connected medical equipment now have a refreshed long-term Linux option for fleets that must stay patched for more than a decade. Canonical released Ubuntu Core 26, the latest long-term supported version of its minimal, immutable operating system, with security maintenance lasting up to 15 years. The release targets devices subject to the European Union’s Cyber Resilience Act and customers running attested edge AI workloads. Every component on … More →
The post Canonical ships Ubuntu Core 26 with 15 years of security maintenance appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/31164614/linux-1500-1-patch.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 15:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Canonical, ships, Ubuntu, Core, with, years, security, maintenance</media:keywords>
</item>

<item>
<title>LaunchDarkly adds real&#45;time controls for AI agents in production</title>
<link>https://block385.com/launchdarkly-adds-real-time-controls-for-ai-agents-in-production</link>
<guid>https://block385.com/launchdarkly-adds-real-time-controls-for-ai-agents-in-production</guid>
<description><![CDATA[ LaunchDarkly has launched AgentControl, a new solution that gives software teams real-time control over AI agents in production. With AgentControl, teams can change how an agent behaves at runtime without redeploying the underlying application. As AI agents move into production, engineering teams need new ways to manage configuration, quality, and runtime behavior. Unlike traditional code, agent behavior may vary across models, prompts, and production contexts, even when application code remains unchanged. Once deployed, agent configurations … More →
The post LaunchDarkly adds real-time controls for AI agents in production appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 15:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>LaunchDarkly, adds, real-time, controls, for, agents, production</media:keywords>
</item>

<item>
<title>Is 2026 the Year AI Bills of Materials Get Real?</title>
<link>https://block385.com/is-2026-the-year-ai-bills-of-materials-get-real</link>
<guid>https://block385.com/is-2026-the-year-ai-bills-of-materials-get-real</guid>
<description><![CDATA[ Understanding AI BOMs and where they fit into risk management for artificial intelligence. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltc910f7f1381f9cc0/6a0c51d37e010876184b0788/robot-book-KittipongJirasukhanont-alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 15:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>2026, the, Year, Bills, Materials, Get, Real</media:keywords>
</item>

<item>
<title>SEPPMail Secure E&#45;Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access</title>
<link>https://block385.com/seppmail-secure-e-mail-gateway-vulnerabilities-enable-rce-and-mail-traffic-access</link>
<guid>https://block385.com/seppmail-secure-e-mail-gateway-vulnerabilities-enable-rce-and-mail-traffic-access</guid>
<description><![CDATA[ Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance.
&quot;These vulnerabilities could have been exploited to read all mail traffic or as an entry vector into the internal network,&quot; ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiortK4EUp9FwJsfVYW-j20LfpbM5qMNelk5-T8BbZ7dEcmBLXnqhWW9loE8GD6aexZv3h-xHEgn_N7ECjV8KXdcGwNxsbhCPP07COzt9c8BhMaVTF4OaSnKD2b98mJjsU1d57OXj2FQtOhKyeo6oPcT0-rrOi-_dKf1iielQQnhsprZ43tHyYFbiYhgFK8/s1600/email-hacking.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 12:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>SEPPMail, Secure, E-Mail, Gateway, Vulnerabilities, Enable, RCE, and, Mail, Traffic, Access</media:keywords>
</item>

<item>
<title>Egnyte unveils Email Capture and AI features to unify fragmented data</title>
<link>https://block385.com/egnyte-unveils-email-capture-and-ai-features-to-unify-fragmented-data</link>
<guid>https://block385.com/egnyte-unveils-email-capture-and-ai-features-to-unify-fragmented-data</guid>
<description><![CDATA[ Egnyte has announced a new set of capabilities designed to consolidate fragmented knowledge. Email Capture centralizes critical communications and attachments from siloed inboxes into the Egnyte folder structure, assisting users to make more informed data-driven decisions based on their entire knowledge base. Egnyte is also launching a set of AI-driven integrations and capabilities specifically designed for the architecture, engineering, and construction (AEC) industry. Data fragmentation is a pervasive problem for organizations that can contribute to … More →
The post Egnyte unveils Email Capture and AI features to unify fragmented data appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 11:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Egnyte, unveils, Email, Capture, and, features, unify, fragmented, data</media:keywords>
</item>

<item>
<title>iProov brings identity verification to video meetings to reduce fraud risks</title>
<link>https://block385.com/iproov-brings-identity-verification-to-video-meetings-to-reduce-fraud-risks</link>
<guid>https://block385.com/iproov-brings-identity-verification-to-video-meetings-to-reduce-fraud-risks</guid>
<description><![CDATA[ iProov has launched iProov Verified Meetings, a new solution that enables organizations to verify the identity of video call participants without adding friction to the user experience. Video meetings have become a trusted and scalable communication channel, but attackers are increasingly exploiting them through AI-generated deepfake and injection attacks, creating new fraud risks. Verified Meetings addresses these threats by helping organizations confirm participant identities before meetings begin. The solution is part of the iProov Workforce … More →
The post iProov brings identity verification to video meetings to reduce fraud risks appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 11:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>iProov, brings, identity, verification, video, meetings, reduce, fraud, risks</media:keywords>
</item>

<item>
<title>Babel Street targets AI&#45;driven threats with new agentic investigation capabilities</title>
<link>https://block385.com/babel-street-targets-ai-driven-threats-with-new-agentic-investigation-capabilities</link>
<guid>https://block385.com/babel-street-targets-ai-driven-threats-with-new-agentic-investigation-capabilities</guid>
<description><![CDATA[ Babel Street has launched Insights Investigator, a new agentic capability that puts tradecraft-trained AI agents at the front edge of investigative work while ensuring analysts remain in control of scope, logic, and outcomes of their missions. As part of the Babel Street Insights platform, Investigator represents a shift from search and AI-assisted queries to analyst-directed, AI-executed investigations. Threat actors are no longer constrained by human bandwidth. Nation-state adversaries, organized criminal networks, and hostile foreign intelligence … More →
The post Babel Street targets AI-driven threats with new agentic investigation capabilities appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 11:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Babel, Street, targets, AI-driven, threats, with, new, agentic, investigation, capabilities</media:keywords>
</item>

<item>
<title>Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer</title>
<link>https://block385.com/compromised-nx-console-18950-targeted-vs-code-developers-with-credential-stealer</link>
<guid>https://block385.com/compromised-nx-console-18950-targeted-vs-code-developers-with-credential-stealer</guid>
<description><![CDATA[ Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace.

The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Code, Cursor, and JetBrains. The VS Code extension has more than 2.2 million installations. The Open ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi61imbY3-QbM_mT_6WAxBXaFeZ3eXwprN147ox_bMvVqh9NrS69IwqwwL4qu2z1eRA8NfrWwyJi9bIDuREGEVZ-LdBMCGTSxdul92ZApPGrzwqOcr3b6YBKC19N97sk75izvamQxOqBzokKhF-__uaEuw74ZbKQLxKxMQWgRXSCR3FE6ULeHGxbiIhuEso/s1600/nconsole.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 10:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Compromised, Console, 18.95.0, Targeted, Code, Developers, with, Credential, Stealer</media:keywords>
</item>

<item>
<title>Popular GitHub Action Tags Redirected to Imposter Commit to Steal CI/CD Credentials</title>
<link>https://block385.com/popular-github-action-tags-redirected-to-imposter-commit-to-steal-cicd-credentials</link>
<guid>https://block385.com/popular-github-action-tags-redirected-to-imposter-commit-to-steal-cicd-credentials</guid>
<description><![CDATA[ In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server.

&quot;Every existing tag in the repository has been moved to point to an imposter commit that does not appear in the action&#039;s normal commit history, ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc7jpVO6HhBuEBTjkwmNjYhKlFmhhmytOqNZHYuGP-dNWrf3AoyE68yoKj77elddOX4Ps2x9jSuwhi5sE-QjK_oEjLXgQW9e6EHx6W0G7qTqYTM3fZh1AQTyrgm2o-PFBeD9ryHnC6fDmK5MYKUzBjU_pJibTilnm1d99WSQkJux6PXXRydkYW5d15Ada-/s1600/step.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 10:30:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Popular, GitHub, Action, Tags, Redirected, Imposter, Commit, Steal, CICD, Credentials</media:keywords>
</item>

<item>
<title>Earbud sensors can authenticate users by their heartbeat, study finds</title>
<link>https://block385.com/earbud-sensors-can-authenticate-users-by-their-heartbeat-study-finds</link>
<guid>https://block385.com/earbud-sensors-can-authenticate-users-by-their-heartbeat-study-finds</guid>
<description><![CDATA[ Researchers built a continuous authentication system called AccLock that identifies a wearer by the tiny vibrations a heartbeat makes inside the ear canal. The signal comes from an accelerometer of the kind already sitting inside many wireless earbuds, so no extra hardware is needed. The point is to keep verifying that the person wearing the device is the legitimate user long after the initial unlock. Example of an application scenario for AccLock (Source: Research paper) … More →
The post Earbud sensors can authenticate users by their heartbeat, study finds appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/14151117/earpod-heartbeat-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 09:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Earbud, sensors, can, authenticate, users, their, heartbeat, study, finds</media:keywords>
</item>

<item>
<title>Public Instagram posts provide raw material for AI phishing campaigns</title>
<link>https://block385.com/public-instagram-posts-provide-raw-material-for-ai-phishing-campaigns</link>
<guid>https://block385.com/public-instagram-posts-provide-raw-material-for-ai-phishing-campaigns</guid>
<description><![CDATA[ A handful of public Instagram posts can give attackers enough material to generate convincing phishing emails with GenAI. Research from the University of Texas at Arlington and Louisiana State University showed how public social media activity can be turned into phishing messages that appear personal and credible to human recipients. Attack pipeline overview (Source: Research paper) The findings highlight a growing problem for security teams and users. Attackers no longer need stolen databases or long … More →
The post Public Instagram posts provide raw material for AI phishing campaigns appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/11150426/instagram-dark-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Public, Instagram, posts, provide, raw, material, for, phishing, campaigns</media:keywords>
</item>

<item>
<title>GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials</title>
<link>https://block385.com/github-actions-supply-chain-attack-redirects-tags-to-steal-cicd-credentials</link>
<guid>https://block385.com/github-actions-supply-chain-attack-redirects-tags-to-steal-cicd-credentials</guid>
<description><![CDATA[ In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server.

&quot;Every existing tag in the repository has been moved to point to an imposter commit that does not appear in the action&#039;s normal commit history, ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgc7jpVO6HhBuEBTjkwmNjYhKlFmhhmytOqNZHYuGP-dNWrf3AoyE68yoKj77elddOX4Ps2x9jSuwhi5sE-QjK_oEjLXgQW9e6EHx6W0G7qTqYTM3fZh1AQTyrgm2o-PFBeD9ryHnC6fDmK5MYKUzBjU_pJibTilnm1d99WSQkJux6PXXRydkYW5d15Ada-/s1600/step.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 08:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>GitHub, Actions, Supply, Chain, Attack, Redirects, Tags, Steal, CICD, Credentials</media:keywords>
</item>

<item>
<title>Mini Shai&#45;Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account</title>
<link>https://block385.com/mini-shai-hulud-pushes-malicious-antv-npm-packages-via-compromised-maintainer-account</link>
<guid>https://block385.com/mini-shai-hulud-pushes-malicious-antv-npm-packages-via-compromised-maintainer-account</guid>
<description><![CDATA[ Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave.

&quot;The attack affects packages tied to the npm maintainer account atool, including echarts-for-react, a widely used React wrapper for Apache ECharts with roughly 1.1 million weekly ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjpyJDg_FqUDfeOeVX8IyhBHj9HqwkGZ-hV7b998CMLiBK2uPpmuQEN1cv1xYXJzRiznN6u_oXjA0lAGWgrkUH9EqaqfOFyW85ZQiz_Cr2YrHl1uxUHqEztt_iWG1LtRfNMpYTIqhS8vKTUOdZiNAf_r_g0r7LzqsvjmCmsr7_lv9jmXvHs5s76BEQCMnql/s1600/npm-malware.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 08:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Mini, Shai-Hulud, Pushes, Malicious, AntV, npm, Packages, via, Compromised, Maintainer, Account</media:keywords>
</item>

<item>
<title>Cybersecurity jobs available right now: May 19, 2026</title>
<link>https://block385.com/cybersecurity-jobs-available-right-now-may-19-2026</link>
<guid>https://block385.com/cybersecurity-jobs-available-right-now-may-19-2026</guid>
<description><![CDATA[ CISO DataFence | Israel | Hybrid – View job details As a CISO, you will develop security roadmaps, compliance plans, risk registers, policies, and control implementation plans while leading audit and regulatory compliance activities. You will manage client projects from planning through delivery, conduct risk assessments, gap analyses, internal audits, and security maturity reviews, and prepare reports and recommendations for stakeholders and executive teams. Cyber Security Analyst ZEE | India | On-site – View job … More →
The post Cybersecurity jobs available right now: May 19, 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/11140416/cybersecurity_jobs-1-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 07:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cybersecurity, jobs, available, right, now:, May, 19, 2026</media:keywords>
</item>

<item>
<title>AI infrastructure is cracking under sovereignty demands</title>
<link>https://block385.com/ai-infrastructure-is-cracking-under-sovereignty-demands</link>
<guid>https://block385.com/ai-infrastructure-is-cracking-under-sovereignty-demands</guid>
<description><![CDATA[ AI deployments are moving into environments with tighter controls around data, infrastructure, and system operations. Organizations are building AI systems across multiple providers, platforms, and computing environments while managing governance, security, and compliance obligations within defined boundaries. NTT DATA’s 2026 Global AI Report A Playbook for Private and Sovereign AI examined these conditions in more than 2,500 organizations. About 35% of CAIOs identify enabling private and sovereign AI as their biggest barrier to adoption, often … More →
The post AI infrastructure is cracking under sovereignty demands appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/10/29154423/ai-brain-1500-1.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>infrastructure, cracking, under, sovereignty, demands</media:keywords>
</item>

<item>
<title>Microsoft Exchange Zero&#45;Day Under Attack, No Patch Available</title>
<link>https://block385.com/microsoft-exchange-zero-day-under-attack-no-patch-available</link>
<guid>https://block385.com/microsoft-exchange-zero-day-under-attack-no-patch-available</guid>
<description><![CDATA[ CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt8a4b55f47bd9ed66/6a0b619572bcb61757c995eb/exchange_Piotr_Swat_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 01:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Exchange, Zero-Day, Under, Attack, Patch, Available</media:keywords>
</item>

<item>
<title>&amp;apos;Claw Chain&amp;apos; Vulnerabilities Threaten OpenClaw Deployments</title>
<link>https://block385.com/claw-chain-vulnerabilities-threaten-openclaw-deployments</link>
<guid>https://block385.com/claw-chain-vulnerabilities-threaten-openclaw-deployments</guid>
<description><![CDATA[ The now patched vulnerabilities in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltf136884c4aa5baab/6a0b76008388efee0d946879/openclaw_jackpress_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 19 May 2026 01:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Claw, Chain, Vulnerabilities, Threaten, OpenClaw, Deployments</media:keywords>
</item>

<item>
<title>Boulevard of Broken Dreams: 2 Decades of Cyber Fails</title>
<link>https://block385.com/boulevard-of-broken-dreams-2-decades-of-cyber-fails</link>
<guid>https://block385.com/boulevard-of-broken-dreams-2-decades-of-cyber-fails</guid>
<description><![CDATA[ From the MGM and Caesars fiasco and MOVEit&#039;s patch nightmare to epic business blunders and the jaded reality of living in a post-breach world, Dark Reading looks back at the mistakes, miscalculations, systemic failures, and cringeworthy moments that still have us shaking our heads. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt8bb440d26c1c8c62/6a077adfeb51442934d177c1/decay-DBURKE-alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 23:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Boulevard, Broken, Dreams:, Decades, Cyber, Fails</media:keywords>
</item>

<item>
<title>Shai&#45;Hulud Worm Clones Spread After Code Release</title>
<link>https://block385.com/shai-hulud-worm-clones-spread-after-code-release</link>
<guid>https://block385.com/shai-hulud-worm-clones-spread-after-code-release</guid>
<description><![CDATA[ The release of Shai-Hulud source code spells trouble for software developers as researchers worry the self-replicating worm could scale. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt4a4214dc2b88ddc4/6a0b5b14fe7bf093eb769187/sandworms_FlixPix_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 23:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Shai-Hulud, Worm, Clones, Spread, After, Code, Release</media:keywords>
</item>

