433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provider. From that server, someone has been pulling records out of Salesforce and ServiceNow portals around the world. The activity has not stopped, and there is more of it … More → The post A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months appeared first on Help Net Security.
http://news.poseidon-us.com/TTzTkJ

Signal’s new security feature checks if your encrypted chats were tampered with

Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, streamlined way to confirm that there’s no unexpected party between you and the other ‘end’ of an end-to-end encrypted session,” Signal engineer Katherine Yen wrote in a blog post. “It works through a system of verifications performed by … More → The post Signal’s new security feature checks if your encrypted chats were tampered with appeared first on Help Net Security.
http://news.poseidon-us.com/TTzTk4

ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5

ScienceLogic has announced Skylar AI 2.5, expanding secure deployment options for organizations with stringent security, sovereignty, and compliance requirements, while introducing enhancements that strengthen AI performance, operational intelligence, and enterprise integrations. The release further improves AI accuracy, platform performance, and natural language user experience across the ScienceLogic AI Platform. Serving as the intelligence layer of the ScienceLogic AI Platform, Skylar AI provides always-on guidance across complex IT environments, a critical capability for organizations operationalizing agentic … More → The post ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5 appeared first on Help Net Security.
http://news.poseidon-us.com/TTzTjs

Deloitte strengthens AI governance to support trusted enterprise adoption

Deloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise. From early exploration to enterprise deployment, Deloitte’s enhanced services provide end-to-end support across the AI lifecycle, combining advisory and assurance services across governance frameworks and AI-enabled transformation to help organizations manage risk while unlocking value. While 74% of companies plan to deploy agentic AI within two years, only 21% report having a … More → The post Deloitte strengthens AI governance to support trusted enterprise adoption appeared first on Help Net Security.
http://news.poseidon-us.com/TTzTj5

Lazarus hackers pair fake job offers with Windows zero-day exploit

The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a long-running campaign in which attackers pose as recruiters and lure targets with job opportunities at well-known companies. One of the decoy documents uncovered during the investigation used a Lockheed Martin job description. Check Point was unable … More → The post Lazarus hackers pair fake job offers with Windows zero-day exploit appeared first on Help Net Security.
http://news.poseidon-us.com/TTzQb2

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft’s August 2026 Patch Tuesday delivered security fixes for 400+ vulnerabilities, including one that has been exploited in zero-day attacks (CVE-2026-68820) and three that were publicly disclosed prior to the release of the patches. Vulnerabilities of note CVE-2026-68820 is a use-after-free flaw that affects the Windows Ancillary Function Driver for WinSock (AFD.sys) and allows a low-privileged local attacker to elevate privileges to SYSTEM. “A locally authenticated attacker could run a specially crafted application on an … More → The post Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) appeared first on Help Net Security.
http://news.poseidon-us.com/TTzJb4

ConnectSecure helps MSPs automate Microsoft 365 security remediation

ConnectSecure has announced that Microsoft 365 Auto Remediation and AI-powered Training Assessments are now live on the ConnectSecure platform. The capabilities help managed service providers (MSPs) address supported M365 security findings, create and measure assessments, support client training and strengthen security posture from one platform. The launch advances ConnectSecure’s focus on proactive, unified protection for MSPs. M365 Auto Remediation helps teams act on supported Microsoft 365 security findings, while Training Assessments streamline the creation, assignment … More → The post ConnectSecure helps MSPs automate Microsoft 365 security remediation appeared first on Help Net Security.
http://news.poseidon-us.com/TTzJZx

CBTS brings continuous penetration testing to enterprise security

CBTS has launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations continuously identify exploitable risks, validate attack paths, and prioritize remediation as their environments evolve. Cloud environments, SaaS applications, connected systems, third-party relationships and AI systems are expanding enterprise attack surfaces faster than traditional testing cycles can track, and the industry’s own breach data backs that up, as vulnerability exploitation now outpaces stolen credentials as attackers’ top … More → The post CBTS brings continuous penetration testing to enterprise security appeared first on Help Net Security.
http://news.poseidon-us.com/TTzJZZ

Crytica’s RDAi detects OT device tampering from within

Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national security, and healthcare without disrupting operations. The need is becoming increasingly urgent as cybersecurity moves toward machine speed. IBM’s Cost of a Data Breach Report 2026 found AI-driven attacks increased 56% year over year, while 50% of organizations with security operations centers (SOCs) have already deployed … More → The post Crytica’s RDAi detects OT device tampering from within appeared first on Help Net Security.
http://news.poseidon-us.com/TTzDSn