News Archives – Help Net Security Daily information security news with a focus on enterprise security.
- Week in review: Accenture data breach, great open-source cybersecurity toolsby Help Net Security on July 12, 2026 at 8:00 am
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security meet Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up DMARC and BIMI, then use a trusted Certificate Authority (CA) to purchase a Mark Certificate, and this means having to … More → The post Week in review: Accenture data breach, great open-source cybersecurity tools appeared first on Help Net Security.
- July 2026 Patch Tuesday forecast: Is CVE tracking still practical?by Help Net Security on July 10, 2026 at 7:30 am
I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications like Office and SharePoint Server as well as the host of development tools and libraries like Visual Studio and .NET. Will the … More → The post July 2026 Patch Tuesday forecast: Is CVE tracking still practical? appeared first on Help Net Security.
- The open source library holding up your stack might have one maintainerby Sinisa Markovic on July 10, 2026 at 7:00 am
Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same label. A new paper argues that the single label hides differences large enough to change how each piece behaves once it lands … More → The post The open source library holding up your stack might have one maintainer appeared first on Help Net Security.
- Most data brokers won’t tell you what happened to your deletion requestby Sinisa Markovic on July 10, 2026 at 6:30 am
Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sharing them. A team at UC Irvine decided to find out what happens when someone sends those requests to the whole California registry. The answer gives consumers … More → The post Most data brokers won’t tell you what happened to your deletion request appeared first on Help Net Security.
- Microsoft is rewriting Windows patch guidance because of AIby Anamarija Pogorelec on July 10, 2026 at 6:00 am
Microsoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess how quickly they roll out monthly security updates, particularly on devices where shorter deployment windows can be implemented without disrupting business operations. “If you’re not delivering critical quality updates with security fixes until a couple of weeks after … More → The post Microsoft is rewriting Windows patch guidance because of AI appeared first on Help Net Security.
- Turning software supply chain security into a daily habitby Help Net Security on July 10, 2026 at 5:30 am
In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day for vulnerability triage, vendor access reviews, identity monitoring, and incident response. Drawing on Group-IB’s High-Tech Crime Trend Report 2026, she shows how supply chain attacks now link phishing, ransomware, and data breaches through inherited trust. … More → The post Turning software supply chain security into a daily habit appeared first on Help Net Security.
- AWS gives its ERP agent deny-by-default rules and a separate identityby Sinisa Markovic on July 10, 2026 at 5:00 am
Accounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across blocked invoices, purchase order approval holds, month-end close, and intercompany reconciliations in almost every industry. Built-in ERP automation, including SAP’s three-way match, still leaves plenty of these exceptions for people to sort out. AWS has released a … More → The post AWS gives its ERP agent deny-by-default rules and a separate identity appeared first on Help Net Security.
- Only 28% of financial workforce MFA is phishing-resistantby Anamarija Pogorelec on July 10, 2026 at 4:30 am
Passwords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant MFA (Source: Secret Double Octopus) Workforce authentication trends Banks and financial organizations use a mix of authentication methods, combining phishing-resistant technologies with methods that remain vulnerable to phishing attacks. Password plus OTP remains more common among organizations with up to … More → The post Only 28% of financial workforce MFA is phishing-resistant appeared first on Help Net Security.
- New infosec products of the week: July 10, 2026by Anamarija Pogorelec on July 10, 2026 at 4:00 am
Here’s a look at the most interesting products from the past week, featuring releases from Attestiv, Automox, Codenotary, and First Recon AI. Codenotary launches AI security platform that learns from AI agent behavior Codenotary has announced AgentMon 3, the latest generation of its enterprise AI security platform, introducing adaptive runtime security policies. These continuously evolve as AI agents operate across an organization by learning from customer-specific workflows, observed behavioral patterns, and threats. Automox MCP Server … More → The post New infosec products of the week: July 10, 2026 appeared first on Help Net Security.
- Extortion crew hijacks Microsoft 365 accounts via fake passkey setupby Zeljka Zorz on July 9, 2026 at 2:22 pm
The Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack starts with a vishing call to an employee. The caller poses as IT and says it’s time to set up a passkey. Everything after that is theater, built to keep the victim occupied while the attacker finalizes everything. The attackers instruct the target to visit a subdomain that … More → The post Extortion crew hijacks Microsoft 365 accounts via fake passkey setup appeared first on Help Net Security.






