<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/feeds/tag/security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro in Security ]]></title>
                <link>https://www.itpro.com/security</link>
        <description><![CDATA[ All the latest security content from the ITPro team ]]></description>
                                    <lastBuildDate>Thu, 24 Sep 2026 16:34:38 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Cyber experts warn FBI breach could have serious real world consequences ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The FBI has confirmed it is “actively and aggressively” investigating a breach which allegedly exposed employee and operational data. </p><p>“The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the http://FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” the agency said in a <a href="https://x.com/FBI/status/2102807819695071709?s=20" target="_blank"><u>post on X.</u></a> </p><p>The statement comes after the ShinyHunters <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware </u></a>group claimed to have compromised critical systems through a third-party vulnerability. </p><p>This, the group said, enabled access to several systems, including jobs portals and background check software, as well as a system used to store information relating to investigations. </p><p>According to ShinyHunters, the third-party software inquisition is Oracle PeopleSoft, an <a href="https://www.itpro.com/strategy/28048/what-is-erp">enterprise resource planning (ERP)</a> suite used in human resources (HR), finance, and supply chain management. </p><p>Earlier this year, ShinyHunters claimed responsibility for a string of attacks after leveraging a zero-day vulnerability in the ERP software. <a href="https://www.itpro.com/security/data-breaches/nissan-employee-data-exposed-in-oracle-peoplesoft-zero-day-attacks"><u>Car manufacturer Nissan</u></a> and the <a href="https://www.itpro.com/security/nottingham-university-cyber-attack-everything-we-know-so-far-as-shinyhunters-claims-responsibility"><u>University of Nottingham</u></a> were two of a string of organizations impacted. </p><p>In its statement on X, the FBI said the “point of breach is still undetermined”, adding that it is working closely with third-party providers related to impacted systems. </p><h2 id="fbi-breach-could-have-huge-consequences">FBI breach could have huge consequences</h2><p>The exact scope of data compromised in the breach remains unconfirmed, however, the group claims to have stolen data on thousands of employees. This includes agent names, badge numbers, and information such as home addresses and contact details. </p><p>Reports from <a href="https://www.reuters.com/world/hacked-fbi-data-has-sensitive-information-about-employees-intelligence-roles-2026-09-23/" target="_blank"><u><em>Reuters</em></u></a> suggest this also includes highly sensitive data on investigations into foreign intelligence operations as well as drug cartel activity. </p><p>If confirmed, exposure of this data could have serious real-world consequences, according to Joe Hancock, partner and head of cyber risk and complex investigations at law firm Mishcon de Reya.</p><p>“If the reports are accurate, this is a serious breach. This kind of data has real utility in the wrong hands, as we saw with the PSNI breach exposing people in sensitive roles translated into real-world risk,” he said. </p><p>“The fact the data appears to have come from an online jobs portal may limit some of the operational impact, but it doesn’t make the exposure of individuals’ identities any less serious,” Hancock added.</p><p>“Linking personal information to specific intelligence, counterespionage, or surveillance roles takes this well beyond conventional identity theft.”</p><p>Andrew Brandt, principal threat intelligence incident commander at Huntress, echoed Hancock’s comments. According to Brandt, a serious concern centers around whether the group might sell data to other criminal or nation-state groups that “could put it to more damaging use”. </p><p>“The FBI handles some of the most serious interstate and transnational crime investigations. It doesn't take much imagination to picture scenarios where employees or their families could be threatened or harmed by this kind of information being released,” he said. </p><h2 id="shinyhunters-claims-attack-is-not-financially-motivated">ShinyHunters claims attack is not financially motivated</h2><p>In a message on its dark web leak site, ShinyHunters claimed the attack was not financially motivated, but instead comes in response to an advisory by the agency which misrepresented the group’s activities. </p><p>The <a href="https://www.ic3.gov/PSA/2026/PSA260515" target="_blank"><u>advisory</u></a>, published by the FBI in May in the wake of <a href="https://www.itpro.com/security/cyber-attacks/universities-worldwide-still-struggling-with-fallout-from-canvas-cyber-attack"><u>attacks on the Canvas academic management system</u></a>, said threat groups such as ShinyHunters often use “real or exaggerated claims” to pressure organizations into paying ransoms. </p><p>The ransomware gang has called on the agency to retract the advisory or it will publish the compromised data. </p><p>ShinyHunters has grown to become one of the most aggressive and active threat groups in the ransomware space, having claimed responsibility for attacks on Salesforce, Canvas, and the European Commission in recent months. </p><p>As <a href="https://www.itpro.com/security/ransomware/cyber-criminal-groups-suffer-from-the-same-security-weaknesses-they-routinely-exploit-shinyhunters-claims-it-hacked-clop-ransomware-rival"><u><em>ITPro </em></u><u>reported this week,</u></a> the group also claims to have hacked a rival ransomware group, Clop. This incident appears to have stemmed from a disagreement between the two ransomware gangs. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/this-kind-of-data-has-real-utility-in-the-wrong-hands-cyber-experts-warn-alleged-fbi-data-breach-could-have-serious-real-world-consequences</link>
                                                                            <description>
                            <![CDATA[ ShinyHunters has threatened to publish compromised FBI data after an advisory rubbed the group the wrong way ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4rhVaYwC6WBYyLW9FwFuCd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jRkfi6dgPf8sAehLXuGT3a-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 16:34:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jRkfi6dgPf8sAehLXuGT3a-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[FBI logo and insignia pictured on a wall alongside a United States flag at the Los Angeles Federal Building. ]]></media:description>                                                            <media:text><![CDATA[FBI logo and insignia pictured on a wall alongside a United States flag at the Los Angeles Federal Building. ]]></media:text>
                                <media:title type="plain"><![CDATA[FBI logo and insignia pictured on a wall alongside a United States flag at the Los Angeles Federal Building. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jRkfi6dgPf8sAehLXuGT3a-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The FBI has confirmed it is “actively and aggressively” investigating a breach which allegedly exposed employee and operational data. </p><p>“The FBI is aware of a cyber-criminal enterprise group claiming a compromise of the http://FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information (PII),” the agency said in a <a href="https://x.com/FBI/status/2102807819695071709?s=20" target="_blank"><u>post on X.</u></a> </p><p>The statement comes after the ShinyHunters <a href="https://www.itpro.com/security/28084/what-is-ransomware"><u>ransomware </u></a>group claimed to have compromised critical systems through a third-party vulnerability. </p><p>This, the group said, enabled access to several systems, including jobs portals and background check software, as well as a system used to store information relating to investigations. </p><p>According to ShinyHunters, the third-party software inquisition is Oracle PeopleSoft, an <a href="https://www.itpro.com/strategy/28048/what-is-erp">enterprise resource planning (ERP)</a> suite used in human resources (HR), finance, and supply chain management. </p><p>Earlier this year, ShinyHunters claimed responsibility for a string of attacks after leveraging a zero-day vulnerability in the ERP software. <a href="https://www.itpro.com/security/data-breaches/nissan-employee-data-exposed-in-oracle-peoplesoft-zero-day-attacks"><u>Car manufacturer Nissan</u></a> and the <a href="https://www.itpro.com/security/nottingham-university-cyber-attack-everything-we-know-so-far-as-shinyhunters-claims-responsibility"><u>University of Nottingham</u></a> were two of a string of organizations impacted. </p><p>In its statement on X, the FBI said the “point of breach is still undetermined”, adding that it is working closely with third-party providers related to impacted systems. </p><h2 id="fbi-breach-could-have-huge-consequences">FBI breach could have huge consequences</h2><p>The exact scope of data compromised in the breach remains unconfirmed, however, the group claims to have stolen data on thousands of employees. This includes agent names, badge numbers, and information such as home addresses and contact details. </p><p>Reports from <a href="https://www.reuters.com/world/hacked-fbi-data-has-sensitive-information-about-employees-intelligence-roles-2026-09-23/" target="_blank"><u><em>Reuters</em></u></a> suggest this also includes highly sensitive data on investigations into foreign intelligence operations as well as drug cartel activity. </p><p>If confirmed, exposure of this data could have serious real-world consequences, according to Joe Hancock, partner and head of cyber risk and complex investigations at law firm Mishcon de Reya.</p><p>“If the reports are accurate, this is a serious breach. This kind of data has real utility in the wrong hands, as we saw with the PSNI breach exposing people in sensitive roles translated into real-world risk,” he said. </p><p>“The fact the data appears to have come from an online jobs portal may limit some of the operational impact, but it doesn’t make the exposure of individuals’ identities any less serious,” Hancock added.</p><p>“Linking personal information to specific intelligence, counterespionage, or surveillance roles takes this well beyond conventional identity theft.”</p><p>Andrew Brandt, principal threat intelligence incident commander at Huntress, echoed Hancock’s comments. According to Brandt, a serious concern centers around whether the group might sell data to other criminal or nation-state groups that “could put it to more damaging use”. </p><p>“The FBI handles some of the most serious interstate and transnational crime investigations. It doesn't take much imagination to picture scenarios where employees or their families could be threatened or harmed by this kind of information being released,” he said. </p><h2 id="shinyhunters-claims-attack-is-not-financially-motivated">ShinyHunters claims attack is not financially motivated</h2><p>In a message on its dark web leak site, ShinyHunters claimed the attack was not financially motivated, but instead comes in response to an advisory by the agency which misrepresented the group’s activities. </p><p>The <a href="https://www.ic3.gov/PSA/2026/PSA260515" target="_blank"><u>advisory</u></a>, published by the FBI in May in the wake of <a href="https://www.itpro.com/security/cyber-attacks/universities-worldwide-still-struggling-with-fallout-from-canvas-cyber-attack"><u>attacks on the Canvas academic management system</u></a>, said threat groups such as ShinyHunters often use “real or exaggerated claims” to pressure organizations into paying ransoms. </p><p>The ransomware gang has called on the agency to retract the advisory or it will publish the compromised data. </p><p>ShinyHunters has grown to become one of the most aggressive and active threat groups in the ransomware space, having claimed responsibility for attacks on Salesforce, Canvas, and the European Commission in recent months. </p><p>As <a href="https://www.itpro.com/security/ransomware/cyber-criminal-groups-suffer-from-the-same-security-weaknesses-they-routinely-exploit-shinyhunters-claims-it-hacked-clop-ransomware-rival"><u><em>ITPro </em></u><u>reported this week,</u></a> the group also claims to have hacked a rival ransomware group, Clop. This incident appears to have stemmed from a disagreement between the two ransomware gangs. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Australian prime minister says OpenAI took ‘way too long’ to reveal agents breached Medicare systems ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI agents hacked into an Australian Medicare data portal, according to reports, and officials are furious that it took months for the company to disclose the incident. </p><p>Australian prime minister Anthony Albanese revealed that an OpenAI agent breached a Medicare statistics website back in June, but the government wasn't alerted to the activity by the AI developer until 10 September. </p><p>Albanese said he'd shared "Australia's extreme concern about this incident" to OpenAI CEO Sam Altman. </p><p>"I also expressed my disappointment that it took the company way too long to inform the Government what had occurred and the nature of the way that that notification occurred as well was unacceptable," he <a href="https://www.pm.gov.au/media/press-conference-new-york" target="_blank"><u>said</u></a>. </p><p>Notably, Albanese hit out at the “unacceptable” manner of disclosure by the company. OpenAI notified authorities via an email sent to a public-facing disclosures mailbox, rather than by directly contacting the government. </p><p>In response, the government is setting up a taskforce to investigate the incident, conduct a review into AI-related cyber incidents, and consider whether a criminal offence may have occurred.  </p><p>A spokesperson for OpenAI said: "We notified the organizations and are providing technical information to support their investigations and help address potential security vulnerabilities." </p><h2 id="what-happened-in-the-openai-medicare-breach">What happened in the OpenAI Medicare breach?</h2><p>The infiltration happened in June, and OpenAI told the Australian government it had spotted the activity in August. OpenAI attributed the gap between discovery and notification to "validating and investigating the facts". </p><p>The agent in question had been tasked with finding information online about public medicine spending as part of an internal test. </p><p>The data accessed did not include individual private or financial data, as the portal in question doesn't include such information. However, non-public facing data including aggregate statistics and internal file names were viewed.</p><p>An OpenAI spokesperson said it had been looking for misaligned model activity when it spotted the incident. </p><p>"During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation," the company said. "In the course of that, our models took actions we did not intend." </p><h2 id="could-openai-face-criminal-charges">Could OpenAI face criminal charges?</h2><p>Deputy prime minister Richard Marles <a href="https://www.bbc.co.uk/news/live/cvgl73pxgndwt" target="_blank"><u>told reporters</u></a> that the Medicare incident was "utterly unacceptable", adding that a task force will examine whether the law has been broken, as it "definitely does raise questions about whether the law has been broken in respect of this." </p><p>PM Albanese also <a href="https://www.pm.gov.au/media/press-conference-new-york" target="_blank"><u>said</u></a> that part of the investigation will consider whether the incident needs to be referred to local police. </p><p>In Australia, computer intrusions are prohibited by its cyber crime law, as is the creation and distribution of malicious software. The task force will also look into "whether or not the legal regime we have in place is fit for purpose in a world where we have an emerging AI capability." </p><h2 id="concerns-mount-over-rogue-ai-agents">Concerns mount over ‘rogue AI agents’ </h2><p>The admission by OpenAI marks the latest in a string of apparent ‘<a href="https://www.itpro.com/security/openai-and-anthropic-admit-rogue-ai-agents-did-more-than-first-thought">rogue AI</a>’ incidents involving the company and counterparts in the industry. </p><p>In July, the company admitted that agents had <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime">breached a Hugging Face production environment</a> after breaking out of a sandbox test environment. </p><p>Just last week, OpenAI revealed <a href="https://www.itpro.com/technology/artificial-intelligence/openai-reveals-six-more-rogue-ai-incidents"><u>six other instances of misaligned behavior by AI agents</u></a>. </p><p>Andrew Kay, director of systems engineering APJ at Illumio, said there will likely be “more high-profile breaches like this” unless robust guardrails are implemented to prevent agents ‘going rogue’.</p><p>“As increasingly autonomous and capable agents emerge, we cannot rely on the illusion of guardrails or assume an AI will always behave as intended,” he said. “It will take whatever action is necessary to achieve the task it has been set.”</p><p>“Rogue or misbehaving AI agents will only become more competent and more prevalent,” Kay added. “The priority must be ensuring that if one breaches a boundary, it cannot access sensitive material, cause serious damage or bring essential services to a standstill.”</p><p>Laura Ellis, senior vice president for artificial intelligence at Arctic Wolf, said the incident is a “timely example of a cyber risk businesses need to be preparing for now”. </p><p>“While the details of this incident are still being investigated, the security lesson is clear and security fundamentals remain unchanged,” she said. “All organizations deploying AI agents should secure them at least as tightly as any other identity: strict permissions, clear guardrails, continuous monitoring, and the ability to act fast when an agent steps outside its intended bounds.”</p><p>Ellis added that safeguards are “only part of the equation”, however. Disclosure of an incident within a “responsible timeline and with appropriate transparency” is vital. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/australian-prime-minister-says-it-took-way-too-long-for-openai-to-reveal-agents-breached-medicare-systems</link>
                                                                            <description>
