September 2026 Patch Tuesday forecast: All we need is more time

The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs: 42 rated Critical, 355 r… Continue reading September 2026 Patch Tuesday forecast: All we need is more time

A five-part inventory for your AI agent credentials

In this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI studios, connect them to enterprise tools, and give them accounts to do useful work… Continue reading A five-part inventory for your AI agent credentials

Your threat feed is someone else’s database: What ingesting malware intel at scale takes

The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard pa… Continue reading Your threat feed is someone else’s database: What ingesting malware intel at scale takes

NIS2 compliance: Fixing IAM and access control before the 2026 audit

The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from tran… Continue reading NIS2 compliance: Fixing IAM and access control before the 2026 audit

The cybercrime supply chain has five stages, each with a price

In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five businesses inside it: harvesters who run inf… Continue reading The cybercrime supply chain has five stages, each with a price

New TCG guidance gives buyers a way to test PQC-ready TPM claims

The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the pla… Continue reading New TCG guidance gives buyers a way to test PQC-ready TPM claims

Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Windows 11’s strongest security defenses can be bypassed without a screwdriver Researchers from the University of Birmingham and Durham University have fo… Continue reading Week in review: Records allegedly stolen from Azure tenants, Medusa ransomware hits 500+ orgs

A hollowed out data layer is making CISOs fly blind into AI attacks

The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have not yet reckoned with is that the AI defenders they are about to deploy will in… Continue reading A hollowed out data layer is making CISOs fly blind into AI attacks