433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-68820 is a use-after-free flaw that affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows a low-privileged local attacker to elevate privileges to SYSTEM. “A locally authenticated attacker could run a specially crafted application on an … More → The post Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) appeared first on Help Net Security.
http://news.poseidon-us.com/TTzJb4

ConnectSecure helps MSPs automate Microsoft 365 security remediation

ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security findings, create and measure assessments, support client training and strengthen security posture from one platform. The launch advances ConnectSecure’s focus on proactive, unified protection for MSPs. M365 Auto Remediation helps teams act on supported Microsoft 365 security findings, while Training Assessments streamline the creation, assignment … More → The post ConnectSecure helps MSPs automate Microsoft 365 security remediation appeared first on Help Net Security.
http://news.poseidon-us.com/TTzJZx

CBTS brings continuous penetration testing to enterprise security

CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve. Cloud environments, SaaS applications, connected systems, third-party relationships and AI systems are expanding enterprise attack surfaces faster than traditional testing cycles can track, and the industry’s own breach data backs that up, as vulnerability exploitation now outpaces stolen credentials as attackers’ top … More → The post CBTS brings continuous penetration testing to enterprise security appeared first on Help Net Security.
http://news.poseidon-us.com/TTzJZZ

Crytica’s RDAi detects OT device tampering from within

Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disrupting operations. The need is becoming increasingly urgent as cybersecurity moves toward machine speed. IBM’s Cost of a Data Breach Report 2026 found AI-driven attacks increased 56% year over year, while 50% of organizations with security operations centers (SOCs) have already deployed … More → The post Crytica’s RDAi detects OT device tampering from within appeared first on Help Net Security.
http://news.poseidon-us.com/TTzDSn

Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily

Google Chrome’s latest measures against abusive web push notifications include automatically revoking notification permissions for inactive and suspicious websites, helping reduce scams, phishing attempts, and other deceptive content. Abusive notifications (Source: Google) Chrome revokes notification permissions for websites users have not recently interacted with and for sites that Google Safe Browsing identifies as engaging in abusive or deceptive notification practices. Users can review and restore revoked permissions at any time through Chrome’s Safety Hub if … More → The post Chrome’s anti-abuse protections block 7 billion unwanted Android notifications daily appeared first on Help Net Security.
http://news.poseidon-us.com/TTzDSm

Split-second deepfake glitch blows digital certificate fraudster’s cover

Spanish police have arrested a man in Murcia accused of using deepfake software to trick a certificate provider’s video identity checks in an attempt to obtain digital signatures he could use for financial fraud. According to the police, the man made 38 attempts using this method on more than 30 citizens. Police haven’t said how many of those attempts succeeded before the scheme was uncovered. The National Police said the investigation started after a company … More → The post Split-second deepfake glitch blows digital certificate fraudster’s cover appeared first on Help Net Security.
http://news.poseidon-us.com/TTzDSX

Post-quantum migration gets harder when every user holds a key

In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where post-quantum key sizes break old size assumptions in IPsec, SSH, TLS and libp2p, why migrating user keys makes blockchains hard to upgrade, and what a silent quantum break would look like from outside. He also gives the argument for funding … More → The post Post-quantum migration gets harder when every user holds a key appeared first on Help Net Security.
http://news.poseidon-us.com/TTz6wh

PentestGPT: Open-source automated penetration testing agentic framework

PentestGPT is an open-source penetration testing agent that points a large language model at a target and lets it work. In its default mode it runs recon, then exploit, then walkthrough, each stage feeding the next. Switch it to pentest mode and the stages become asset discovery, vulnerability identification, report. No human sits in the loop. The agent drives Claude Code or Codex, runs the tools, and decides what to try next. Gelei Deng and … More → The post PentestGPT: Open-source automated penetration testing agentic framework appeared first on Help Net Security.
http://news.poseidon-us.com/TTz6wf