Category index

Cyber Security

4276 articles

4276 ARTICLES

Mythos Asks the Right Question. It Doesn't Answer It.
CYBERSECURITY

Mythos Asks the Right Question. It Doesn't Answer It.

AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you’ve been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? The honest answer is

1 MIN READ arrow_forward
2026 Minimum Elements for a Software Bill of Materials (SBOM)
CYBERSECURITY

2026 Minimum Elements for a Software Bill of Materials (SBOM)

CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM), that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new guidance incorporates stakeholder feedback from a 2025 public comment period and reflects current SBOM tools and needs while preserving the core principles of the original NTIA document. An SBOM serves as an “ingredients list” for software and is a key building block of software security and supply chain risk management. Organizations can use SBOM data to better understand the makeup of their software components and supply chains and make more risk-informed decisions. Minimum elements for an SBOM describe the baseline technologies and practices that an SBOM should include. While the minimum elements for an SBOM apply to all software, some software types—such as artificial intelligence and software as a service in cloud environments—may require additional elements. Any effort to improve software transparency, regardless of the software type, should begin with the application of minimum elements.

1 MIN READ arrow_forward
CISA Adds One Known Exploited Vulnerability to Catalog
CYBERSECURITY

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.

2 MIN READ arrow_forward
Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
CYBERSECURITY

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser’s renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. “No settings or additional user interaction are required,” Eten Zou,

1 MIN READ arrow_forward
MIND AI DLP Agents automate DLP classification, investigations and remediation
CYBERSECURITY

MIND AI DLP Agents automate DLP classification, investigations and remediation

MIND has announced MIND AI DLP Agents with capabilities focused on classification, investigation, policies, remediation and exception management. MIND also includes a Model Context Protocol (MCP) interface that enables security teams to direct data security work through any MCP-connected client using natural language. AI has fundamentally changed the speed and scale at which sensitive data moves. GenAI applications, Agentic AI and autonomous workflows create and move data faster than security teams can manually govern it. … More → The post MIND AI DLP Agents automate DLP classification, investigations and remediation appeared first on Help Net Security.

1 MIN READ arrow_forward
73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack
CYBERSECURITY

73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack

Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by Vanson Bourne in January

1 MIN READ arrow_forward
These near-mint ASUS Chromebook refurbs are only $145
CYBERSECURITY

These near-mint ASUS Chromebook refurbs are only $145

Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade “A” rating, but it still only costs $144.97 (reg. $369.99) on sale.

1 MIN READ arrow_forward
Contrast CVE Shield aims to protect applications while security teams deploy patches
CYBERSECURITY

Contrast CVE Shield aims to protect applications while security teams deploy patches

Contrast Security has announced Contrast CVE Shield, designed to help organisations defend against the growing number of exploits generated with advanced AI models such as Claude Mythos. Contrast CVE Shield runs inside the application, where it detects, monitors and blocks attempts to exploit known vulnerabilities. Applications continue to function normally while security teams gain visibility into which vulnerabilities are present, which are being targeted and which exploitation attempts have been prevented. Using a runtime microsandbox … More → The post Contrast CVE Shield aims to protect applications while security teams deploy patches appeared first on Help Net Security.

1 MIN READ arrow_forward
Long-Lived Vulnerability in Microsoft Secure Boot
CYBERSECURITY

Long-Lived Vulnerability in Microsoft Secure Boot

Microsoft’s Secure Boot has had a serious vulnerability for most of its existence. An industry-wide standard Microsoft invented to protect Windows, and later Linux, devices from firmware infections has been trivial to bypass for 13 of its 14 years of existence. The discovery was made by researchers at security firm ESET after identifying 11 firmware images, at least one from 2013, that were known to be defective but remained signed by the software company anyway. The images are known as shims, which were invented to extend Secure Boot to Linux devices and utility software. Using a technique simple enough to be performed by novice hackers, these old, forgotten shims can be used to completely circumvent the protection, which is embedded into the UEFI (Unified Extensible Firmware Interface) of the device’s motherboard. The gaffe is the result of the failure by Microsoft, which oversees the signing of shims, to revoke the publicly available images once vulnerabilities were found in them…

1 MIN READ arrow_forward