                            <![CDATA[ The Australian PM has expressed concerns about an incident that saw an AI agent access healthcare stats ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AMVdL5UgRrRohLEuAdNvy8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ToWRc23zBXyTLJf6tTFChR-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 09:37:37 +0000</pubDate>                                                                                                                                <updated>Thu, 24 Sep 2026 09:49:09 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ToWRc23zBXyTLJf6tTFChR-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Australian prime minister Anthony Albanese pictured speaking to the media at Parliament House on September 08, 2026 in Canberra, Australia.]]></media:description>                                                            <media:text><![CDATA[Australian prime minister Anthony Albanese pictured speaking to the media at Parliament House on September 08, 2026 in Canberra, Australia.]]></media:text>
                                <media:title type="plain"><![CDATA[Australian prime minister Anthony Albanese pictured speaking to the media at Parliament House on September 08, 2026 in Canberra, Australia.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ToWRc23zBXyTLJf6tTFChR-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI agents hacked into an Australian Medicare data portal, according to reports, and officials are furious that it took months for the company to disclose the incident. </p><p>Australian prime minister Anthony Albanese revealed that an OpenAI agent breached a Medicare statistics website back in June, but the government wasn't alerted to the activity by the AI developer until 10 September. </p><p>Albanese said he'd shared "Australia's extreme concern about this incident" to OpenAI CEO Sam Altman. </p><p>"I also expressed my disappointment that it took the company way too long to inform the Government what had occurred and the nature of the way that that notification occurred as well was unacceptable," he <a href="https://www.pm.gov.au/media/press-conference-new-york" target="_blank"><u>said</u></a>. </p><p>Notably, Albanese hit out at the “unacceptable” manner of disclosure by the company. OpenAI notified authorities via an email sent to a public-facing disclosures mailbox, rather than by directly contacting the government. </p><p>In response, the government is setting up a taskforce to investigate the incident, conduct a review into AI-related cyber incidents, and consider whether a criminal offence may have occurred.  </p><p>A spokesperson for OpenAI said: "We notified the organizations and are providing technical information to support their investigations and help address potential security vulnerabilities." </p><h2 id="what-happened-in-the-openai-medicare-breach">What happened in the OpenAI Medicare breach?</h2><p>The infiltration happened in June, and OpenAI told the Australian government it had spotted the activity in August. OpenAI attributed the gap between discovery and notification to "validating and investigating the facts". </p><p>The agent in question had been tasked with finding information online about public medicine spending as part of an internal test. </p><p>The data accessed did not include individual private or financial data, as the portal in question doesn't include such information. However, non-public facing data including aggregate statistics and internal file names were viewed.</p><p>An OpenAI spokesperson said it had been looking for misaligned model activity when it spotted the incident. </p><p>"During this review, we identified activity involving several Australian government websites and services as our models attempted to look up answers, and available statistics for questions about Australia during an internal evaluation," the company said. "In the course of that, our models took actions we did not intend." </p><h2 id="could-openai-face-criminal-charges">Could OpenAI face criminal charges?</h2><p>Deputy prime minister Richard Marles <a href="https://www.bbc.co.uk/news/live/cvgl73pxgndwt" target="_blank"><u>told reporters</u></a> that the Medicare incident was "utterly unacceptable", adding that a task force will examine whether the law has been broken, as it "definitely does raise questions about whether the law has been broken in respect of this." </p><p>PM Albanese also <a href="https://www.pm.gov.au/media/press-conference-new-york" target="_blank"><u>said</u></a> that part of the investigation will consider whether the incident needs to be referred to local police. </p><p>In Australia, computer intrusions are prohibited by its cyber crime law, as is the creation and distribution of malicious software. The task force will also look into "whether or not the legal regime we have in place is fit for purpose in a world where we have an emerging AI capability." </p><h2 id="concerns-mount-over-rogue-ai-agents">Concerns mount over ‘rogue AI agents’ </h2><p>The admission by OpenAI marks the latest in a string of apparent ‘<a href="https://www.itpro.com/security/openai-and-anthropic-admit-rogue-ai-agents-did-more-than-first-thought">rogue AI</a>’ incidents involving the company and counterparts in the industry. </p><p>In July, the company admitted that agents had <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime">breached a Hugging Face production environment</a> after breaking out of a sandbox test environment. </p><p>Just last week, OpenAI revealed <a href="https://www.itpro.com/technology/artificial-intelligence/openai-reveals-six-more-rogue-ai-incidents"><u>six other instances of misaligned behavior by AI agents</u></a>. </p><p>Andrew Kay, director of systems engineering APJ at Illumio, said there will likely be “more high-profile breaches like this” unless robust guardrails are implemented to prevent agents ‘going rogue’.</p><p>“As increasingly autonomous and capable agents emerge, we cannot rely on the illusion of guardrails or assume an AI will always behave as intended,” he said. “It will take whatever action is necessary to achieve the task it has been set.”</p><p>“Rogue or misbehaving AI agents will only become more competent and more prevalent,” Kay added. “The priority must be ensuring that if one breaches a boundary, it cannot access sensitive material, cause serious damage or bring essential services to a standstill.”</p><p>Laura Ellis, senior vice president for artificial intelligence at Arctic Wolf, said the incident is a “timely example of a cyber risk businesses need to be preparing for now”. </p><p>“While the details of this incident are still being investigated, the security lesson is clear and security fundamentals remain unchanged,” she said. “All organizations deploying AI agents should secure them at least as tightly as any other identity: strict permissions, clear guardrails, continuous monitoring, and the ability to act fast when an agent steps outside its intended bounds.”</p><p>Ellis added that safeguards are “only part of the equation”, however. Disclosure of an incident within a “responsible timeline and with appropriate transparency” is vital. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Barracuda Networks launches new AI security solution for MSPs ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.itpro.com/business/business-strategy/barracuda-targets-channel-growth-with-partner-program-revamp"><u>Barracuda Networks</u></a> has announced the launch of a new AI security and governance solution for resource-constrained organizations and <a href="https://www.itpro.com/business/why-you-cant-rely-on-traditional-managed-service-providers"><u>managed service providers (MSPs)</u></a><u>.</u></p><p>Slated for availability from October 2026, Barracuda Data AI Security integrates AI visibility, data protection, threat defense, and governance capabilities into a single, easy-to-deploy offering.</p><p>Built on the company’s BarracudaONE platform, the solution aims to help businesses accelerate their AI adoption by securing sensitive data, enforcing responsible AI use, as well as demonstrating compliance.</p><p>The move comes as organizations continue to embrace AI technologies faster than they can implement safety and governance measures. According to <a href="https://blog.barracuda.com/2026/09/22/ai-security-governance-skills-gap" target="_blank"><u>recent findings from Barracuda Research</u></a>, nearly half of senior IT leaders believe their teams lack the necessary skills to securely govern AI that is already present across their businesses.</p><p>In an announcement, Barracuda chief product officer Neal Bradbury said the speed of AI adoption is creating “one of the most urgent new security and compliance challenges” as organizations struggle to keep pace.</p><p>“Organizations need a practical way to secure AI as a new attack surface, protect sensitive data, enforce responsible use, and demonstrate compliance,” he explained. </p><p>“At the same time, they need the confidence to embrace and accelerate AI adoption as a driver of productivity and innovation. Barracuda AI Data Security delivers those capabilities in a single, easy-to-deploy solution.”</p><h2 id="encouraging-safer-ai-adoption">Encouraging safer AI adoption</h2><p>AI Data Security is powered by Barracuda’s IQ AI engine and offers protection across more than 1,300 generative <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> – including Copilot, <a href="https://www.itpro.com/technology/artificial-intelligence/openai-just-revealed-what-people-really-use-chatgpt-for-and-70-percent-of-queries-have-nothing-to-do-with-work">ChatGPT</a>, <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal">Claude</a>, and Gemini.</p><p>The solution serves up a host of benefits for organizations, including full visibility into AI usage and the safe enabling of approved AI tools, alongside an ability to inspect prompts and uploads in real time.</p><p>Sensitive information such as passwords, customer data, and proprietary code are automatically blocked from reaching genAI services, Barracuda said, while AI threat detection guards against the likes of prompt injection, jailbreak attempts, and policy-violating topics.</p><p>Elsewhere, the offering also delivers a compliance-ready audit trail, capturing AI interactions with one-click exports for insurers and auditors, alongside flexible AI policies that enable tailored AI rules.</p><h2 id="strengthening-protection-for-msps">Strengthening protection for MSPs</h2><p>Barracuda said its new solution has been designed to help smaller businesses and MSPs that may be struggling with overcoming complexity, skill, and cost hurdles around AI adoption.</p><p>With rapid deployment in minutes, the offering eliminates the need for specialized AI security expertise thanks to familiar firewall style workflows, alongside guided configuration through Barracuda’s Bailey AI assistant. </p><p>MSPs can also leverage centralized multitenant management and bundled pricing designed to fit their existing service models.</p><p>Barracuda Data AI will be included in the vendor’s SecureEdge Premium Access platform at no extra cost, the firm added, while further tools will be added in due course.</p><p>“This is the first of several innovations that will expand our AI Security suite and help businesses unlock AI's full potential, securely,” Bradbury said. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/barracuda-networks-launches-new-ai-security-solution-for-msps</link>
                                                                            <description>
                            <![CDATA[ The easy-to-deploy offering combines security, governance, and compliance capabilities for resource-constrained organizations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Jwp4rQ65nGXczAcMdakMuU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zMGVGzLkXVKouNxp3mejej-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 08:54:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zMGVGzLkXVKouNxp3mejej-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of Barracuda Networks pictured on a sign at the 12th hole prior to the start of the Barracuda Championship at Tahoe Mountain Club&#039;s Old Greenwood course.]]></media:description>                                                            <media:text><![CDATA[Logo of Barracuda Networks pictured on a sign at the 12th hole prior to the start of the Barracuda Championship at Tahoe Mountain Club&#039;s Old Greenwood course.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of Barracuda Networks pictured on a sign at the 12th hole prior to the start of the Barracuda Championship at Tahoe Mountain Club&#039;s Old Greenwood course.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zMGVGzLkXVKouNxp3mejej-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/business-strategy/barracuda-targets-channel-growth-with-partner-program-revamp"><u>Barracuda Networks</u></a> has announced the launch of a new AI security and governance solution for resource-constrained organizations and <a href="https://www.itpro.com/business/why-you-cant-rely-on-traditional-managed-service-providers"><u>managed service providers (MSPs)</u></a><u>.</u></p><p>Slated for availability from October 2026, Barracuda Data AI Security integrates AI visibility, data protection, threat defense, and governance capabilities into a single, easy-to-deploy offering.</p><p>Built on the company’s BarracudaONE platform, the solution aims to help businesses accelerate their AI adoption by securing sensitive data, enforcing responsible AI use, as well as demonstrating compliance.</p><p>The move comes as organizations continue to embrace AI technologies faster than they can implement safety and governance measures. According to <a href="https://blog.barracuda.com/2026/09/22/ai-security-governance-skills-gap" target="_blank"><u>recent findings from Barracuda Research</u></a>, nearly half of senior IT leaders believe their teams lack the necessary skills to securely govern AI that is already present across their businesses.</p><p>In an announcement, Barracuda chief product officer Neal Bradbury said the speed of AI adoption is creating “one of the most urgent new security and compliance challenges” as organizations struggle to keep pace.</p><p>“Organizations need a practical way to secure AI as a new attack surface, protect sensitive data, enforce responsible use, and demonstrate compliance,” he explained. </p><p>“At the same time, they need the confidence to embrace and accelerate AI adoption as a driver of productivity and innovation. Barracuda AI Data Security delivers those capabilities in a single, easy-to-deploy solution.”</p><h2 id="encouraging-safer-ai-adoption">Encouraging safer AI adoption</h2><p>AI Data Security is powered by Barracuda’s IQ AI engine and offers protection across more than 1,300 generative <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> – including Copilot, <a href="https://www.itpro.com/technology/artificial-intelligence/openai-just-revealed-what-people-really-use-chatgpt-for-and-70-percent-of-queries-have-nothing-to-do-with-work">ChatGPT</a>, <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal">Claude</a>, and Gemini.</p><p>The solution serves up a host of benefits for organizations, including full visibility into AI usage and the safe enabling of approved AI tools, alongside an ability to inspect prompts and uploads in real time.</p><p>Sensitive information such as passwords, customer data, and proprietary code are automatically blocked from reaching genAI services, Barracuda said, while AI threat detection guards against the likes of prompt injection, jailbreak attempts, and policy-violating topics.</p><p>Elsewhere, the offering also delivers a compliance-ready audit trail, capturing AI interactions with one-click exports for insurers and auditors, alongside flexible AI policies that enable tailored AI rules.</p><h2 id="strengthening-protection-for-msps">Strengthening protection for MSPs</h2><p>Barracuda said its new solution has been designed to help smaller businesses and MSPs that may be struggling with overcoming complexity, skill, and cost hurdles around AI adoption.</p><p>With rapid deployment in minutes, the offering eliminates the need for specialized AI security expertise thanks to familiar firewall style workflows, alongside guided configuration through Barracuda’s Bailey AI assistant. </p><p>MSPs can also leverage centralized multitenant management and bundled pricing designed to fit their existing service models.</p><p>Barracuda Data AI will be included in the vendor’s SecureEdge Premium Access platform at no extra cost, the firm added, while further tools will be added in due course.</p><p>“This is the first of several innovations that will expand our AI Security suite and help businesses unlock AI's full potential, securely,” Bradbury said. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Quantum threats: What CISOs should do to prepare ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The threat from quantum is already on most security leaders’ radars, but experts argue the reality is growing near. Concerningly, the figures show a lack of preparation for quantum capabilities that will give adversaries the ability to break encryption. </p><p>Organizations could face a ticking quantum time bomb, according to <a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them"><u>research</u></a> from DigiCert, with the vast majority of firms aware that they aren’t properly prepared. While an overwhelming 85% of IT and <a href="https://www.itpro.com/security/is-the-ciso-role-in-crisis"><u>security leaders</u></a> believe that quantum computing advances will break existing security standards within a decade, only 7% have deployed quantum-safe certificates so far.</p><p>According to recent data from <a href="https://urldefense.com/v3/__https:/www.ibm.com/reports/data-breach__;!!DlCMXiNAtWOc!yCNGVEso8H_eMpPtMB1VtfDUQNhSZB49j0FUHiQ-jZYvh4p18xlZZ82p3ZSG3shyoHFBy0ssZidT9KGvM4Se04R9yg$"><u>IBM's Cost of a Data Breach Report</u></a>, 69%of organizations have no plan in place for <a href="https://www.itpro.com/business/get-started-on-post-quantum-encryption-organizations-warned"><u>post-quantum cryptography</u></a> (PQC).</p><p>With ‘harvest now, decrypt later’ attacks a real risk for firms, what steps should CISOs be taking now to ensure they are prepared? </p><h2 id="the-quantum-timeline">The quantum timeline </h2><p>No one can give an exact date for when quantum computing will be able to break today’s widely-used public key cryptography, but the risk is close enough that governments, standards bodies and major technology companies are already acting.</p><p>The US National Institute of Standards and Technology (NIST) released its first three final post-quantum cryptography <a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards"><u>standards</u></a> in 2024, while the UK’s National Cyber Security Centre (NCSC) has set a <a href="https://www.ncsc.gov.uk/guidance/pqc-migration-timelines"><u>target</u></a> for organizations to complete PQC migration by 2035. </p><p>Technology giants such as <a href="https://blog.cloudflare.com/post-quantum-roadmap/"><u>Cloudflare</u></a> and <a href="https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/"><u>Google</u></a> are setting their own post-quantum security milestones for 2029.