<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Help Net Security</title>
	<atom:link href="https://www.helpnetsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.helpnetsecurity.com/</link>
	<description>Daily information security news with a focus on enterprise security.</description>
	<lastBuildDate>Fri, 02 Oct 2026 12:47:00 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.6</generator>

<image>
	<url>https://img.helpnetsecurity.com/wp-content/uploads/2019/09/09093400/cropped-hns2-32x32.png</url>
	<title>Help Net Security</title>
	<link>https://www.helpnetsecurity.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>AI is giving attackers a head start, Microsoft warns</title>
		<link>https://www.helpnetsecurity.com/2026/10/02/ai-cybersecurity-threats-microsoft-report/</link>
		
		<dc:creator><![CDATA[Sinisa Markovic]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 12:47:00 +0000</pubDate>
				<category><![CDATA[Don't miss]]></category>
		<category><![CDATA[Hot stuff]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[survey]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386618</guid>

					<description><![CDATA[<p>Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft&#8217;s 2026 Digital Defense Report, covering July 2025 to June 2026, describes a near-term period in which attackers collect the benefits of AI first and defenders have to move quickly to close the gap. &#8220;AI is changing the physics of cybersecurity,&#8221; the company said. Bugs found faster than they get fixed Vulnerability discovery and weaponization once &#8230; <a href="https://www.helpnetsecurity.com/2026/10/02/ai-cybersecurity-threats-microsoft-report/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/02/ai-cybersecurity-threats-microsoft-report/">AI is giving attackers a head start, Microsoft warns</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Chinese spies impersonate White House, Anthropic figures to phish AI policy experts</title>
		<link>https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/</link>
		
		<dc:creator><![CDATA[Sinisa Markovic]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 10:21:55 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[cyber espionage]]></category>
		<category><![CDATA[government]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Proofpoint]]></category>
		<category><![CDATA[USA]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386581</guid>

					<description><![CDATA[<p>A China-aligned espionage group has been posing as a former White House official and a prominent economist to get into the cloud accounts of AI policy experts in the US, Proofpoint have found. The group, which the researchers track as TA419, ran several credential phishing campaigns in July 2026. “In July 2026, TA419 impersonated multiple individuals, including a former member of the White House Office of Science and Technology Policy leadership team, in credential phishing &#8230; <a href="https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/02/china-aligned-ta419-phishing-ai-policy-experts/">Chinese spies impersonate White House, Anthropic figures to phish AI policy experts</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)</title>
		<link>https://www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/</link>
		
		<dc:creator><![CDATA[Sinisa Markovic]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 08:50:59 +0000</pubDate>
				<category><![CDATA[Hot stuff]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[Fortinet]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386564</guid>

					<description><![CDATA[<p>Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available. About CVE-2026-104286 “An Improper Limitation of a Pathname to a Restricted Directory (&#8216;Path Traversal&#8217;) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker &#8230; <a href="https://www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/">Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Criminal recruiters want people on your payroll</title>
		<link>https://www.helpnetsecurity.com/2026/10/02/intel-471-insider-threat-recruitment-report/</link>
		
		<dc:creator><![CDATA[Anamarija Pogorelec]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 06:00:05 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[cybercriminals]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[insider threat]]></category>
		<category><![CDATA[Intel 471]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[security controls]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386436</guid>

					<description><![CDATA[<p>Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information lookups, account resets, transaction approvals and shipment changes can become services sold to criminal customers, according to Intel 471’s Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services report. A market for insider capabilities Cybercriminals sought employees at specific organizations, offered payments to brokers and referrers to find suitable personnel, &#8230; <a href="https://www.helpnetsecurity.com/2026/10/02/intel-471-insider-threat-recruitment-report/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/02/intel-471-insider-threat-recruitment-report/">Criminal recruiters want people on your payroll</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Android 17 makes it harder for spyware to cover its tracks</title>
		<link>https://www.helpnetsecurity.com/2026/10/02/android-17-advanced-protection-features/</link>
		
		<dc:creator><![CDATA[Anamarija Pogorelec]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 05:30:37 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[mobile security]]></category>
		<category><![CDATA[privacy]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386487</guid>

					<description><![CDATA[<p>When a journalist suspects their phone has been hacked, the first question is whether any trace of the attack is left. Google has added six features to Advanced Protection in Android 17, including one that keeps a copy of that evidence off the device. Existing users will receive a notification when the new capabilities become available on their devices. Forensic logging and data retention Intrusion Logging records security and network events, including app activity. Users &#8230; <a href="https://www.helpnetsecurity.com/2026/10/02/android-17-advanced-protection-features/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/02/android-17-advanced-protection-features/">Android 17 makes it harder for spyware to cover its tracks</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Botnets, adversarial attacks and data poisoning top leaders&#8217; AI threat list</title>
		<link>https://www.helpnetsecurity.com/2026/10/02/pwc-attacks-on-ai-systems/</link>
		
