Features – Help Net Security

Features Archives – Help Net Security Daily information security news with a focus on enterprise security.

  • What your vendor says about PQC tells you if they are ready
    by Mirko Zorz on September 1, 2026 at 4:30 am

    In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity mappings, billing records and call metadata, and which becomes worthless within hours. It walks through the order of work, starting with a crypto inventory and hybrid key exchange on TLS interfaces, then IPsec links. It also names the … More → The post What your vendor says about PQC tells you if they are ready appeared first on Help Net Security.

  • What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree
    by Mirko Zorz on August 31, 2026 at 6:00 am

    In this Help Net Security interview, Dr. Joye Purser, Global Field CISO at Cohesity, explains how to rank vulnerabilities when KEV, EPSS, and CVSS point in different directions. Active exploitation comes first, then exploit likelihood, then technical severity, with adjustments for asset exposure, business criticality, and compensating controls. The interview sets a 24 to 72 hour remediation target for exploited internet-facing systems and covers what an organization gives up to meet it, the hidden failure … More → The post What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree appeared first on Help Net Security.

  • What 90 days and a small budget can buy in AI agent security
    by Mirko Zorz on August 28, 2026 at 5:30 am

    In this interview with Help Net Security, Prasad Tharippala, Field CISO at Versa, explains what organizations miss when they run open-weight models in house. He covers the hidden costs of GPU infrastructure, licensing review and staffing, and why hardening and incident response become the buyer’s job. He walks through red-teaming AI agents, what counts as a failing result, and the five questions buyers should ask agent platforms. For teams with 90 days and little budget, … More → The post What 90 days and a small budget can buy in AI agent security appeared first on Help Net Security.

  • AI will not fix a governance problem in your camera estate
    by Mirko Zorz on August 27, 2026 at 5:30 am

    Camera systems often outlive the companies that install them. In this Help Net Security interview, Rob Janssens, EMEA Cyber Security Director at Hikvision Europe, discusses what happens when the integrator is gone, the documentation is lost, and nobody holds the admin credentials. He explains why products should let customers recover control on their own, and how secure-by-default settings reduce the damage of predictable installation mistakes. He also weighs source code escrow, country-of-origin rules, and what … More → The post AI will not fix a governance problem in your camera estate appeared first on Help Net Security.

  • Production data in testing is still common, and Tricentis’ CISO wants it gone
    by Mirko Zorz on August 26, 2026 at 5:30 am

    In this Help Net Security interview, Erika Dean, CISO at Tricentis, talks about keeping production data out of test environments and why she thinks the alternatives are good enough now. She explains how her team caught a prompt injection gap in red-teaming and held a release for a week until it was fixed. Dean describes what gets an AI vendor rejected, mostly vague answers about where data lives and how long it is kept. She … More → The post Production data in testing is still common, and Tricentis’ CISO wants it gone appeared first on Help Net Security.

  • AI supply chain risk is showing up in developer workflows first
    by Mirko Zorz on August 25, 2026 at 6:00 am

    In this Help Net Security interview, Dr. Jaushin Lee, CEO of Zentera Systems, discusses where AI supply chain risk shows up. He says most incidents still hit developer workflows and open-source package repositories, while poisoned model weights and compromised MCP servers stay mostly in research demos. He explains why segmentation buys more risk reduction per dollar than tooling, where self-hosting a model falls short, and which semiconductor isolation practices software teams should copy. He also … More → The post AI supply chain risk is showing up in developer workflows first appeared first on Help Net Security.

  • Post-quantum migration gets harder when every user holds a key
    by Mirko Zorz on August 12, 2026 at 6:00 am

    In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break old size assumptions in IPsec, SSH, TLS and libp2p, why migrating user keys makes blockchains hard to upgrade, and what a silent quantum break would look like from outside. He also gives the argument for funding … More → The post Post-quantum migration gets harder when every user holds a key appeared first on Help Net Security.

  • An AI tool found 84 flaws in 5G network software and 23 of them still have no fix
    by Mirko Zorz on August 11, 2026 at 5:30 am

    Researchers at Nanyang Technological University turned a set of AI agents loose on the software that runs 4G and 5G phone networks, and the agents came back with 84 security flaws nobody had reported before. Developers have confirmed 83 of them, and 81 now carry CVE numbers. The most serious one lets an attacker take over a subscriber’s data session, so the network delivers that subscriber’s traffic to the attacker instead of to the internet. … More → The post An AI tool found 84 flaws in 5G network software and 23 of them still have no fix appeared first on Help Net Security.

  • What the first year of EU AI Act transparency enforcement could look like
    by Mirko Zorz on August 7, 2026 at 5:30 am

    In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large fines, when an AI agent working through a ticket queue counts as interacting with a person, and how security teams should handle simulated phishing that uses cloned voices. He also weighs where the first enforcement … More → The post What the first year of EU AI Act transparency enforcement could look like appeared first on Help Net Security.

  • ShieldFont fights AI scraping by handing crawlers the wrong words
    by Mirko Zorz on August 7, 2026 at 4:30 am

    Isaque Seneda and Gabriel Abrucio built a web font that draws one set of words on screen and leaves a different set in the page’s source code. A person reading in a browser sees the writing as written. A scraper pulling the HTML gets different words in the same grammar, at the same URL, off the same bytes. ShieldFont started in October 2025 with support from the type foundry Playtype. The site that deploys it … More → The post ShieldFont fights AI scraping by handing crawlers the wrong words appeared first on Help Net Security.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.