</p><p>The quantum threat is often compared to the <a href="https://www.itpro.com/bugs/32143/the-facts-of-the-y2k-bug-and-why-it-was-nothing-like-brexit"><u>millennium “bug”</u></a> (Y2K). It has even earned its own moniker: “Y2Q”, or “Q-Day”. </p><p>But unlike Y2K, there won’t be “a single moment of failure”, says Mark Hughes, global managing partner, cybersecurity services at IBM. He says the reality could see risks materialize over multiple years. “Different cryptographic systems will fail earlier than others, and that all depends on design and key size,” he predicts.</p><h2 id="harvest-now-decrypt-later">Harvest now, decrypt later</h2><p>DigiCert’s survey highlights concerns about ‘harvest now, decrypt later’ attacks, where adversaries steal information for use at a later date. Over 80% say at least some of their encrypted data is vulnerable, with around one-third reckoning more than a quarter could be at risk.</p><p>Simon Pamplin, chief technology officer at Certes, describes how attackers do not need a large-scale quantum computer today to create a future breach. “They can collect encrypted data now, store it, and wait until the capability exists to decrypt it.”</p><p>He says the quantum threat timeline is “much shorter than many organizations assume”.</p><p>“Whether a cryptographically relevant quantum computer arrives in 2029, 2035, or later, the data being harvested today may still be valuable when that moment arrives.”</p><p>Firms are often unaware of the type of data at risk. “People often think about passwords and payment details, but they're usually not the biggest concern,” says Tristan Shortland, CTO of Infinity Group. He says the most exposed data is information with a long shelf life: “Intellectual property, product designs, merger and acquisition discussions, healthcare records, legal documents and sensitive communications that retain value for years.”</p><p>This matters most in sectors with complex operational or national security requirements, including critical national infrastructure, financial services, energy and manufacturing, says Ben Packman, CSO at PQShield, which helped to create the quantum standards being enforced by NIST and the NCSC. “One unsupported system, legacy platform or unprepared supplier can create risk across a much wider technology estate.”</p><p>At the same time, quantum poses other threats beyond attackers stealing data to decrypt at a later point. “If future quantum computers are able to break the cryptography behind digital signatures and certificates, attackers could potentially make malicious software, fake updates or fraudulent communications appear legitimate,” warns Packman.</p><h2 id="mitigating-the-quantum-threat">Mitigating the quantum threat</h2><p>With the risks in mind, it makes sense to start preparing to secure data now to mitigate the quantum threat. This means building cryptographic agility into the systems, suppliers and upgrade cycles organizations already rely on, experts say.</p><p>“Organizations need cryptography that is agile enough to evolve as standards mature, threats change, and new implementation requirements emerge,” advises Packman.</p><p>He believes preparation starts with understanding where quantum-vulnerable public-key cryptography is used, which systems are most exposed, and which suppliers' systems depend on.</p><p>Pamplin concurs. From there, companies should “prioritize long-life and high-value data”, rather than “trying to treat everything equally”, he advises. </p><p>“80% of your data loss risk sits within 20% of your applications. That is where you should focus first.”</p><p>NIST calls for vulnerable public key algorithms to start being deprecated after 2030 and generally disallowed after 2035. Yet preparation must come sooner, says Paul Holt, group VP EMEA at DigiCert. </p><p>He warns that the process of inventorying an organization’s use of cryptography across the enterprise, creating post-quantum roadmaps for each use case, and executing the transition “can span many years”. </p><p>At the same time, he points out that beyond understanding quantum, security leaders are “struggling to convince the rest of the business that budget and resources are needed now”.</p><p>This is where crypto-agility becomes essential, according to Holt. “Weathering the transition to a quantum-safe posture demands the ability to adapt and scale digital certificate management. Meanwhile, organizations must migrate cryptography to approved post-quantum algorithms.”</p><p></p><p>Finally, he says certificates must be “immediately discoverable and manageable continuously and at scale”.</p><p>Yet when considering quantum preparedness, it’s also important not to rush. The quality of implementation will matter just as much as the standards themselves,” says Packman. </p><p>“Replacing cryptography as part of a planned upgrade is cheaper and less disruptive than retrofitting it later under tighter deadlines.”</p><p>He believes every scheduled technology refresh is “a chance to introduce quantum-safe capability, assess supplier roadmaps, validate implementations or retire systems that may become difficult to support later”.</p><p>While quantum attacks are still likely to be some years away, experts think IT and security leaders should start to view the area as part of the bigger picture. Shortland believes quantum is increasingly a governance issue. </p><p>“Boards routinely assess climate, geopolitical and supply chain risk over a 10-year horizon,” Packman adds. </p><p>“Quantum belongs in that category because it has the potential to undermine decisions being made about data today.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/quantum-threats-what-cisos-should-do-to-prepare</link>
                                                                            <description>
                            <![CDATA[ The quantum threat might seem years away, but the risk of ‘harvest now, decrypt later’ attacks is real. Here’s what CISOs should do to prepare... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qvDK9vahBZoiqDCGtkZmpQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 24 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:description>                                                            <media:text><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The threat from quantum is already on most security leaders’ radars, but experts argue the reality is growing near. Concerningly, the figures show a lack of preparation for quantum capabilities that will give adversaries the ability to break encryption. </p><p>Organizations could face a ticking quantum time bomb, according to <a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them"><u>research</u></a> from DigiCert, with the vast majority of firms aware that they aren’t properly prepared. While an overwhelming 85% of IT and <a href="https://www.itpro.com/security/is-the-ciso-role-in-crisis"><u>security leaders</u></a> believe that quantum computing advances will break existing security standards within a decade, only 7% have deployed quantum-safe certificates so far.</p><p>According to recent data from <a href="https://urldefense.com/v3/__https:/www.ibm.com/reports/data-breach__;!!DlCMXiNAtWOc!yCNGVEso8H_eMpPtMB1VtfDUQNhSZB49j0FUHiQ-jZYvh4p18xlZZ82p3ZSG3shyoHFBy0ssZidT9KGvM4Se04R9yg$"><u>IBM's Cost of a Data Breach Report</u></a>, 69%of organizations have no plan in place for <a href="https://www.itpro.com/business/get-started-on-post-quantum-encryption-organizations-warned"><u>post-quantum cryptography</u></a> (PQC).</p><p>With ‘harvest now, decrypt later’ attacks a real risk for firms, what steps should CISOs be taking now to ensure they are prepared? </p><h2 id="the-quantum-timeline">The quantum timeline </h2><p>No one can give an exact date for when quantum computing will be able to break today’s widely-used public key cryptography, but the risk is close enough that governments, standards bodies and major technology companies are already acting.</p><p>The US National Institute of Standards and Technology (NIST) released its first three final post-quantum cryptography <a href="https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards"><u>standards</u></a> in 2024, while the UK’s National Cyber Security Centre (NCSC) has set a <a href="https://www.ncsc.gov.uk/guidance/pqc-migration-timelines"><u>target</u></a> for organizations to complete PQC migration by 2035. </p><p>Technology giants such as <a href="https://blog.cloudflare.com/post-quantum-roadmap/"><u>Cloudflare</u></a> and <a href="https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/"><u>Google</u></a> are setting their own post-quantum security milestones for 2029.</p><p>The quantum threat is often compared to the <a href="https://www.itpro.com/bugs/32143/the-facts-of-the-y2k-bug-and-why-it-was-nothing-like-brexit"><u>millennium “bug”</u></a> (Y2K). It has even earned its own moniker: “Y2Q”, or “Q-Day”. </p><p>But unlike Y2K, there won’t be “a single moment of failure”, says Mark Hughes, global managing partner, cybersecurity services at IBM. He says the reality could see risks materialize over multiple years. “Different cryptographic systems will fail earlier than others, and that all depends on design and key size,” he predicts.</p><h2 id="harvest-now-decrypt-later">Harvest now, decrypt later</h2><p>DigiCert’s survey highlights concerns about ‘harvest now, decrypt later’ attacks, where adversaries steal information for use at a later date. Over 80% say at least some of their encrypted data is vulnerable, with around one-third reckoning more than a quarter could be at risk.</p><p>Simon Pamplin, chief technology officer at Certes, describes how attackers do not need a large-scale quantum computer today to create a future breach. “They can collect encrypted data now, store it, and wait until the capability exists to decrypt it.”</p><p>He says the quantum threat timeline is “much shorter than many organizations assume”.</p><p>“Whether a cryptographically relevant quantum computer arrives in 2029, 2035, or later, the data being harvested today may still be valuable when that moment arrives.”</p><p>Firms are often unaware of the type of data at risk. “People often think about passwords and payment details, but they're usually not the biggest concern,” says Tristan Shortland, CTO of Infinity Group. He says the most exposed data is information with a long shelf life: “Intellectual property, product designs, merger and acquisition discussions, healthcare records, legal documents and sensitive communications that retain value for years.”</p><p>This matters most in sectors with complex operational or national security requirements, including critical national infrastructure, financial services, energy and manufacturing, says Ben Packman, CSO at PQShield, which helped to create the quantum standards being enforced by NIST and the NCSC. “One unsupported system, legacy platform or unprepared supplier can create risk across a much wider technology estate.”</p><p>At the same time, quantum poses other threats beyond attackers stealing data to decrypt at a later point. “If future quantum computers are able to break the cryptography behind digital signatures and certificates, attackers could potentially make malicious software, fake updates or fraudulent communications appear legitimate,” warns Packman.</p><h2 id="mitigating-the-quantum-threat">Mitigating the quantum threat</h2><p>With the risks in mind, it makes sense to start preparing to secure data now to mitigate the quantum threat. This means building cryptographic agility into the systems, suppliers and upgrade cycles organizations already rely on, experts say.</p><p>“Organizations need cryptography that is agile enough to evolve as standards mature, threats change, and new implementation requirements emerge,” advises Packman.</p><p>He believes preparation starts with understanding where quantum-vulnerable public-key cryptography is used, which systems are most exposed, and which suppliers' systems depend on.</p><p>Pamplin concurs. From there, companies should “prioritize long-life and high-value data”, rather than “trying to treat everything equally”, he advises. </p><p>“80% of your data loss risk sits within 20% of your applications. That is where you should focus first.”</p><p>NIST calls for vulnerable public key algorithms to start being deprecated after 2030 and generally disallowed after 2035. Yet preparation must come sooner, says Paul Holt, group VP EMEA at DigiCert. </p><p>He warns that the process of inventorying an organization’s use of cryptography across the enterprise, creating post-quantum roadmaps for each use case, and executing the transition “can span many years”. </p><p>At the same time, he points out that beyond understanding quantum, security leaders are “struggling to convince the rest of the business that budget and resources are needed now”.</p><p>This is where crypto-agility becomes essential, according to Holt. “Weathering the transition to a quantum-safe posture demands the ability to adapt and scale digital certificate management. Meanwhile, organizations must migrate cryptography to approved post-quantum algorithms.”</p><p></p><p>Finally, he says certificates must be “immediately discoverable and manageable continuously and at scale”.</p><p>Yet when considering quantum preparedness, it’s also important not to rush. The quality of implementation will matter just as much as the standards themselves,” says Packman. </p><p>“Replacing cryptography as part of a planned upgrade is cheaper and less disruptive than retrofitting it later under tighter deadlines.”</p><p>He believes every scheduled technology refresh is “a chance to introduce quantum-safe capability, assess supplier roadmaps, validate implementations or retire systems that may become difficult to support later”.</p><p>While quantum attacks are still likely to be some years away, experts think IT and security leaders should start to view the area as part of the bigger picture. Shortland believes quantum is increasingly a governance issue. </p><p>“Boards routinely assess climate, geopolitical and supply chain risk over a 10-year horizon,” Packman adds. </p><p>“Quantum belongs in that category because it has the potential to undermine decisions being made about data today.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft takes down ‘EvilTokens’ cyber crime service ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft has disrupted the EvilTokens cyber crime platform in a coordinated campaign that saw 50 websites seized and two men arrested in the UK.</p><p>The EvilTokens <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing as a service (PhaaS)</a> platform emerged in February on Telegram, giving cyber criminals AI the ability to tailor phishing lures and analyze compromised inboxes to identify high-value targets.</p><p>In the short time it’s been up and running, the platform has been used to compromise more than 12,000 inboxes at more than 10,000 organizations. </p><p>Campaigns have targeted various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with most activity in the US, Canada, the UK, Australia, India, and France.</p><p>Customers paid a $1,500 fee up front to use the service, with a recurring $500 subscription for continued access to the kit and control panel. </p><p>This kit offered further products, including Antibot redirector, B2B Sender, Office 365 Capture Link, and a Simple Mail Transfer Protocol (SMTP) Sender, each of which carried additional monthly fees.</p><h2 id="what-hackers-got-with-eviltokens">What hackers got with EvilTokens</h2><p>Subscribers were offered personalized lures, with AI used to create targeted phishing emails that were specifically aligned to the target’s role. </p><p>According to Microsoft, themes used to increase the chances of a response included document signing services, its own cloud services, third-party services such as cloud identity, file hosting and payment or invoicing, as well as other miscellaneous services like voicemail and eFax.</p><p>Notably, the service was centered around an AI-style <a href="https://www.itpro.com/networking/27171/what-is-a-chatbot">chatbot </a>that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other situations where fraud was most likely to succeed. </p><p>It could even recommend strategies for carrying out fraud, including drafting messages that impersonated trusted contacts to help criminals trick their victims into taking action. </p><p>"AI was not simply <a href="https://www.itpro.com/technology/artificial-intelligence/six-generative-ai-cyber-security-threats-and-how-to-mitigate-them">helping attackers write more convincing messages</a>. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible," said Steven Masada, associate general counsel and general manager at Microsoft’s Digital Crimes Unit.  </p><h2 id="how-microsoft-tackled-eviltokens">How Microsoft tackled EvilTokens</h2><p>Microsoft, with authorization from the US District Court for the Eastern District of Virginia and the help of several other companies, has now seized 50 websites used to operate the service. </p><p>More than 150 other domains tied to its supporting infrastructure have also been seized.</p><p>"While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service," Masada said. </p><p>Cloudflare, meanwhile, was able to identify the complete list of domain infrastructure and hundreds of Cloudflare accounts used by EvilTokens’ customers. </p><p>It carried out a technical sweep, blocking hundreds of domains and killing malicious Cloudflare Worker scripts. Where infrastructure couldn't be legally seized, it made use of interstitial warning pages.</p><p>As a result of the operation, the UK Metropolitan Police Service’s cyber crime team has now arrested two men, aged 32 and 38, suspected of being involved. </p><p>Authorities also seized digital devices and other items for examination. Both men have been released on police bail while the investigation continues. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-crime/microsoft-takes-down-eviltokens-hacker-service-that-used-ai-to-decide-who-to-target-who-to-impersonate-and-how-to-most-effectively-exploit-victims</link>
                                                                            <description>
                            <![CDATA[ In just six months, the EvilTokens phishing as a service platform hit thousands of organizations worldwide ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JwALktbjXJkwtgxuF8BP3Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hnJfsmgKFbPVuGP5idio46-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 23 Sep 2026 12:52:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/hnJfsmgKFbPVuGP5idio46-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Microsoft logo and branding illuminated against a dark backdrop on the company&#039;s vendor stall at Fira Gran Via during Mobile World Congress (MWC) 2026.]]></media:description>                                                            <media:text><![CDATA[Microsoft logo and branding illuminated against a dark backdrop on the company&#039;s vendor stall at Fira Gran Via during Mobile World Congress (MWC) 2026.]]></media:text>
