<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Help Net Security</title>
	<atom:link href="https://www.helpnetsecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.helpnetsecurity.com/</link>
	<description>Daily information security news with a focus on enterprise security.</description>
	<lastBuildDate>Fri, 31 Jul 2026 12:55:46 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.5</generator>

<image>
	<url>https://img.helpnetsecurity.com/wp-content/uploads/2019/09/09093400/cropped-hns2-32x32.png</url>
	<title>Help Net Security</title>
	<link>https://www.helpnetsecurity.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released</title>
		<link>https://www.helpnetsecurity.com/2026/08/02/week-in-review-claude-breached-three-companies-during-tests-ad-cs-domain-takeover-poc-released/</link>
		
		<dc:creator><![CDATA[Help Net Security]]></dc:creator>
		<pubDate>Sun, 02 Aug 2026 08:00:17 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Week in review]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=379331</guid>

					<description><![CDATA[<p>Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To reduce the risk, Luke Hinds and Stephen Parkinson co-founded nolabs and released Nono, an open-source &#8230; <a href="https://www.helpnetsecurity.com/2026/08/02/week-in-review-claude-breached-three-companies-during-tests-ad-cs-domain-takeover-poc-released/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/08/02/week-in-review-claude-breached-three-companies-during-tests-ad-cs-domain-takeover-poc-released/">Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Cybercrime goes subscription: AI, malware and infrastructure on demand</title>
		<link>https://www.helpnetsecurity.com/2026/07/31/infoblox-domain-abuse-campaigns-report/</link>
		
		<dc:creator><![CDATA[Anamarija Pogorelec]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 13:00:02 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[BEC scams]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[Infoblox]]></category>
		<category><![CDATA[report]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=379602</guid>

					<description><![CDATA[<p>Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report. “Cybercrime is becoming more efficient, automated, and harder to stop. Driven by economics and fueled in part by frontier AI, it &#8230; <a href="https://www.helpnetsecurity.com/2026/07/31/infoblox-domain-abuse-campaigns-report/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/31/infoblox-domain-abuse-campaigns-report/">Cybercrime goes subscription: AI, malware and infrastructure on demand</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Criminals used AI and children&#8217;s coding software to build a multimillion-dollar ad fraud empire</title>
		<link>https://www.helpnetsecurity.com/2026/07/31/fuyao-ad-fraud-botnet-android-tv-boxes/</link>
		
		<dc:creator><![CDATA[Sinisa Markovic]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 12:19:31 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[BitSight]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[fraud]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=380195</guid>

					<description><![CDATA[<p>A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device identity spoofing, AI-generated websites, and residential proxy services to generate advertising revenue without device owners&#8217; knowledge. “Fuyao’s business model operates under its ability to always identify where an ad lives on a website, spoof the device &#8230; <a href="https://www.helpnetsecurity.com/2026/07/31/fuyao-ad-fraud-botnet-android-tv-boxes/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/31/fuyao-ad-fraud-botnet-android-tv-boxes/">Criminals used AI and children&#8217;s coding software to build a multimillion-dollar ad fraud empire</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Anthropic&#8217;s Claude breached three companies during security tests</title>
		<link>https://www.helpnetsecurity.com/2026/07/31/anthropic-claude-cybersecurity-incidents/</link>
		
		<dc:creator><![CDATA[Sinisa Markovic]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 09:41:35 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[agentic AI]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[Claude Code]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[LLMs]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=380160</guid>

					<description><![CDATA[<p>Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI&#8217;s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting a previously unknown vulnerability and reached the systems of Hugging Face, the open-source machine learning platform. &#8220;After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which &#8230; <a href="https://www.helpnetsecurity.com/2026/07/31/anthropic-claude-cybersecurity-incidents/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/31/anthropic-claude-cybersecurity-incidents/">Anthropic&#8217;s Claude breached three companies during security tests</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Traefik Labs introduces Distro Zero secure runtime for API and AI gateways</title>
		<link>https://www.helpnetsecurity.com/2026/07/31/traefik-labs-distro-zero-image/</link>
		
		<dc:creator><![CDATA[Industry News]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 08:18:57 +0000</pubDate>
				<category><![CDATA[Industry news]]></category>
		<category><![CDATA[Traefik Labs]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=380155</guid>

					<description><![CDATA[<p>Traefik Labs has introduced the Distro Zero image, a hardened, vendor-supported secure runtime delivered as Traefik Hub in proxy mode. It gives platform and security teams a container whose entire executable content is a single memory-safe binary, with validated cryptography built inside it and every advanced capability, from API gateway to AI and MCP gateway to full API management, unlocked by license on that same binary. No binary swap, no migration, no re-validation as needs &#8230; <a href="https://www.helpnetsecurity.com/2026/07/31/traefik-labs-distro-zero-image/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/31/traefik-labs-distro-zero-image/">Traefik Labs introduces Distro Zero secure runtime for API and AI gateways</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Horizon3.ai expands NodeZero with automated web application attack path testing</title>
		<link>https://www.helpnetsecurity.com/2026/07/31/horizon3-ai-nodezero-webapp-pentesting/</link>
		
		<dc:creator><![CDATA[Industry News]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 08:06:59 +0000</pubDate>
				<category><![CDATA[Industry news]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[Black Hat USA 2026]]></category>
		<category><![CDATA[Horizon3.ai]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=380150</guid>

