A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a g… Continue reading A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

Post-quantum migration gets harder when every user holds a key

In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum k… Continue reading Post-quantum migration gets harder when every user holds a key

An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81… Continue reading An AI tool found 84 flaws in 5G network software and 23 of them still have no fix

What the first year of EU AI Act transparency enforcement could look like

In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an A… Continue reading What the first year of EU AI Act transparency enforcement could look like

ShieldFont fights AI scraping by handing crawlers the wrong words

Isaque Seneda and Gabriel Abrucio built a web font that draws one set of words on screen and leaves a different set in the page’s source code. A person reading in a browser sees the writing as written. A scraper pulling the HTML gets different wo… Continue reading ShieldFont fights AI scraping by handing crawlers the wrong words

Three in four AI-generated vulnerability patches leave something broken

Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time in four, it is a fix. Researchers at 1Pas… Continue reading Three in four AI-generated vulnerability patches leave something broken

Browser security is where software, data, and AI meet

In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where appli… Continue reading Browser security is where software, data, and AI meet

Browser security is where software, data, and AI meet

In this interview with Help Net Security, Rui Ribeiro, CEO of Jscrambler, explains why the browser has become a security problem organizations do not control. Companies do not own the device, the extensions, or the network path, yet that is where appli… Continue reading Browser security is where software, data, and AI meet

Cloudflare OS goes open source with a record of everything its agents read

Cloudflare open sourced Cloudflare OS, the agent platform whose first version its own employees have used since May. Every resource an agent reads gets recorded, the record follows whatever the agent produces, and when a second person opens that output… Continue reading Cloudflare OS goes open source with a record of everything its agents read