                                <media:title type="plain"><![CDATA[Microsoft logo and branding illuminated against a dark backdrop on the company&#039;s vendor stall at Fira Gran Via during Mobile World Congress (MWC) 2026.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hnJfsmgKFbPVuGP5idio46-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has disrupted the EvilTokens cyber crime platform in a coordinated campaign that saw 50 websites seized and two men arrested in the UK.</p><p>The EvilTokens <a href="https://www.itpro.com/security/cyber-security/368284/what-is-phishing-as-a-service-phaas">phishing as a service (PhaaS)</a> platform emerged in February on Telegram, giving cyber criminals AI the ability to tailor phishing lures and analyze compromised inboxes to identify high-value targets.</p><p>In the short time it’s been up and running, the platform has been used to compromise more than 12,000 inboxes at more than 10,000 organizations. </p><p>Campaigns have targeted various industries, including wholesale distribution, construction, financial services, real estate, higher education, and healthcare, with most activity in the US, Canada, the UK, Australia, India, and France.</p><p>Customers paid a $1,500 fee up front to use the service, with a recurring $500 subscription for continued access to the kit and control panel. </p><p>This kit offered further products, including Antibot redirector, B2B Sender, Office 365 Capture Link, and a Simple Mail Transfer Protocol (SMTP) Sender, each of which carried additional monthly fees.</p><h2 id="what-hackers-got-with-eviltokens">What hackers got with EvilTokens</h2><p>Subscribers were offered personalized lures, with AI used to create targeted phishing emails that were specifically aligned to the target’s role. </p><p>According to Microsoft, themes used to increase the chances of a response included document signing services, its own cloud services, third-party services such as cloud identity, file hosting and payment or invoicing, as well as other miscellaneous services like voicemail and eFax.</p><p>Notably, the service was centered around an AI-style <a href="https://www.itpro.com/networking/27171/what-is-a-chatbot">chatbot </a>that could analyze a victim’s inbox and help criminals identify trusted relationships, payment authorizations, and sensitive responsibilities, as well as other situations where fraud was most likely to succeed. </p><p>It could even recommend strategies for carrying out fraud, including drafting messages that impersonated trusted contacts to help criminals trick their victims into taking action. </p><p>"AI was not simply <a href="https://www.itpro.com/technology/artificial-intelligence/six-generative-ai-cyber-security-threats-and-how-to-mitigate-them">helping attackers write more convincing messages</a>. It helped them decide who to target, who to impersonate, and how to most effectively exploit the relationship to extract as much money as possible," said Steven Masada, associate general counsel and general manager at Microsoft’s Digital Crimes Unit.  </p><h2 id="how-microsoft-tackled-eviltokens">How Microsoft tackled EvilTokens</h2><p>Microsoft, with authorization from the US District Court for the Eastern District of Virginia and the help of several other companies, has now seized 50 websites used to operate the service. </p><p>More than 150 other domains tied to its supporting infrastructure have also been seized.</p><p>"While EvilTokens used AI to identify targets and prioritize fraud opportunities, Microsoft investigators used reverse engineering and AI-powered tools to analyze evidence, accelerate the investigation, and identify the infrastructure supporting the service," Masada said. </p><p>Cloudflare, meanwhile, was able to identify the complete list of domain infrastructure and hundreds of Cloudflare accounts used by EvilTokens’ customers. </p><p>It carried out a technical sweep, blocking hundreds of domains and killing malicious Cloudflare Worker scripts. Where infrastructure couldn't be legally seized, it made use of interstitial warning pages.</p><p>As a result of the operation, the UK Metropolitan Police Service’s cyber crime team has now arrested two men, aged 32 and 38, suspected of being involved. </p><p>Authorities also seized digital devices and other items for examination. Both men have been released on police bail while the investigation continues. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC talks up agents for cyber defense  – but there's an 'inconvenient truth' businesses need to accept ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has issued <a href="https://www.ncsc.gov.uk/blogs/one-does-not-simply-defend-agentically" target="_blank"><u>advice</u></a> on how cybersecurity professionals can adopt agentic AI to help automate security tasks and manage risks. </p><p>Using AI automation for defense isn't generally about overcoming technical challenges, according to Dave Chismon, NCSC CTO for architecture, but more of a question of organizational politics, meaning that defenders can't simply put AI to work in the same way attackers can. </p><p>"This is an inconvenient truth, as it suggests that the threat from AI-enabled cyber attacks will grow, whilst autonomous / agentic cyber defense might struggle to keep up unless we approach things differently," he said.</p><p>"Rather than trying to mimic attackers’ use of agentic tooling (and risk breaking things), defenders need to solve the problem by explicitly considering the constraints."</p><p>Notably, the NCSC said automation can involve offensive techniques being applied defensively, such as penetration testing and vulnerability research or discovery. </p><p>This generally happens in a way that minimizes risks to the business; applications are tested before they go live, and vulnerabilities are handed to development teams to fix.</p><p>Elsewhere, technical and dynamic approaches can be used for cyber defence - but also need evaluating from a business point of view. </p><p>"Establishing a SOC is also typically a lengthy (and often expensive) process. Legal aspects and policies need to be agreed, and data then exported from live systems to a new platform where malicious activity can be detected and triaged before the team takes action," said Chismon.</p><p>Both mean doing a lot of work up front to show that vulnerability detection or missing patches won't harm the business.</p><h2 id="a-new-framework-for-agentic-ai-adoption">A new framework for agentic AI adoption</h2><p>To help with this, the NCSC has outlined a framework for estimating the 'riskiness' of a defensive action and identifying the lowest-risk actions that can be automated –  these are often tasks that involve advising a human, rather than affecting a system directly.</p><p>Some of this will be covered by the government's planned <a href="https://www.itpro.com/security/the-ncsc-wants-to-build-an-ai-powered-cyber-shield-to-protect-the-uk-from-hackers-heres-how-itll-work"><u>Cyber Shield</u></a>, a national-scale agentic cyber defence ecosystem, with its ‘AI for Cyber Defence’ problem book expected soon. </p><p>However, Chismon warned that more research is needed on agentic AI, particularly in terms of how to deterministically prove that ‘low risk’ actions really are low risk. </p><p>Examples include using AI to help analyse traffic logs and show conclusively that the organization does know all the routes clients connect by, or establishing whether AI can reverse engineer or otherwise assess a system and its binaries to show exactly which network calls it could ever make.</p><p>"Answering these questions will give us, and the organizations we protect, the confidence to take automated defensive actions. Furthermore, it opens up the chance to automate the hardening of systems and reduce attack surfaces and exposure, which will be crucial in combating AI-enabled cyber attacks," said Chismon.</p><p>"All these efforts will take time, effort, and research. Organizations cannot risk just waiting for agentic defence to roll in and protect them; they also need to be focussing on improving their security the traditional way."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ncsc-talks-up-agents-for-cyber-defense-but-theres-an-inconvenient-truth-businesses-need-to-accept</link>
                                                                            <description>
                            <![CDATA[ Cyber defenders need to identify the lowest-risk actions that can be automated before making decisions about adoption ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UFAKsoY2PP9FocHPgEYNjX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 14:42:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:description>                                                            <media:text><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:text>
                                <media:title type="plain"><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do">National Cyber Security Centre (NCSC)</a> has issued <a href="https://www.ncsc.gov.uk/blogs/one-does-not-simply-defend-agentically" target="_blank"><u>advice</u></a> on how cybersecurity professionals can adopt agentic AI to help automate security tasks and manage risks. </p><p>Using AI automation for defense isn't generally about overcoming technical challenges, according to Dave Chismon, NCSC CTO for architecture, but more of a question of organizational politics, meaning that defenders can't simply put AI to work in the same way attackers can. </p><p>"This is an inconvenient truth, as it suggests that the threat from AI-enabled cyber attacks will grow, whilst autonomous / agentic cyber defense might struggle to keep up unless we approach things differently," he said.</p><p>"Rather than trying to mimic attackers’ use of agentic tooling (and risk breaking things), defenders need to solve the problem by explicitly considering the constraints."</p><p>Notably, the NCSC said automation can involve offensive techniques being applied defensively, such as penetration testing and vulnerability research or discovery. </p><p>This generally happens in a way that minimizes risks to the business; applications are tested before they go live, and vulnerabilities are handed to development teams to fix.</p><p>Elsewhere, technical and dynamic approaches can be used for cyber defence - but also need evaluating from a business point of view. </p><p>"Establishing a SOC is also typically a lengthy (and often expensive) process. Legal aspects and policies need to be agreed, and data then exported from live systems to a new platform where malicious activity can be detected and triaged before the team takes action," said Chismon.</p><p>Both mean doing a lot of work up front to show that vulnerability detection or missing patches won't harm the business.</p><h2 id="a-new-framework-for-agentic-ai-adoption">A new framework for agentic AI adoption</h2><p>To help with this, the NCSC has outlined a framework for estimating the 'riskiness' of a defensive action and identifying the lowest-risk actions that can be automated –  these are often tasks that involve advising a human, rather than affecting a system directly.</p><p>Some of this will be covered by the government's planned <a href="https://www.itpro.com/security/the-ncsc-wants-to-build-an-ai-powered-cyber-shield-to-protect-the-uk-from-hackers-heres-how-itll-work"><u>Cyber Shield</u></a>, a national-scale agentic cyber defence ecosystem, with its ‘AI for Cyber Defence’ problem book expected soon. </p><p>However, Chismon warned that more research is needed on agentic AI, particularly in terms of how to deterministically prove that ‘low risk’ actions really are low risk. </p><p>Examples include using AI to help analyse traffic logs and show conclusively that the organization does know all the routes clients connect by, or establishing whether AI can reverse engineer or otherwise assess a system and its binaries to show exactly which network calls it could ever make.</p><p>"Answering these questions will give us, and the organizations we protect, the confidence to take automated defensive actions. Furthermore, it opens up the chance to automate the hardening of systems and reduce attack surfaces and exposure, which will be crucial in combating AI-enabled cyber attacks," said Chismon.</p><p>"All these efforts will take time, effort, and research. Organizations cannot risk just waiting for agentic defence to roll in and protect them; they also need to be focussing on improving their security the traditional way."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber teams are being pushed to breaking point – and AI is doing little to alleviate strain  ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.itpro.com/security/cybersecurity-teams-are-wasting-time-money-and-effort-dealing-with-tool-sprawl-and-multi-vendor-ecosystems">Cybersecurity teams</a> are being pushed to breaking point, according to new research, with sluggish workforce growth struggling to keep pace with a rising tide of attacks. </p><p>In a new survey from <a href="https://www.itpro.com/security/cybersecurity-teams-are-understaffed-overworked-and-underfunded-and-it-s-taking-a-massive-toll-on-mental-health"><u>ISACA</u></a>, more than one-third (38%) of European IT and cyber professionals said their organization has faced more attacks this year than all of 2025. </p><p>Yet despite escalating threats, more than half (56%) said they remain chronically understaffed and underfunded (55%). </p><p>Chris Dimitriadis, global chief strategy officer at ISACA, said the survey shows many organizations are struggling to adapt to an increasingly perilous threat landscape. </p><p>“The growing gap between rising threats and under-resourcing for cybersecurity is taking a toll on the people tasked with managing it,” he commented. “Too often we are seeing budgets being sunk into crisis response, but there’s still a distinct lack of investment in the workforce, training, and resources needed to prevent attacks and protect organizations in the first place.”</p><p>Dimitriadis added that better funding and a “clear path for improving <a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>cyber resilience</u></a>” should be a C-suite priority. </p><p>Regardless of repeated warnings over <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cybersecurity</u></a> threats, things are expected to deteriorate further, according to ISACA. More than half (54%) of cybersecurity professionals said they expect their organization to experience a serious cyber attack within the next year. </p><h2 id="cybersecurity-teams-face-evolving-threats">Cybersecurity teams face evolving threats</h2><p>The types of threats teams face are also expanding and accelerating, which is placing additional pressure on practitioners. <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">Social engineering</a> attacks ranked as the most common threat encountered by teams, cited by 46% of respondents. </p><p>Crucially, these techniques are now being supported and supercharged by AI, creating new risks for teams and allowing threat actors to ramp up and refine targeting. </p><p>The findings from ISACA follow <a href="https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026"><u>analysis from Kaseya</u></a> earlier this year, which specifically highlighted the use of AI in phishing attacks. Research from the firm warned that AI-generated phishing has now “become the baseline” for threat actors. </p><p>All told, ISACA said AI presents “difficult and serious challenges” for cybersecurity teams. Attacks that previously took days or weeks are now being automated at scale, allowing threat actors to “operate at the speed of intent”. </p><h2 id="fighting-fire-with-fire">Fighting fire with fire</h2><p>While AI-powered threats pose a serious risk for teams, ISACA noted that the technology is helping them keep pace with escalating threats. </p><p>In a statement, the association said AI’s “exponential growth has proved to be an aid” for practitioners – and use of the technology in frontline operations is expanding rapidly. </p><p>More than one-third (37%) of respondents now <a href="https://www.itpro.com/security/enterprises-cant-keep-a-lid-on-surging-cyber-incident-costs">use AI to automate threat detection</a> and response, for example. While this marks just an 8% increase compared to 2025 figures, it highlights a step in the right direction for teams. </p><p>“AI is also being used for endpoint security by 29% and to automate routine security tasks by 35%,” ISACA said in a statement. </p><h2 id="growing-stress">Growing stress</h2><p>This combination of pressures on cyber teams is having a direct impact on workforce morale, according to ISACA. Nearly three-quarters (72%) of respondents said their role is now more stressful compared to five years ago. </p><p>Threat landscape complexity was cited as the leading factor behind this, cited by 72% of practitioners. However, other reasons cited include unrealistic expectations and too much work (57%) and a lack of relevant skills training (35%). </p><p>Notably, while cyber professionals have raised repeated concerns on this front, ISACA said 21% of companies still take “no action” to mitigate burnout. </p><p>Burnout has been a <a href="https://www.itpro.com/security/fighting-the-always-on-culture-thats-savaging-mental-health-in-cyber-security"><u>long-running issue in the cybersecurity sector</u></a>, and one that continues to plague organizations. </p><p>An April 2026 <a href="https://issa.org/life-and-times-of-cybersecurity-professionals-volume-viii/" target="_blank"><u>survey by the Information Systems Security Association (ISSA)</u></a> aligns closely with ISACA’s research. Nearly seven-in-ten workers revealed their jobs have become more difficult over the last two years, for example. </p><p>Nearly half of cyber professionals said they are considering leaving their job, with 53% citing stress and 34% highlighting poor work-life balance. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/rising-threats-and-under-resourcing-for-cybersecurity-is-taking-a-toll-on-the-people-tasked-with-managing-it-cyber-teams-are-being-pushed-to-breaking-point-and-ai-is-doing-little-to-alleviate-strain</link>
                                                                            <description>
                            <![CDATA[ An increasingly perilous threat landscape and lack of funding means cyber teams are being stretched too thin ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h84TjDKMsVdg96NgUe84P7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JGevYoMiLSmeszVdWsZpEQ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 10:15:43 +0000</pubDate>                                                                                                                                <updated>Tue, 22 Sep 2026 10:17:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JGevYoMiLSmeszVdWsZpEQ-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A male cybersecurity professional sitting at a desk in dimly lit room with hands placed on head with a stressed expression.]]></media:description>                                                            <media:text><![CDATA[A male cybersecurity professional sitting at a desk in dimly lit room with hands placed on head with a stressed expression.]]></media:text>
