Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Encrypted DNS still tells an eavesdropper where to look Encrypted DNS runs across much of the Internet. DNS over TLS, HTTPS, and QUIC keep the contents of… Continue reading Week in review: Fortibleed campaign’s impact on orgs, Cisco Unified CM flaw exploited

Product showcase: How to evaluate AI SOC platforms and where Prophet AI leads

The Agentic SOC market is loud. Dozens of vendors promise to take alert triage, investigation, and response off your analysts’ plates, but most claims have never been tested in production. The hard part is separating operational improvement from … Continue reading Product showcase: How to evaluate AI SOC platforms and where Prophet AI leads

23 ClawHub plugins squatting official scopes expose AI registry security gaps

Plugin registries for AI agents use npm-style scopes like @openclaw/ and @clawhub/ to signal who published a package. But on ClawHub, a registry whose plugins run with Claude, OpenClaw, and other agents, those official scopes weren’t reserved to … Continue reading 23 ClawHub plugins squatting official scopes expose AI registry security gaps

Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: A hardware neural network backdoor that hides in plain sight Deep learning systems on edge devices often rely on third-party-designed FPGAs and ASICs for … Continue reading Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack

How security teams are getting credential visibility into developer endpoints

As we noted in our earlier analysis, attackers already know secrets are on your developers’ machines, the only question is whether security teams do. The supply chain attack calendar of 2026 has been relentless. Megalodon backdoored 5,500 GitHub … Continue reading How security teams are getting credential visibility into developer endpoints

Navigating SEC, NIS2, and DORA incident disclosure timelines under pressure

In this Help Net Security video, Rick Goud, Global Field CTO at Kiteworks, discusses how to handle SEC, NIS2, and DORA disclosure timelines during a security incident. He opens with a 3.47 a.m. call: the team cannot confirm whether customer data left t… Continue reading Navigating SEC, NIS2, and DORA incident disclosure timelines under pressure

EU Cybersecurity Act 2.0: When good regulation goes bad

Over recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But … Continue reading EU Cybersecurity Act 2.0: When good regulation goes bad

The rise of machine identities and agentic AI: Securing trust in the next era of digital autonomy

In the latest episode of Identity Insider, I sat down with Chris Hughes, a cybersecurity expert who’s involved in OWASP’s work on non-human and machine identity security. Unsurprisingly, our discussion centered on the rapidly changing cyber… Continue reading The rise of machine identities and agentic AI: Securing trust in the next era of digital autonomy

How to use NIST and ISO frameworks to govern AI agents

Security leaders no longer need convincing that AI agents introduce risk. What’s missing is how to govern them once they move into production and begin operating autonomously across enterprise environments. AI agents already read sensitive documents, i… Continue reading How to use NIST and ISO frameworks to govern AI agents