<item>
<title>Game over for 74 suspected scammers after Dutch cops plastered their faces on billboards</title>
<link>https://block385.com/game-over-for-74-suspected-scammers-after-dutch-cops-plastered-their-faces-on-billboards</link>
<guid>https://block385.com/game-over-for-74-suspected-scammers-after-dutch-cops-plastered-their-faces-on-billboards</guid>
<description><![CDATA[ The Dutch police’s Game Over?! campaign, which publicly displays images of suspected fraudsters to encourage self-surrenders and gather public tips, is proving successful, with the identities of 74 of the 100 suspects shown already identified. A digital display promoting the Dutch police’s Game Over?! campaign (Source: Politie) Launched in March 2026, the campaign displays blurred photos of 100 suspected fraudsters on billboards along motorways, petrol stations, and supermarkets, as well as in television and online … More →
The post Game over for 74 suspected scammers after Dutch cops plastered their faces on billboards appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/25153040/fraud-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 21:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Game, over, for, suspected, scammers, after, Dutch, cops, plastered, their, faces, billboards</media:keywords>
</item>

<item>
<title>AI is drowning software maintainers in junk security reports</title>
<link>https://block385.com/ai-is-drowning-software-maintainers-in-junk-security-reports</link>
<guid>https://block385.com/ai-is-drowning-software-maintainers-in-junk-security-reports</guid>
<description><![CDATA[ AI-assisted vulnerability research has exploded, unleashing a firehose of low-quality reports on overworked software maintainers who are wasting hours sifting through noise instead of fixing real problems. Linus Torvalds, the Linux kernel’s creator, says the flood has made the project’s security mailing list “almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools.” Too many duplicates, and too much AI slop “If you found a bug using … More →
The post AI is drowning software maintainers in junk security reports appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18172114/sea-code-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 21:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>drowning, software, maintainers, junk, security, reports</media:keywords>
</item>

<item>
<title>INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests</title>
<link>https://block385.com/interpol-operation-ramz-disrupts-mena-cybercrime-networks-with-201-arrests</link>
<guid>https://block385.com/interpol-operation-ramz-disrupts-mena-cybercrime-networks-with-201-arrests</guid>
<description><![CDATA[ INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects.
The initiative involved the efforts of 13 countries from the region between October 2025 and February 2026, aiming to investigate and neutralize malicious infrastructure, arrest perpetrators behind these ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivxxVYex3z2F03m6RYOR72whyegN5TEzzNxZO3tTOSHNTQ4tqCeD-H-F0c3K8dInMfh1EwPQP0jtoHEA4agDOYN2sF7qxGMHnuhsWges5me7ESa8_ycNj0vHf1TeeTgqetA1yOQ5Gi6a7jsV5khO3PVNcbkrBRCTMRNRb_qPLwBUdlvZJUCDvGjtmSVuod/s1600/hackers.png" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 20:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>INTERPOL, Operation, Ramz, Disrupts, MENA, Cybercrime, Networks, with, 201, Arrests</media:keywords>
</item>

<item>
<title>Fuel Tank Breaches Expand Scope of Iran&amp;apos;s Cyber Offensive</title>
<link>https://block385.com/fuel-tank-breaches-expand-scope-of-irans-cyber-offensive</link>
<guid>https://block385.com/fuel-tank-breaches-expand-scope-of-irans-cyber-offensive</guid>
<description><![CDATA[ Security experts have long warned that insecure automatic tank gauge (ATG) systems exposed on the Internet can be tampered with by threat actors. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt7f692ec12934e4c2/6a0af74e239afa81b3940d8e/iran1800_Hakan_Gider_alamy.png" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 19:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Fuel, Tank, Breaches, Expand, Scope, Irans, Cyber, Offensive</media:keywords>
</item>

<item>
<title>⚡ Weekly Recap: Exchange 0&#45;Day, npm Worm, Fake AI Repo, Cisco Exploit and More</title>
<link>https://block385.com/weekly-recap-exchange-0-day-npm-worm-fake-ai-repo-cisco-exploit-and-more</link>
<guid>https://block385.com/weekly-recap-exchange-0-day-npm-worm-fake-ai-repo-cisco-exploit-and-more</guid>
<description><![CDATA[ Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjFzN7ITW3vwaWKn1m-BGZGI1JicT1T8d5v4LZbTvOTe7m1Xj4pk1pFECjAOvxey4XzXg7vGiU5Xzifs4qkzr9cbg2iPboHfPAHHBmi3O8OIAArhJlbr52gwKMkdqrIuIK77Pq8EzCTQM1hV5MsLuTbV4GXbXzr7miv0jA6o0Bn35RgBjc2cnd6qPq2-0Di/s1600/recapss.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 18:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>⚡, Weekly, Recap:, Exchange, 0-Day, npm, Worm, Fake, Repo, Cisco, Exploit, and, More</media:keywords>
</item>

<item>
<title>Attackers are exploiting critical NGINX vulnerability (CVE&#45;2026&#45;42945)</title>
<link>https://block385.com/attackers-are-exploiting-critical-nginx-vulnerability-cve-2026-42945</link>
<guid>https://block385.com/attackers-are-exploiting-critical-nginx-vulnerability-cve-2026-42945</guid>
<description><![CDATA[ A critical NGINX vulnerability (CVE-2026-42945) disclosed last week is being exploited by attackers, VulnCheck security researcher Patrick Garrity revealed on Saturday. The vulnerability, dubbed NGINX Rift, can be reliably exploited to trigger a denial-of-service condition and can potentially allow for unauthenticated remote code execution, all achievable by sending a specially crafted HTTP request to a vulnerable NGINX instance. What is NGINX? NGINX is the most widely deployed web server and, as such, it’s one of … More →
The post Attackers are exploiting critical NGINX vulnerability (CVE-2026-42945) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/03/25161729/nginx-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Attackers, are, exploiting, critical, NGINX, vulnerability, CVE-2026-42945</media:keywords>
</item>

<item>
<title>How to Reduce Phishing Exposure Before It Turns into Business Disruption</title>
<link>https://block385.com/how-to-reduce-phishing-exposure-before-it-turns-into-business-disruption</link>
<guid>https://block385.com/how-to-reduce-phishing-exposure-before-it-turns-into-business-disruption</guid>
<description><![CDATA[ What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is the gap many SOCs still struggle with: the attacks that leave teams unsure what was exposed, who else was targeted, and how far the risk has spread.
Early phishing detection closes that gap. It helps teams move from uncertainty to evidence faster, ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu4cbMji6f7O37Q6sBOEkOEXWMs7Eg4ixA0RdW8AiO6cIPai9yYqLTvVVkUH9ApXP8XycVeezSCvDMXhldVsCiaA-_kr5SwWJ4EjTfkyX0RdUacOUF3plBO9C6PHCLsUGM-L-ZthpQA7mhdPmH4nLgPPQIVBWK9BZUNQf7V17Y_5jVVvZ0FNaiOsG7mvs/s1600/anyrun-main.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 16:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>How, Reduce, Phishing, Exposure, Before, Turns, into, Business, Disruption</media:keywords>
</item>

<item>
<title>SmartBear expands ReadyAPI with AI&#45;powered API testing capabilities</title>
<link>https://block385.com/smartbear-expands-readyapi-with-ai-powered-api-testing-capabilities</link>
<guid>https://block385.com/smartbear-expands-readyapi-with-ai-powered-api-testing-capabilities</guid>
<description><![CDATA[ SmartBear has announced ReadyAPI’s new AI test generation capability that accelerates API testing by up to 80% while giving teams control to enable or disable AI. While competitors focus on speed alone, ReadyAPI’s AI test generation capability is architected for quality at scale and addresses the testing gap by aligning validation with development velocity without compromising application integrity. The AI capability automates repetitive test creation while QA professionals maintain oversight and strategic orchestration. Users can … More →
The post SmartBear expands ReadyAPI with AI-powered API testing capabilities appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>SmartBear, expands, ReadyAPI, with, AI-powered, API, testing, capabilities</media:keywords>
</item>

<item>
<title>Developer Workstations Are Now Part of the Software Supply Chain</title>
<link>https://block385.com/developer-workstations-are-now-part-of-the-software-supply-chain</link>
<guid>https://block385.com/developer-workstations-are-now-part-of-the-software-supply-chain</guid>
<description><![CDATA[ Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer environments and CI/CD pipelines, including API keys, cloud credentials, SSH keys, and tokens. This is ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjylLL25uQ3uU6RshKkTv9isR22Y_6_b4uJJ4koE1MqtmGs4IWdz88_aH8up_7WDxghA7-GeMbm6gpoKUXRw99Cm1ljO03H8bdcv91vvO_ch313e_JAwtYH-CewZJF2WkNrYWtcp-acMiPTvSs5aan7v2DLpEjVSBuEarfJ-eCLEHCL2WK9zjxOho_gj3k/s1600/git.gif" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 14:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Developer, Workstations, Are, Now, Part, the, Software, Supply, Chain</media:keywords>
</item>

<item>
<title>Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws</title>
<link>https://block385.com/ivanti-fortinet-sap-vmware-n8n-patch-rce-sql-injection-privilege-escalation-flaws</link>
<guid>https://block385.com/ivanti-fortinet-sap-vmware-n8n-patch-rce-sql-injection-privilege-escalation-flaws</guid>
<description><![CDATA[ Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code.
Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exploited to achieve information disclosure or client-side attacks.
&quot;External control of a file name ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2iqd3uRuOdLaM83LyZC9GOeOLeP9BnBVQQQzF7LZUeBTXfGo6e6b9c7PSC0Tkt_vhN_FUFUiDwnLXXNmzpIubE5bI0rA7dRaDhuiV35uiNTcMab7o8E_1ehn3CzUUsfno-6fYECbYzGNS1dyNof1ihn-hf4QYjLn7ZD53y_byQigukme9w-LAeBKDWXAg/s1600/patches.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 14:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Ivanti, Fortinet, SAP, VMware, n8n, Patch, RCE, SQL, Injection, Privilege, Escalation, Flaws</media:keywords>
</item>

<item>
<title>Attackers accessed, downloaded code from Grafana Labs’ GitHub</title>
<link>https://block385.com/attackers-accessed-downloaded-code-from-grafana-labs-github</link>
<guid>https://block385.com/attackers-accessed-downloaded-code-from-grafana-labs-github</guid>
<description><![CDATA[ A threat actor has managed to access Grafana Labs’ GitHub environment and download the company’s codebase, the open-source observability and data visualization firm announced on Sunday. The breach is significant given Grafana Labs’ widespread use across enterprise engineering and DevOps teams worldwide. Grafana Labs is best known for its open-source dashboard and visualization platform, but also offers tools for log aggregation (Loki), continuous profiling (Pyroscope), distributed tracing (Tempo), and a hosted SaaS option (Grafana Cloud). … More →
The post Attackers accessed, downloaded code from Grafana Labs’ GitHub appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18081431/grafana-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 13:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Attackers, accessed, downloaded, code, from, Grafana, Labs’, GitHub</media:keywords>
</item>

<item>
<title>MiniPlasma Windows 0&#45;Day Enables SYSTEM Privilege Escalation on Fully Patched Systems</title>
<link>https://block385.com/miniplasma-windows-0-day-enables-system-privilege-escalation-on-fully-patched-systems</link>
<guid>https://block385.com/miniplasma-windows-0-day-enables-system-privilege-escalation-on-fully-patched-systems</guid>
<description><![CDATA[ Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems.
Codenamed MiniPlasma, the vulnerability impacts &quot;cldflt.sys,&quot; which refers to the Windows Cloud Files Mini Filter Driver, ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvmx8dRRiQKx4cT0aT1-zTuzdjfThwxmlbzb2ikeeqIXUXGdcJhRrq4BykcdBB572URpoAHQhSTSyahR3M7TyvOsLSCekQGCUFM8sTcdsxkrpRFrT41wF8EqKA5LjzYHpzUtro2136Iy55cKQ_wixFUSsFDnilkUNCvrDvJbHBKK3k_IelHt9lOmbW01_u/s1600/windows-exploits.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 12:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>MiniPlasma, Windows, 0-Day, Enables, SYSTEM, Privilege, Escalation, Fully, Patched, Systems</media:keywords>
</item>

<item>
<title>Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware</title>
<link>https://block385.com/four-malicious-npm-packages-deliver-infostealers-and-phantom-bot-ddos-malware</link>
<guid>https://block385.com/four-malicious-npm-packages-deliver-infostealers-and-phantom-bot-ddos-malware</guid>
<description><![CDATA[ Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP.
The list of identified packages is below -

chalk-tempalte (825 Downloads)
@deadcode09284814/axios-util (284 Downloads)
axois-utils (963 Downloads)
color-style-utils (934 Downloads)

&quot;One of the packages (chalk-tempalte) ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbN7WbW1cUkMzMJl0HPvRrQQUc5MQEE3Pvrc735aG7RGwpguum4POxa4yeQjyYIyiAYBDj_Zl6Ud8esex0AnQSG2J6TVWat57BLALA4WTi3gr5mfrLC2AHloSuvzx6fg9bTxZUvO-aA5VwHjyqbYecAWm2DnM9SRyt0M1GaqYzlBBKdgUR8BXV3xIDVnVN/s1600/npm-hacking.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 12:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Four, Malicious, npm, Packages, Deliver, Infostealers, and, Phantom, Bot, DDoS, Malware</media:keywords>
</item>

<item>
<title>Pre&#45;Stuxnet Fast16 Malware Tampered with Nuclear Weapons Simulations</title>
<link>https://block385.com/pre-stuxnet-fast16-malware-tampered-with-nuclear-weapons-simulations</link>
<guid>https://block385.com/pre-stuxnet-fast16-malware-tampered-with-nuclear-weapons-simulations</guid>
<description><![CDATA[ A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations.
According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that are central to nuclear weapon design.
&quot;Fast16&#039;s hook engine is selectively interested in ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEis3jEEpg3n_4z5YYUwDaXETZ4KJGxCqjzrZMHUmpgvOCC7pxoSs6Rn9klL5REej9UUJJxIrOstlQDWjbTeAOUhJ7wFSoTvpLkOVx3hb5fKerxA6NkeNMDQ7bt4F-kLwEPXWZPCsVa_wXaonk9mb9CKTF4cVDToquGN57Xzw1VmszeNoEKVEvtcHMSnTCOi/s1600/fast16-stuxnet.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 12:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Pre-Stuxnet, Fast16, Malware, Tampered, with, Nuclear, Weapons, Simulations</media:keywords>
</item>

<item>
<title>201 arrested in INTERPOL disruption of phishing and fraud networks</title>
<link>https://block385.com/201-arrested-in-interpol-disruption-of-phishing-and-fraud-networks</link>
<guid>https://block385.com/201-arrested-in-interpol-disruption-of-phishing-and-fraud-networks</guid>
<description><![CDATA[ Operation Ramz, a cybercrime initiative coordinated by INTERPOL across the MENA region, focused on disrupting phishing campaigns, malware activity, and cyber scams that caused substantial financial losses across the region. The operation resulted in the arrest of 201 individuals and the identification of an additional 382 suspects. Moroccan authorities seized computers, smartphones and external hard drives containing banking data and software used for phishing operations. (Source: INTERPOL) Authorities identified 3,867 victims and seized 53 servers. … More →
The post 201 arrested in INTERPOL disruption of phishing and fraud networks appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/18104734/interpol-mena-operation_ramz.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 11:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>201, arrested, INTERPOL, disruption, phishing, and, fraud, networks</media:keywords>
</item>

<item>
<title>AI shrinks vulnerability exploitation window to hours</title>
<link>https://block385.com/ai-shrinks-vulnerability-exploitation-window-to-hours</link>
<guid>https://block385.com/ai-shrinks-vulnerability-exploitation-window-to-hours</guid>
<description><![CDATA[ Time has become organizations’ biggest vulnerability because the gap between vulnerability discovery and exploitation has narrowed to hours, according to Synack’s 2026 State of Vulnerabilities Report. Total vulnerabilities by severity (2022-2025) (Source: Synack) AI expands the attack surface Agentic AI systems that act autonomously across systems introduce new risks that require human expertise to identify and understand. Automated scanning detects known signatures but can miss logic flaws, misconfigurations, and unexpected behavior. In 2025, mean time … More →
The post AI shrinks vulnerability exploitation window to hours appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/03/24081916/downtime-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>shrinks, vulnerability, exploitation, window, hours</media:keywords>
</item>

