Category index

Cyber Security

4276 articles

4276 ARTICLES

Prompt injection is becoming the XSS of the web agent era
CYBERSECURITY

Prompt injection is becoming the XSS of the web agent era

Autonomous web agents read whatever a page displays, and much of that content comes from strangers. Product reviews, seller listings, and advertisements sit beside trusted site menus on a single page. An agent that reads all of that text as instructions can be steered by any of it. A group at UC Berkeley describe Cross-Site Prompting, or XSP, as the agent-era version of Cross-Site Scripting. Their system, Prismata, sits between a web agent and the … More → The post Prompt injection is becoming the XSS of the web agent era appeared first on Help Net Security.

1 MIN READ arrow_forward
The script, not the voice, is what makes AI voice phishing work
CYBERSECURITY

The script, not the voice, is what makes AI voice phishing work

The call comes in at 4:40 on a Friday. The voice belongs to a senior manager, or sounds close enough, and she needs a password reset before a flight. She is polite, she is in a hurry, and she has the last four of the badge number. Researchers at Harvard Kennedy School, Meta and elsewhere ran a version of that moment past 4,100 US adults, using six commercial voice systems and human callers as a … More → The post The script, not the voice, is what makes AI voice phishing work appeared first on Help Net Security.

1 MIN READ arrow_forward
The five step plan that cuts security budget waste
CYBERSECURITY

The five step plan that cuts security budget waste

In this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, and that mismatch is where the money goes. He walks through the two big leaks, overlapping tools that flag the same issue three times, and shelfware that covers a third of the estate at 100% of the invoice. The license … More → The post The five step plan that cuts security budget waste appeared first on Help Net Security.

1 MIN READ arrow_forward
A hard drive reliability check on 341,263 drives, from 4TB to past 20TB
CYBERSECURITY

A hard drive reliability check on 341,263 drives, from 4TB to past 20TB

Large cloud storage operators track their hard drives every day, recording which units keep running and which ones drop off the racks. Backblaze does this at scale, and its Q1 2026 report covers a fleet built for continuous use. The analysis covered 341,263 hard drives, after boot drives and a small group of units that missed the reporting thresholds were set aside. The pool spans capacities from 4TB to past 20TB. The quarterly annualized failure … More → The post A hard drive reliability check on 341,263 drives, from 4TB to past 20TB appeared first on Help Net Security.

1 MIN READ arrow_forward
New infosec products of the week: July 17, 2026
CYBERSECURITY

New infosec products of the week: July 17, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI Meeting Guard delivers real-time deepfake detection for enterprise meetings Polygraf AI has announced Meeting Guard, a real-time AI fraud detection solution for enterprise meetings built to detect fraud and protect meeting security. It joins virtual meetings as a visible participant and delivers near-real-time security analysis to every attendee. Built for enterprise … More → The post New infosec products of the week: July 17, 2026 appeared first on Help Net Security.

1 MIN READ arrow_forward
ACR Stealer: Two observed intrusion chains amid increased threat activity
CYBERSECURITY

ACR Stealer: Two observed intrusion chains amid increased threat activity

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. The post ACR Stealer: Two observed intrusion chains amid increased threat activity appeared first on Microsoft Security Blog.

1 MIN READ arrow_forward