Skip to content

company

Help Net Security

Help Net Security is an online trade publication covering cybersecurity news, research, product releases, and expert commentary for IT security professionals.

Known aliases

  • HelpNetSecurity
  • helpnetsecurity.com

Relationships

No evidence-backed relationships are recorded.

Current stories

security2 publishers

Sophos starts selling an agentic AI service that ranks and prices security fixes for boards

Sophos made CISO Advantage generally available, an agentic AI service that turns a security assessment into a ranked, costed fix list for leadership to fund. The pitch puts a vendor-ranked spending plan in front of boards, either directly or through MSPs that already act as a customer's stand-in security chief.

Reality

Evidence30
Adoption10
Hype gap+45
Incentives85
Confidence65
security1 publisher

EU's Cyber Resilience Act puts Helm chart and Kubernetes operator vendors on a 24-hour exploit clock

EU Cyber Resilience Act rules have required 24-hour ENISA warnings on exploited flaws in commercial container images since Sept. 11, 2026. Vendors of supported Kubernetes operators and Helm charts are on the same clock, well before the rest of the law is enforced in December 2027.

Reality

Evidence50
Adoption
Insufficient
Hype gap+10
Incentives
Insufficient
Confidence55

Earlier coverage

  1. Rabbit's OS3 hands a cloud chat window direct control of five endpoints per account

    Security · September 22, 2026 · 1 publisher

  2. Agentic deployments drive European AI spending toward $470 billion by 2030, IDC forecasts

    Security · September 21, 2026 · 1 publisher

  3. FBI ties $1.6 billion in losses to police and government impersonation scams over 19 months

    Security · September 21, 2026 · 1 publisher

  4. Keyword filtering caught one in ten malicious intents on a 1,100-intent 6G benchmark

    Security · September 20, 2026 · 1 publisher

  5. Sapio survey ties 84 percent of enterprise AI compliance incidents to process design

    Security · September 20, 2026 · 1 publisher

  6. Fewer than three in ten of 319 WordPress professionals have a breach recovery plan

    Security · September 17, 2026 · 1 publisher

  7. meshIQ's Gourab Basu puts the agent control boundary inside the execution path

    Security · September 17, 2026 · 1 publisher

  8. Gremlin reports clearing nine times as many vulnerabilities with the same staff

    Security · September 17, 2026 · 1 publisher

  9. Ukrainian investigators say a Jetson Orin ran the targeting on the drone that killed three

    Security · September 16, 2026 · 1 publisher

  10. Nozomi Compass puts OT change approvals on the asset feed that powers Vantage

    Security · September 16, 2026 · 1 publisher

  11. Open-source DeepZero hands an LLM the signed Windows drivers missing from loldrivers.io

    Security · September 15, 2026 · 1 publisher

  12. Stolen OAuth tokens opened Gmail and Drive in both the Vercel and Composio breaches

    Security · September 15, 2026 · 1 publisher

  13. Nearly half of surveyed organizations had an AI agent take an unapproved action in the past year

    Security · September 15, 2026 · 1 publisher

  14. Shrinking public TLS certificates to 47 days turns a 1,000-certificate estate into 21 renewals a day

    Security · September 13, 2026 · 1 publisher

  15. An attacker's Markdown playbooks drove a six-hour credential harvest from inside the victim's cloud

    Build · September 12, 2026 · 1 publisher

  16. Arctic Wolf's incident response lead wants the ransom ceiling signed before the intrusion

    Security · September 11, 2026 · 1 publisher

  17. AI governance lands on 79% of CISOs without a matching increase in resources

    Security · September 9, 2026 · 1 publisher

  18. Fourteen percent of attack actions raised an alert across Picus's 338 million simulations

    Security · September 9, 2026 · 1 publisher

  19. Gartner: without structured evaluation, only about one in five AI SOC pilots seen achieving measurable gains by 2028

    Security · September 9, 2026 · 1 publisher

  20. BleachBit 6.0.4 repairs a Windows file shredder that skipped scattered clusters

    Security · September 9, 2026 · 1 publisher

  21. Teams will hide external-sender QR codes behind a user click from October 2026

    Security · September 4, 2026 · 1 publisher

  22. Consuming a malware feed at GitHub's scale bills out in rip-outs and credential rotation

    Security · September 3, 2026 · 1 publisher

  23. AI merger claims fall into the gap between tail and go-forward D&O policies

    Security · September 3, 2026 · 1 publisher

  24. National Life Group's CISO says AI-written exploits now outrun human patch cycles

    Security · September 2, 2026 · 1 publisher

  25. Thousands of credentials survived five years of pentests inside Jira ticket comments

    Security · September 1, 2026 · 1 publisher

  26. Gemini overruled a 0.006-second script that had already handed it the right answer

    Security · September 1, 2026 · 1 publisher

  27. October moves NIS2 from transposition into enforcement across the EU

    Security · August 31, 2026 · 1 publisher

  28. Ask your PQC vendor about crypto-agility. Watch which ones plead for stable standards instead.

    Security · August 31, 2026 · 1 publisher

  29. Cohesity's field CISO ranks KEV above EPSS above CVSS in a tiebreaker she would hand an analyst

    Security · August 31, 2026 · 1 publisher

  30. Three AI scanners disagreed on 95 percent of one codebase's findings in Contrast's test

    Security · August 31, 2026 · 1 publisher

  31. Self-hosting an open-weight model transfers six security jobs to the buyer

    Security · August 29, 2026 · 1 publisher

  32. By year six nobody can log in to the cameras, and AI will not find the password

    Security · August 26, 2026 · 1 publisher

  33. Hack The Box's agent numbers: 4.2% of the flags, mostly in hands that needed no help

    Security · August 26, 2026 · 1 publisher

  34. Tricentis' CISO says the excuse for production data in test environments has expired

    Security · August 26, 2026 · 1 publisher

  35. The exploit was the toll gate: Gartner's top emerging risk moved five places in one quarter

    Security · August 26, 2026 · 1 publisher

  36. CISA's new logging architecture is really a free audit kit: can your logs rebuild the attack?

    Security · August 25, 2026 · 1 publisher

  37. AI supply chain incidents are still bad packages and unwatched build pipelines

    Security · August 25, 2026 · 1 publisher

  38. An agent guard that runs on your laptop, and cannot tell you whether anyone keeps it on

    Security · August 24, 2026 · 1 publisher

  39. Ransomware's victim list barely moves: 73% of disclosed hits landed on mid-market firms

    Security · August 24, 2026 · 1 publisher

  40. A CVSS 10.0 RCE in Entra ID was exploited in the wild, and there was nothing to patch

    Security · August 21, 2026 · 1 publisher