<item>
<title>Lyrie: Open&#45;source autonomous pentesting agent</title>
<link>https://block385.com/lyrie-open-source-autonomous-pentesting-agent</link>
<guid>https://block385.com/lyrie-open-source-autonomous-pentesting-agent</guid>
<description><![CDATA[ Penetration testing has usually required weeks of manual work, specialized tooling, and teams with narrow skill sets. Lyrie, an open-source autonomous security agent built by OTT Cybersecurity, compresses that process into a command line tool and publishes the entire codebase. The project reached version 3.1.0 this month. The release adds XChaCha20-Poly1305 memory encryption for sensitive threat data, seven new proof-of-concept generators covering prompt injection, auth bypass, CSRF, open redirect, race conditions, secret exposure, and cross-site … More →
The post Lyrie: Open-source autonomous pentesting agent appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/14105322/lyrie-ai_agent-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 09:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Lyrie:, Open-source, autonomous, pentesting, agent</media:keywords>
</item>

<item>
<title>The AI backdoor your security stack is not built to see</title>
<link>https://block385.com/the-ai-backdoor-your-security-stack-is-not-built-to-see</link>
<guid>https://block385.com/the-ai-backdoor-your-security-stack-is-not-built-to-see</guid>
<description><![CDATA[ Enterprises deploying LLMs have spent the past two years building defenses around a reasonable assumption: malicious behavior leaves a trace in the input. Scan for suspicious tokens, filter unusual characters, watch for prompt injection patterns. New research from Microsoft and the Institute of Science Tokyo demonstrates that this defensive posture has a blind spot, and the cost of that blind spot could be measured in leaked proprietary data and regulatory exposure. The attack, called MetaBackdoor, … More →
The post The AI backdoor your security stack is not built to see appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/11/27170627/pressure-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 09:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, backdoor, your, security, stack, not, built, see</media:keywords>
</item>

<item>
<title>When ransomware hits, confidence doesn’t restore endpoints</title>
<link>https://block385.com/when-ransomware-hits-confidence-doesnt-restore-endpoints</link>
<guid>https://block385.com/when-ransomware-hits-confidence-doesnt-restore-endpoints</guid>
<description><![CDATA[ Ransomware, supply chain vulnerabilities, insider threats, compliance failures, and software disruptions remain major concerns for security leaders, according to The Ransomware Reality: Zero Days to Recover report by Absolute Security. How CISOs currently ensure endpoint resilience against ransomware (overall, %) (Source: Absolute Security) A survey of 750 CISOs from enterprise organizations with more than 5,000 employees in the United States and the United Kingdom revealed gaps between ransomware frequency, confidence in recovery capabilities, and remediation … More →
The post When ransomware hits, confidence doesn’t restore endpoints appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/08/27131513/ransomware-keyboard2.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 07:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>When, ransomware, hits, confidence, doesn’t, restore, endpoints</media:keywords>
</item>

<item>
<title>Product showcase: McAfee + ChatGPT integration turns doubt into a scam check</title>
<link>https://block385.com/product-showcase-mcafee-chatgpt-integration-turns-doubt-into-a-scam-check</link>
<guid>https://block385.com/product-showcase-mcafee-chatgpt-integration-turns-doubt-into-a-scam-check</guid>
<description><![CDATA[ McAfee + ChatGPT integration brings real-time scam detection in conversations and gives users an easier way to verify suspicious content before clicking or responding. It is available to anyone, without requiring a McAfee or ChatGPT subscription. It combines conversational AI with McAfee’s cybersecurity intelligence to help users evaluate potentially dangerous content such as messages, emails, links, screenshots, and social media posts for signs of scams or phishing. How McAfee + ChatGPT helps identify phishing attempts … More →
The post Product showcase: McAfee + ChatGPT integration turns doubt into a scam check appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/15083333/mcafee_openai-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 07:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Product, showcase:, McAfee, ChatGPT, integration, turns, doubt, into, scam, check</media:keywords>
</item>

<item>
<title>Can Laws Stop Deepfakes? South Korea Aims to Find Out</title>
<link>https://block385.com/can-laws-stop-deepfakes-south-korea-aims-to-find-out</link>
<guid>https://block385.com/can-laws-stop-deepfakes-south-korea-aims-to-find-out</guid>
<description><![CDATA[ South Korea&#039;s local elections next month will be a test bed for how effective regulations might be to stymie the flow of deepfakes. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltbca6faddbee78c86/6a073d95eb9f4a233d786122/Lee_Jay-myung_Xinhua_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 05:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Can, Laws, Stop, Deepfakes, South, Korea, Aims, Find, Out</media:keywords>
</item>

<item>
<title>Debian 13.5 point release lands with security fixes, bug patches</title>
<link>https://block385.com/debian-135-point-release-lands-with-security-fixes-bug-patches</link>
<guid>https://block385.com/debian-135-point-release-lands-with-security-fixes-bug-patches</guid>
<description><![CDATA[ Debian 13.5 is the fifth point release for the stable distribution “trixie.” The update folds in roughly 100 Debian Security Advisories and corrections for more than 130 source packages, covering everything from the Linux kernel and Apache HTTP Server to OpenSSH, sudo, systemd, OpenSSL, glibc, and FreeRDP. Fresh installer images carrying the same fixes will follow at the regular download locations. Sysadmins running trixie do not need to reinstall. Existing media remain valid, and machines … More →
The post Debian 13.5 point release lands with security fixes, bug patches appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/01/07123846/debian-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Mon, 18 May 2026 01:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Debian, 13.5, point, release, lands, with, security, fixes, bug, patches</media:keywords>
</item>

<item>
<title>NGINX CVE&#45;2026&#45;42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE</title>
<link>https://block385.com/nginx-cve-2026-42945-exploited-in-the-wild-causing-worker-crashes-and-possible-rce</link>
<guid>https://block385.com/nginx-cve-2026-42945-exploited-in-the-wild-causing-worker-crashes-and-possible-rce</guid>
<description><![CDATA[ A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck.
The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting NGINX versions 0.6.27 through 1.30.0. According to AI-native security company depthfirst, the ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgdFtAiSRukEdQXVvEzXdQKy0O9SY7RCuqFLuAEIBe4rECuQuUS76qEXnxPuEcKIIFUysRNOGdBW2Mf2n1sh1W35aU0nCksWiW7v-20p1K7RhdPPDnxKh7kt_OmQaPrmtYPJ3larEwWr9iHeQMoRtlW767YpsXBFP5-5CQ2jTJUB_jWaMmt_29uLJvaGZE_/s1600/nginx.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sun, 17 May 2026 18:30:09 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>NGINX, CVE-2026-42945, Exploited, the, Wild, Causing, Worker, Crashes, and, Possible, RCE</media:keywords>
</item>

<item>
<title>Week in review: Cisco patches SD&#45;WAN 0&#45;day, unpatched Microsoft Exchange Server flaw exploited</title>
<link>https://block385.com/week-in-review-cisco-patches-sd-wan-0-day-unpatched-microsoft-exchange-server-flaw-exploited</link>
<guid>https://block385.com/week-in-review-cisco-patches-sd-wan-0-day-unpatched-microsoft-exchange-server-flaw-exploited</guid>
<description><![CDATA[ Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Review: Foundations of Cybersecurity, 2nd edition Jason Andress has refreshed his introductory security text for No Starch Press. He writes in the introduction that the term security now extends past data center servers to cloud resources, mobile devices, the Internet of Things, and AI. Foundations of Cybersecurity: A Straightforward Introduction book is aimed at newcomers to the field, network and … More →
The post Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploited appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2023/07/16184416/week-in-review2.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sun, 17 May 2026 11:00:10 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Week, review:, Cisco, patches, SD-WAN, 0-day, unpatched, Microsoft, Exchange, Server, flaw, exploited</media:keywords>
</item>

<item>
<title>Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt</title>
<link>https://block385.com/grafana-github-token-breach-led-to-codebase-download-and-extortion-attempt</link>
<guid>https://block385.com/grafana-github-token-breach-led-to-codebase-download-and-extortion-attempt</guid>
<description><![CDATA[ Grafana has disclosed that an &quot;unauthorized party&quot; obtained a token that granted them the ability to access the company&#039;s GitHub environment and download its codebase.


  &quot;Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations,&quot; Grafana
  said
  in a series of ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjNcCJY0s2GwOwFeSuqVz941pWrGK3theum-FBFyYO97JnK22OamMheCtr9yEEFfHMvurI7UBgl72blFK6Hm9u358g1V9HbZOk5vocuYMvgjfYLmf2XPNsSG1IiFxlbLvnRaotutjUB5I7sVLVTf1HTozz9FoeVxA3DJOn9wAOolL-HwmATDLlAD-Mgs-tO/s1600/grafana.jpg" length="49398" type="image/jpeg"/>
<pubDate>Sun, 17 May 2026 10:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Grafana, GitHub, Token, Breach, Led, Codebase, Download, and, Extortion, Attempt</media:keywords>
</item>

<item>
<title>Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming</title>
<link>https://block385.com/funnel-builder-flaw-under-active-exploitation-enables-woocommerce-checkout-skimming</link>
<guid>https://block385.com/funnel-builder-flaw-under-active-exploitation-enables-woocommerce-checkout-skimming</guid>
<description><![CDATA[ A critical security vulnerability impacting the
  Funnel Builder
  plugin for WordPress has come under active exploitation in the wild to
  inject malicious JavaScript code
  into WooCommerce checkout pages with the goal of stealing payment data.



  Details of the activity were
  published
  by Sansec this week. The vulnerability currently does not have an official CVE identifier. It ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYS8AhChFEeH6IwT4x1eB5VAeGfriF4VVcwINAxXVIGyap3g0CKx0R2BdI4s99cE3Q5JHr-KUVHqdhAFNfQIrCTJ6p-vq7u5naMTwb-WFjgis4vBdR29M94wAT-Dqh46zsbo4heSJOVdFRxXzR3SgHt2ZoTPPBEbB3cu4azACiFFl7jcIGNxw1d_U7eVU9/s1600/funnel.png" length="49398" type="image/jpeg"/>
<pubDate>Sat, 16 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Funnel, Builder, Flaw, Under, Active, Exploitation, Enables, WooCommerce, Checkout, Skimming</media:keywords>
</item>

<item>
<title>The Boring Stuff is Dangerous Now</title>
<link>https://block385.com/the-boring-stuff-is-dangerous-now</link>
<guid>https://block385.com/the-boring-stuff-is-dangerous-now</guid>
<description><![CDATA[ AI agents capable of discovering and exploiting obscure vulnerabilities are emerging alongside developers producing vast amounts of potentially flawed AI-generated code, forcing defenders to adapt accordingly. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blted41bae888a74bd1/6a0780b73c21f620148b9b52/cyberattack_fear_Yuri_Arcurs_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 23:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, Boring, Stuff, Dangerous, Now</media:keywords>
</item>

<item>
<title>Turla Turns Kazuar Backdoor Into Modular P2P Botnet for Persistent Access</title>
<link>https://block385.com/turla-turns-kazuar-backdoor-into-modular-p2p-botnet-for-persistent-access</link>
<guid>https://block385.com/turla-turns-kazuar-backdoor-into-modular-p2p-botnet-for-persistent-access</guid>
<description><![CDATA[ The Russian state-sponsored hacking group known as
  
    Turla
  
  has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that&#039;s engineered for stealth and persistent access to compromised hosts.



  Turla, per the U.S. Cybersecurity and Infrastructure Security Agency (CISA), is assessed to be affiliated with Center 16 of Russia&#039;s Federal Security Service (FSB) ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8BT1AOScncZQM_A-0WBdCzTDAHGHSey48_Mywhij-TJupCdzP3s3o-MIImRtMZcoV2OqX3RjRV4COpVqkB1mrH3d_zjwvSTwCEXOq_2m80HgDo-xwAZ1KpR1h8eN9dAHGcKN_PpcE0cBsnv67FcthDycHLBJMYs8NkPszWNiQqdbhyL0YIlwVJn4NtgaR/s1600/code.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 20:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Turla, Turns, Kazuar, Backdoor, Into, Modular, P2P, Botnet, for, Persistent, Access</media:keywords>
</item>

<item>
<title>Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems</title>
<link>https://block385.com/taiwan-bullet-train-hack-highlights-cybersecurity-gaps-in-rail-systems</link>
<guid>https://block385.com/taiwan-bullet-train-hack-highlights-cybersecurity-gaps-in-rail-systems</guid>
<description><![CDATA[ A Taiwanese student experimenting with software-defined radio technology shut down three bullet trains for nearly an hour, leading to an anti-terrorism response. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltba3a137dbf767ae6/6a061f2f41bd583c0c8882d7/taiwan-bullet-trains-eric1207cvb-shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 19:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Taiwan, Bullet, Train, Hack, Highlights, Cybersecurity, Gaps, Rail, Systems</media:keywords>
</item>

<item>
<title>Congress Puts Heat on Instructure After Canvas Outage</title>
<link>https://block385.com/congress-puts-heat-on-instructure-after-canvas-outage</link>
<guid>https://block385.com/congress-puts-heat-on-instructure-after-canvas-outage</guid>
<description><![CDATA[ The House Committee on Homeland Security sent a letter about the Canvas cyberattack, the same day that the edtech company said it reached an &quot;agreement&quot; with the ShinyHunters cybercriminals. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltb9f102c416e36970/6a062de47896f162656ad15c/canvas_pictoKraft_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 19:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Congress, Puts, Heat, Instructure, After, Canvas, Outage</media:keywords>
</item>

<item>
<title>Four OpenClaw Flaws Enable Data Theft, Privilege Escalation, and Persistence</title>
<link>https://block385.com/four-openclaw-flaws-enable-data-theft-privilege-escalation-and-persistence</link>
<guid>https://block385.com/four-openclaw-flaws-enable-data-theft-privilege-escalation-and-persistence</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence.


