433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

Government measures compliance, but does accountability help programs succeed?

“I would love to see more happen with the actual outcomes and move the GPRA indicators to have more of an outcome orientation,” said Dr. Abraham Wandersman.
http://news.poseidon-us.com/TTfts0

OpenAI: Our models breached Hugging Face during a cyber capability test

The recent Hugging Face breach was the work of several OpenAI models, the AI research company claimed in a blog post. The breach Late last week, the company behind Hugging Face, a platform that enables users to share machine learning models and datasets, said some of its internal datasets had been accessed without authorization. The attack vector was, according to Hugging Face, a malicious dataset that exploited code-execution paths in the company’s dataset processing pipeline, … More → The post OpenAI: Our models breached Hugging Face during a cyber capability test appeared first on Help Net Security.
http://news.poseidon-us.com/TTfmQW

OpenAI Presence connects AI agents to enterprise data with built-in guardrails

OpenAI has introduced Presence, a product designed to help companies deploy AI agents that handle customer support and internal service requests across voice and chat. (Source: OpenAI) The company describes Presence as a deployment platform rather than a standalone model. “Presence brings together the components teams need to run agents in production: policies and standard operating procedures, guardrails, approved actions, simulations, evaluation tools, and a Codex-powered improvement process,” OpenAI said. “Together, these components help teams … More → The post OpenAI Presence connects AI agents to enterprise data with built-in guardrails appeared first on Help Net Security.
http://news.poseidon-us.com/TTfmQT

Astelia extends reachability analysis with agentic AI for vulnerability management

Astelia has added agentic capabilities to its reachability analysis platform as organizations face shrinking exploit windows and the growing challenge of managing vulnerabilities. At the core of the platform is Astelia’s reachability analysis, which determines whether a vulnerability can be reached and exploited within a specific environment. By correlating network topology with the technical requirements needed to exploit a given vulnerability, Astelia identifies that less than 1% of findings present real exposure, eliminating the noise … More → The post Astelia extends reachability analysis with agentic AI for vulnerability management appeared first on Help Net Security.
http://news.poseidon-us.com/TTfmQM

ThreatDown expands security visibility to AI tools and machine identities

ThreatDown has announced a synchronized expansion of its AI and identity security capabilities to protect organizations from emerging, unmanaged risks. The company launched AI visibility, giving security and managed service provider (MSP) teams a full inventory of the AI tools running across their environments, while simultaneously extending its ITDR capabilities to secure non-human identities (NHI). By bringing governance to service accounts, API tokens, OAuth credentials, and machine identities, ThreatDown helps close critical exposure points that … More → The post ThreatDown expands security visibility to AI tools and machine identities appeared first on Help Net Security.
http://news.poseidon-us.com/TTfmQK

Swimlane AI SOC automates security operations for MSSPs

Swimlane has announced the launch of Swimlane AI SOC for MSSPs, which the company says is designed to empower managed security service providers through agentic AI automation rather than compete for their customers. Some AI SOC providers are moving into managed services, turning former partners into competitors for the very MSSPs they once supported. Swimlane is taking the opposite approach. MSSPs that build their AI SOC on Swimlane Turbine keep the customer relationship, keep the … More → The post Swimlane AI SOC automates security operations for MSSPs appeared first on Help Net Security.
http://news.poseidon-us.com/TTfmPt

Modern Attack Vectors | Recorded Future

What is an attack vector, and how does it impact your business? Discover the top threat actor targets in 2026 and learn attack vector vs attack surface dynamics.
http://news.poseidon-us.com/TTflP4

Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522)

Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the offensive security company warned on Tuesday. WatchTowr’s global honeypot network registered successful exploitation attempts on July 20, mere hours after the release of the proof-of-concept exploit and … More → The post Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) appeared first on Help Net Security.
http://news.poseidon-us.com/TTfc11

Glow exits stealth with $180 million to secure the AI-enabled endpoint

Glow has emerged from stealth with $180 million in funding at a $1.2 billion valuation to advance a prevention-first approach to endpoint security. The funding round was led by Sequoia, Cyberstarts, Greenoaks, and Redpoint Ventures, with participation from Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures. The company will use the funding to expand its go-to-market team in the United States and grow Glow Labs, its cybersecurity research division. Glow was founded … More → The post Glow exits stealth with $180 million to secure the AI-enabled endpoint appeared first on Help Net Security.
http://news.poseidon-us.com/TTfc10

US seizes over 1,000 domains used for illegal World Cup 2026 streams

The US Department of Justice has seized more than 1,000 internet domains that streamed FIFA World Cup 2026 matches without a license. The domain seizure notice (Source: US Department of Justice) The seizures came in three waves over the course of the tournament. The first two rounds took down nearly 400 domains by the end of June, and two later rounds pushed the total past 1,000. The effort, named “Operation Offsides”, was led by the … More → The post US seizes over 1,000 domains used for illegal World Cup 2026 streams appeared first on Help Net Security.
http://news.poseidon-us.com/TTfc0z