433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

Cisco FMC static credentials exploited by attackers (CVE-2026-20316)

A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Two FMC flaws, one indicator of compromise CVE-2026-20316, reported by Jimi Sebree of Horizon3.ai, is found in the FMC software’s web interface. The static user credentials are for a low-privileged account, and they can be used by attackers to log in to an … More → The post Cisco FMC static credentials exploited by attackers (CVE-2026-20316) appeared first on Help Net Security.
http://news.poseidon-us.com/TTmw7Q

Dropzone AI turns threat hunting into a routine SOC operation

Dropzone AI has announced the general availability of AI Threat Hunter, its proactive threat hunting agent. The tool enables security teams to run structured hunt packs across their environments to identify hidden threats, emerging risks, and security coverage gaps that traditional alerts may miss. Security alerts flag activity that matches predefined detection rules, helping teams identify known threats and suspicious behavior, but they are only one lens into the environment. Threat hunting looks for everything … More → The post Dropzone AI turns threat hunting into a routine SOC operation appeared first on Help Net Security.
http://news.poseidon-us.com/TTmw7N

PortSwigger introduces Burp AT for agentic AI security testing

PortSwigger has announced the public beta of Burp AT, a new addition to Burp Suite that brings agentic AI to professional penetration testing. Burp AT enables penetration testers to delegate defined investigative tasks to AI agents that use Burp Suite’s tools, project context, and purpose-built pentesting capabilities. Testers control how much work the agents perform, while Burp Suite enforces scope, permissions, and approval rules. Responsibility for defining scope, exercising judgment, and validating findings remains with … More → The post PortSwigger introduces Burp AT for agentic AI security testing appeared first on Help Net Security.
http://news.poseidon-us.com/TTmw7C

Coordinated cyberattack hits more than 30 Minnesota water utilities

A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. MNIT confirmed the attack in a statement published July 28 and said it activated its cybersecurity incident response capabilities as soon as it learned of the intrusion. The agency has since been working with a broad set of partners to … More → The post Coordinated cyberattack hits more than 30 Minnesota water utilities appeared first on Help Net Security.
http://news.poseidon-us.com/TTmm7h

Data breach cost 2026 averaged $4.99 million, AI attacks ran higher

More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI. Defenders bought similar technology and aimed it somewhere else. Half of breached organizations put AI agents inside a security operations center, mostly on threat hunting, automated response and containment. Among that group, 18% aimed agents at vulnerability scanning and management, the work … More → The post Data breach cost 2026 averaged $4.99 million, AI attacks ran higher appeared first on Help Net Security.
http://news.poseidon-us.com/TTmg0s

200 new CVEs a day and no realistic way to patch them all

Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’s three-day patching deadline under BOD 26-04, why virtual patching buys time, and how AI-generated proof-of-concept code muddies the evidence. He also ranks incident reports, honeypot hits, scanning and PoC chatter by how … More → The post 200 new CVEs a day and no realistic way to patch them all appeared first on Help Net Security.
http://news.poseidon-us.com/TTmg0q

Top companies to visit at Black Hat USA 2026

Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global security community. The event opens with four days of immersive, expert-led Trainings (August 1-4), continues with Summit Day on Tuesday, August 4, and closes with a two-day main conference featuring Briefings, open-source tool demos in Arsenal, a Business Hall, and opportunities to learn and connect. From cutting-edge innovators to industry veterans launching … More → The post Top companies to visit at Black Hat USA 2026 appeared first on Help Net Security.
http://news.poseidon-us.com/TTmg0m

Impersonation protection: How to protect your executives when the truth isn’t clear

How do you protect your executives when truth doesn’t seem to be truth anymore? It’s a question BlackCloak Founder and CEO Dr. Chris Pierson recently discussed this dilemma with SVP of Product Matt Covington. Advances in AI, voice, and video impersonation make it difficult to establish trust when communicating digitally. BlackCloak offers a solution to this evolving threat with their Impersonation Protection service. It’s an out of band function that operates directly from within the … More → The post Impersonation protection: How to protect your executives when the truth isn’t clear appeared first on Help Net Security.
http://news.poseidon-us.com/TTmg0C

Product showcase: Dashlane Password Manager is more security toolkit than password vault

Dashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encrypted vault. It also includes a password generator, password health reports, an authenticator, credential sharing, dark web monitoring and phishing protection. The service is available on Windows, macOS, Linux (web app), Android, iPhone and iPad, with browser extensions for Chrome, Edge, Firefox, Safari and other Chromium-based browsers. Passwords, passkeys and other vault items … More → The post Product showcase: Dashlane Password Manager is more security toolkit than password vault appeared first on Help Net Security.
http://news.poseidon-us.com/TTmZJd