  The vulnerabilities, collectively dubbed
  
    Claw Chain
  
  by Cyera, can permit an attacker to establish a foothold, expose sensitive data, and plant backdoors. A brief description of the flaws is below - ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgz_tK9S8jS_n5CK694-FLGjQP5_Mmpg7z9ZRiBayWsJLsuFRIm-8j1hTlhH90779FvnvhpiFKeGP9CzI5RCPsxQEnOzAIQsPzUsAJhUWtNm9iwf9C1W9DbDmqoQ_jjHhM7huYDV210OB9o1L9NPoJ0IL6R9Xc-V4JQ91Kn-b47_2ravRJ6-qlZOVrqsuAz/s1600/openclaw.png" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 18:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Four, OpenClaw, Flaws, Enable, Data, Theft, Privilege, Escalation, and, Persistence</media:keywords>
</item>

<item>
<title>Cisco patches another actively exploited SD&#45;WAN zero&#45;day (CVE&#45;2026&#45;20182)</title>
<link>https://block385.com/cisco-patches-another-actively-exploited-sd-wan-zero-day-cve-2026-20182</link>
<guid>https://block385.com/cisco-patches-another-actively-exploited-sd-wan-zero-day-cve-2026-20182</guid>
<description><![CDATA[ Cisco has patched yet another Catalyst SD-WAN Controller authentication bypass vulnerability (CVE-2026-20182) that has been exploited as a zero-day by “a highly sophisticated cyber threat actor”. About CVE-2026-20182 CVE-2026-20182 – affecting both Cisco Catalyst SD-WAN Controller (the “brain” of the Cisco Catalyst SD-WAN solution) and Cisco Catalyst SD-WAN Manager (the management plane for the entire SD-WAN fabric) – stems from a flawed peering authentication mechanism. It affects both on-prem and cloud deployments. CVE-2026-20182 was reported … More →
The post Cisco patches another actively exploited SD-WAN zero-day (CVE-2026-20182) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/15100810/cisco-lines-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 15:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cisco, patches, another, actively, exploited, SD-WAN, zero-day, CVE-2026-20182</media:keywords>
</item>

<item>
<title>Akamai to acquire LayerX for $205 million</title>
<link>https://block385.com/akamai-to-acquire-layerx-for-205-million</link>
<guid>https://block385.com/akamai-to-acquire-layerx-for-205-million</guid>
<description><![CDATA[ Akamai has entered into a definitive agreement to acquire LayerX, a provider of browser-based AI usage control and secure enterprise browser (SEB) technology. LayerX’s solutions will extend Akamai’s protection into the browser, where the majority of enterprise tasks now occur and where today’s workforce engages with generative AI applications, SaaS AI solutions, and AI agents. With this acquisition, Akamai is taking a critical step in the evolution of its zero trust security portfolio and addressing … More →
The post Akamai to acquire LayerX for $205 million appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 15:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Akamai, acquire, LayerX, for, 205, million</media:keywords>
</item>

<item>
<title>Google lets Workspace admins apply one policy across all SAML apps</title>
<link>https://block385.com/google-lets-workspace-admins-apply-one-policy-across-all-saml-apps</link>
<guid>https://block385.com/google-lets-workspace-admins-apply-one-policy-across-all-saml-apps</guid>
<description><![CDATA[ Google has updated Context-Aware Access (CAA) in Google Workspace to introduce a default policy assignment for SAML applications. SAML applications are third-party or internal applications that use the Security Assertion Markup Language (SAML) protocol to enable single sign-on (SSO) with Google Workspace credentials. Google says this update introduces a default assignment that serves as a universal security baseline, automatically protecting any SAML-based application that does not have a specific policy already assigned. By establishing this … More →
The post Google lets Workspace admins apply one policy across all SAML apps appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/10114613/google-lock-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 15:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Google, lets, Workspace, admins, apply, one, policy, across, all, SAML, apps</media:keywords>
</item>

<item>
<title>Cyber Pioneers Ponder Past as Prologue</title>
<link>https://block385.com/cyber-pioneers-ponder-past-as-prologue</link>
<guid>https://block385.com/cyber-pioneers-ponder-past-as-prologue</guid>
<description><![CDATA[ Robert &quot;RSnake&quot; Hansen, Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier reflect on how their favorite columns penned for Dark Reading over the past 20 years have stood the test of time. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt6c991c2f510526e0/6a060dc5384002716e815d4f/typewriter_and_mobile_phone_mauritius_images_GmbH_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cyber, Pioneers, Ponder, Past, Prologue</media:keywords>
</item>

<item>
<title>What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface</title>
<link>https://block385.com/what-45-days-of-watching-your-own-tools-will-tell-you-about-your-real-attack-surface</link>
<guid>https://block385.com/what-45-days-of-watching-your-own-tools-will-tell-you-about-your-real-attack-surface</guid>
<description><![CDATA[ In Your Biggest Security Risk Isn&#039;t Malware — It&#039;s What You Already Trust, we made a simple argument: the most dangerous activity inside most organizations no longer looks like an attack. It looks like administration. PowerShell, WMIC, netsh, Certutil, MSBuild — the same trusted utilities your IT team uses every day are also the preferred toolkit of modern threat actors. Bitdefender&#039;s analysis ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVcSUDrpIZyFrHqIlIGnXfIShsEamRNviaM6TguPwmQI9KkhrIXOQbQ0WVKiOkcBGkFqKTKZmK16zPChmlcCbZHIkX3K_C0sjnyXYJjpZuJXO3OiIhUe7Ez8jCNiTxh0FGYS2-RR6HKsl9pWJVgc_uXAtHXj0hgU-mLSsOh-QHft6A92KtgWPQhk1OVPA/s1600/Attack-Surface.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 14:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>What, Days, Watching, Your, Own, Tools, Will, Tell, You, About, Your, Real, Attack, Surface</media:keywords>
</item>

<item>
<title>TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates</title>
<link>https://block385.com/tanstack-supply-chain-attack-hits-two-openai-employee-devices-forces-macos-updates</link>
<guid>https://block385.com/tanstack-supply-chain-attack-hits-two-openai-employee-devices-forces-macos-updates</guid>
<description><![CDATA[ OpenAI has disclosed that two of its employee devices in its corporate environment were impacted via the Mini Shai-Hulud supply chain attack on TanStack, but noted that no user data, production systems, or intellectual property were compromised or modified in an unauthorized manner.
&quot;Upon identification of the malicious activity, we worked quickly to investigate, contain, and take steps to ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj1l4Vq20M4553fkDfGbO9VqLV9Au-6EefivLp8HT2W5QxJvgWf1mr6pg5xsbC5j3FCJzOOCJv_CImY1LjjFYIN_25ajki1iS_EVPvTyeVY7bC3ogcQFzHmE1Xyaz3cRXneilC0rWcb8dLbUapLI_jZ-uBaUkku48absoxM6TG16jS3xxtw9lhhtCvJmemK/s1600/chatgpt.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 14:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>TanStack, Supply, Chain, Attack, Hits, Two, OpenAI, Employee, Devices, Forces, macOS, Updates</media:keywords>
</item>

<item>
<title>Rocky Linux launches opt&#45;in security repository for urgent fixes</title>
<link>https://block385.com/rocky-linux-launches-opt-in-security-repository-for-urgent-fixes</link>
<guid>https://block385.com/rocky-linux-launches-opt-in-security-repository-for-urgent-fixes</guid>
<description><![CDATA[ Rocky Linux has introduced a Security Repository that allows the distribution to ship urgent security fixes ahead of upstream Enterprise Linux when public exploit code exists and upstream patches are unavailable. “The repository is disabled by default. That’s intentional. The default Rocky Linux experience stays exactly what it has always been: predictable, stable, and fully upstream-compatible. Administrators who want access to accelerated fixes can opt in when they need it,” Eric Hendricks of the Rocky … More →
The post Rocky Linux launches opt-in security repository for urgent fixes appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/15113413/rocky_linux-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 13:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Rocky, Linux, launches, opt-in, security, repository, for, urgent, fixes</media:keywords>
</item>

<item>
<title>Unpatched Microsoft Exchange Server vulnerability exploited (CVE&#45;2026&#45;42897)</title>
<link>https://block385.com/unpatched-microsoft-exchange-server-vulnerability-exploited-cve-2026-42897</link>
<guid>https://block385.com/unpatched-microsoft-exchange-server-vulnerability-exploited-cve-2026-42897</guid>
<description><![CDATA[ A critical cross-site scripting (XSS) vulnerability (CVE-2026-42897) in Microsoft Exchange Server is being exploited by attackers, Microsoft warned on Thursday. A permanent fix is still in the works. In the meantime, Microsoft provided temporary mitigations. About CVE-2026-42897 CVE-2026-42897 affects on-premises versions of Microsoft Exchange Server: Subscription Edition RTM, 2019, and 2016. Exchange Online is not affected. Flagged by an anonymous researcher, the vulnerability allows an unauthorized attacker to perform spoofing over a network. “An attacker … More →
The post Unpatched Microsoft Exchange Server vulnerability exploited (CVE-2026-42897) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/05/28084624/microsoft_exchange_1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 13:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Unpatched, Microsoft, Exchange, Server, vulnerability, exploited, CVE-2026-42897</media:keywords>
</item>

<item>
<title>Thieves unlock stolen iPhones using cheap tools sold on Telegram</title>
<link>https://block385.com/thieves-unlock-stolen-iphones-using-cheap-tools-sold-on-telegram</link>
<guid>https://block385.com/thieves-unlock-stolen-iphones-using-cheap-tools-sold-on-telegram</guid>
<description><![CDATA[ Helping a friend recover a stolen phone, Infoblox researchers uncovered a thriving Telegram-based underground marketplace selling unlocking tools and phishing infrastructure used to monetize stolen iPhones. Activation Lock can remotely disable a stolen iPhone and prevent normal resale, with owners also able to lock individual components. Even with those protections, more than 7.35 million iPhones are reportedly stolen each year in the United States alone. “A locked device is almost worthless on the black market, … More →
The post Thieves unlock stolen iPhones using cheap tools sold on Telegram appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/01/30083802/apple-map-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 13:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Thieves, unlock, stolen, iPhones, using, cheap, tools, sold, Telegram</media:keywords>
</item>

<item>
<title>Keycard helps developers secure autonomous AI agents with scoped access</title>
<link>https://block385.com/keycard-helps-developers-secure-autonomous-ai-agents-with-scoped-access</link>
<guid>https://block385.com/keycard-helps-developers-secure-autonomous-ai-agents-with-scoped-access</guid>
<description><![CDATA[ Keycard has announced Keycard for Multi-Agent Apps, extending its platform to support delegated, session-based access across systems of autonomous agents. Keycard lets developers build apps where every agent has its own identity, access is scoped to each task and every action is fully attributable across agents, users and systems. “Enterprises are rebuilding business functions around AI agents. Right now the developers building these systems have to choose: give agents broad access and they’re ungovernable or … More →
The post Keycard helps developers secure autonomous AI agents with scoped access appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 11:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Keycard, helps, developers, secure, autonomous, agents, with, scoped, access</media:keywords>
</item>

<item>
<title>On&#45;Prem Microsoft Exchange Server CVE&#45;2026&#45;42897 Exploited via Crafted Email</title>
<link>https://block385.com/on-prem-microsoft-exchange-server-cve-2026-42897-exploited-via-crafted-email</link>
<guid>https://block385.com/on-prem-microsoft-exchange-server-cve-2026-42897-exploited-via-crafted-email</guid>
<description><![CDATA[ Microsoft has disclosed a new security vulnerability impacting on-premise versions of Exchange Server that it said has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue.
&quot; ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEirN79ZRjEd5wnVbOTlJJsWjQ54cwSj2bM5NDzBSgAFO8f_9LrlIwQRI0ZogQX42iejmhgc1n2YcA91pFrVqtqNKKyAIXblcQ1Yx9LTs1TeNDbNN6JMUBXCKDK1W0IwnwvYl1dhQmcyTPHwakckKT_Kc9fAUDAJRj94g2pENrjy4UyTCCniOXI2rO-q66PC/s1600/Microsoft-Exchange.png" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 10:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>On-Prem, Microsoft, Exchange, Server, CVE-2026-42897, Exploited, via, Crafted, Email</media:keywords>
</item>

<item>
<title>Zombie linkages are keeping expired domains trusted for years</title>
<link>https://block385.com/zombie-linkages-are-keeping-expired-domains-trusted-for-years</link>
<guid>https://block385.com/zombie-linkages-are-keeping-expired-domains-trusted-for-years</guid>
<description><![CDATA[ Domains expire, get transferred, and return to the market every day. The systems connected to those domains can continue trusting the original owner long after control has changed. Researchers at USC and the University of Twente examined this problem in three widely used systems: Web PKI, Maven Central, and Ethereum Name Service. They use the term “zombie linkages” to describe lingering trust records that remain active after the original domain owner no longer controls the … More →
The post Zombie linkages are keeping expired domains trusted for years appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/22100811/domain_security-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 09:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Zombie, linkages, are, keeping, expired, domains, trusted, for, years</media:keywords>
</item>

<item>
<title>Deepfake detection is losing ground to generative models</title>
<link>https://block385.com/deepfake-detection-is-losing-ground-to-generative-models</link>
<guid>https://block385.com/deepfake-detection-is-losing-ground-to-generative-models</guid>
<description><![CDATA[ Deepfake detection has been built around a single question for close to a decade. Given a video or audio clip, is it real or synthetic? Commercial detectors analyze pixels, frequencies, and biometric signals to answer that question, and the best of them post strong accuracy numbers on standard benchmarks. In deployment, performance drops sharply on content from newer generators. Researchers at the Vector Institute think this gap is structural, and closing it means rethinking what … More →
The post Deepfake detection is losing ground to generative models appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/12150122/face-person-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Deepfake, detection, losing, ground, generative, models</media:keywords>
</item>

<item>
<title>CISA Adds Cisco SD&#45;WAN CVE&#45;2026&#45;20182 to KEV After Admin Access Exploits</title>
<link>https://block385.com/cisa-adds-cisco-sd-wan-cve-2026-20182-to-kev-after-admin-access-exploits</link>
<guid>https://block385.com/cisa-adds-cisco-sd-wan-cve-2026-20182-to-kev-after-admin-access-exploits</guid>
<description><![CDATA[ The U.S.Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly disclosed vulnerability impacting Cisco Catalyst SD-WAN Controller to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to remediate the issue by May 17, 2026.
The vulnerability is a critical authentication bypass tracked as CVE-2026-20182. It&#039;s ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg4XG5z00sF3uL0ZbhtZNiergQ9QVaZJydwP1pXEdPh2o29mwvTS2nPKRbxHftwnEJ1pvxMQS9TQknWqbovk-vW7BRPHUSsBhN4yL2iOwJnlmK7lzCdW9tJbKtKLbnfSZSWgfGlWQ6HO807gjR6dP61VylH1zxWtvfo3c7ui8aBecSjVz5miCG0jHoa8rUA/s1600/cisa-exploit.png" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 08:30:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CISA, Adds, Cisco, SD-WAN, CVE-2026-20182, KEV, After, Admin, Access, Exploits</media:keywords>
</item>

<item>
<title>The AI oversight paradox: Is the investment worth the cost of watching it?</title>
<link>https://block385.com/the-ai-oversight-paradox-is-the-investment-worth-the-cost-of-watching-it</link>
<guid>https://block385.com/the-ai-oversight-paradox-is-the-investment-worth-the-cost-of-watching-it</guid>
<description><![CDATA[ Unlike in 2025, when AI adoption and testing drove business strategies, organizations in 2026 want proven ROI before committing budgets, according to a report by Globalization Partners. How global executives characterize their organization’s approach to AI adoption (Source: Globalization Partners) 62% of business leaders said they felt pressure from their organizations to use AI, while only 38% found AI tools personally beneficial. Companies also began building in-house solutions to address security and compliance requirements. “A … More →
The post The AI oversight paradox: Is the investment worth the cost of watching it? appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/04/04143313/question.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, oversight, paradox:, the, investment, worth, the, cost, watching, it</media:keywords>
</item>

<item>
<title>New infosec products of the week: May 15, 2026</title>
<link>https://block385.com/new-infosec-products-of-the-week-may-15-2026</link>
<guid>https://block385.com/new-infosec-products-of-the-week-may-15-2026</guid>
<description><![CDATA[ Here’s a look at the most interesting products from the past week Alation, Apricorn, Versa Networks, and TrustCloud. The questionnaire-based TPRM model is broken, and TrustCloud has a fix TrustCloud announced a new version of TrustLens, its third party risk management (TPRM) solution. The new TrustLens agentic AI capabilities focus on delivering four requirements every CISO wants in their TPRM program: speed, accuracy, coverage, and proactive risk mitigation. Alation AI Governance creates a system of … More →
The post New infosec products of the week: May 15, 2026 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/03/28091843/infosec-week-1200.webp" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, infosec, products, the, week:, May, 15, 2026</media:keywords>
</item>

<item>
<title>Taiwan Incident Highlights Cybersecurity Gaps in Rail Systems</title>
<link>https://block385.com/taiwan-incident-highlights-cybersecurity-gaps-in-rail-systems</link>
<guid>https://block385.com/taiwan-incident-highlights-cybersecurity-gaps-in-rail-systems</guid>
<description><![CDATA[ A Taiwanese student experimenting with software-defined radio technology shut down three bullet trains for nearly an hour, leading to an anti-terrorism response. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltba3a137dbf767ae6/6a061f2f41bd583c0c8882d7/taiwan-bullet-trains-eric1207cvb-shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 05:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Taiwan, Incident, Highlights, Cybersecurity, Gaps, Rail, Systems</media:keywords>
</item>

<item>
<title>SecurityScorecard Snags Driftnet to Level Up Threat Intelligence</title>
<link>https://block385.com/securityscorecard-snags-driftnet-to-level-up-threat-intelligence</link>
<guid>https://block385.com/securityscorecard-snags-driftnet-to-level-up-threat-intelligence</guid>
<description><![CDATA[ The acquisition looks to boost visibility into third-party ecosystems, which are becoming a bigger concern as vectors for supply chain attacks. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltfcc8475497281343/67e40db954e011810a508de7/threat_intelligence_(1800)_Futuristic_overlay_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Fri, 15 May 2026 01:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>SecurityScorecard, Snags, Driftnet, Level, Threat, Intelligence</media:keywords>
</item>

