Scareware ads keep running on Google’s transparency tool, even after they’re reported

A team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to Google doesn’t mea… Continue reading Scareware ads keep running on Google’s transparency tool, even after they’re reported

Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows file shares, an entire Active Directory domain, SharePoint, OneDrive, Teams c… Continue reading Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira

Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers

Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct ma… Continue reading Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers

What your vendor says about PQC tells you if they are ready

In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity… Continue reading What your vendor says about PQC tells you if they are ready

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical s… Continue reading What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

What 90 days and a small budget can buy in AI agent security

In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why harde… Continue reading What 90 days and a small budget can buy in AI agent security

AI will not fix a governance problem in your camera estate

Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody… Continue reading AI will not fix a governance problem in your camera estate

Production data in testing is still common, and Tricentis’ CISO wants it gone

In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-tea… Continue reading Production data in testing is still common, and Tricentis’ CISO wants it gone

AI supply chain risk is showing up in developer workflows first

In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and com… Continue reading AI supply chain risk is showing up in developer workflows first