433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

Senate CR would delay OMB’s grants rewrite

It also includes provisions to expand hiring authority for the National Taxpayer Advocate and the Office of Appeals.
http://news.poseidon-us.com/TTr3mz

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026, N‑able saw an increase in licensing issues for our on-premises N‑central customers. Licensing issues are not uncommon, but the volume was high and the engineering and security teams were engaged,” N-able shared. “On the morning of … More → The post Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) appeared first on Help Net Security.
http://news.poseidon-us.com/TTr2K7

Mimecast introduces AI agent governance and managed threat response

Mimecast has unveiled Agent Risk Center, a beta capability for discovering, monitoring, and governing AI agents, alongside Managed Threat Response, a redesigned 24/7 service that combines AI-assisted triage with analyst-confirmed remediation. According to Mimecast’s analysis, 98% of organizations already have unsanctioned AI tools in use, and by 2029 more than a billion agents will take some 217 billion actions a day1 on employees’ behalf with limited visibility for security tools. The Mimecast Agent Risk Center … More → The post Mimecast introduces AI agent governance and managed threat response appeared first on Help Net Security.
http://news.poseidon-us.com/TTr2K5

Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s AI agent misconfigured a file server, inadvertently exposing the entire infrastructure. “This visibility enabled us to understand their full tool set, how the attackers orchestrated multiple AI platforms and gave us a peek into their targeting,” Unit … More → The post Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers appeared first on Help Net Security.
http://news.poseidon-us.com/TTr2K3

SentinelOne expands security operations automation with governed AI

SentinelOne has today announced governed, closed-loop response across the Singularity Platform, delivering trustworthy automation for security operations. Purple AI and Singularity Hyperautomation now autonomously investigate alerts, reach verdicts, and execute responses. Security teams set the boundaries first, deciding where AI acts on its own and where it stops for human sign-off. The Autonomous SOC now runs from alert to action, at the speed and scale of AI, with the confidence and control of human defenders. … More → The post SentinelOne expands security operations automation with governed AI appeared first on Help Net Security.
http://news.poseidon-us.com/TTr2Jw

Horizon3.ai hits $2 billion valuation in $250 million funding round

Horizon3.ai has announced a $250 million Series E at a valuation of more than $2 billion, tripling its valuation from $650 million at Series D in just over a year. The oversubscribed round was co-led by existing investors NightDragon and NEA, with participation from seven new investors and five returning backers. The capital underscores accelerating global demand for safe, autonomous security validation as AI-driven cyberattacks escalate. “We invented the concept of AI Hackers and spent … More → The post Horizon3.ai hits $2 billion valuation in $250 million funding round appeared first on Help Net Security.
http://news.poseidon-us.com/TTr2JG

Is the federal workforce doing better than we think? Gallup’s latest research may surprise you

Gallup’s Christos Makridis shares why trust, not tech, shapes engagement, AI adoption and resilience across the federal workforce.
http://news.poseidon-us.com/TTqy0T

CISA lays out new guidance for using open-source software

The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, and evaluating open source AI systems. Using open source software Federal agencies can benefit from open source software because its source code can be independently reviewed, reducing reliance on vendor claims. It can reduce dependence on a single … More → The post CISA lays out new guidance for using open-source software appeared first on Help Net Security.
http://news.poseidon-us.com/TTqw0T

KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)

A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of it. Nicknamed “KindaRails2Shell” by the researchers who found it, the flaw lets an attacker sneak a booby-trapped file past a website’s image-upload feature and use it to pry open the server’s secrets. About … More → The post KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066) appeared first on Help Net Security.
http://news.poseidon-us.com/TTqw0Q