<item>
<title>Maximum Severity Cisco SD&#45;WAN Bug Exploited in the Wild</title>
<link>https://block385.com/maximum-severity-cisco-sd-wan-bug-exploited-in-the-wild</link>
<guid>https://block385.com/maximum-severity-cisco-sd-wan-bug-exploited-in-the-wild</guid>
<description><![CDATA[ This is the second time this year a threat actor has leveraged a CVSS 10.0 vulnerability in Cisco&#039;s network control system. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt413a34f746df538e/6a0626f76111611c85c510d8/Cisco-MTP-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 23:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Maximum, Severity, Cisco, SD-WAN, Bug, Exploited, the, Wild</media:keywords>
</item>

<item>
<title>Cisco Catalyst SD&#45;WAN Controller Auth Bypass Actively Exploited to Gain Admin Access</title>
<link>https://block385.com/cisco-catalyst-sd-wan-controller-auth-bypass-actively-exploited-to-gain-admin-access</link>
<guid>https://block385.com/cisco-catalyst-sd-wan-controller-auth-bypass-actively-exploited-to-gain-admin-access</guid>
<description><![CDATA[ Cisco has released updates to address a maximum-severity authentication bypass flaw in Catalyst SD-WAN Controller that it said has been exploited in limited attacks.
The vulnerability, tracked as CVE-2026-20182, carries a CVSS score of 10.0.
&quot;A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh9rok1ToP_K0gWug0GnICltZkvx6bMRyhHfTJG1AcSfrGpM_fOVc61O3Fpyen_IW-wpb4s6Hl3qZcU5nEs77SMWSpKNDR4rrlY2syVVSNEBrpHx8RkWmYaN9MZORNICc8LNhuNjXqqhxmy7JN-y389oyQnAAFoBMJC1NoQSQFaOZ2MnrpKQRfv_eYXIoWI/s1600/cisco-exploit.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 22:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cisco, Catalyst, SD-WAN, Controller, Auth, Bypass, Actively, Exploited, Gain, Admin, Access</media:keywords>
</item>

<item>
<title>Stealer Backdoor Found in 3 Node&#45;IPC Versions Targeting Developer Secrets</title>
<link>https://block385.com/stealer-backdoor-found-in-3-node-ipc-versions-targeting-developer-secrets</link>
<guid>https://block385.com/stealer-backdoor-found-in-3-node-ipc-versions-targeting-developer-secrets</guid>
<description><![CDATA[ Cybersecurity researchers are sounding the alarm about what has been described as &quot;malicious activity&quot; in newly published versions of node-ipc.
According to Socket and StepSecurity, three different versions of the npm package have been confirmed as malicious -

node-ipc@9.1.6
node-ipc@9.2.3
node-ipc@12.0.1

&quot;Early analysis indicates that node-ipc@9.1.6, node-ipc@9.2.3, and node-ipc@12.0.1 ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTj2m9-HHmDEDzKIsalsJ_HJcwcUsIFajvcpTLP9QMyqS9F_JroTH7lXeOGZFuO6j6F-RzbIo1kBIQ0udSFQGzjN2hxO8ZfyFeHM5557BPI1sjiJ7cEMJJE62t11e07Wt1CsmAntpLHSM0XbnQDvVYNBfNdAOsob9kN6G6-mQjKX68fEE1nzy_Bn4TvxyK/s1600/node.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 22:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Stealer, Backdoor, Found, Node-IPC, Versions, Targeting, Developer, Secrets</media:keywords>
</item>

<item>
<title>ThreatsDay Bulletin: PAN&#45;OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories</title>
<link>https://block385.com/threatsday-bulletin-pan-os-rce-mythos-curl-bug-ai-tokenizer-attacks-and-10-stories</link>
<guid>https://block385.com/threatsday-bulletin-pan-os-rce-mythos-curl-bug-ai-tokenizer-attacks-and-10-stories</guid>
<description><![CDATA[ Everything is still on fire.
This week feels dumb in the worst way — bad links, weak checks, fake help desks, shady forum posts, and people turning supply chain attacks into some cursed little game for clout and cash. Half of it feels new. Half of it feels like crap we should have fixed years ago.
The mess keeps getting louder: users get tricked, boxes get popped, tools meant for normal work ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjImYNT-qC7frGzEXeok3KDX_JNMKote6V1FVXIpkAoSEER2z1YyT8dpFq5RtRhBQ0cweEPbBIuioDWFf5rw_Mf-0V6rXR2ZrMh2ISDa7X7NlV9zIGsoLSAnyd_86eVkrR4wU24yxbuCYaAmyGFwlF77YCjvgU3n43P-yFT-pzjsmQ35Oaut1klg62bs_-i/s1600/threatsday-2.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>ThreatsDay, Bulletin:, PAN-OS, RCE, Mythos, cURL, Bug, Tokenizer, Attacks, and, 10, Stories</media:keywords>
</item>

<item>
<title>&amp;apos;FrostyNeighbor&amp;apos; APT Carefully Targets Govt Orgs in Poland, Ukraine</title>
<link>https://block385.com/frostyneighbor-apt-carefully-targets-govt-orgs-in-poland-ukraine</link>
<guid>https://block385.com/frostyneighbor-apt-carefully-targets-govt-orgs-in-poland-ukraine</guid>
<description><![CDATA[ Attackers uniquely fingerprint victims before delivering spear-phishing payloads aimed at espionage, in the latest campaign from the Belarussian nation-state threat group. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltf983cc244eaa1c16/6a04800d239afae8d4940268/Frost_Piotr_Malczyk_AlamyStockPhoto.png" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 19:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>FrostyNeighbor, APT, Carefully, Targets, Govt, Orgs, Poland, Ukraine</media:keywords>
</item>

<item>
<title>Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike</title>
<link>https://block385.com/ghostwriter-targets-ukrainian-government-with-geofenced-pdf-phishing-cobalt-strike</link>
<guid>https://block385.com/ghostwriter-targets-ukrainian-government-with-geofenced-pdf-phishing-cobalt-strike</guid>
<description><![CDATA[ The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine.
Active since at least 2016, Ghostwriter has been linked to both cyber espionage and influence operations targeting neighboring countries, particularly Ukraine. It&#039;s also tracked under the monikers FrostyNeighbor, PUSHCHA, Storm-0257, TA445, UAC‑0057 ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEld5BcqD9rYWVjx7o_XlV5pN_9djvilow0iIYP-LlFEzGReX8fTPZ0gKi9zMGVLTT8qddHu5FyBMaZpQroEzYFpsoPWf96hD7JeTdqsROemmavXW2pDxNwc9kjvpJdhahmXA5Ng88tN1lyO5rqzC3K6JNwPFPWBo7OzSsaiQIN8JJsXvMrGhewMfzpouF/s1600/uk.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 18:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Ghostwriter, Targets, Ukrainian, Government, With, Geofenced, PDF, Phishing, Cobalt, Strike</media:keywords>
</item>

<item>
<title>Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE&#45;2026&#45;46300)</title>
<link>https://block385.com/fragnesia-new-linux-kernel-lpe-bug-was-spawned-by-dirty-frag-patch-cve-2026-46300</link>
<guid>https://block385.com/fragnesia-new-linux-kernel-lpe-bug-was-spawned-by-dirty-frag-patch-cve-2026-46300</guid>
<description><![CDATA[ Researchers have found and disclosed yet another local privilege escalation (LPE) vulnerability in the Linux kernel: CVE-2026-46300, aka “Fragnesia”. The flaw is in the same class of vulnerabilities as the recently disclosed Dirty Frag bug(s). Like Dirty Frag, it affects the same Linux module (xfrm-ESP). In fact, according to Dirty Frag discoverer Hyunwoo Kim, Fragnesia was “accidentally activated” by the patch fixing one of the original Dirty Frag vulnerabilities (i.e., CVE-2026-43284). CVE-2026-46300 explained Fragnesia was … More →
The post Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/14160504/tux-1500-1.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 17:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Fragnesia:, New, Linux, kernel, LPE, bug, was, spawned, Dirty, Frag, patch, CVE-2026-46300</media:keywords>
</item>

<item>
<title>HYCU  aiR detects insider risk and AI activity from backups</title>
<link>https://block385.com/hycu-air-detects-insider-risk-and-ai-activity-from-backups</link>
<guid>https://block385.com/hycu-air-detects-insider-risk-and-ai-activity-from-backups</guid>
<description><![CDATA[ HYCU has announced HYCU aiR (AI Resilience), an AI-native solution that turns backup data across dozens of applications into a live and actionable intelligence for security, compliance, and IT teams. aiR lets organizations search, query, and run purpose-built agents to surface insider risk, sensitive data exposure, identity drift, and AI agent activity, using their backup data. Every backup is a timestamped record of what happened inside an organization’s applications. HYCU aiR is the first solution … More →
The post HYCU  aiR detects insider risk and AI activity from backups appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 17:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>HYCU, aiR, detects, insider, risk, and, activity, from, backups</media:keywords>
</item>

<item>
<title>Checkbox Assessments Aren&amp;apos;t Fit to Measure Risk</title>
<link>https://block385.com/checkbox-assessments-arent-fit-to-measure-risk</link>
<guid>https://block385.com/checkbox-assessments-arent-fit-to-measure-risk</guid>
<description><![CDATA[ Security governance needs to be more than an annual compliance exercise. New companies are emerging to address risk-management gaps in current audit tools. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt730562b46d0b78c5/66be4145fa2d5811b851cb52/Risk(1800)_Andriy_Popov_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 17:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Checkbox, Assessments, Arent, Fit, Measure, Risk</media:keywords>
</item>

<item>
<title>AI Drives Cybersecurity Investments, Widening &amp;apos;Valley of Death&amp;apos;</title>
<link>https://block385.com/ai-drives-cybersecurity-investments-widening-valley-of-death</link>
<guid>https://block385.com/ai-drives-cybersecurity-investments-widening-valley-of-death</guid>
<description><![CDATA[ In a role reversal, investment dollars in AI security startups exceeded the value of AI acquisitions in 1Q26 by more than $1 billion, a rare occurrence. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt8d0adcdfb0592b29/6a023182733969819914d590/venturecapital_AlekseyFuntap_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Drives, Cybersecurity, Investments, Widening, Valley, Death</media:keywords>
</item>

<item>
<title>Foxconn Attack Highlights Manufacturing&amp;apos;s Cyber Crisis</title>
<link>https://block385.com/foxconn-attack-highlights-manufacturings-cyber-crisis</link>
<guid>https://block385.com/foxconn-attack-highlights-manufacturings-cyber-crisis</guid>
<description><![CDATA[ A Nitrogen ransomware attack on Foxconn&#039;s North American facilities is one of 600 hits on manufacturers this year, as gangs increasingly target the sector for its low tolerance for downtime. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt2bde2506b3de4da9/6a04dd5c239afae6399403b6/foxconn_ada_Images_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Foxconn, Attack, Highlights, Manufacturings, Cyber, Crisis</media:keywords>
</item>

<item>
<title>Cofense  adds AI&#45;powered campaign detection to stop phishing attacks</title>
<link>https://block385.com/cofense-adds-ai-powered-campaign-detection-to-stop-phishing-attacks</link>
<guid>https://block385.com/cofense-adds-ai-powered-campaign-detection-to-stop-phishing-attacks</guid>
<description><![CDATA[ Cofense has announced new advancements to its Phishing Defense Platform aimed at improving detection and response to AI-powered phishing attacks. The updates include AI-driven phishing detection, enhanced triage automation, and AI-assisted training campaign creation designed to strengthen protection across the phishing lifecycle. Phishing threats are no longer one-off emails. Attackers launch coordinated, polymorphic campaigns that deliberately vary content, senders, and delivery patterns to evade both traditional and AI-only detection approaches. The Cofense platform combines AI … More →
The post Cofense  adds AI-powered campaign detection to stop phishing attacks appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 15:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Cofense, adds, AI-powered, campaign, detection, stop, phishing, attacks</media:keywords>
</item>

<item>
<title>PraisonAI CVE&#45;2026&#45;44338 Auth Bypass Targeted Within Hours of Disclosure</title>
<link>https://block385.com/praisonai-cve-2026-44338-auth-bypass-targeted-within-hours-of-disclosure</link>
<guid>https://block385.com/praisonai-cve-2026-44338-auth-bypass-targeted-within-hours-of-disclosure</guid>
<description><![CDATA[ Threat actors have been observed attempting to exploit a recently disclosed security vulnerability in PraisonAI, an open-source multi-agent orchestration framework, within four hours of public disclosure.
The vulnerability in question is CVE-2026-44338 (CVSS score: 7.3), a case of missing authentication that exposes sensitive endpoints to anyone, potentially allowing an attacker to invoke the ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2IaSkdVZD_wyJJT-sODoazviDXhw3MGkn5XHYocnTL1YfLJpgJ-1wNaAm0Rk0phyrIv8vS73SNNkPSmlxRkK9ySAQGnn_tCP9JcVKyqee6lxjlYEp0cs2C_R9cDtgCEXwsjWtx1XnafF5r_fAuDDAvg0CRMOgJk8ZMwSjRsw1Js90uR-97t-rh5yU12Oj/s1600/praison.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 14:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>PraisonAI, CVE-2026-44338, Auth, Bypass, Targeted, Within, Hours, Disclosure</media:keywords>
</item>

<item>
<title>How AI Hallucinations Are Creating Real Security Risks</title>
<link>https://block385.com/how-ai-hallucinations-are-creating-real-security-risks</link>
<guid>https://block385.com/how-ai-hallucinations-are-creating-real-security-risks</guid>
<description><![CDATA[ AI hallucinations are introducing serious security risks into critical infrastructure decision-making by exploiting human trust through highly confident yet incorrect outputs. When an AI model lacks certainty, it doesn’t have a mechanism to recognize that. Instead, it generates the most probable response based on patterns in its training data, even if that response is inaccurate. These outputs ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi45HPlwBwWVoL1fRSEGy7bjtz4Z05lAO8NWxLqPrzQ93c3j5aaj_CaK5gCrJC6aYP0ePV36n27rw33vJv5mUXf3mtdOEItJjHrSkzckVGAdTU2UMp8s-HAVjNUE7jVDeTH0UikGxNZWeB6J3qVNguP2iO5V5-qUgW3g_IqxZ9cMEZy0tS0iEsl8MnSjB0/s1600/keeper.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 14:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>How, Hallucinations, Are, Creating, Real, Security, Risks</media:keywords>
</item>

<item>
<title>AI cyber capability is speeding past earlier projections</title>
<link>https://block385.com/ai-cyber-capability-is-speeding-past-earlier-projections</link>
<guid>https://block385.com/ai-cyber-capability-is-speeding-past-earlier-projections</guid>
<description><![CDATA[ AI cyber capability is improving faster than expected, with newer models surpassing earlier projections, according to the UK government’s AI Security Institute (AISI). AISI measures AI cyber capability using “time horizon benchmarks”, which estimate how long AI systems can complete cybersecurity tasks autonomously compared to human experts. “In February 2026, we estimated that frontier models’ 80%-reliability cyber time horizon had doubled every 4.7 months since reasoning models emerged in late 2024, given a 2.5M token … More →
The post AI cyber capability is speeding past earlier projections appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/11/17092123/research-ai-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 13:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>cyber, capability, speeding, past, earlier, projections</media:keywords>
</item>

<item>
<title>Microsoft’s WinUI agent plugin trims token use by over 70% during development</title>
<link>https://block385.com/microsofts-winui-agent-plugin-trims-token-use-by-over-70-during-development</link>
<guid>https://block385.com/microsofts-winui-agent-plugin-trims-token-use-by-over-70-during-development</guid>
<description><![CDATA[ Microsoft published a plugin on May 13 that lets GitHub Copilot CLI and Claude Code drive the full WinUI 3 development cycle, from project scaffolding through signed MSIX packaging. The WinUI agent plugin ships one agent, eight skills, and several supporting tools targeting the loop developers run dozens of times a day: scaffold, build, run, test, iterate. Native Windows app development with WinUI 3 pulls together several moving parts that rarely sit cleanly together for … More →
The post Microsoft’s WinUI agent plugin trims token use by over 70% during development appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/14121743/winui-agent-plugin.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 13:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft’s, WinUI, agent, plugin, trims, token, use, over, 70, during, development</media:keywords>
</item>

