433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (656) 236-3022

Hugging Face breached by autonomous AI agent

Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16), the company said that earlier that week, it identified unauthorized access to some internal datasets and to several credentials used by its services. The intrusion was executed via a malicious dataset that abused … More → The post Hugging Face breached by autonomous AI agent appeared first on Help Net Security.
http://news.poseidon-us.com/TTcnnj

The Windows 10 hangover is becoming a security problem

Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered vulnerabilities unpatched. “There’s a temporary bridge that we need to consider when looking at these numbers. Microsoft’s consumer Extended Security Updates program keeps eligible Windows 10 devices patched for one extra year, until October 12, … More → The post The Windows 10 hangover is becoming a security problem appeared first on Help Net Security.
http://news.poseidon-us.com/TTcjnj

Meet Dusseldorf, Microsoft’s open-source out-of-band security platform

Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package meant to run inside a private environment. Dusseldorf is an out-of-band application security testing platform. It captures inbound network traffic across several protocols and lets an operator craft automated responses for validation workflows. … More → The post Meet Dusseldorf, Microsoft’s open-source out-of-band security platform appeared first on Help Net Security.
http://news.poseidon-us.com/TTcbBX

More alerts are making your team slower, and an outcome-based SOC fixes that

In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers called a help desk, reset a privileged cloud account, and exposed thousands of passwords in three minutes. Ransomware groups can go from access to payload in under three hours. … More → The post More alerts are making your team slower, and an outcome-based SOC fixes that appeared first on Help Net Security.
http://news.poseidon-us.com/TTcbBV

A forensic tool for backdoored code completions in AI assistants

Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before training starts. A poisoned example teaches a model to write insecure code when it sees a certain cue, and the flaw sits quietly until the right prompt … More → The post A forensic tool for backdoored code completions in AI assistants appeared first on Help Net Security.
http://news.poseidon-us.com/TTcbB8

Nearly half of open-source AI projects never reach production

Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as model capability improves. Open source AI in 2026, in four numbers. (Source: Mozilla) “Without investment in the infrastructure, tooling, and governance around open models, we risk locking in a system where only restrictive, closed AI … More → The post Nearly half of open-source AI projects never reach production appeared first on Help Net Security.
http://news.poseidon-us.com/TTcWsx