433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (656) 236-3022

Shufti simplifies cross-border compliance with the Glocal Platform

Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. For decades, global expansion has come with an unwritten rule: every new market needs a new compliance provider. A solution built for one region may not fully support the regulations, document ecosystems, verification methods, or risk … More → The post Shufti simplifies cross-border compliance with the Glocal Platform appeared first on Help Net Security.
http://news.poseidon-us.com/TTdgVS

SonicWall SMA zero-days were exploited weeks before disclosure

Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22, 2026, well before the flaws became public. According to the researchers, the attackers’ goal was stealthy, long-term access: once inside, the intruders could reach stored or cached credentials, capture network traffic, and potentially intercept … More → The post SonicWall SMA zero-days were exploited weeks before disclosure appeared first on Help Net Security.
http://news.poseidon-us.com/TTdgVF

Fake FBI agents target people who already got scammed

Scammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier alert from April 2025. Since then, the bureau says, the scammers have picked up new tricks, including AI-generated video of FBI officials and spoofed versions of the IC3 website itself. “Complainants report scammers use a … More → The post Fake FBI agents target people who already got scammed appeared first on Help Net Security.
http://news.poseidon-us.com/TTdgTW

AWS wants GuardDuty to automate the first steps of threat investigations

Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at no additional cost in 10 AWS Regions. Usage is limited to 10 investigations per account per day, with a cumulative limit of 100 investigations per account during the preview period. Failed investigations do not count toward these … More → The post AWS wants GuardDuty to automate the first steps of threat investigations appeared first on Help Net Security.
http://news.poseidon-us.com/TTdbWG

Estée Lauder discloses data breach tied to Oracle EBS vulnerability

Cosmetics company Estée Lauder disclosed a data breach tied to a vulnerability in Oracle E-Business Suite (EBS) used for the company’s human resources operations. Estée Lauder is one of the largest beauty companies in the world, known for its prestige skincare, makeup, fragrance, and haircare brands. “We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the … More → The post Estée Lauder discloses data breach tied to Oracle EBS vulnerability appeared first on Help Net Security.
http://news.poseidon-us.com/TTdbWC

Open-source maintainers still work underfunded as sponsorship crosses $100 million

A maintainer patches a library late at night that ships inside thousands of products, and no invoice follows. Sebastián Ramírez and Caleb Porzio spent years in that position. Ramírez, known as tiangolo, builds tools that other Python projects depend on. Porzio built Livewire and Alpine.js, tools thousands of web developers reach for. That gap carries a cost. Critical projects lose their maintainers to salaried jobs elsewhere, security fixes slow down, and the software supply chain … More → The post Open-source maintainers still work underfunded as sponsorship crosses $100 million appeared first on Help Net Security.
http://news.poseidon-us.com/TTdbVw

The air gap is a myth and other OT security truths

Benjamin Bachmann, Director Group Information Security at Bilfinger, speaks with Help Net Security about defending industrial plants. He explains why attackers want to control operations instead of stealing data, and why the air gap is mostly a myth. Bachmann covers how containment plans get negotiated before an incident, how to build visibility on old equipment through network monitoring, and how ransomware crews price their demands on downtime. He also questions the idea that people are … More → The post The air gap is a myth and other OT security truths appeared first on Help Net Security.
http://news.poseidon-us.com/TTdSrH

Nobody was checking the drives that encrypt your laptop

A drive ships with a label promising hardware encryption. You plug it in, set a password, and trust the chip inside to handle the rest. Millions of laptops and workstations run this way, on solid-state drives built to the TCG Opal2 standard. Milan Brož and three colleagues bought 38 of those drives and ran them through a test bench. Brož maintains cryptsetup, the tool that configures disk encryption on most Linux systems. The drives came … More → The post Nobody was checking the drives that encrypt your laptop appeared first on Help Net Security.
http://news.poseidon-us.com/TTdSrC

PR3TACK preemptive framework maps threats before attackers use them

Defensive frameworks in cybersecurity record what attackers have already done. Analysts study a breach, document the method, and build detections around confirmed activity. This cycle leaves a gap between the moment an attacker invents a technique and the moment defenders learn to catch it. PR3TACK, the Preemptive Tactics and Countermeasures Knowledgebase, aims to close that gap. Vishal Thakur of Atlassian built the open framework that catalogs plausible attacker tactics, techniques, and procedures that remain unobserved … More → The post PR3TACK preemptive framework maps threats before attackers use them appeared first on Help Net Security.
http://news.poseidon-us.com/TTdSqv