<item>
<title>Microsoft turns Copilot Studio into an AI agent control center</title>
<link>https://block385.com/microsoft-turns-copilot-studio-into-an-ai-agent-control-center</link>
<guid>https://block385.com/microsoft-turns-copilot-studio-into-an-ai-agent-control-center</guid>
<description><![CDATA[ The Microsoft Copilot Studio April 2026 updates improve visibility and governance for admins and expand workflow capabilities for managing agents. Copilot surfaces agent status in the authoring experience, giving admins insight into each agent’s security and protection posture. Customers can identify issues such as authentication gaps or policy impacts and investigate them at the source. Analytics Viewer role Insights can be shared through the generally available Analytics Viewer role, which grants access to the Analytics … More →
The post Microsoft turns Copilot Studio into an AI agent control center appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/14101308/microsoft_copilot_studio.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 13:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, turns, Copilot, Studio, into, agent, control, center</media:keywords>
</item>

<item>
<title>Windows Zero&#45;Days Expose BitLocker Bypasses And CTFMON Privilege Escalation</title>
<link>https://block385.com/windows-zero-days-expose-bitlocker-bypasses-and-ctfmon-privilege-escalation</link>
<guid>https://block385.com/windows-zero-days-expose-bitlocker-bypasses-and-ctfmon-privilege-escalation</guid>
<description><![CDATA[ An anonymous cybersecurity researcher who disclosed three Microsoft Defender vulnerabilities has returned with two more zero-days involving a BitLocker bypass and a privilege escalation impacting Windows Collaborative Translation Framework (CTFMON).
The security defects have been codenamed YellowKey and GreenPlasma, respectively, by the researcher, who goes by the online aliases Chaotic Eclipse ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgXt7ooDl2PwJY4nazAKdW9rmILsmosve2FZaO9usxTk_rkksEEvsLgY-uc_MErXvjvusuWjN7PWRM9KaRXB1OkL75gio7tcqpMsPZxaFNE9XDpYmARH3Dw_gGgddwWXHSt5VUJ-lb56F9bCVzTYghEo7qELWVv8K_W8V1BrWgssgqWkzPJxW6I31i_GyYf/s1600/windowss.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 12:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Windows, Zero-Days, Expose, BitLocker, Bypasses, And, CTFMON, Privilege, Escalation</media:keywords>
</item>

<item>
<title>CERN’s open source KiCad library gives the world 17,000 circuit board components</title>
<link>https://block385.com/cerns-open-source-kicad-library-gives-the-world-17000-circuit-board-components</link>
<guid>https://block385.com/cerns-open-source-kicad-library-gives-the-world-17000-circuit-board-components</guid>
<description><![CDATA[ CERN has released its complete KiCad component library under an open source license, making it available to hardware designers anywhere in the world. The library, maintained by CERN’s Design Office, contains more than 17,000 electronic components in the form of schematic symbols and printed circuit board footprints. Layout of a printed circuit board made using KiCad (Source: CERN) KiCad is a free and open source software suite for printed circuit board design. Because it uses … More →
The post CERN’s open source KiCad library gives the world 17,000 circuit board components appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/14094304/kicad-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 11:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>CERN’s, open, source, KiCad, library, gives, the, world, 17, 000, circuit, board, components</media:keywords>
</item>

<item>
<title>18&#45;Year&#45;Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE</title>
<link>https://block385.com/18-year-old-nginx-rewrite-module-flaw-enables-unauthenticated-rce</link>
<guid>https://block385.com/18-year-old-nginx-rewrite-module-flaw-enables-unauthenticated-rce</guid>
<description><![CDATA[ Cybersecurity researchers have disclosed multiple security vulnerabilities impacting NGINX Plus and NGINX Open, including a critical flaw that remained undetected for 18 years.
The vulnerability, discovered by depthfirst, is a heap buffer overflow issue impacting ngx_http_rewrite_module (CVE-2026-42945, CVSS v4 score: 9.2) that could allow an attacker to achieve remote code execution or cause a ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhCvxtNv7UYYMCITB2HLsBgkN83LdRXcw0wmP9gMAfXeNpmJoOJKNIaQb55b-GLDeQHx-dUBkASGDYgstnvYAE5eFuwyzMSxY804fn56OaTsGlESOab9y-kFHJ-iV5iUlWrc5j27WLduUDhW6nRSjkv5tFMKZjDbbmDdk7_NMZ3y7sipHKy7t4XuMQ9YfG/s1600/nn.gif" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 10:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>18-Year-Old, NGINX, Rewrite, Module, Flaw, Enables, Unauthenticated, RCE</media:keywords>
</item>

<item>
<title>New Fragnesia Linux Kernel LPE Grants Root Access via Page Cache Corruption</title>
<link>https://block385.com/new-fragnesia-linux-kernel-lpe-grants-root-access-via-page-cache-corruption</link>
<guid>https://block385.com/new-fragnesia-linux-kernel-lpe-grants-root-access-via-page-cache-corruption</guid>
<description><![CDATA[ Details have emerged about a new variant of the recent Dirty Frag Linux local privilege escalation (LPE) vulnerability that allows local attackers to gain root access, making it the third such bug to be identified in the kernel within a span of two weeks.
Codenamed Fragnesia, the security vulnerability is tracked as CVE-2026-46300 (CVSS score: 7.8) and is rooted in the Linux kernel&#039;s XFRM ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZEVPJhl5rAx5o22-s1GQ6E1KKHMlOsazAfObgwK72r5EGxr52OkNRHHQXJdHt39DQop0SAhxE_t9nMKgXxHNgYv1zyB-ZR1IqCIKUK2feTpx1swr4dZzKLpZ5uldjrOAX6qH-wYnUfRWieA2xQWPbAUB1JpXhkBGq4AA0Ft07F7MFqZSHCS9SMR6uXjoC/s1600/linux-2.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 10:30:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, Fragnesia, Linux, Kernel, LPE, Grants, Root, Access, via, Page, Cache, Corruption</media:keywords>
</item>

<item>
<title>Closing the AI governance gap in your enterprise</title>
<link>https://block385.com/closing-the-ai-governance-gap-in-your-enterprise</link>
<guid>https://block385.com/closing-the-ai-governance-gap-in-your-enterprise</guid>
<description><![CDATA[ In this Help Net Security video, Casey Bleeker, CEO at SurePath AI, talks about the AI governance gap that exists in almost every organization. Drawing from three years of conversations with IT, business, and security leaders, Casey explains why AI adoption is outpacing governance maturity by a wide margin, creating friction between security teams pushing for responsible use and business leaders worried about falling behind competitors. Casey walks through what a typical audit reveals at … More →
The post Closing the AI governance gap in your enterprise appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/12203032/door-open.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 09:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Closing, the, governance, gap, your, enterprise</media:keywords>
</item>

<item>
<title>Vector embedding security gap exposes enterprise AI pipelines</title>
<link>https://block385.com/vector-embedding-security-gap-exposes-enterprise-ai-pipelines</link>
<guid>https://block385.com/vector-embedding-security-gap-exposes-enterprise-ai-pipelines</guid>
<description><![CDATA[ Enterprise adoption of retrieval-augmented generation has moved sensitive corporate content into a new storage format that existing security tools cannot inspect. Companies deploying internal AI assistants convert documents into high-dimensional numerical vectors and ship them to embedding services and vector databases over ordinary HTTPS connections. Data loss prevention products scan documents and network traffic, and they read none of it. A research framework called VectorSmuggle, released by Jascha Wanger of ThirdKey under the Apache 2.0 … More →
The post Vector embedding security gap exposes enterprise AI pipelines appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/12134206/vectorsmuggle-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Vector, embedding, security, gap, exposes, enterprise, pipelines</media:keywords>
</item>

<item>
<title>Machine identities outnumber humans 109 to 1</title>
<link>https://block385.com/machine-identities-outnumber-humans-109-to-1</link>
<guid>https://block385.com/machine-identities-outnumber-humans-109-to-1</guid>
<description><![CDATA[ Organizations manage an average of 109 machine identities for every human identity. AI agents account for a growing share of those identities, with companies expecting AI agent growth of 85% over the next 12 months. Machine identities are projected to increase by 77%, and human identities by 56%, based on data from Palo Alto Networks’ 2026 Identity Security Landscape report. Which identity security controls does your organization apply across the AI agent lifecycle? (SOurce: Palo … More →
The post Machine identities outnumber humans 109 to 1 appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/09/16094152/identity-person.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 07:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Machine, identities, outnumber, humans, 109</media:keywords>
</item>

<item>
<title>Over 70% of organizations hit by identity breaches</title>
<link>https://block385.com/over-70-of-organizations-hit-by-identity-breaches</link>
<guid>https://block385.com/over-70-of-organizations-hit-by-identity-breaches</guid>
<description><![CDATA[ Attackers rely on stolen credentials, compromised service accounts, and social engineering attacks targeting employees, according to Sophos’ The State of Identity Security 2026 survey. What do you estimate to be the overall cost to your organization to rectify the identity breach? Base: organization could not stop the security breach. n=510. (Source: Sophos) Identity attack trends A survey of 5,000 IT and cybersecurity leaders across 17 countries found that more than 70% of organizations were affected … More →
The post Over 70% of organizations hit by identity breaches appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/10/28162754/face-glitch-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 07:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Over, 70, organizations, hit, identity, breaches</media:keywords>
</item>

<item>
<title>Checkbox Assessments Aren&amp;apos;t Fit to Measure to Risk</title>
<link>https://block385.com/checkbox-assessments-arent-fit-to-measure-to-risk</link>
<guid>https://block385.com/checkbox-assessments-arent-fit-to-measure-to-risk</guid>
<description><![CDATA[ Security governance needs to be more than an annual compliance exercise. New companies are emerging to address risk-management gaps in current audit tools. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt730562b46d0b78c5/66be4145fa2d5811b851cb52/Risk(1800)_Andriy_Popov_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 01:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Checkbox, Assessments, Arent, Fit, Measure, Risk</media:keywords>
</item>

<item>
<title>Attackers Weaponize RubyGems for Data Dead Drops</title>
<link>https://block385.com/attackers-weaponize-rubygems-for-data-dead-drops</link>
<guid>https://block385.com/attackers-weaponize-rubygems-for-data-dead-drops</guid>
<description><![CDATA[ Threat actors are publishing RubyGems packages that include scrapers targeting public-facing UK government servers, but with no clear objective. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt5c3a7f42da5b1b95/6a04cc6a3840020cbc815a66/ruby_Zerilli_Media_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 01:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Attackers, Weaponize, RubyGems, for, Data, Dead, Drops</media:keywords>
</item>

<item>
<title>Tables Turn on &amp;apos;The Gentlemen&amp;apos; RaaS Gang With Data Leak</title>
<link>https://block385.com/tables-turn-on-the-gentlemen-raas-gang-with-data-leak</link>
<guid>https://block385.com/tables-turn-on-the-gentlemen-raas-gang-with-data-leak</guid>
<description><![CDATA[ An OPSEC failure provides a window into what helped the ransomware group rise: a generous affiliate model, opportunistic TTPs, and an effective organizational structure. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/bltd4988365b90a7362/6a04c7e73c21f66c138b9490/Top_hats-Guy_Corbishley-Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Thu, 14 May 2026 01:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Tables, Turn, The, Gentlemen, RaaS, Gang, With, Data, Leak</media:keywords>
</item>

<item>
<title>Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape</title>
<link>https://block385.com/dark-reading-celebrates-20-years-as-a-leading-authority-on-cybersecurity-highlighting-the-people-events-ideas-and-technologies-shaping-the-modern-risk-landscape</link>
<guid>https://block385.com/dark-reading-celebrates-20-years-as-a-leading-authority-on-cybersecurity-highlighting-the-people-events-ideas-and-technologies-shaping-the-modern-risk-landscape</guid>
<description><![CDATA[ Informa TechTarget&#039;s flagship cybersecurity media brand launches a special content series to mark two decades as a trusted source for cybersecurity professionals. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt850556f866500627/654a5a8e05eb4d040a046894/325351_DR23_Graphics_General_Large_Text_v1.png" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 23:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Dark, Reading, Celebrates, Years, Leading, Authority, Cybersecurity, Highlighting, the, People, Events, Ideas, and, Technologies, Shaping, the, Modern, Risk, Landscape</media:keywords>
</item>

<item>
<title>WhatsApp adds Incognito Chat for private Meta AI conversations</title>
<link>https://block385.com/whatsapp-adds-incognito-chat-for-private-meta-ai-conversations</link>
<guid>https://block385.com/whatsapp-adds-incognito-chat-for-private-meta-ai-conversations</guid>
<description><![CDATA[ The company launched Incognito Chat with Meta AI, a feature that lets users hold AI conversations the platform itself cannot read. The rollout will reach WhatsApp and the standalone Meta AI app over the coming months. How Incognito Chat works Incognito Chat runs on top of Meta’s Private Processing technology, the same infrastructure the company introduced earlier for AI tools in WhatsApp. Messages sent through an Incognito Chat are handled inside a secure environment that … More →
The post WhatsApp adds Incognito Chat for private Meta AI conversations appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/13171417/meta_ai_incognito_chat-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 19:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>WhatsApp, adds, Incognito, Chat, for, private, Meta, conversations</media:keywords>
</item>

<item>
<title>[Webinar] How Modern Attack Paths Cross Code, Pipelines, and Cloud</title>
<link>https://block385.com/webinar-how-modern-attack-paths-cross-code-pipelines-and-cloud</link>
<guid>https://block385.com/webinar-how-modern-attack-paths-cross-code-pipelines-and-cloud</guid>
<description><![CDATA[ TL;DR: Stop chasing thousands of &quot;toast&quot; alerts. Join experts from Wiz to learn how hackers connect tiny flaws to build a &quot;Lethal Chain&quot; to your data—and how to break it. Register for the Strategic Briefing Here.
Most security tools work like a smoke alarm that goes off every time you burn a piece of toast. You get so many alerts that you eventually start to ignore them.
The real danger? While ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-X1ZWS1wjhotRXh44H3uH6bxJmz3fwKA9tFIuYxCVV_b_BhzNKscxBa_St0ybBNSIpHYTlgBf0YvsuY1B2FUJebmGwtpkgeDh7DutT4ERpurg_iRTfDNbyWWzFOt5Z8PLGDu-kywwNTPdNVK_UDcAC8ZzdFCry5xDvx8c8l9QtNJKk6J4ZQVRIpvAfzwf/s1600/wiz.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 18:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Webinar, How, Modern, Attack, Paths, Cross, Code, Pipelines, and, Cloud</media:keywords>
</item>

<item>
<title>Tuskira’s Kairo exposes hidden AI&#45;driven breach paths</title>
<link>https://block385.com/tuskiras-kairo-exposes-hidden-ai-driven-breach-paths</link>
<guid>https://block385.com/tuskiras-kairo-exposes-hidden-ai-driven-breach-paths</guid>
<description><![CDATA[ Tuskira has announced the launch of Kairo, a breach modeling capability that detects deep, hidden breach paths by leveraging its security data mesh and digital twin technology. Kairo helps security teams improve breach resilience by modeling how attackers can leverage new AI models to laterally move across an environment, identifying deep hidden kill chains across cloud, IT &amp; OT infrastructure. Kairo also validates detected breach paths against existing security controls if attackers can also bypass … More →
The post Tuskira’s Kairo exposes hidden AI-driven breach paths appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 17:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Tuskira’s, Kairo, exposes, hidden, AI-driven, breach, paths</media:keywords>
</item>

<item>
<title>LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly</title>
<link>https://block385.com/latam-vibe-hackers-generate-custom-hacking-tools-on-the-fly</link>
<guid>https://block385.com/latam-vibe-hackers-generate-custom-hacking-tools-on-the-fly</guid>
<description><![CDATA[ In the latest evolution of automated cyberattacks, two threat campaigns heavily leveraged AI agents to support attacks against entities in Mexico and Brazil. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt21f9c2318a5ab687/6a038ac9398f1c61e4de8097/evil_robot_Anna_Vaczi_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>LatAm, Vibe, Hackers, Generate, Custom, Hacking, Tools, the, Fly</media:keywords>
</item>