                                <media:title type="plain"><![CDATA[A male cybersecurity professional sitting at a desk in dimly lit room with hands placed on head with a stressed expression.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JGevYoMiLSmeszVdWsZpEQ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cybersecurity-teams-are-wasting-time-money-and-effort-dealing-with-tool-sprawl-and-multi-vendor-ecosystems">Cybersecurity teams</a> are being pushed to breaking point, according to new research, with sluggish workforce growth struggling to keep pace with a rising tide of attacks. </p><p>In a new survey from <a href="https://www.itpro.com/security/cybersecurity-teams-are-understaffed-overworked-and-underfunded-and-it-s-taking-a-massive-toll-on-mental-health"><u>ISACA</u></a>, more than one-third (38%) of European IT and cyber professionals said their organization has faced more attacks this year than all of 2025. </p><p>Yet despite escalating threats, more than half (56%) said they remain chronically understaffed and underfunded (55%). </p><p>Chris Dimitriadis, global chief strategy officer at ISACA, said the survey shows many organizations are struggling to adapt to an increasingly perilous threat landscape. </p><p>“The growing gap between rising threats and under-resourcing for cybersecurity is taking a toll on the people tasked with managing it,” he commented. “Too often we are seeing budgets being sunk into crisis response, but there’s still a distinct lack of investment in the workforce, training, and resources needed to prevent attacks and protect organizations in the first place.”</p><p>Dimitriadis added that better funding and a “clear path for improving <a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>cyber resilience</u></a>” should be a C-suite priority. </p><p>Regardless of repeated warnings over <a href="https://www.itpro.com/security/28133/what-is-cyber-security"><u>cybersecurity</u></a> threats, things are expected to deteriorate further, according to ISACA. More than half (54%) of cybersecurity professionals said they expect their organization to experience a serious cyber attack within the next year. </p><h2 id="cybersecurity-teams-face-evolving-threats">Cybersecurity teams face evolving threats</h2><p>The types of threats teams face are also expanding and accelerating, which is placing additional pressure on practitioners. <a href="https://www.itpro.com/security/phishing/why-social-engineering-is-such-a-problem-and-how-your-business-can-protect-itself">Social engineering</a> attacks ranked as the most common threat encountered by teams, cited by 46% of respondents. </p><p>Crucially, these techniques are now being supported and supercharged by AI, creating new risks for teams and allowing threat actors to ramp up and refine targeting. </p><p>The findings from ISACA follow <a href="https://www.itpro.com/security/phishing/ai-generated-phishing-became-the-baseline-for-hackers-last-year-kaseya-warns-its-going-to-get-worse-in-2026"><u>analysis from Kaseya</u></a> earlier this year, which specifically highlighted the use of AI in phishing attacks. Research from the firm warned that AI-generated phishing has now “become the baseline” for threat actors. </p><p>All told, ISACA said AI presents “difficult and serious challenges” for cybersecurity teams. Attacks that previously took days or weeks are now being automated at scale, allowing threat actors to “operate at the speed of intent”. </p><h2 id="fighting-fire-with-fire">Fighting fire with fire</h2><p>While AI-powered threats pose a serious risk for teams, ISACA noted that the technology is helping them keep pace with escalating threats. </p><p>In a statement, the association said AI’s “exponential growth has proved to be an aid” for practitioners – and use of the technology in frontline operations is expanding rapidly. </p><p>More than one-third (37%) of respondents now <a href="https://www.itpro.com/security/enterprises-cant-keep-a-lid-on-surging-cyber-incident-costs">use AI to automate threat detection</a> and response, for example. While this marks just an 8% increase compared to 2025 figures, it highlights a step in the right direction for teams. </p><p>“AI is also being used for endpoint security by 29% and to automate routine security tasks by 35%,” ISACA said in a statement. </p><h2 id="growing-stress">Growing stress</h2><p>This combination of pressures on cyber teams is having a direct impact on workforce morale, according to ISACA. Nearly three-quarters (72%) of respondents said their role is now more stressful compared to five years ago. </p><p>Threat landscape complexity was cited as the leading factor behind this, cited by 72% of practitioners. However, other reasons cited include unrealistic expectations and too much work (57%) and a lack of relevant skills training (35%). </p><p>Notably, while cyber professionals have raised repeated concerns on this front, ISACA said 21% of companies still take “no action” to mitigate burnout. </p><p>Burnout has been a <a href="https://www.itpro.com/security/fighting-the-always-on-culture-thats-savaging-mental-health-in-cyber-security"><u>long-running issue in the cybersecurity sector</u></a>, and one that continues to plague organizations. </p><p>An April 2026 <a href="https://issa.org/life-and-times-of-cybersecurity-professionals-volume-viii/" target="_blank"><u>survey by the Information Systems Security Association (ISSA)</u></a> aligns closely with ISACA’s research. Nearly seven-in-ten workers revealed their jobs have become more difficult over the last two years, for example. </p><p>Nearly half of cyber professionals said they are considering leaving their job, with 53% citing stress and 34% highlighting poor work-life balance. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ShinyHunters claims it hacked Clop ransomware rival ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A battle has broken out between a pair of cyber crime groups, highlighting how even hackers need to be wary of vulnerabilities in their infrastructure. </p><p><a href="https://www.itpro.com/security/data-breaches/european-commission-confirms-data-breach-as-shinyhunters-group-claims-responsibility"><u>ShinyHunters</u></a>, known for a <a href="https://www.itpro.com/security/cyber-attacks/google-cyber-researchers-were-tracking-the-shinyhunters-groups-salesforce-attacks-then-realized-theyd-fallen-victim"><u>series of devastating attacks</u></a> in recent years, claims it has taken over the website and infrastructure of rival hacking group, Clop. The incident appears to be in response to a threat from Clop and part of a wider disagreement between the two hacking groups. </p><p>"We basically own them ​now," ShinyHunters said via an online chat conversation with <a href="https://www.reuters.com/legal/government/cybercrime-feud-erupts-dark-web-notorious-group-claims-hijack-rivals-website-2026-09-21/" target="_blank"><u><em>Reuters</em></u></a>. Clop's dark web site appears to remain offline and the targeted group has yet to make a public statement. </p><p>ShinyHunters used an unauthenticated file upload flaw in Grav CMS, leveraging the flaw by uploading a text file to the Clop site, according to a report in <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/" target="_blank"><u><em>Bleeping Computer</em></u></a>, which said the file included a warning against "threatening" ShinyHunters. </p><p>The attackers later defaced the Clop site with ASCII art, and added their rivals to the list of victims on its data leak list, the report added, with a note asking for a ransom and apology in order to get the website back. </p><p>"Kindly excuse our unprofessionalism," the <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/" target="_blank"><u>note added</u></a>. </p><h2 id="a-funny-twist-if-true">A funny twist, if true </h2><p>Steven Thomson, senior SOC analyst at Barrier Networks, said the incident was a "funny twist", but added it should be viewed cautiously as ShinyHunters has “a lot to gain from the publicity surrounding the 'apparent' breach."</p><p>Jamie Akhtar, CEO and co-founder of CyberSmart, said the incident is a “striking reminder that cyber criminal groups suffer from the same security weaknesses they routinely exploit in legitimate organisations”. </p><p>"Clop’s alleged compromise appears to have moved beyond website defacement to the possible theft of source code, logs and Tor service keys, potentially exposing both its infrastructure and operational methods."</p><p>William Wright, CEO of Closed Door Security, echoed Akhtar’s comments, particularly given that Clop has an “extensive track record” of waging supply chain attacks. </p><p>“The group’s site getting hacked through similar means shows that not even experienced threat actors are immune to such attacks,” he said. </p><h2 id="shinyhunters-and-clop-competing-for-dominance">ShinyHunters and Clop competing for dominance</h2><p>In recent years, ShinyHunters has emerged as one of the most aggressive ransomware groups globally. In February this year, <a href="https://www.itpro.com/security/google-issues-warning-over-shinyhunters-branded-vishing-campaigns"><u>Google sounded the alarm over a ShinyHunters vishing campaign</u></a> which targeted corporate environments. </p><p>Weeks later, <a href="https://www.itpro.com/security/cyber-attacks/salesforce-issues-customer-alert-as-shinyhunters-group-claims-experience-cloud-breach"><u>Salesforce warned customers</u></a> after ShinyHunters claimed to have breached its Experience Cloud. Notably, the group claimed responsibility for a<a href="https://www.itpro.com/security/cyber-attacks/universities-worldwide-still-struggling-with-fallout-from-canvas-cyber-attack"><u> devastating attack on education platform Canvas</u></a> that impacted universities around the world. </p><p>Clop, meanwhile, has been a notorious player on the ransomware scene for several years. </p><p>The group has run a series of highly damaging campaigns in recent years, targeting everything from <a href="https://www.itpro.com/security/cyber-attacks/microsoft-links-papercut-server-attacks-to-cl0p-lockbit-ransomware?"><u>print management software</u></a> to the <a href="https://www.itpro.com/security/cyber-attacks/moveit-cyber-attack-cl0p-sparks-speculation-that-its-lost-control-of-hack"><u>MOVEit File Transfer system</u></a> to gain access. </p><p>That prolific activity hasn't left the two groups too busy for infighting, it would seem. </p><p>Javvad Malik, Lead <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do"><u>CISO </u></a>Advisor at KnowBe4, said the incident was a timely reminder that cyber crime gangs are competitive businesses. </p><p>"When relationships are built on deception and fear, double-crossing and betrayal is always a credible threat," Malik said. "For defenders, it reinforces the need to understand not just the technology, but the motivations and behaviours of the people behind the attacks."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ransomware/cyber-criminal-groups-suffer-from-the-same-security-weaknesses-they-routinely-exploit-shinyhunters-claims-it-hacked-clop-ransomware-rival</link>
                                                                            <description>
                            <![CDATA[ An attack on the cyber crime gang could prove dangerous for previous victims of data leaks, experts have warned ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JWjk8yMiuV5o53zNBtBgtk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 09:57:18 +0000</pubDate>                                                                                                                                <updated>Tue, 22 Sep 2026 10:55:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Ransomware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A battle has broken out between a pair of cyber crime groups, highlighting how even hackers need to be wary of vulnerabilities in their infrastructure. </p><p><a href="https://www.itpro.com/security/data-breaches/european-commission-confirms-data-breach-as-shinyhunters-group-claims-responsibility"><u>ShinyHunters</u></a>, known for a <a href="https://www.itpro.com/security/cyber-attacks/google-cyber-researchers-were-tracking-the-shinyhunters-groups-salesforce-attacks-then-realized-theyd-fallen-victim"><u>series of devastating attacks</u></a> in recent years, claims it has taken over the website and infrastructure of rival hacking group, Clop. The incident appears to be in response to a threat from Clop and part of a wider disagreement between the two hacking groups. </p><p>"We basically own them ​now," ShinyHunters said via an online chat conversation with <a href="https://www.reuters.com/legal/government/cybercrime-feud-erupts-dark-web-notorious-group-claims-hijack-rivals-website-2026-09-21/" target="_blank"><u><em>Reuters</em></u></a>. Clop's dark web site appears to remain offline and the targeted group has yet to make a public statement. </p><p>ShinyHunters used an unauthenticated file upload flaw in Grav CMS, leveraging the flaw by uploading a text file to the Clop site, according to a report in <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/" target="_blank"><u><em>Bleeping Computer</em></u></a>, which said the file included a warning against "threatening" ShinyHunters. </p><p>The attackers later defaced the Clop site with ASCII art, and added their rivals to the list of victims on its data leak list, the report added, with a note asking for a ransom and apology in order to get the website back. </p><p>"Kindly excuse our unprofessionalism," the <a href="https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/" target="_blank"><u>note added</u></a>. </p><h2 id="a-funny-twist-if-true">A funny twist, if true </h2><p>Steven Thomson, senior SOC analyst at Barrier Networks, said the incident was a "funny twist", but added it should be viewed cautiously as ShinyHunters has “a lot to gain from the publicity surrounding the 'apparent' breach."</p><p>Jamie Akhtar, CEO and co-founder of CyberSmart, said the incident is a “striking reminder that cyber criminal groups suffer from the same security weaknesses they routinely exploit in legitimate organisations”. </p><p>"Clop’s alleged compromise appears to have moved beyond website defacement to the possible theft of source code, logs and Tor service keys, potentially exposing both its infrastructure and operational methods."</p><p>William Wright, CEO of Closed Door Security, echoed Akhtar’s comments, particularly given that Clop has an “extensive track record” of waging supply chain attacks. </p><p>“The group’s site getting hacked through similar means shows that not even experienced threat actors are immune to such attacks,” he said. </p><h2 id="shinyhunters-and-clop-competing-for-dominance">ShinyHunters and Clop competing for dominance</h2><p>In recent years, ShinyHunters has emerged as one of the most aggressive ransomware groups globally. In February this year, <a href="https://www.itpro.com/security/google-issues-warning-over-shinyhunters-branded-vishing-campaigns"><u>Google sounded the alarm over a ShinyHunters vishing campaign</u></a> which targeted corporate environments. </p><p>Weeks later, <a href="https://www.itpro.com/security/cyber-attacks/salesforce-issues-customer-alert-as-shinyhunters-group-claims-experience-cloud-breach"><u>Salesforce warned customers</u></a> after ShinyHunters claimed to have breached its Experience Cloud. Notably, the group claimed responsibility for a<a href="https://www.itpro.com/security/cyber-attacks/universities-worldwide-still-struggling-with-fallout-from-canvas-cyber-attack"><u> devastating attack on education platform Canvas</u></a> that impacted universities around the world. </p><p>Clop, meanwhile, has been a notorious player on the ransomware scene for several years. </p><p>The group has run a series of highly damaging campaigns in recent years, targeting everything from <a href="https://www.itpro.com/security/cyber-attacks/microsoft-links-papercut-server-attacks-to-cl0p-lockbit-ransomware?"><u>print management software</u></a> to the <a href="https://www.itpro.com/security/cyber-attacks/moveit-cyber-attack-cl0p-sparks-speculation-that-its-lost-control-of-hack"><u>MOVEit File Transfer system</u></a> to gain access. </p><p>That prolific activity hasn't left the two groups too busy for infighting, it would seem. </p><p>Javvad Malik, Lead <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do"><u>CISO </u></a>Advisor at KnowBe4, said the incident was a timely reminder that cyber crime gangs are competitive businesses. </p><p>"When relationships are built on deception and fear, double-crossing and betrayal is always a credible threat," Malik said. "For defenders, it reinforces the need to understand not just the technology, but the motivations and behaviours of the people behind the attacks."