July 2026 Patch Tuesday forecast: Is CVE tracking still practical?

I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers… Continue reading July 2026 Patch Tuesday forecast: Is CVE tracking still practical?

Turning software supply chain security into a daily habit

In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day … Continue reading Turning software supply chain security into a daily habit

How to implement a continuous offensive security testing program

The hard part was never finding the exposure. It was deciding what to do about it: whether to patch, mitigate, monitor, or accept, and banking that that decision would still hold tomorrow. A penetration test answers this question for the day it runs, t… Continue reading How to implement a continuous offensive security testing program

Your company already adopted AI and nobody is governing access

In this Help Net Security video, Antoine Berton, CTO at Elba Security, breaks down the AI attack surface. Your company already adopted AI, and every adoption creates access that nobody governs. A quick click on a Friday afternoon connects a free AI too… Continue reading Your company already adopted AI and nobody is governing access

How to prioritize AI agent security by business impact

Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application … Continue reading How to prioritize AI agent security by business impact

How to prioritize AI agent security by business impact

Your CEO calls about an AI agent security incident in finance. He wants to know whether money moved, whether financial data was exposed, who owned the agent and why it had this level of access. The agent was connected to a spend management application … Continue reading How to prioritize AI agent security by business impact

Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the security bill is coming due Companies keep bolting AI and LLM features onto their products, and the… Continue reading Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack

Geopolitical cyber threats are turning HR into a security front line

In this Help Net Security video, Roman Sannikov, Global Research Coordinator at iCOUNTER, explains why geopolitics belongs in every security team’s threat model. With open and simmering conflicts around the world, attacks can come from actors tha… Continue reading Geopolitical cyber threats are turning HR into a security front line

What a financial planner taught me about cybersecurity

When I spoke at a recent cybersecurity awareness event for financial planners and tax advisors, the audience really engaged with the subject. As happens at conferences the world over, people often come up to speakers to ask follow-up questions, or just… Continue reading What a financial planner taught me about cybersecurity

Getting boards to fund ERM means speaking their currency

In this Help Net Security video, Greg Young, VP Cybersecurity and Corporate Development at TrendAI, explains how to build Enterprise Risk Management that a board will pay for. Drawing on nearly four decades in cybersecurity, including time as a CISO an… Continue reading Getting boards to fund ERM means speaking their currency