<item>
<title>Signal responds to phishing attacks with new in&#45;app security warnings</title>
<link>https://block385.com/signal-responds-to-phishing-attacks-with-new-in-app-security-warnings</link>
<guid>https://block385.com/signal-responds-to-phishing-attacks-with-new-in-app-security-warnings</guid>
<description><![CDATA[ Signal is adding new protections for users following recent phishing and social engineering attacks. In March, the FBI and CISA issued a warning stating that Signal had become a primary target of Russian intelligence-linked hackers. Dutch and German security authorities were among the first to identify phishing campaigns targeting Signal users. The scheme centered on Signal’s “linked devices” feature. Attackers contacted targets while posing as trusted entities, including support teams or known contacts. Victims were … More →
The post Signal responds to phishing attacks with new in-app security warnings appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/13140947/signal-app-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 17:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Signal, responds, phishing, attacks, with, new, in-app, security, warnings</media:keywords>
</item>

<item>
<title>Microsoft&amp;apos;s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday</title>
<link>https://block385.com/microsofts-mdash-ai-system-finds-16-windows-flaws-fixed-in-patch-tuesday</link>
<guid>https://block385.com/microsofts-mdash-ai-system-finds-16-windows-flaws-fixed-in-patch-tuesday</guid>
<description><![CDATA[ Microsoft has unveiled a new multi-model artificial intelligence (AI)-driven system called MDASH to facilitate vulnerability discovery and remediation at scale, adding that it&#039;s being tested by some customers as part of a limited private preview.
MDASH, short for multi-model agentic scanning harness, is designed as a model-agnostic system that uses bespoke AI agents for different vulnerability ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg1Iq16GS3jdGiIU24GHBkwg6unk05ctdgYwXO5df8zRu1qko95_XhszCjq6jlEIRozLsrtZHgi5GqDZnS1Sw_KDzUzsagwP0If3VswmYHsnuYwVseU2lapxQiPpItTdAiv-CCdTFR87ZVOu65buyvmvzmdWuJPKHuPA4DSo58HQIMAV__2ymsmRe2g3UVe/s1600/windows-ai.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 16:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsofts, MDASH, System, Finds, Windows, Flaws, Fixed, Patch, Tuesday</media:keywords>
</item>

<item>
<title>Azerbaijani Energy Firm Hit by Repeated Microsoft Exchange Exploitation</title>
<link>https://block385.com/azerbaijani-energy-firm-hit-by-repeated-microsoft-exchange-exploitation</link>
<guid>https://block385.com/azerbaijani-energy-firm-hit-by-repeated-microsoft-exchange-exploitation</guid>
<description><![CDATA[ A threat actor with affiliations to China has been linked to a &quot;multi-wave intrusion&quot; targeting an unnamed Azerbaijani oil and gas company between late December 2025 and late February 2026, marking an expansion of its targeting.
The activity has been attributed by Bitdefender with moderate-to-high confidence to a hacking group known as FamousSparrow (aka UAT-9244), which shares some level of ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjOfGXVOYqF2EcrcnYIDCnTYdmWpV-uaZ5nV0_0ukZ8uCk19wFFOax_VvgwO8LtlIkVo8pvcSSBs8Afc66yo2PbiMDjq4UDqnytAqP-Nq8CqTOfEtqwuWRmjbUpRYzqaAXFnRiXozR34fXAPE8O6Gcix6f08Sped3oVUXcjIOTE04N8IInA0qVeG0Sc6LzB/s1600/energy-cyberattack.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 16:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Azerbaijani, Energy, Firm, Hit, Repeated, Microsoft, Exchange, Exploitation</media:keywords>
</item>

<item>
<title>KDE gets over €1 million investment to strengthen security and core infrastructure</title>
<link>https://block385.com/kde-gets-over-1-million-investment-to-strengthen-security-and-core-infrastructure</link>
<guid>https://block385.com/kde-gets-over-1-million-investment-to-strengthen-security-and-core-infrastructure</guid>
<description><![CDATA[ European governments and public institutions have been shifting away from proprietary software for years, and the financial infrastructure supporting open-source alternatives is growing to match. Germany’s Sovereign Tech Fund announced today that it is investing more than €1 million in KDE, the open-source project behind the Plasma desktop environment and a broad range of Linux software. The investment will go toward strengthening KDE’s testing infrastructure, security architecture, and the frameworks underpinning its communication services. KDE … More →
The post KDE gets over €1 million investment to strengthen security and core infrastructure appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/13125115/kde-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 15:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>KDE, gets, over, €1, million, investment, strengthen, security, and, core, infrastructure</media:keywords>
</item>

<item>
<title>AI Agents Generate Custom Hacking Tools on the Fly</title>
<link>https://block385.com/ai-agents-generate-custom-hacking-tools-on-the-fly</link>
<guid>https://block385.com/ai-agents-generate-custom-hacking-tools-on-the-fly</guid>
<description><![CDATA[ Two threat campaigns heavily leveraged AI agents to support attacks against entities in Mexico and Brazil. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt21f9c2318a5ab687/6a038ac9398f1c61e4de8097/evil_robot_Anna_Vaczi_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 15:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Agents, Generate, Custom, Hacking, Tools, the, Fly</media:keywords>
</item>

<item>
<title>It&amp;apos;s Patch Tuesday for Microsoft &amp;amp;amp; Not a Zero&#45;Day In Sight</title>
<link>https://block385.com/its-patch-tuesday-for-microsoft-not-a-zero-day-in-sight</link>
<guid>https://block385.com/its-patch-tuesday-for-microsoft-not-a-zero-day-in-sight</guid>
<description><![CDATA[ It&#039;s the first time in two years with no zero-days. But with 137 flaws to patch, including nine critical ones, admins still have plenty of work to do. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blta3704ee375f0b629/6a038cf3ee64ff5eb73bf289/swbug_Andrii_Yalanskyi_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 15:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Its, Patch, Tuesday, for, Microsoft, &amp;amp, Not, Zero-Day, Sight</media:keywords>
</item>

<item>
<title>Apricorn hardens ASK3 encrypted USB drive for extreme conditions</title>
<link>https://block385.com/apricorn-hardens-ask3-encrypted-usb-drive-for-extreme-conditions</link>
<guid>https://block385.com/apricorn-hardens-ask3-encrypted-usb-drive-for-extreme-conditions</guid>
<description><![CDATA[ Apricorn has announced enhancements to its Aegis Secure Key 3.0 (ASK3), delivering faster performance and new environmental protection capabilities designed to secure the device and its data in the most demanding physical circumstances. The ASK3 was updated to meet and exceed the latest NIST Cryptographic Module Validation Program (CMVP) for FIPS 140-3 Level 3 validation, for which it has formally been submitted. This positions the ASK3 for use by government, defence contractors, and organisations across … More →
The post Apricorn hardens ASK3 encrypted USB drive for extreme conditions appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 15:00:06 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Apricorn, hardens, ASK3, encrypted, USB, drive, for, extreme, conditions</media:keywords>
</item>

<item>
<title>China&amp;apos;s &amp;apos;FamousSparrow&amp;apos; APT Nests in South Caucasus Energy Firm</title>
<link>https://block385.com/chinas-famoussparrow-apt-nests-in-south-caucasus-energy-firm</link>
<guid>https://block385.com/chinas-famoussparrow-apt-nests-in-south-caucasus-energy-firm</guid>
<description><![CDATA[ The cyberthreat group targets an Azerbaijani oil and gas firm with repeated attacks, as the China-linked actors extend targeting beyond hospitality, telecom, and government sectors. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt69a3ca2781c97543/6a039734559f883c8de4d9ec/pair-of-java-sparrows-Alen_Thien-shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 15:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Chinas, FamousSparrow, APT, Nests, South, Caucasus, Energy, Firm</media:keywords>
</item>

<item>
<title>[Webinar] Why Your AppSec Tools Miss the &amp;quot;Lethal Path&amp;quot; (and How to Fix It)</title>
<link>https://block385.com/webinar-why-your-appsec-tools-miss-the-lethal-path-and-how-to-fix-it</link>
<guid>https://block385.com/webinar-why-your-appsec-tools-miss-the-lethal-path-and-how-to-fix-it</guid>
<description><![CDATA[ TL;DR: Stop chasing thousands of &quot;toast&quot; alerts. Join experts from Wiz and Okta/GitLab to learn how hackers connect tiny flaws to build a &quot;Lethal Chain&quot; to your data—and how to break it. Register for the Strategic Briefing Here.
Most security tools work like a smoke alarm that goes off every time you burn a piece of toast. You get so many alerts that you eventually start to ignore them.
The real ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh-X1ZWS1wjhotRXh44H3uH6bxJmz3fwKA9tFIuYxCVV_b_BhzNKscxBa_St0ybBNSIpHYTlgBf0YvsuY1B2FUJebmGwtpkgeDh7DutT4ERpurg_iRTfDNbyWWzFOt5Z8PLGDu-kywwNTPdNVK_UDcAC8ZzdFCry5xDvx8c8l9QtNJKk6J4ZQVRIpvAfzwf/s1600/wiz.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 14:30:13 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Webinar, Why, Your, AppSec, Tools, Miss, the, Lethal, Path, and, How, Fix, It</media:keywords>
</item>

<item>
<title>Most Remediation Programs Never Confirm the Fix Actually Worked</title>
<link>https://block385.com/most-remediation-programs-never-confirm-the-fix-actually-worked</link>
<guid>https://block385.com/most-remediation-programs-never-confirm-the-fix-actually-worked</guid>
<description><![CDATA[ Security teams have never had better visibility into their environments and never been worse at confirming what they fix stays fixed.
Mandiant&#039;s M-Trends 2026 report puts the mean time to exploit at an estimated negative seven days. The Verizon 2025 DBIR puts median time to remediate edge device vulnerabilities at 32 days. These numbers have understandably driven the industry toward a clear ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg70Fxtk3MEmUdZjXl_ocBSlT80rWfXtIj2kxPvypzCSlEK4cqkm8lo16NXHjvyCw9niiPk2gKSPhgTjSFTZpetxg2As7QL0AyWWHoTuvtcp1Ok-ALMfcUwaUMAyE8asDu-KjVDoUP4VLCOSDPWHru7V-ix6Xs-VSHvHDJ8KRn6NLq_EJJBm0B4xwa9vbLp/s1600/pentera.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 14:30:13 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Most, Remediation, Programs, Never, Confirm, the, Fix, Actually, Worked</media:keywords>
</item>

<item>
<title>Microsoft Patches 138 Vulnerabilities, Including DNS and Netlogon RCE Flaws</title>
<link>https://block385.com/microsoft-patches-138-vulnerabilities-including-dns-and-netlogon-rce-flaws</link>
<guid>https://block385.com/microsoft-patches-138-vulnerabilities-including-dns-and-netlogon-rce-flaws</guid>
<description><![CDATA[ Microsoft on Tuesday released patches for 138 security vulnerabilities spanning its product portfolio, although none of them have been listed as publicly known or under active attack.
Of the 138 flaws, 30 are rated Critical, 104 are rated Important, three are rated Moderate, and one is rated Low in severity. As many as 61 vulnerabilities are classified as privilege escalation bugs, followed by ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjk3m3CoTiKH2QVXSFAOVKKnTl-Ybt1FDE4M7BGK_ujskSYNQ8pOlcvZfyNv8CW2EJIVdMQaORcCE0H-_ufTvD6hR-LOOZ64GZPS_9bH7YrE4i0r4LrGCn7vXmG0GjpFk8aNlRR_4_GjrM-jhXBS1NzIbYiRydcmiNSXIV2eUczvgjGmp34_gNz3M5kt-Jf/s1600/windows-patch-update.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 14:30:13 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, Patches, 138, Vulnerabilities, Including, DNS, and, Netlogon, RCE, Flaws</media:keywords>
</item>

<item>
<title>Microsoft’s agentic security system found four critical Windows RCE flaws</title>
<link>https://block385.com/microsofts-agentic-security-system-found-four-critical-windows-rce-flaws</link>
<guid>https://block385.com/microsofts-agentic-security-system-found-four-critical-windows-rce-flaws</guid>
<description><![CDATA[ Microsoft responded to growing competition in AI security by announcing that its new agentic security system helped researchers discover 16 new vulnerabilities in the Windows networking and authentication stack, including four critical remote code execution (RCE) flaws. MDASH architecture diagram (Source: Microsoft) Two of the four flaws — CVE-2026-40361 and CVE-2026-40364 — were deemed by Microsoft to be more likely to be exploited. The multi-model agentic scanning harness, codenamed MDASH, was built by Microsoft’s Autonomous … More →
The post Microsoft’s agentic security system found four critical Windows RCE flaws appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2025/08/05120625/microsoft-ai-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 13:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft’s, agentic, security, system, found, four, critical, Windows, RCE, flaws</media:keywords>
</item>

<item>
<title>GemStuffer Abuses 150+ RubyGems to Exfiltrate Scraped U.K. Council Portal Data</title>
<link>https://block385.com/gemstuffer-abuses-150-rubygems-to-exfiltrate-scraped-uk-council-portal-data</link>
<guid>https://block385.com/gemstuffer-abuses-150-rubygems-to-exfiltrate-scraped-uk-council-portal-data</guid>
<description><![CDATA[ Cybersecurity researchers are calling attention to a new campaign dubbed GemStuffer that has targeted the RubyGems repository with more than 150 gems that use the registry as a data exfiltration channel rather than for malware distribution.
&quot;The packages do not appear designed for mass developer compromise,&quot; Socket said. &quot;Many have little or no download activity, and the payloads are repetitive, ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZpbB_p88zZf6q_DhwCbgnYn2okFYqa7pwIPmknojvkOC3heteNMp3C6bzD_6WKChB4yVK0wLyoJ_-DebN0c229j-twjPyMAC-qkfGs1tjlaEoNg30fpEDh9DIByfz_h4nKhalTC_Su-FP0AYxywL_x85ILq1t-QFPtuMa_-KbLKlfsX15kvGpPCs1OZpw/s1600/rubygemss.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 12:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>GemStuffer, Abuses, 150, RubyGems, Exfiltrate, Scraped, U.K., Council, Portal, Data</media:keywords>
</item>

<item>
<title>Versa CSPM brings continuous visibility to cloud risk and compliance exposure</title>
<link>https://block385.com/versa-cspm-brings-continuous-visibility-to-cloud-risk-and-compliance-exposure</link>
<guid>https://block385.com/versa-cspm-brings-continuous-visibility-to-cloud-risk-and-compliance-exposure</guid>
<description><![CDATA[ Versa has announced Versa Cloud Security Posture Management (CSPM), extending the VersaONE Universal SASE Platform to provide continuous visibility, prioritization, and remediation of cloud risk across environments. With CSPM, Versa combines secure access protection and cloud posture risk on a single platform, delivering the visibility security teams need to quantify and reduce enterprise cyber exposure. For years, security has evolved in silos. Access is protected, but cloud misconfiguration risk remains fragmented and hard to see. … More →
The post Versa CSPM brings continuous visibility to cloud risk and compliance exposure appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 11:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Versa, CSPM, brings, continuous, visibility, cloud, risk, and, compliance, exposure</media:keywords>
</item>

<item>
<title>Android Adds Intrusion Logging for Sophisticated Spyware Forensics</title>
<link>https://block385.com/android-adds-intrusion-logging-for-sophisticated-spyware-forensics</link>
<guid>https://block385.com/android-adds-intrusion-logging-for-sophisticated-spyware-forensics</guid>
<description><![CDATA[ Google on Tuesday unveiled a new opt-in Android feature called Intrusion Logging for storing forensic logs to better analyze sophisticated spyware attacks.
Intrusion Logging, available as part of Advanced Protection Mode, enables &quot;persistent and privacy-preserving forensics logging to allow for investigation of devices in the event of a suspected compromise,&quot; the company said.
The feature, it ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBNoTD0wrxHsoNUfZVLT2ImOUNC-2Md_wih6gTim-zbqkCzgGfXbtvlDgDMWeczo9RzINqu7qqk_3XK0KHSdbpLMPbR9xg_pLpjtoxugUt3B5-G9pL9wBCMI80Rx-Aw9eNxH-XXE2XpQHDtqaGDeXe3P4mGDvPgmDiqom8B2Xdfz7irCpOZVvhP9jsqudo/s1600/adnroid-Intrusion-Logging.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 10:30:08 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Android, Adds, Intrusion, Logging, for, Sophisticated, Spyware, Forensics</media:keywords>
</item>