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data embassies and sovereign dispersion ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Rising geopolitical instability, cyber threats, and concentration risks associated with data localization are prompting governments to move beyond traditional sovereignty models centered on data residency and geopatriation. As a result, data embassies are emerging as a practical approach to ensuring continuity of government services and operations. </p><p>These legally protected enclaves enable a nation to host critical digital infrastructure on foreign soil while retaining full sovereignty and data control, and interest is being led by small, highly digitized states facing active conflict or severe hybrid threats, according to Daniel Nieto, senior director analyst, Gartner. </p><p>“Sovereign dispersion decouples legal authority from physical location, whereas multi-region cloud back-ups simply move data geographically while remaining entirely subject to the host nation’s courts, laws and warrants,” he says. </p><p>“A true data embassy is established through formal bilateral treaties that grant foreign-hosted server racks the same statutory diplomatic immunity and inviolability as a physical embassy. Practically, it maintains an active, low-latency ‘digital twin’ with automated rerouting, keeping core civic services running during a crisis, rather than sitting as a passive backup repository.” </p><p>During a ‘black sky’ event, such as total domestic infrastructure collapse from a cyberattack, power failure, or physical strike, automated network routing immediately redirects traffic to the extraterritorial node, explains Nieto. </p><p>“This ensures citizens can continuously access core registries, tax systems and central bank ledgers even if the physical capital is entirely compromised.” </p><h2 id="the-rise-of-the-data-embassy">The rise of the data embassy</h2><p>Gartner predicts that at least 15% of nations in unstable regions will establish formal data embassy agreements by 2029. The world's first was established back in 2015 by Estonia, born out of an analogue workaround that saw diplomats transport hard drives of critical state data to Estonian embassies abroad. </p><p>“We thought, okay, we’re very much a digital state, so why are we doing this manually? Maybe there’s a better framework for that," says Allan Allmere, IT architecture and infrastructure advisor, Estonia’s Ministry of Justice and Digital Affairs. </p><p>That question led to the creation of its data embassy as a ‘last mile’ solution to ensure E-Estonia, the country’s digital backbone, would continue to run “if all else failed.” </p><p>Nothing like it had been attempted before, so it meant finding a country willing to even define what a ‘data embassy’ was. Estonia wanted to stay within Europe and found two countries genuinely open to the idea. “We settled on Luxembourg, partly because smaller countries are typically more flexible and agile, and partly because it had Tier IV rated data centers – the highest classification available, used by NATO.” </p><p>“Tier IV certification provides the fault tolerance and continuity that critical systems require, and is the same standard provided by the Government IT Center to their public administration clients,” adds a technical advisor at Luxembourg's government IT center. </p><p>“Hosting a partner state’s critical systems builds on that same foundation, with the addition of a dedicated environment and a specific bilateral legal framework.” </p><p>That legal framework rests on firmer ground than it might appear, as when it comes to international law, the consensus is that existing international rules apply, says Agnes Kasper, head of the Law Branch at NATO's Cooperative Cyber Defence Center of Excellence (CCDCOE). “There is no 'new law,' the question is rather how this vast existing law applies.” </p><p>She notes that the Vienna Conventions on diplomatic and consular relations – largely customary international law, binding even beyond their signatories – predate the cyber age and don't directly address arrangements like data embassies, "which is why it was necessary to write specific conditions into a separate intergovernmental contract."</p><h2 id="continuously-evolving">Continuously evolving</h2><p>Allmere treats Estonia’s data embassy project as a startup: “It's never done; it's always evolving.” There have been three steps so far, starting with storage of 10 critical datasets. This has since expanded, and step two was the addition of a live government cloud in Luxembourg, which was added this year. “This gives agencies an active site abroad rather than pure backup. Step three is still in development, but will be a long-term archival layer, built for recovery decades into the future, when current technology may be obsolete.” </p><p>Ministries are responsible for their own datasets, each preparing a full backup that will enable rebuilding, “keeping in mind that that might not be them,” notes Allmere. That backup is then encrypted and sent directly to Luxembourg over a private encrypted connection. </p><p>The data can be downloaded from the embassy at any time, but as a security measure, nothing can be altered or deleted and, to ensure readiness and resilience, each ministry must undertake a mandatory restoration test each year. </p><p>Data protection relies on multiple layers of security controls. At the state level, this hinges on a principle Nieto calls encryption as a border including encryption as a border (EaaB). “This is where data is fully encrypted using hardware security modules (HSMs), with keys retained strictly within the origin state – ensuring the host nation holds the hardware ‘lock,’ but only the home nation holds the ‘key.’</p><p>“For maximum security defense and intelligence workloads, this is bolstered by post-quantum cryptography, zero-trust architectures and physical air gaps.” </p><h2 id="enterprise-takeaways">Enterprise takeaways</h2><p>Estonia's approach may be a national-scale answer, but the same residency-versus-resilience question is now landing on enterprise IT leaders' desks, well before most of them are forced to make a similar call with their own data.</p><p>“Enterprise IT leaders must realize that physical data localization offers a false sense of security, as concentrating infrastructure locally creates an operational target. True resilience requires decoupling data location from operational control by maintaining strict encryption key sovereignty across dispersed locations,” says Nieto. </p><p>“Furthermore, enterprises should architect systems using containerized applications managed via Infrastructure as Code (IaC), allowing them to rapidly tear down and redeploy their entire digital stack to a neutral jurisdiction within hours if geopolitical or vendor risks escalate.”</p><p>While replicating the data embassy model would be considerably more difficult for private businesses, experts agree that many of the technical resilience principles are transferable.</p><p>“Without diplomatic machinery, a business can pilot a low-cost version of sovereign dispersion by decoupling its encryption keys from its cloud hosting provider. An enterprise can store encrypted secondary database replicas in a stable, foreign cloud region while retaining total control of the decryption keys in an on-premises or neutral third-party HSM,” says Nieto. </p><p>“Combining this with IaC allows the business to test asynchronous, containerized failovers to an isolated secondary jurisdiction without handing control over to a single vendor or host state.”</p><p>The underlying logic behind a data embassy still applies to businesses’ distributed continuity solutions, adds Allmere. “You need to make sure you don’t put all your eggs in one basket – don’t trust just one location, or even just one provider.”</p><p>He goes on to highlight the risk of cloud concentration. "Two or three years ago, I was in the camp of ‘let's put everything in the cloud, and it’ll be safe.’ Now I think that’s not so wise, because 71% of the whole cloud market in Europe is owned by just three US companies. </p><p>“You also need to consider how fast you can move from one cloud to another if needed. Feel free to use the big providers like Amazon, Microsoft, or Google, but I recommend avoiding their bespoke offerings, or you could become locked in,” he concludes. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-protection/data-embassies-and-sovereign-dispersion</link>
                                                                            <description>
                            <![CDATA[ Sovereign dispersion offers IT leaders an early look at how the residency-versus-resilience trade-off could be resolved at scale, before they're forced to make the same call with their own data ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ABw7JHVVGvodqBugtd2uRZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pRhefonPokRnWg4pyjgCe-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 22 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 22 Sep 2026 10:17:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Keri Allan ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oJZkdPii464j27ff4GCcoT-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pRhefonPokRnWg4pyjgCe-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A map of the world formed from glowing, blue digital data points to represent data sovereignty.]]></media:description>                                                            <media:text><![CDATA[A map of the world formed from glowing, blue digital data points to represent data sovereignty.]]></media:text>
                                <media:title type="plain"><![CDATA[A map of the world formed from glowing, blue digital data points to represent data sovereignty.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pRhefonPokRnWg4pyjgCe-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Rising geopolitical instability, cyber threats, and concentration risks associated with data localization are prompting governments to move beyond traditional sovereignty models centered on data residency and geopatriation. As a result, data embassies are emerging as a practical approach to ensuring continuity of government services and operations. </p><p>These legally protected enclaves enable a nation to host critical digital infrastructure on foreign soil while retaining full sovereignty and data control, and interest is being led by small, highly digitized states facing active conflict or severe hybrid threats, according to Daniel Nieto, senior director analyst, Gartner. </p><p>“Sovereign dispersion decouples legal authority from physical location, whereas multi-region cloud back-ups simply move data geographically while remaining entirely subject to the host nation’s courts, laws and warrants,” he says. </p><p>“A true data embassy is established through formal bilateral treaties that grant foreign-hosted server racks the same statutory diplomatic immunity and inviolability as a physical embassy. Practically, it maintains an active, low-latency ‘digital twin’ with automated rerouting, keeping core civic services running during a crisis, rather than sitting as a passive backup repository.” </p><p>During a ‘black sky’ event, such as total domestic infrastructure collapse from a cyberattack, power failure, or physical strike, automated network routing immediately redirects traffic to the extraterritorial node, explains Nieto. </p><p>“This ensures citizens can continuously access core registries, tax systems and central bank ledgers even if the physical capital is entirely compromised.” </p><h2 id="the-rise-of-the-data-embassy">The rise of the data embassy</h2><p>Gartner predicts that at least 15% of nations in unstable regions will establish formal data embassy agreements by 2029. The world's first was established back in 2015 by Estonia, born out of an analogue workaround that saw diplomats transport hard drives of critical state data to Estonian embassies abroad. </p><p>“We thought, okay, we’re very much a digital state, so why are we doing this manually? Maybe there’s a better framework for that," says Allan Allmere, IT architecture and infrastructure advisor, Estonia’s Ministry of Justice and Digital Affairs. </p><p>That question led to the creation of its data embassy as a ‘last mile’ solution to ensure E-Estonia, the country’s digital backbone, would continue to run “if all else failed.” </p><p>Nothing like it had been attempted before, so it meant finding a country willing to even define what a ‘data embassy’ was. Estonia wanted to stay within Europe and found two countries genuinely open to the idea. “We settled on Luxembourg, partly because smaller countries are typically more flexible and agile, and partly because it had Tier IV rated data centers – the highest classification available, used by NATO.” </p><p>“Tier IV certification provides the fault tolerance and continuity that critical systems require, and is the same standard provided by the Government IT Center to their public administration clients,” adds a technical advisor at Luxembourg's government IT center. </p><p>“Hosting a partner state’s critical systems builds on that same foundation, with the addition of a dedicated environment and a specific bilateral legal framework.” </p><p>That legal framework rests on firmer ground than it might appear, as when it comes to international law, the consensus is that existing international rules apply, says Agnes Kasper, head of the Law Branch at NATO's Cooperative Cyber Defence Center of Excellence (CCDCOE). “There is no 'new law,' the question is rather how this vast existing law applies.” </p><p>She notes that the Vienna Conventions on diplomatic and consular relations – largely customary international law, binding even beyond their signatories – predate the cyber age and don't directly address arrangements like data embassies, "which is why it was necessary to write specific conditions into a separate intergovernmental contract."</p><h2 id="continuously-evolving">Continuously evolving</h2><p>Allmere treats Estonia’s data embassy project as a startup: “It's never done; it's always evolving.” There have been three steps so far, starting with storage of 10 critical datasets. This has since expanded, and step two was the addition of a live government cloud in Luxembourg, which was added this year. “This gives agencies an active site abroad rather than pure backup. Step three is still in development, but will be a long-term archival layer, built for recovery decades into the future, when current technology may be obsolete.” </p><p>Ministries are responsible for their own datasets, each preparing a full backup that will enable rebuilding, “keeping in mind that that might not be them,” notes Allmere. That backup is then encrypted and sent directly to Luxembourg over a private encrypted connection. </p><p>The data can be downloaded from the embassy at any time, but as a security measure, nothing can be altered or deleted and, to ensure readiness and resilience, each ministry must undertake a mandatory restoration test each year. </p><p>Data protection relies on multiple layers of security controls. At the state level, this hinges on a principle Nieto calls encryption as a border including encryption as a border (EaaB). “This is where data is fully encrypted using hardware security modules (HSMs), with keys retained strictly within the origin state – ensuring the host nation holds the hardware ‘lock,’ but only the home nation holds the ‘key.’</p><p>“For maximum security defense and intelligence workloads, this is bolstered by post-quantum cryptography, zero-trust architectures and physical air gaps.” </p><h2 id="enterprise-takeaways">Enterprise takeaways</h2><p>Estonia's approach may be a national-scale answer, but the same residency-versus-resilience question is now landing on enterprise IT leaders' desks, well before most of them are forced to make a similar call with their own data.</p><p>“Enterprise IT leaders must realize that physical data localization offers a false sense of security, as concentrating infrastructure locally creates an operational target. True resilience requires decoupling data location from operational control by maintaining strict encryption key sovereignty across dispersed locations,” says Nieto. </p><p>“Furthermore, enterprises should architect systems using containerized applications managed via Infrastructure as Code (IaC), allowing them to rapidly tear down and redeploy their entire digital stack to a neutral jurisdiction within hours if geopolitical or vendor risks escalate.”</p><p>While replicating the data embassy model would be considerably more difficult for private businesses, experts agree that many of the technical resilience principles are transferable.</p><p>“Without diplomatic machinery, a business can pilot a low-cost version of sovereign dispersion by decoupling its encryption keys from its cloud hosting provider. An enterprise can store encrypted secondary database replicas in a stable, foreign cloud region while retaining total control of the decryption keys in an on-premises or neutral third-party HSM,” says Nieto. </p><p>“Combining this with IaC allows the business to test asynchronous, containerized failovers to an isolated secondary jurisdiction without handing control over to a single vendor or host state.”</p><p>The underlying logic behind a data embassy still applies to businesses’ distributed continuity solutions, adds Allmere. “You need to make sure you don’t put all your eggs in one basket – don’t trust just one location, or even just one provider.”</p><p>He goes on to highlight the risk of cloud concentration. "Two or three years ago, I was in the camp of ‘let's put everything in the cloud, and it’ll be safe.’ Now I think that’s not so wise, because 71% of the whole cloud market in Europe is owned by just three US companies. </p><p>“You also need to consider how fast you can move from one cloud to another if needed. Feel free to use the big providers like Amazon, Microsoft, or Google, but I recommend avoiding their bespoke offerings, or you could become locked in,” he concludes. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Freelance tech pros beware: North Korean cyber criminals are targeting gig workers in a new malware campaign ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Security agencies have issued an alert after <a href="https://www.itpro.com/security/fake-north-korean-it-workers-are-rampant-heres-how-to-spot-the-telltale-signs-a-new-hire-is-a-hacker">North Korean-backed cyber criminals</a> were found posing as recruiters to target freelance IT workers. </p><p>WaterPlum - also known as Contagious Interview - <a href="https://www.itpro.com/security/this-new-hacker-group-is-targeting-software-developers-with-phony-job-offers-and-fake-projects">targets software developers</a> and  IT professionals in Japan, the US, Europe, and other countries.</p><p><a href="https://www.ic3.gov/CSA/2026/260918.pdf"><u>According to</u></a> security agencies in Japan, the US, Australia, and Germany, the group has infected at least 30,000 devices in more than 100 countries, and has stolen funds or account credentials from over 7,000 cryptocurrency wallets. </p><p>The group's takings amount to $10.7 million so far, with agencies warning workers to remain vigilant for potential scams. </p><p>Victims are recruited internationally through social media platforms, online job platforms, gig work platforms, or freelance marketplaces.</p><p>As part of the recruitment process, they're required to take part in technical online virtual interviews or complete assignments - during which they're instructed to carry out a coding assignment or troubleshoot an error in the online video conferencing platform. </p><p>However, doing this downloads and executes malicious files hosted on multiple online collaboration platforms and code repositories. These include Node Package Manager (NPM1) packages embedded with either BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and related variants.</p><p>Once in, the attackers use Remote-Access Trojans (RATs) to maintain connectivity, persistence, and pathways to pivot across victim systems, using infostealers to exfiltrate the victim’s sensitive data and cryptocurrency to a Command-and-Control (C2) IP address for remote management of infected devices or networks.</p><p>"Beyond immediate credential theft, successful infections provide WaterPlum actors opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments," Japanese authorities said. "Stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency."</p><p>Data targeted for exfiltration includes authentication data stored in web browsers such as IDs and passwords, clipboard information, key-logs, screenshots, and cryptocurrency-wallet data including private keys and seed phrases.</p><h2 id="another-north-korean-threat-campaign">Another North Korean threat campaign</h2><p>According to the agencies, the criminals behind this are mainly based in North Korea, China, or Russia, with a few in Africa and Southeast Asia. </p><p>They're also operating laptop farms to provide fake IT workers, in one case extorting a company over payment and publishing its proprietary source code online. In another, an IT worker hired for website maintenance defaced the hiring company’s website and rendered the site inaccessible.</p><p>Nick Tausek, lead security automation architect at Swimlane, said the campaign represents an expansion of the familiar North Korean playbook to take job fraud in two directions. </p><p>"Fake IT workers seek salary income and trusted access from inside a company. WaterPlum targets legitimate applicants from the outside. Stolen credentials, source code, and identity documents can then support espionage, extortion, or new fraudulent personas," he said.</p><p>"The shared laptop farms and IP addresses cited in the advisory suggest these aren’t isolated schemes. Each operation can feed the other. They can steal identities and credentials that help fraudulent workers appear legitimate. Those workers can then gain trusted access to corporate systems, opening further opportunities for theft or disruption."</p><p>Ross Filipek, <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>at Corsica Technologies, urged developers, freelancers, and organizations at large to remain on guard. </p><p>"One compromised workstation can expose several employers or clients without any of them being directly attacked. Organizations need to know how outside developers access their environments and what information can leave through those accounts. Unknown code should be isolated before execution," said Ross Filipek, CISO at Corsica Technologies. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/freelance-tech-pros-beware-north-korean-cyber-criminals-are-targeting-gig-workers-in-a-new-malware-campaign</link>
