Ransomware negotiation tactics have turned into a business process

In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations. Ross walks through the tactics groups use once an attack begins, from rese… Continue reading Ransomware negotiation tactics have turned into a business process→

Product showcase: Doppler secures secrets for humans, pipelines, and AI agents

Every engineering team has spent years trying to keep credentials out of source code. Then AI agents moved the problem. Coding agents review code, agents run workflows, and MCP servers broker access to databases, cloud providers, and internal APIs on a… Continue reading Product showcase: Doppler secures secrets for humans, pipelines, and AI agents→

September 2026 Patch Tuesday forecast: All we need is more time

The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs: 42 rated Critical, 355 r… Continue reading September 2026 Patch Tuesday forecast: All we need is more time→

A five-part inventory for your AI agent credentials

In this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI studios, connect them to enterprise tools, and give them accounts to do useful work… Continue reading A five-part inventory for your AI agent credentials→

Your threat feed is someone else’s database: What ingesting malware intel at scale takes

The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard pa… Continue reading Your threat feed is someone else’s database: What ingesting malware intel at scale takes→

NIS2 compliance: Fixing IAM and access control before the 2026 audit

The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from tran… Continue reading NIS2 compliance: Fixing IAM and access control before the 2026 audit→

The cybercrime supply chain has five stages, each with a price

In this Help Net Security video, Chris Nyhuis, CEO at Vigilant, explains why the picture of a lone ransomware attacker is about 15 years out of date. He walks through the cybercrime supply chain and the five businesses inside it: harvesters who run inf… Continue reading The cybercrime supply chain has five stages, each with a price→

New TCG guidance gives buyers a way to test PQC-ready TPM claims

The Trusted Computing Group has published requirements that spell out what a Trusted Platform Module has to do before anyone calls it quantum-safe. A TPM is the chip that holds a machine’s keys and records measurements of its firmware, so the pla… Continue reading New TCG guidance gives buyers a way to test PQC-ready TPM claims→