Help Net Security Daily information security news with a focus on enterprise security.
- Week in review: Accenture data breach, great open-source cybersecurity toolsby Help Net Security on July 12, 2026 at 8:00 am
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security meet Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority (CA) to purchase a Mark Certificate, and this means having to … More → The post Week in review: Accenture data breach, great open-source cybersecurity tools appeared first on Help Net Security.
- Incode brings on-device processing to age estimation for privacy-focused verificationby Industry News on July 10, 2026 at 12:24 pm
Incode has launched On-Device Age Estimation, an age verification capability that performs age estimation and liveness detection directly on the user’s device, without transmitting facial data off the device. The company’s age estimation models are now available to run entirely on-device. The solution combines on-device age estimation with deepfake and spoofing detection. More than 30 age assurance laws are now in force worldwide. In the UK, the Online Safety Act’s “highly effective” age check requirement … More → The post Incode brings on-device processing to age estimation for privacy-focused verification appeared first on Help Net Security.
- July 2026 Patch Tuesday forecast: Is CVE tracking still practical?by Help Net Security on July 10, 2026 at 7:30 am
I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications like Office and SharePoint Server as well as the host of development tools and libraries like Visual Studio and .NET. Will the … More → The post July 2026 Patch Tuesday forecast: Is CVE tracking still practical? appeared first on Help Net Security.
- Workato expands Agent Studio with Headless API, AI guardrailsby Industry News on July 10, 2026 at 7:02 am
Workato has announced two new capabilities for Agent Studio: Headless API and Agent Guardrails. Headless API lets Genies, Workato’s AI agents built on Agent Studio, be embedded into any business application surface, on web, mobile, or inside another agent’s own environment. Agent Guardrails are configurable to the business and ensure that wherever a Genie is embedded, it enforces company data privacy policies, ties every action to a real identity, and remains secure, auditable, and compliant … More → The post Workato expands Agent Studio with Headless API, AI guardrails appeared first on Help Net Security.
- The open source library holding up your stack might have one maintainerby Sinisa Markovic on July 10, 2026 at 7:00 am
Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same label. A new paper argues that the single label hides differences large enough to change how each piece behaves once it lands … More → The post The open source library holding up your stack might have one maintainer appeared first on Help Net Security.
- Most data brokers won’t tell you what happened to your deletion requestby Sinisa Markovic on July 10, 2026 at 6:30 am
Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sharing them. A team at UC Irvine decided to find out what happens when someone sends those requests to the whole California registry. The answer gives consumers … More → The post Most data brokers won’t tell you what happened to your deletion request appeared first on Help Net Security.
- Microsoft is rewriting Windows patch guidance because of AIby Anamarija Pogorelec on July 10, 2026 at 6:00 am
Microsoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess how quickly they roll out monthly security updates, particularly on devices where shorter deployment windows can be implemented without disrupting business operations. “If you’re not delivering critical quality updates with security fixes until a couple of weeks after … More → The post Microsoft is rewriting Windows patch guidance because of AI appeared first on Help Net Security.
- Turning software supply chain security into a daily habitby Help Net Security on July 10, 2026 at 5:30 am
In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day for vulnerability triage, vendor access reviews, identity monitoring, and incident response. Drawing on Group-IB’s High-Tech Crime Trend Report 2026, she shows how supply chain attacks now link phishing, ransomware, and data breaches through inherited trust. … More → The post Turning software supply chain security into a daily habit appeared first on Help Net Security.
- AWS gives its ERP agent deny-by-default rules and a separate identityby Sinisa Markovic on July 10, 2026 at 5:00 am
Accounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across blocked invoices, purchase order approval holds, month-end close, and intercompany reconciliations in almost every industry. Built-in ERP automation, including SAP’s three-way match, still leaves plenty of these exceptions for people to sort out. AWS has released a … More → The post AWS gives its ERP agent deny-by-default rules and a separate identity appeared first on Help Net Security.
- Only 28% of financial workforce MFA is phishing-resistantby Anamarija Pogorelec on July 10, 2026 at 4:30 am
Passwords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant MFA (Source: Secret Double Octopus) Workforce authentication trends Banks and financial organizations use a mix of authentication methods, combining phishing-resistant technologies with methods that remain vulnerable to phishing attacks. Password plus OTP remains more common among organizations with up to … More → The post Only 28% of financial workforce MFA is phishing-resistant appeared first on Help Net Security.