                                                                            <description>
                            <![CDATA[ Fake tests during the recruitment process infect applicants' devices to steal cryptocurrency ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uzPtGcXw94V9M9mmCsMV5a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Sep 2026 11:29:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:description>                                                            <media:text><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security agencies have issued an alert after <a href="https://www.itpro.com/security/fake-north-korean-it-workers-are-rampant-heres-how-to-spot-the-telltale-signs-a-new-hire-is-a-hacker">North Korean-backed cyber criminals</a> were found posing as recruiters to target freelance IT workers. </p><p>WaterPlum - also known as Contagious Interview - <a href="https://www.itpro.com/security/this-new-hacker-group-is-targeting-software-developers-with-phony-job-offers-and-fake-projects">targets software developers</a> and  IT professionals in Japan, the US, Europe, and other countries.</p><p><a href="https://www.ic3.gov/CSA/2026/260918.pdf"><u>According to</u></a> security agencies in Japan, the US, Australia, and Germany, the group has infected at least 30,000 devices in more than 100 countries, and has stolen funds or account credentials from over 7,000 cryptocurrency wallets. </p><p>The group's takings amount to $10.7 million so far, with agencies warning workers to remain vigilant for potential scams. </p><p>Victims are recruited internationally through social media platforms, online job platforms, gig work platforms, or freelance marketplaces.</p><p>As part of the recruitment process, they're required to take part in technical online virtual interviews or complete assignments - during which they're instructed to carry out a coding assignment or troubleshoot an error in the online video conferencing platform. </p><p>However, doing this downloads and executes malicious files hosted on multiple online collaboration platforms and code repositories. These include Node Package Manager (NPM1) packages embedded with either BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, or StoatWaffle <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>and related variants.</p><p>Once in, the attackers use Remote-Access Trojans (RATs) to maintain connectivity, persistence, and pathways to pivot across victim systems, using infostealers to exfiltrate the victim’s sensitive data and cryptocurrency to a Command-and-Control (C2) IP address for remote management of infected devices or networks.</p><p>"Beyond immediate credential theft, successful infections provide WaterPlum actors opportunities to infiltrate organizations employing targeted developers, enabling espionage, intellectual property theft, and additional lateral movement in corporate environments," Japanese authorities said. "Stolen ID images can also be used by North Korean IT workers to impersonate victims and generate foreign currency."</p><p>Data targeted for exfiltration includes authentication data stored in web browsers such as IDs and passwords, clipboard information, key-logs, screenshots, and cryptocurrency-wallet data including private keys and seed phrases.</p><h2 id="another-north-korean-threat-campaign">Another North Korean threat campaign</h2><p>According to the agencies, the criminals behind this are mainly based in North Korea, China, or Russia, with a few in Africa and Southeast Asia. </p><p>They're also operating laptop farms to provide fake IT workers, in one case extorting a company over payment and publishing its proprietary source code online. In another, an IT worker hired for website maintenance defaced the hiring company’s website and rendered the site inaccessible.</p><p>Nick Tausek, lead security automation architect at Swimlane, said the campaign represents an expansion of the familiar North Korean playbook to take job fraud in two directions. </p><p>"Fake IT workers seek salary income and trusted access from inside a company. WaterPlum targets legitimate applicants from the outside. Stolen credentials, source code, and identity documents can then support espionage, extortion, or new fraudulent personas," he said.</p><p>"The shared laptop farms and IP addresses cited in the advisory suggest these aren’t isolated schemes. Each operation can feed the other. They can steal identities and credentials that help fraudulent workers appear legitimate. Those workers can then gain trusted access to corporate systems, opening further opportunities for theft or disruption."</p><p>Ross Filipek, <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>at Corsica Technologies, urged developers, freelancers, and organizations at large to remain on guard. </p><p>"One compromised workstation can expose several employers or clients without any of them being directly attacked. Organizations need to know how outside developers access their environments and what information can leave through those accounts. Unknown code should be isolated before execution," said Ross Filipek, CISO at Corsica Technologies. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why secure behavior management Is becoming the channel's next growth opportunity ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The channel has fundamentally been built on change. From cloud adoption and zero trust to AI, partners have positioned themselves as trusted guides, helping customers navigate the availability of new technological innovations. Yet as technology advances at an unprecedented pace, so has the scale and complexity of cyber risk. This is being driven not only by technology itself, but by the people using it. As a result, the role of the channel partner is evolving with it.</p><p>Success for channel partners is no longer about chasing every emerging trend or expanding into every new technology category. Instead, the partners that will shine are those that become agile, specialized advisors, helping organizations navigate AI, compliance requirements, and the evolving threat landscape. A key part of that role is secure behavior management, which means strengthening the human layer of security through continuous and measurable behavior change.</p><p>However, as the pace of innovation continues to accelerate, this raises an important question: can channel partners realistically keep pace with technological change whilst simultaneously empowering customers?</p><h2 id="the-challenge-of-keeping-pace">The challenge of keeping pace</h2><p>In recent years, the cybersecurity industry has witnessed significant growth in technological advancements, with new solutions emerging weekly, regulatory requirements tightening, and threat actors becoming more sophisticated in their tactics. On the one hand, this has greatly benefited channel partners by providing an opportunity to expand their portfolios. Every innovation presents another opportunity to sell, another vendor relationship to manage, and another service to offer. On the other hand, this approach often creates more problems than it solves.</p><p>Partners that focus solely on emerging trends frequently end up with complex technology stacks that are difficult to explain, differentiate, and sell. As a result, customer conversations become focused on the product rather than on real business outcomes. </p><p>The partners experiencing the strongest growth are taking a different approach by focusing on understanding the problems their customers are trying to solve. By developing expertise in specific areas, partners are able to build credibility around those challenges and create clear pathways to measurable outcomes. This, in turn, enables them to act as trusted advisors that customers can rely on. </p><h2 id="from-supplier-to-trusted-advisor">From supplier to trusted advisor</h2><p>Becoming a trusted advisor within the channel has never been more critical. Customers are often overwhelmed by choice, particularly in a crowded market. For this reason, they require partners who can help them understand risk, prioritize investment, and make informed decisions. </p><p>While this shift doesn't typically happen overnight, that doesn't mean it's not attainable. An example of this can be seen in an MSP partner who initially positioned behavioral security technology as a straightforward add-on to phishing simulations and compliance training, with conversations centered largely on awareness activity. Then, within a few months, they changed their approach to focus on measurable human risk.</p><p>Rather than focusing on training delivery, they began helping customers understand and measure human risk. Behavioral data became a regular part of customer reviews, enabling meaningful conversations about where risk existed, what was improving, and where additional attention was needed. As a result, the service evolved from a product sale into a managed secure behavior management program, and customer relationships became significantly stronger.  Customer relationships also became significantly stronger. The solution became embedded within wider security discussions, opportunities for expansion emerged naturally, and the partner established itself as a strategic advisor rather than a supplier of tools.</p><p>This shift illustrates an important lesson for the wider channel. Customers place greater value on partners who can interpret data, provide context, and guide decision-making than those who simply provide technology.</p><h2 id="why-human-risk-is-becoming-a-channel-opportunity">Why human risk is becoming a channel opportunity </h2><p>Managing human risk remains a persistent challenge for many organizations, and that persistence is what creates a real opportunity for forward-thinking channel partners to capitalize on. Despite years of investment in security awareness training, 62% of confirmed breaches still involved the human element, according to <a href="https://www.verizon.com/business/resources/reports/dbir/"><u>Verizon's 2026 Data Breach Investigations Report </u></a>. This demonstrates that traditional security awareness training methods, including e-learning modules and annual refreshers, remain ineffective, and it's time for organizations to take a different approach. </p><p>The focus should move away from training completion rates and compliance tick-boxes towards establishing baselines for risky behavior, demonstrating clear reductions over time, and providing evidence of genuine improvement, reflecting the core principles of secure behavior management. The partners who make that shift now will not only differentiate themselves in a crowded market but will position themselves as the trusted advisors that forward-thinking organizations increasingly need.</p><h2 id="looking-ahead">Looking ahead</h2><p>As the cybersecurity solutions market continues to develop, the most successful channel partners will be those that recognize technology alone is no longer enough. </p><p>Organizations require guidance on how their employees interact with that technology, where behavioral risks exist, and how those risks can be reduced over time. </p><p>Secure behavior management provides partners with an opportunity to move beyond transactional product sales and deliver ongoing, measurable value. In doing so, they can deepen customer relationships, create recurring service opportunities, and strengthen their position as trusted advisors at a time when organizations are looking for greater clarity in an evolving security landscape.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/why-secure-behavior-management-is-becoming-the-channels-next-growth-opportunity</link>
                                                                            <description>
                            <![CDATA[ Channel partners must shift from just selling tools to capitalizing on secure behavior management ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CEjnVzrgaFit5ZGV473oMY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 21 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Marshall-Brown ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/DH3tzfXt4g7Fjveakcaprd-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:description>                                                            <media:text><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The channel has fundamentally been built on change. From cloud adoption and zero trust to AI, partners have positioned themselves as trusted guides, helping customers navigate the availability of new technological innovations. Yet as technology advances at an unprecedented pace, so has the scale and complexity of cyber risk. This is being driven not only by technology itself, but by the people using it. As a result, the role of the channel partner is evolving with it.</p><p>Success for channel partners is no longer about chasing every emerging trend or expanding into every new technology category. Instead, the partners that will shine are those that become agile, specialized advisors, helping organizations navigate AI, compliance requirements, and the evolving threat landscape. A key part of that role is secure behavior management, which means strengthening the human layer of security through continuous and measurable behavior change.</p><p>However, as the pace of innovation continues to accelerate, this raises an important question: can channel partners realistically keep pace with technological change whilst simultaneously empowering customers?</p><h2 id="the-challenge-of-keeping-pace">The challenge of keeping pace</h2><p>In recent years, the cybersecurity industry has witnessed significant growth in technological advancements, with new solutions emerging weekly, regulatory requirements tightening, and threat actors becoming more sophisticated in their tactics. On the one hand, this has greatly benefited channel partners by providing an opportunity to expand their portfolios. Every innovation presents another opportunity to sell, another vendor relationship to manage, and another service to offer. On the other hand, this approach often creates more problems than it solves.</p><p>Partners that focus solely on emerging trends frequently end up with complex technology stacks that are difficult to explain, differentiate, and sell. As a result, customer conversations become focused on the product rather than on real business outcomes. </p><p>The partners experiencing the strongest growth are taking a different approach by focusing on understanding the problems their customers are trying to solve. By developing expertise in specific areas, partners are able to build credibility around those challenges and create clear pathways to measurable outcomes. This, in turn, enables them to act as trusted advisors that customers can rely on. </p><h2 id="from-supplier-to-trusted-advisor">From supplier to trusted advisor</h2><p>Becoming a trusted advisor within the channel has never been more critical. Customers are often overwhelmed by choice, particularly in a crowded market. For this reason, they require partners who can help them understand risk, prioritize investment, and make informed decisions. </p><p>While this shift doesn't typically happen overnight, that doesn't mean it's not attainable. An example of this can be seen in an MSP partner who initially positioned behavioral security technology as a straightforward add-on to phishing simulations and compliance training, with conversations centered largely on awareness activity. Then, within a few months, they changed their approach to focus on measurable human risk.</p><p>Rather than focusing on training delivery, they began helping customers understand and measure human risk. Behavioral data became a regular part of customer reviews, enabling meaningful conversations about where risk existed, what was improving, and where additional attention was needed. As a result, the service evolved from a product sale into a managed secure behavior management program, and customer relationships became significantly stronger.  Customer relationships also became significantly stronger. The solution became embedded within wider security discussions, opportunities for expansion emerged naturally, and the partner established itself as a strategic advisor rather than a supplier of tools.</p><p>This shift illustrates an important lesson for the wider channel. Customers place greater value on partners who can interpret data, provide context, and guide decision-making than those who simply provide technology.</p><h2 id="why-human-risk-is-becoming-a-channel-opportunity">Why human risk is becoming a channel opportunity </h2><p>Managing human risk remains a persistent challenge for many organizations, and that persistence is what creates a real opportunity for forward-thinking channel partners to capitalize on. Despite years of investment in security awareness training, 62% of confirmed breaches still involved the human element, according to <a href="https://www.verizon.com/business/resources/reports/dbir/"><u>Verizon's 2026 Data Breach Investigations Report </u></a>. This demonstrates that traditional security awareness training methods, including e-learning modules and annual refreshers, remain ineffective, and it's time for organizations to take a different approach. </p><p>The focus should move away from training completion rates and compliance tick-boxes towards establishing baselines for risky behavior, demonstrating clear reductions over time, and providing evidence of genuine improvement, reflecting the core principles of secure behavior management. The partners who make that shift now will not only differentiate themselves in a crowded market but will position themselves as the trusted advisors that forward-thinking organizations increasingly need.