433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (656) 236-3022

AI agents tricked into recommending malicious GitHub repositories

Roughly 7,600 malicious GitHub repositories were uncovered, more than 800 of them posing as AI Skills or Model Context Protocol (MCP) servers, in a wave that peaked in April 2026, according to Island. The scale of the FakeGit operation (Source: Island) The fake repositories are tied to about 6,600 accounts, around 1,400 of which were built around AI tools, agents, or workflows, and span individual and enterprise use, ranging from Gmail and WhatsApp integrations to … More → The post AI agents tricked into recommending malicious GitHub repositories appeared first on Help Net Security.
http://news.poseidon-us.com/TTdqQw

Teleport enhances Identity Security platform with new AI agent behavior controls

Teleport has expanded its Identity Security platform with three new capabilities designed to ensure that agent behavior remains within defined boundaries: Beams Session Summaries, Agentic Classifiers, and Risk Scoring. They give enterprises a foundational harness for identifying and preventing agent misalignment as autonomous agents take on greater responsibility inside production infrastructure. The announcement follows Teleport’s recent white paper, From Zero Trust to Agent Trust, which argues that zero trust is necessary but insufficient to govern … More → The post Teleport enhances Identity Security platform with new AI agent behavior controls appeared first on Help Net Security.
http://news.poseidon-us.com/TTdqQs

JadePuffer returns with ransomware built to target AI models and infrastructure

JadePuffer, the threat actor behind the recently documented extortion operation executed end-to-end by an AI agent, is now attempting to leverage ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure. The extortion contact embedded in the ransomware is the same one Sysdig researchers found when analyzing that prior campaign. “This is the same operator with a materially upgraded toolkit,” they noted. How JadePuffer first surfaced Earlier this month, Sysdig researchers revealed that … More → The post JadePuffer returns with ransomware built to target AI models and infrastructure appeared first on Help Net Security.
http://news.poseidon-us.com/TTdqQr

Druva brings backup, recovery and governance to AI workloads

Druva has announced Druva AI Resilience, a new approach that helps organizations recover, govern, and defend the systems, activity, and context behind AI-powered work. The launch introduces new and expanded capabilities for Microsoft Copilot, Claude Code, Druva Model Context Protocol (MCP), and Dru SRE Agent for agentic service reliability with expanded Dru MetaGraph functionality. These innovations bring enterprise-grade resilience to AI-powered work and the backup environments organizations rely on to recover. Businesses have spent decades … More → The post Druva brings backup, recovery and governance to AI workloads appeared first on Help Net Security.
http://news.poseidon-us.com/TTdqQn

Cisco’s open-weight Antares models make vulnerability localization cheaper

A security analyst opens an unfamiliar repository, pulls up a vulnerability advisory, and starts hunting for the file where the weakness lives. The naming conventions belong to someone else. Evidence sits in scattered corners of a codebase that runs to thousands of files. That first stage of triage burns hours and expertise, and it is the part Cisco set out to speed up. Today, the company released Antares, a family of small language models built … More → The post Cisco’s open-weight Antares models make vulnerability localization cheaper appeared first on Help Net Security.
http://news.poseidon-us.com/TTdqQJ

Shufti simplifies cross-border compliance with the Glocal Platform

Shufti has launched the Shufti Glocal Platform, a compliance lifecycle management solution designed to help organizations manage identity verification, fraud prevention, risk assessment, and regulatory compliance through a single platform across every industry, every region, and every use case. For decades, global expansion has come with an unwritten rule: every new market needs a new compliance provider. A solution built for one region may not fully support the regulations, document ecosystems, verification methods, or risk … More → The post Shufti simplifies cross-border compliance with the Glocal Platform appeared first on Help Net Security.
http://news.poseidon-us.com/TTdgVS

SonicWall SMA zero-days were exploited weeks before disclosure

Two recently disclosed SonicWall SMA 1000 vulnerabilities – CVE-2026-15409 and CVE-2026-15410 – were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances, Volexity researchers revealed. The intrusions began as early as June 22, 2026, well before the flaws became public. According to the researchers, the attackers’ goal was stealthy, long-term access: once inside, the intruders could reach stored or cached credentials, capture network traffic, and potentially intercept … More → The post SonicWall SMA zero-days were exploited weeks before disclosure appeared first on Help Net Security.
http://news.poseidon-us.com/TTdgVF

Fake FBI agents target people who already got scammed

Scammers are impersonating FBI personnel who supposedly handle Internet Crime Complaint Center (IC3) complaints, using that disguise to deceive and revictimize people who already lost money once. The IC3 published the update on July 20, 2026, building on an earlier alert from April 2025. Since then, the bureau says, the scammers have picked up new tricks, including AI-generated video of FBI officials and spoofed versions of the IC3 website itself. “Complainants report scammers use a … More → The post Fake FBI agents target people who already got scammed appeared first on Help Net Security.
http://news.poseidon-us.com/TTdgTW

AWS wants GuardDuty to automate the first steps of threat investigations

Amazon GuardDuty investigation agent is now in public preview. The feature provides AI-powered investigations of GuardDuty findings, AWS accounts and AWS organizations, helping security teams reduce investigation time. During the public preview, the investigation agent is available at no additional cost in 10 AWS Regions. Usage is limited to 10 investigations per account per day, with a cumulative limit of 100 investigations per account during the preview period. Failed investigations do not count toward these … More → The post AWS wants GuardDuty to automate the first steps of threat investigations appeared first on Help Net Security.
http://news.poseidon-us.com/TTdbWG