Aggregator
CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities Catalog
+100 к уязвимости: опасный троян охотится на геймеров через Telegram и Hugging Face
AI threats leave SecOps teams burned out and exposed
Security teams are leaning hard into AI, and fast. A recent survey of 500 senior cybersecurity pros at big U.S. companies found that 86% have ramped up their AI use in the past year. The main reason? They’re trying to keep up with a surge in AI-powered attacks. But even as AI tools help with tasks like threat detection and data analysis, the pressure on security teams is getting worse. Nearly 70% of respondents say … More →
The post AI threats leave SecOps teams burned out and exposed appeared first on Help Net Security.
Black Kite unveils AI-powered cyber assessments
Black Kite announced AI-powered cyber assessments, an automated solution for streamlining third-party cyber risk assessments. With its automation-led approach, Black Kite is redefining how enterprises assess risk across their vendor ecosystems to make informed decisions and bring cyber resilience to their supply chain. “Managing cyber ecosystem risks is complex, and all too often, enterprises are further challenged by cyber assessment processes that do not work in today’s environment,” said Chuck Schauber, CPO, Black Kite. “In … More →
The post Black Kite unveils AI-powered cyber assessments appeared first on Help Net Security.
CVE-2025-4577 | Smash Balloon Custom Facebook Feed Plugin up to 4.3.1 on WordPress Attribute data-color cross site scripting (EUVD-2025-17658)
CVE-2025-2918 | Ultimate Blocks Plugin up to 3.3.3 on WordPress Widget cross site scripting (EUVD-2025-17659)
CVE-2025-4774 | Premium Addons for Elementor Plugin up to 4.11.8 on WordPress Countdown Widget cross site scripting (EUVD-2025-17660)
84 500 уязвимых инстансов — хакеры уже знают, куда бить, вопрос лишь во времени
CVE-2025-49004 | Caido up to 0.47.x authentication spoofing (GHSA-jmxf-xw2r-vjrg)
CVE-2025-0037 | AMD Platform Loader and Manager PLM Runtime Service input validation (EUVD-2025-17611)
CVE-2025-42990 | SAP UI5 applications up to UI_700 200 cross site scripting (EUVD-2025-17598)
CVE-2025-42989 | SAP NetWeaver Application Server for ABAP 7.89/7.93/9.14/9.15 RFC Inbound authorization (EUVD-2025-17599)
Securing agentic AI systems before they go rogue
In this Help Net Security video, Eoin Wickens, Director of Threat Intelligence at HiddenLayer, explores the security risks posed by agentic AI. He breaks down how agentic AI functions, its potential to revolutionize business operations, and the vulnerabilities it introduces, such as prompt injection and excessive system privileges. Wickens offers real-world attack examples, explains why traditional security practices need rethinking, and outlines practical steps to mitigate risk. Learn why monitoring, logging, and privilege scoping are … More →
The post Securing agentic AI systems before they go rogue appeared first on Help Net Security.