Aggregator
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
Ученые создали миниатюрный ядерный огненный шар в лаборатории
Бесшовное покрытие, дроны и лазеры вместо проводов. Китай представил прототип беспроводного интернета будущего
Lessons for organizations from the Verizon 2026 Data Breach Investigations Report
This is my favourite time of the year, not just because spring is here and the promise of summer is on the way. But also, because one of my must reads each year gets published. There are a few must read reports that I have on my reading list for each year and the Verizon Data Breach Investigations Report is on top of that list. The latest Verizon 2026 Data Breach Investigations Report (DBIR) once … More →
The post Lessons for organizations from the Verizon 2026 Data Breach Investigations Report appeared first on Help Net Security.
四月全球风能太阳能发电量超过天然气发电量
AI 定向注入攻击:加密货币窃取供应链攻击新邪招
OpenHack: Open-source AI-powered vulnerability research
Source-guided vulnerability research increasingly leans on coding harnesses such as Claude Code, Codex, and Cursor to drive agent-based reviews of application code. A new MIT-licensed project from the Dutch security firm Hadrian, called OpenHack, packages that approach into a file-based workspace that any of those harnesses can run. OpenHack is a set of agents and tools that mimics how Hadrian’s research team performs automated vulnerability research. The workflow runs inside a coding harness or a … More →
The post OpenHack: Open-source AI-powered vulnerability research appeared first on Help Net Security.
JVN: NEC AtermシリーズにおけるOSコマンドインジェクションの脆弱性(NV26-003)
ZDI-CAN-30890: Anysphere
JVN: NEC Atermシリーズにおけるクロスサイトスクリプティングの脆弱性(NV26-002)
Скачали PDF-редактор? Готовьтесь прощаться с паролями от всех ваших аккаунтов
Boards want cyber risk in dollars, not CVE counts
In this Help Net Security video, Ziv Levi, SVP of Technology at CYE, explains why translating cyber risk into dollars is one of the most pressing tasks for security leaders. Boards and executives want cyber exposure described in business terms, not technical jargon. Levi walks through a three-step financial translation framework. First, identify business exposure by mapping attack paths to the assets that matter most, such as intellectual property and customer data. Second, focus on … More →
The post Boards want cyber risk in dollars, not CVE counts appeared first on Help Net Security.
JVN: Linuxカーネルにおける複数の脆弱性
Фабрика утечек: берёшь старый Facebook, добавляешь Eatigo, называешь банком — готово, можно продавать
Turns out the C-suite loves shadow AI
Senior decision-makers are the heaviest users of unapproved AI tools, and they continue using them despite being aware of the security and privacy risks linked to shadow AI, according to TrustedTech’s Shadow AI in the Workplace report. The study found that 65% of decision-makers use shadow AI, compared with 31% of employees below decision-maker level. Net Shadow AI use (Source: TrustedTech) The data suggests that shadow AI is not mainly driven by junior employees experimenting … More →
The post Turns out the C-suite loves shadow AI appeared first on Help Net Security.