		<dc:creator><![CDATA[Sinisa Markovic]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 05:00:28 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[PwC]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[survey]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386354</guid>

					<description><![CDATA[<p>Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and technology leaders in 71 countries between May and July 2026. Half of the security and technology executives among them ranked such attacks in their top five preparedness gaps, ahead of every other threat on the list. More than half of the leaders asked about AI-enabled attacks put three &#8230; <a href="https://www.helpnetsecurity.com/2026/10/02/pwc-attacks-on-ai-systems/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/02/pwc-attacks-on-ai-systems/">Botnets, adversarial attacks and data poisoning top leaders&#8217; AI threat list</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>AI agents keep access to company data after their work is done</title>
		<link>https://www.helpnetsecurity.com/2026/10/02/delinea-ai-policy-adoption-enforcement-report/</link>
		
		<dc:creator><![CDATA[Anamarija Pogorelec]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 04:30:21 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[agentic AI]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[Delinea]]></category>
		<category><![CDATA[identity protection]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[report]]></category>
		<category><![CDATA[security controls]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386381</guid>

					<description><![CDATA[<p>IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap. “Written policy is only as good as your ability to enforce it at the moment an AI agent acts,” said Art Gilliland, CEO of Delinea. “Our research echoes what I hear from leaders constantly: they have the AI policies &#8230; <a href="https://www.helpnetsecurity.com/2026/10/02/delinea-ai-policy-adoption-enforcement-report/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/02/delinea-ai-policy-adoption-enforcement-report/">AI agents keep access to company data after their work is done</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>New infosec products of the week: October 2, 2026</title>
		<link>https://www.helpnetsecurity.com/2026/10/02/new-infosec-products-of-the-week-october-2-2026/</link>
		
		<dc:creator><![CDATA[Anamarija Pogorelec]]></dc:creator>
		<pubDate>Fri, 02 Oct 2026 04:00:35 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[BlackFog]]></category>
		<category><![CDATA[Thales]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386370</guid>

					<description><![CDATA[<p>Here’s a look at the most interesting products from the past week, featuring releases from BlackFog, Genea, Vega, and Thales. Vega II brings security-trained AI and lasting memory to the SOC Vega has introduced Vega II, its biggest platform release since emerging from stealth. The update brings frontier AI trained for security operations into the SOC, gives teams a lasting record of what they have learned, and removes the legacy SIEM and data pipeline barriers &#8230; <a href="https://www.helpnetsecurity.com/2026/10/02/new-infosec-products-of-the-week-october-2-2026/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/02/new-infosec-products-of-the-week-october-2-2026/">New infosec products of the week: October 2, 2026</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>16-year-old suspected leader of KillSec ransomware group arrested</title>
		<link>https://www.helpnetsecurity.com/2026/10/01/killsec-ransomware-16-year-old-main-operator-arrested/</link>
		
		<dc:creator><![CDATA[Sinisa Markovic]]></dc:creator>
		<pubDate>Thu, 01 Oct 2026 13:59:02 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Eurojust]]></category>
		<category><![CDATA[Europol]]></category>
		<category><![CDATA[law enforcement]]></category>
		<category><![CDATA[ransomware]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386537</guid>

					<description><![CDATA[<p>A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide. Seizure notice (Source: Eurojust) According to Eurojust, KillSec has been active since 2024. The group got into organizations&#8217; systems by exploiting poorly secured access, particularly access linked to cloud storage. “Once inside, the KillSec group stole data and copied it to their own infrastructure. They then threatened to make the stolen &#8230; <a href="https://www.helpnetsecurity.com/2026/10/01/killsec-ransomware-16-year-old-main-operator-arrested/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/01/killsec-ransomware-16-year-old-main-operator-arrested/">16-year-old suspected leader of KillSec ransomware group arrested</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval</title>
		<link>https://www.helpnetsecurity.com/2026/10/01/deepkeeps-ai-lens-flags-coding-agent-data-leaks-and-routes-destructive-commands-for-approval/</link>
		
		<dc:creator><![CDATA[Industry News]]></dc:creator>
		<pubDate>Thu, 01 Oct 2026 13:57:07 +0000</pubDate>
				<category><![CDATA[Industry news]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=386546</guid>

					<description><![CDATA[<p>DeepKeep has announced AI Lens for Developers, a new extension to the company&#8217;s AI usage control and runtime protection modules to secure software developers and their coding agents that can write, modify, and execute code on their behalf. The capability gives security teams policy enforcement, audit visibility, and runtime security over coding agents such as Cursor and Claude Code, closing a critical gap most security programs have ever had to cover before. 90% of developers &#8230; <a href="https://www.helpnetsecurity.com/2026/10/01/deepkeeps-ai-lens-flags-coding-agent-data-leaks-and-routes-destructive-commands-for-approval/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/10/01/deepkeeps-ai-lens-flags-coding-agent-data-leaks-and-routes-destructive-commands-for-approval/">DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
	</channel>
</rss>