					<description><![CDATA[<p>Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure. Web applications have never been more exposed or more critical to secure. The rapid deployment of “vibe-coded” applications built with generative AI has introduced a wave of systems riddled with exploitable flaws. At the same time, threat actors are &#8230; <a href="https://www.helpnetsecurity.com/2026/07/31/horizon3-ai-nodezero-webapp-pentesting/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/31/horizon3-ai-nodezero-webapp-pentesting/">Horizon3.ai expands NodeZero with automated web application attack path testing</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>AttackIQ targets CTEM execution with AVA Agentic OS</title>
		<link>https://www.helpnetsecurity.com/2026/07/31/attackiq-ava-agentic-os/</link>
		
		<dc:creator><![CDATA[Industry News]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 07:56:38 +0000</pubDate>
				<category><![CDATA[Industry news]]></category>
		<category><![CDATA[AttackIQ]]></category>
		<category><![CDATA[Black Hat]]></category>
		<category><![CDATA[Black Hat USA 2026]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=380146</guid>

					<description><![CDATA[<p>AttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management. CTEM has emerged as the strategic framework for managing cyber risk, yet many organizations continue to struggle to operationalize CTEM across fragmented security technologies, disconnected workflows, and manual processes. Security teams have invested heavily in tools that identify risk, but they lack an intelligent operational layer that continuously transforms intelligence into action. AVA Agentic OS fills that gap &#8230; <a href="https://www.helpnetsecurity.com/2026/07/31/attackiq-ava-agentic-os/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/31/attackiq-ava-agentic-os/">AttackIQ targets CTEM execution with AVA Agentic OS</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Resecurity expands threat intelligence integration ecosystem with IBM QRadar</title>
		<link>https://www.helpnetsecurity.com/2026/07/31/resecurity-ibm-qradar/</link>
		
		<dc:creator><![CDATA[Industry News]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 07:32:38 +0000</pubDate>
				<category><![CDATA[Industry news]]></category>
		<category><![CDATA[IBM]]></category>
		<category><![CDATA[Resecurity]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=380140</guid>

					<description><![CDATA[<p>Resecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM) platform used by the leading Fortune 100 corporations worldwide. The plugin is available for activation via IBM Application Exchange. The integration leverages open standards STIX and TAXII (including version 2.1) to ingest, normalize, and correlate indicators of compromise (IOCs) providing flexible configuration of data ingestion and processing workflows. Security teams can configure log sources &#8230; <a href="https://www.helpnetsecurity.com/2026/07/31/resecurity-ibm-qradar/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/31/resecurity-ibm-qradar/">Resecurity expands threat intelligence integration ecosystem with IBM QRadar</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Aviation cyber risk sits on the ground, the blindness sits in the air</title>
		<link>https://www.helpnetsecurity.com/2026/07/31/eliran-almong-cyviation-aviation-cyber-risk/</link>
		
		<dc:creator><![CDATA[Mirko Zorz]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 05:30:40 +0000</pubDate>
				<category><![CDATA[Don't miss]]></category>
		<category><![CDATA[Features]]></category>
		<category><![CDATA[Hot stuff]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[boardroom]]></category>
		<category><![CDATA[CXO]]></category>
		<category><![CDATA[cyber risk]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[opinion]]></category>
		<category><![CDATA[risk management]]></category>
		<category><![CDATA[strategy]]></category>
		<category><![CDATA[tips]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=379714</guid>

					<description><![CDATA[<p>In this interview with Help Net Security, Eliran Almog, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where drone command channels accept unsigned messages. He argues the Electronic Flight Bag matters less than the data loading chain behind it, makes the case for digital twins, and &#8230; <a href="https://www.helpnetsecurity.com/2026/07/31/eliran-almong-cyviation-aviation-cyber-risk/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/31/eliran-almong-cyviation-aviation-cyber-risk/">Aviation cyber risk sits on the ground, the blindness sits in the air</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>Companies push AI, sysadmins keep it on a short leash</title>
		<link>https://www.helpnetsecurity.com/2026/07/31/action1-sysadmins-ai-expectations-report/</link>
		
		<dc:creator><![CDATA[Anamarija Pogorelec]]></dc:creator>
		<pubDate>Fri, 31 Jul 2026 05:00:26 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Action1]]></category>
		<category><![CDATA[AI]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[report]]></category>
		<guid isPermaLink="false">https://www.helpnetsecurity.com/?p=379923</guid>

					<description><![CDATA[<p>In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1&#8217;s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic. The largest shortfalls appeared in high-impact operational and security functions, where AI needs to understand business context, system dependencies, risk, and the consequences of an incorrect action. Areas with the widest expectation-reality gaps (Source: Action1) Sysadmins view patch management and &#8230; <a href="https://www.helpnetsecurity.com/2026/07/31/action1-sysadmins-ai-expectations-report/" rel="nofollow">More <span class="meta-nav">&#8594;</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/31/action1-sysadmins-ai-expectations-report/">Companies push AI, sysadmins keep it on a short leash</a> appeared first on <a href="https://www.helpnetsecurity.com">Help Net Security</a>.</p>
]]></description>
		
		
		
			</item>
	</channel>
</rss>
