Category index

Cyber Security

4276 articles

4276 ARTICLES

Agent Val Now Validates the Entire Attack Surface: From Network to Host
CYBERSECURITY

Agent Val Now Validates the Entire Attack Surface: From Network to Host

Powered by TruConfirm — Exploit Validation That Now Runs on the Network and the Host Executive Summary Qualys TruConfirm now validates exploitability across the entire attack surface, not just the network. Cloud Agent-Based TruConfirm brings the same proof-based validation model to the endpoint, closing the gap on local, kernel, browser, and post-authentication CVEs that network

1 MIN READ arrow_forward
Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
CYBERSECURITY

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026, N‑able saw an increase in licensing issues for our on-premises N‑central customers. Licensing issues are not uncommon, but the volume was high and the engineering and security teams were engaged,” N-able shared. “On the morning of … More → The post Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) appeared first on Help Net Security.

1 MIN READ arrow_forward
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
CYBERSECURITY

⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from

1 MIN READ arrow_forward
Mimecast introduces AI agent governance and managed threat response
CYBERSECURITY

Mimecast introduces AI agent governance and managed threat response

Mimecast has unveiled Agent Risk Center, a beta capability for discovering, monitoring, and governing AI agents, alongside Managed Threat Response, a redesigned 24/7 service that combines AI-assisted triage with analyst-confirmed remediation. According to Mimecast’s analysis, 98% of organizations already have unsanctioned AI tools in use, and by 2029 more than a billion agents will take some 217 billion actions a day1 on employees’ behalf with limited visibility for security tools. The Mimecast Agent Risk Center … More → The post Mimecast introduces AI agent governance and managed threat response appeared first on Help Net Security.

1 MIN READ arrow_forward
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
CYBERSECURITY

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s AI agent misconfigured a file server, inadvertently exposing the entire infrastructure. “This visibility enabled us to understand their full tool set, how the attackers orchestrated multiple AI platforms and gave us a peek into their targeting,” Unit … More → The post Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers appeared first on Help Net Security.

1 MIN READ arrow_forward
SentinelOne expands security operations automation with governed AI
CYBERSECURITY

SentinelOne expands security operations automation with governed AI

SentinelOne has today announced governed, closed-loop response across the Singularity Platform, delivering trustworthy automation for security operations. Purple AI and Singularity Hyperautomation now autonomously investigate alerts, reach verdicts, and execute responses. Security teams set the boundaries first, deciding where AI acts on its own and where it stops for human sign-off. The Autonomous SOC now runs from alert to action, at the speed and scale of AI, with the confidence and control of human defenders. … More → The post SentinelOne expands security operations automation with governed AI appeared first on Help Net Security.

1 MIN READ arrow_forward