<item>
<title>The hidden risk of non&#45;human identities in AI adoption</title>
<link>https://block385.com/the-hidden-risk-of-non-human-identities-in-ai-adoption</link>
<guid>https://block385.com/the-hidden-risk-of-non-human-identities-in-ai-adoption</guid>
<description><![CDATA[ An employee with persistent, unsupervised admin access across critical systems, with no audit trail, no clear owner, and no regular access reviews, would raise immediate concern in most organizations. Yet non-human identities and AI agents are often granted that same kind of persistent, broadly privileged access. As AI adoption grows, that gap is becoming harder to ignore. NHIs today encompass far more than traditional service accounts and API keys. They also often include AI agents … More →
The post The hidden risk of non-human identities in AI adoption appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/11132505/delinea_ai_identities.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 09:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>The, hidden, risk, non-human, identities, adoption</media:keywords>
</item>

<item>
<title>Sandyaa: Open&#45;source autonomous security bug hunter</title>
<link>https://block385.com/sandyaa-open-source-autonomous-security-bug-hunter</link>
<guid>https://block385.com/sandyaa-open-source-autonomous-security-bug-hunter</guid>
<description><![CDATA[ Source code auditing has traditionally relied on static analyzers that flag long lists of potential issues, leaving engineers to sort bugs from noise. A new open-source project from offensive-security firm SecureLayer7 takes a different route, using LLMs to read a codebase, trace how data moves through it, and produce working exploit code for the vulnerabilities it confirms. Their open-source tool, called Sandyaa, was released under an MIT license. How the auditor operates Sandyaa accepts either … More →
The post Sandyaa: Open-source autonomous security bug hunter appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/10111940/sandyaa-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 09:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Sandyaa:, Open-source, autonomous, security, bug, hunter</media:keywords>
</item>

<item>
<title>NetSPI AI&#45;powered Continuous Pentesting identifies high&#45;impact vulnerabilities</title>
<link>https://block385.com/netspi-ai-powered-continuous-pentesting-identifies-high-impact-vulnerabilities</link>
<guid>https://block385.com/netspi-ai-powered-continuous-pentesting-identifies-high-impact-vulnerabilities</guid>
<description><![CDATA[ NetSPI launched AI-powered Continuous Pentesting offerings, designed to help organizations continuously identify, validate and reduce risk across dynamic external and cloud environments. Organizations are managing an expanding number of potential entry points as new internet-facing resources, including cloud assets, applications, APIs, and AI-centric assets, are introduced. Each deployment can create new risk, making it harder for security teams to maintain a view of exposure without continuous, validated insight. NetSPI’s Continuous Pentesting offerings include Continuous External … More →
The post NetSPI AI-powered Continuous Pentesting identifies high-impact vulnerabilities appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 09:00:02 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>NetSPI, AI-powered, Continuous, Pentesting, identifies, high-impact, vulnerabilities</media:keywords>
</item>

<item>
<title>Android pushes new scam, theft, and AI protections in 2026 update wave</title>
<link>https://block385.com/android-pushes-new-scam-theft-and-ai-protections-in-2026-update-wave</link>
<guid>https://block385.com/android-pushes-new-scam-theft-and-ai-protections-in-2026-update-wave</guid>
<description><![CDATA[ Phone scammers spoofing bank caller IDs have driven an estimated $980 million in annual losses worldwide, according to Europol. Android’s 2026 security roadmap takes direct aim at that pattern with a verified call system built in partnership with banks, alongside a wider set of protections covering app behavior, device theft, location data, and on-device AI processing. Verified financial calls A new feature called verified financial calls will check incoming calls against the official app of … More →
The post Android pushes new scam, theft, and AI protections in 2026 update wave appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/12204108/android-security-privacy.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 07:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Android, pushes, new, scam, theft, and, protections, 2026, update, wave</media:keywords>
</item>

<item>
<title>Researchers open&#45;source a Wi&#45;Fi cyber range for security training</title>
<link>https://block385.com/researchers-open-source-a-wi-fi-cyber-range-for-security-training</link>
<guid>https://block385.com/researchers-open-source-a-wi-fi-cyber-range-for-security-training</guid>
<description><![CDATA[ Wireless security training programs lean heavily on generic network labs, with Wi-Fi appearing as a checkbox alongside Bluetooth, Zigbee, and cellular. Hands-on environments dedicated to IEEE 802.11 are uncommon, even as Wi-Fi remains the default on-ramp to corporate networks and a recurring entry point for attackers. A new paper from researchers at the Norwegian University of Science and Technology and the University of the Aegean takes aim at that gap with a cyber range built … More →
The post Researchers open-source a Wi-Fi cyber range for security training appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/11170922/wireless-connection.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 07:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Researchers, open-source, Wi-Fi, cyber, range, for, security, training</media:keywords>
</item>

<item>
<title>Fedora Hummingbird brings the container security model to a Linux host OS</title>
<link>https://block385.com/fedora-hummingbird-brings-the-container-security-model-to-a-linux-host-os</link>
<guid>https://block385.com/fedora-hummingbird-brings-the-container-security-model-to-a-linux-host-os</guid>
<description><![CDATA[ Container image security pipelines have spent the past several years pushing toward minimal footprints, hermetic builds, and continuous CVE remediation. The Fedora Project is now applying that same approach to the host operating system. At Red Hat Summit 2026, Fedora announced Fedora Hummingbird, a container-based rolling Linux distribution delivered as an OCI image. “The Linux market has split: IT operations teams need the decades-long stability of Red Hat Enterprise Linux, while builders, both human and … More →
The post Fedora Hummingbird brings the container security model to a Linux host OS appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/12202003/fedora_hummingbird-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 01:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Fedora, Hummingbird, brings, the, container, security, model, Linux, host</media:keywords>
</item>

<item>
<title>It&amp;apos;s Patch Tuesday for Microsoft and Not a Zero&#45;Day In Sight</title>
<link>https://block385.com/its-patch-tuesday-for-microsoft-and-not-a-zero-day-in-sight</link>
<guid>https://block385.com/its-patch-tuesday-for-microsoft-and-not-a-zero-day-in-sight</guid>
<description><![CDATA[ It&#039;s the first time in two years with no zero-days. But with 137 flaws to patch, including nine critical ones, admins still have plenty of work to do. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blta3704ee375f0b629/6a038cf3ee64ff5eb73bf289/swbug_Andrii_Yalanskyi_shutterstock.jpg" length="49398" type="image/jpeg"/>
<pubDate>Wed, 13 May 2026 01:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Its, Patch, Tuesday, for, Microsoft, and, Not, Zero-Day, Sight</media:keywords>
</item>

<item>
<title>Microsoft May 2026 Patch Tuesday: Many fixes, but no zero&#45;days</title>
<link>https://block385.com/microsoft-may-2026-patch-tuesday-many-fixes-but-no-zero-days</link>
<guid>https://block385.com/microsoft-may-2026-patch-tuesday-many-fixes-but-no-zero-days</guid>
<description><![CDATA[ Microsoft has marked May 2026 Patch Tuesday by releasing fixes for 120+ CVE-numbered vulnerabilities, none of which (for a change) are actively exploited or have been publicly disclosed. Still, some deserve more consideration and should be addressed sooner than others. Patches to prioritize For Satnam Narang, senior staff research engineer at Tenable, the four critical remote code execution bugs in Microsoft Word stand out in this release, and especially the two (CVE-2026-40361, CVE-2026-40364) that have … More →
The post Microsoft May 2026 Patch Tuesday: Many fixes, but no zero-days appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/05/12193553/patch-tuesday-2-1500.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 12 May 2026 23:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Microsoft, May, 2026, Patch, Tuesday:, Many, fixes, but, zero-days</media:keywords>
</item>

<item>
<title>New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution</title>
<link>https://block385.com/new-exim-bdat-vulnerability-exposes-gnutls-builds-to-potential-code-execution</link>
<guid>https://block385.com/new-exim-bdat-vulnerability-exposes-gnutls-builds-to-potential-code-execution</guid>
<description><![CDATA[ Exim has released security updates to address a severe security issue affecting certain configurations that could enable memory corruption and potential code execution.
Exim is an open-source Mail Transfer Agent (MTA) designed for Unix-like systems to receive, route, and deliver email.
The vulnerability, tracked as CVE-2026-45185, aka Dead.Letter, has been described as a use-after-free ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrSn3emm_NbwXDi3elR0wo5ErHhg-gPT4-u4zk7MHZg4u0ruMmj2_KGgPF8fz06Riv6Gu5NXMN3eBP8H5bVf6dmvOz-lvb-qrvhLlssLUzl97ZVmIWoIOmMPOGrupv864dt0d4V_dxgaaxYYNuy2z9rbZMWIOcjlwZaiifq4-ktRqlEBCJ6a_m3MFiwq65/s1600/exim.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 12 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>New, Exim, BDAT, Vulnerability, Exposes, GnuTLS, Builds, Potential, Code, Execution</media:keywords>
</item>

<item>
<title>RubyGems Suspends New Signups After Hundreds of Malicious Packages Are Uploaded</title>
<link>https://block385.com/rubygems-suspends-new-signups-after-hundreds-of-malicious-packages-are-uploaded</link>
<guid>https://block385.com/rubygems-suspends-new-signups-after-hundreds-of-malicious-packages-are-uploaded</guid>
<description><![CDATA[ RubyGems, the standard package manager for the Ruby programming language, has temporarily paused account sign ups following what has been described as a &quot;major malicious attack.&quot;
&quot;We&#039;re dealing with a major malicious attack on Ruby Gems right now,&quot; Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, said in a post on X. &quot;Signups are paused for the time being. ]]></description>
<enclosure url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEggIbYm86Vn45Nd86Hd5IEqHufRIS5Ud3spGUy5JWHy-My-NBVocyj-aR7E3gBKibPnrWd5DRYnDfmbaHUMuaYcNn_paUIDN11VLySLNUsXwFwVIALsNo419985zWvtepK7NVp9J4W3d7uHGWkQFgqI6zY_9Y5LWe5hsTLk-c9ZMKQ4TDlUMcMh8-_vhdIH/s1600/rubygems.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 12 May 2026 20:30:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>RubyGems, Suspends, New, Signups, After, Hundreds, Malicious, Packages, Are, Uploaded</media:keywords>
</item>

<item>
<title>Stealthy hackers exploit cPanel flaw in active backdoor campaign (CVE&#45;2026&#45;41940)</title>
<link>https://block385.com/stealthy-hackers-exploit-cpanel-flaw-in-active-backdoor-campaign-cve-2026-41940</link>
<guid>https://block385.com/stealthy-hackers-exploit-cpanel-flaw-in-active-backdoor-campaign-cve-2026-41940</guid>
<description><![CDATA[ Security researchers at XLab have outlined an active attack campaign targeting CVE-2026-41940, the recently disclosed vulnerability in cPanel &amp; WHM, and have linked it to a stealthy hacking group that has been operating largely undetected for years. The vulnerability allows an attacker to log into a cPanel server without a username or password, effectively handing them administrator control over the cPanel host system, its configurations and databases, and the websites it manages. The attack campaign … More →
The post Stealthy hackers exploit cPanel flaw in active backdoor campaign (CVE-2026-41940) appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2026/04/30141939/cpanel-1500-1.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 12 May 2026 19:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Stealthy, hackers, exploit, cPanel, flaw, active, backdoor, campaign, CVE-2026-41940</media:keywords>
</item>

<item>
<title>ThreatDown ITDR prevents credential&#45;based attacks</title>
<link>https://block385.com/threatdown-itdr-prevents-credential-based-attacks</link>
<guid>https://block385.com/threatdown-itdr-prevents-credential-based-attacks</guid>
<description><![CDATA[ ThreatDown, the former corporate business unit of Malwarebytes, launched ThreatDown Identity Threat Detection and Response (ITDR). ITDR is a new product that helps security teams monitor identities to detect suspicious activity, misconfigurations, and active attacks targeting user accounts and privileges. With native integrations for Microsoft Entra ID, Okta, and Active Directory, security teams gain unified visibility across hybrid identity environments without deploying additional agents. Natively integrated with the ThreatDown EDR and MDR platform, ITDR delivers … More →
The post ThreatDown ITDR prevents credential-based attacks appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 12 May 2026 19:00:07 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>ThreatDown, ITDR, prevents, credential-based, attacks</media:keywords>
</item>

<item>
<title>Exaforce raises $125 million to respond to AI&#45;powered attacks</title>
<link>https://block385.com/exaforce-raises-125-million-to-respond-to-ai-powered-attacks</link>
<guid>https://block385.com/exaforce-raises-125-million-to-respond-to-ai-powered-attacks</guid>
<description><![CDATA[ Exaforce announced a $125 million Series B financing round, one of the largest ever in the emerging AI SOC space. The round includes participation from HarbourVest, Peak XV, Mayfield, Khosla Ventures, Seligman Ventures and AICONIC. The new capital will help Exaforce scale its AI-native security operations platform, deepen its real-time reasoning capabilities, and expand globally. Coming just one year after its $75 million Series A, the round brings Exaforce’s total funding to $200 million. AI … More →
The post Exaforce raises $125 million to respond to AI-powered attacks appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 12 May 2026 19:00:05 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Exaforce, raises, 125, million, respond, AI-powered, attacks</media:keywords>
</item>

<item>
<title>SAP unveils Autonomous Enterprise for AI&#45;driven business operations</title>
<link>https://block385.com/sap-unveils-autonomous-enterprise-for-ai-driven-business-operations</link>
<guid>https://block385.com/sap-unveils-autonomous-enterprise-for-ai-driven-business-operations</guid>
<description><![CDATA[ SAP introduced the Autonomous Enterprise to help enhance the world’s most critical business workflows, so that humans and AI work together to meet the accelerating demands of global business profitably, strategically and safely. “For the mission-critical processes of our customers, ‘almost right’ just isn’t good enough,” said Christian Klein, CEO of SAP SE. “By uniting SAP Business AI Platform with SAP Autonomous Suite, we anchor AI agents in the business processes, data and governance so … More →
The post SAP unveils Autonomous Enterprise for AI-driven business operations appeared first on Help Net Security. ]]></description>
<enclosure url="https://img.helpnetsecurity.com/wp-content/uploads/2024/11/28150559/hns-large_logo.webp" length="49398" type="image/jpeg"/>
<pubDate>Tue, 12 May 2026 19:00:04 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>SAP, unveils, Autonomous, Enterprise, for, AI-driven, business, operations</media:keywords>
</item>

<item>
<title>Hugging Face Packages Weaponized With a Single File Tweak</title>
<link>https://block385.com/hugging-face-packages-weaponized-with-a-single-file-tweak</link>
<guid>https://block385.com/hugging-face-packages-weaponized-with-a-single-file-tweak</guid>
<description><![CDATA[ A tokenizer library file present in Hugging Face AI models can be manipulated to hijack the model&#039;s outputs and exfiltrate data. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blte4a392e468c2fede/6a02399dd02601ddfa8e5443/Hugging_Face_Sidney_Van_den_Boogaard_Alamy.jpg" length="49398" type="image/jpeg"/>
<pubDate>Tue, 12 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Hugging, Face, Packages, Weaponized, With, Single, File, Tweak</media:keywords>
</item>

<item>
<title>Worm Redux: Fresh Mini Shai&#45;Hulud Infections Bite Supply Chain</title>
<link>https://block385.com/worm-redux-fresh-mini-shai-hulud-infections-bite-supply-chain</link>
<guid>https://block385.com/worm-redux-fresh-mini-shai-hulud-infections-bite-supply-chain</guid>
<description><![CDATA[ Hundreds of npm packages infected by the self-propagating, credential-stealing worm from TeamPCP are related to the open source TanStack ecosystem. ]]></description>
<enclosure url="https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt98af205e9fd3397b/6a030d8e8affd2e99d18dd19/sandworms_FlixPix_Alamy.png" length="49398" type="image/jpeg"/>
<pubDate>Tue, 12 May 2026 19:00:03 +0200</pubDate>
<dc:creator>jakovs</dc:creator>
<media:keywords>Worm, Redux:, Fresh, Mini, Shai-Hulud, Infections, Bite, Supply, Chain</media:keywords>
</item>

</channel>
</rss>