</p><h2 id="looking-ahead">Looking ahead</h2><p>As the cybersecurity solutions market continues to develop, the most successful channel partners will be those that recognize technology alone is no longer enough. </p><p>Organizations require guidance on how their employees interact with that technology, where behavioral risks exist, and how those risks can be reduced over time. </p><p>Secure behavior management provides partners with an opportunity to move beyond transactional product sales and deliver ongoing, measurable value. In doing so, they can deepen customer relationships, create recurring service opportunities, and strengthen their position as trusted advisors at a time when organizations are looking for greater clarity in an evolving security landscape.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Building a pre-emptive security architecture — what is it and how can your business adopt one? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Dealing with shifting sands is par for the course for cybersecurity practitioners, but what's happening now is different. Indeed, it’s more of a sea change that upends conventional wisdom and business-as-usual approaches to safeguarding an organization. The impact of AI in cybersecurity changes not just the nature of the threats and attack modalities but also adds new challenges, such as dealing with massive spikes in volume. </p><p>These challenges are why many across the cybersecurity industry see value in building and propagating a pre-emptive cybersecurity architecture that deviates from a conventionally static and reactive approach. After all, getting ahead of any threat is better than letting it fester – responding only when the damage has taken place. Such an approach may seem like common sense, so why hasn't this notion become more widespread among practitioners?</p><h2 id="what-is-pre-emptive-security-and-how-does-it-differ-from-conventional-cybersecurity-models">What is pre-emptive security – and how does it differ from conventional cybersecurity models?</h2><p>The traditional detect and respond cybersecurity framework has served businesses well for as long as they've tapped into cyberspace. But changes primarily driven by AI are exposing frailties in this model. For example, recent <a href="https://www.crowdstrike.com/en-us/global-threat-report/"><u>Crowdstrike</u></a> research shows a plunge to just 29 minutes for the time it takes for an attacker to move from initial compromise to laterally breaking out to other systems. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-09-18-gartner-says-that-in-the-age-of-genai-preemptive-capabilities-not-detection-and-response-are-the-future-of-cybersecurity"><u>Garner</u></a>, meanwhile, forecasts there will be a 300% spike in the number of documented vulnerabilities between 2025 and 2030. There's also the question of <a href="https://www.itpro.com/security/uk-cybersecurity-workers-are-overworked-overwhelmed-and-burning-out-faster-than-global-counterparts-heres-why"><u>practitioner burnout</u></a>, with conventional frameworks relying on overworked humans to investigate security alerts raised after, not before, an intrusion has been detected – and shut off a threat as a matter of urgency.</p><p>So what's the alternative? "In simple terms, pre-emptive security architecture means putting security controls directly in the path of an attack so that the attack gets blocked, diverted or contained before any serious damage has happened," explains Mudita Khurana, staff security engineer at Airbnb and cybersecurity expert with a decade of experience in application security, security tooling, vulnerability management and AI security.</p><p>"The idea is more architectural than a particular security product or control (thus the word architecture in the term itself)," she continues, adding: "It is a way of connecting security controls across different layers (like users, applications, systems, data, etc.) so that even if one layer is compromised, the blast radius remains limited because of other existing controls."</p><p>This is an environment in which attacks are far more likely to "fail on contact" or never really get a grip on systems, Steven Coppola, security engineer at BARR Advisory, tells <em>ITPro</em>. That is, instead of an architecture that relies on somebody noticing the attack while it's happening. </p><p>"I love analogies — for pre-emptive security architectures, I use a house," he says. "Detect and respond is akin to a good alarm and a fast call to the police department. A pre-emptive strategy is thinking ahead about where the doors will go, what they are made of, and whether the valuables need to be in the house at all." </p><h2 id="what-does-pre-emptive-security-entail">What does pre-emptive security entail?</h2><p>Framing pre-emptive security as a list of components or a single blueprint misses the mark, experts tell <em>ITPro</em>. Nor is this architecture a product that you can buy. Gartner's managing vice president Carl Manion <a href="https://www.gartner.com/en/articles/preemptive-cybersecurity-solutions"><u>distilled the trend</u></a> into three elements, including 'deceive', 'disrupt', and 'deny' – and also warned product leaders that they may face losses in market share if they fail to embrace this security architecture in the services they provide to organizations. </p><p>His first thesis is to deny hackers entry with a preemptive shield, including advanced obfuscation technologies. Next, organizations should deceive bad actors using decoys, misdirection, and illusion to throw them off the scent. Finally, organizations should anticipate emerging threats and prepare to disrupt these rather than waiting for the attack to materialize and engaging in damage control after the fact.</p><p>"I believe that there are many other security controls that can support these three areas that Gartner has set out," adds Khurana. </p><p>"For example, zero trust access controls and separation between systems can limit the reach of an attack. Secure development checks can prevent vulnerable code from being deployed in the first place, and encryption can protect stored data so even if someone steals files, they can't read them without the encryption key."</p><p>She also noted that confidential computing – in which data is processed inside a separate hardware-protected area with only approved code running within it – can add another layer of defense. </p><p>Coppola adds: "Confidential computing closes the gap in the middle, which is data in use. The workload runs inside a hardware-protected enclave — essentially a walled-off section of the processor—so the data stays encrypted even while it is being processed. Even the cloud provider or someone with admin rights on the host cannot read it."</p><p>Even if the attacker reaches the underlying server or cloud infrastructure, there is no immediate access to the data, which should be protected. However, it must also be combined with proper access controls and sufficient application security. </p><h2 id="how-can-businesses-implement-pre-emptive-security">How can businesses implement pre-emptive security?</h2><p>Chris Bailey, head of innovation at systems integrator Jigsaw24, tells <em>ITPro</em> that any plans to implement pre-emptive security should be shaped around a clear idea of what your organization is protecting, how sensitive the data is, and the internal policies. </p><p>"Start by identifying the data and systems you’re trying to protect. From there, map out where the vulnerabilities lie, how people access the environment, and what the worst-case scenario would look like," he advises. "Once that is clear, it is important to establish clear policies around access, roles and devices. Ask who genuinely needs access to a particular system or data, what they need to be able to do, and whether that access can be restricted further."</p><p>At this stage, Khurana explains that it's important first to understand how an attacker may reach the services or data sources, a process similar to threat modeling, and then where the attacks can be denied, deceived, or disrupted. "This is where the team takes the threats and paths from the previous activity and understands where the controls can sit. If a path is found [to be] unnecessary, it should be removed. For legitimate paths, the principle of least privilege should be adopted."</p><p>After putting controls into place, organizations should test them under realistic conditions to make sure they work well, she adds. This may involve penetration testing – which Bailey adds is important because it gives businesses the chance to identify weaknesses before an attacker does – as well as continuous auditing and monitoring.</p><p>Organizations should also carry out attack exercises to see if the controls set in place actually stop the intended attack path, and that, importantly, things can be quickly rolled back if the attacks disrupt important business processes. </p><p>It's also worth considering escalating the approach. If pre-emptive security works for one service, teams may feel more confident in applying this to more critical services. </p><p>While implementing a new approach to safeguarding your organization, it's also important to remember not to simply ditch or replace old techniques. Coppola tells <em>ITPro</em> that pre-emptive controls can make alerts more meaningful – but don't replace them. Then, when it comes to measuring attack paths, he says: "The question at the end of the quarter should be: what can an attacker with stolen credentials reach now versus 90 days ago? If the answer isn’t shrinking, the program in place is not working, no matter how many products were deployed."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/building-a-pre-emptive-security-architecture-what-is-it-and-how-can-your-business-adopt-one</link>
                                                                            <description>
                            <![CDATA[ Getting ahead of attacks is always better than waiting for an attack and then limiting the fallout – but this is often easier said than done ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uZ74yh2g2jdbLnwTpJhR7V</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jjqT56iBq9KiBwDMVBCW5a-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Sep 2026 14:31:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Infrastructure]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jjqT56iBq9KiBwDMVBCW5a-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital security and privacy background. Cyber and crypto security shield on futuristic screen technology background]]></media:description>                                                            <media:text><![CDATA[Digital security and privacy background. Cyber and crypto security shield on futuristic screen technology background]]></media:text>
                                <media:title type="plain"><![CDATA[Digital security and privacy background. Cyber and crypto security shield on futuristic screen technology background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jjqT56iBq9KiBwDMVBCW5a-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Dealing with shifting sands is par for the course for cybersecurity practitioners, but what's happening now is different. Indeed, it’s more of a sea change that upends conventional wisdom and business-as-usual approaches to safeguarding an organization. The impact of AI in cybersecurity changes not just the nature of the threats and attack modalities but also adds new challenges, such as dealing with massive spikes in volume. </p><p>These challenges are why many across the cybersecurity industry see value in building and propagating a pre-emptive cybersecurity architecture that deviates from a conventionally static and reactive approach. After all, getting ahead of any threat is better than letting it fester – responding only when the damage has taken place. Such an approach may seem like common sense, so why hasn't this notion become more widespread among practitioners?</p><h2 id="what-is-pre-emptive-security-and-how-does-it-differ-from-conventional-cybersecurity-models">What is pre-emptive security – and how does it differ from conventional cybersecurity models?</h2><p>The traditional detect and respond cybersecurity framework has served businesses well for as long as they've tapped into cyberspace. But changes primarily driven by AI are exposing frailties in this model. For example, recent <a href="https://www.crowdstrike.com/en-us/global-threat-report/"><u>Crowdstrike</u></a> research shows a plunge to just 29 minutes for the time it takes for an attacker to move from initial compromise to laterally breaking out to other systems. <a href="https://www.gartner.com/en/newsroom/press-releases/2025-09-18-gartner-says-that-in-the-age-of-genai-preemptive-capabilities-not-detection-and-response-are-the-future-of-cybersecurity"><u>Garner</u></a>, meanwhile, forecasts there will be a 300% spike in the number of documented vulnerabilities between 2025 and 2030. There's also the question of <a href="https://www.itpro.com/security/uk-cybersecurity-workers-are-overworked-overwhelmed-and-burning-out-faster-than-global-counterparts-heres-why"><u>practitioner burnout</u></a>, with conventional frameworks relying on overworked humans to investigate security alerts raised after, not before, an intrusion has been detected – and shut off a threat as a matter of urgency.</p><p>So what's the alternative? "In simple terms, pre-emptive security architecture means putting security controls directly in the path of an attack so that the attack gets blocked, diverted or contained before any serious damage has happened," explains Mudita Khurana, staff security engineer at Airbnb and cybersecurity expert with a decade of experience in application security, security tooling, vulnerability management and AI security.</p><p>"The idea is more architectural than a particular security product or control (thus the word architecture in the term itself)," she continues, adding: "It is a way of connecting security controls across different layers (like users, applications, systems, data, etc.) so that even if one layer is compromised, the blast radius remains limited because of other existing controls."</p><p>This is an environment in which attacks are far more likely to "fail on contact" or never really get a grip on systems, Steven Coppola, security engineer at BARR Advisory, tells <em>ITPro</em>. That is, instead of an architecture that relies on somebody noticing the attack while it's happening. </p><p>"I love analogies — for pre-emptive security architectures, I use a house," he says. "Detect and respond is akin to a good alarm and a fast call to the police department. A pre-emptive strategy is thinking ahead about where the doors will go, what they are made of, and whether the valuables need to be in the house at all." </p><h2 id="what-does-pre-emptive-security-entail">What does pre-emptive security entail?</h2><p>Framing pre-emptive security as a list of components or a single blueprint misses the mark, experts tell <em>ITPro</em>. Nor is this architecture a product that you can buy. Gartner's managing vice president Carl Manion <a href="https://www.gartner.com/en/articles/preemptive-cybersecurity-solutions"><u>distilled the trend</u></a> into three elements, including 'deceive', 'disrupt', and 'deny' – and also warned product leaders that they may face losses in market share if they fail to embrace this security architecture in the services they provide to organizations. </p><p>His first thesis is to deny hackers entry with a preemptive shield, including advanced obfuscation technologies. Next, organizations should deceive bad actors using decoys, misdirection, and illusion to throw them off the scent. Finally, organizations should anticipate emerging threats and prepare to disrupt these rather than waiting for the attack to materialize and engaging in damage control after the fact.</p><p>"I believe that there are many other security controls that can support these three areas that Gartner has set out," adds Khurana. </p><p>"For example, zero trust access controls and separation between systems can limit the reach of an attack. Secure development checks can prevent vulnerable code from being deployed in the first place, and encryption can protect stored data so even if someone steals files, they can't read them without the encryption key."</p><p>She also noted that confidential computing – in which data is processed inside a separate hardware-protected area with only approved code running within it – can add another layer of defense. </p><p>Coppola adds: "Confidential computing closes the gap in the middle, which is data in use. The workload runs inside a hardware-protected enclave — essentially a walled-off section of the processor—so the data stays encrypted even while it is being processed. Even the cloud provider or someone with admin rights on the host cannot read it."</p><p>Even if the attacker reaches the underlying server or cloud infrastructure, there is no immediate access to the data, which should be protected. However, it must also be combined with proper access controls and sufficient application security. </p><h2 id="how-can-businesses-implement-pre-emptive-security">How can businesses implement pre-emptive security?</h2><p>Chris Bailey, head of innovation at systems integrator Jigsaw24, tells <em>ITPro</em> that any plans to implement pre-emptive security should be shaped around a clear idea of what your organization is protecting, how sensitive the data is, and the internal policies. </p><p>"Start by identifying the data and systems you’re trying to protect. From there, map out where the vulnerabilities lie, how people access the environment, and what the worst-case scenario would look like," he advises. "Once that is clear, it is important to establish clear policies around access, roles and devices. Ask who genuinely needs access to a particular system or data, what they need to be able to do, and whether that access can be restricted further."</p><p>At this stage, Khurana explains that it's important first to understand how an attacker may reach the services or data sources, a process similar to threat modeling, and then where the attacks can be denied, deceived, or disrupted. "This is where the team takes the threats and paths from the previous activity and understands where the controls can sit. If a path is found [to be] unnecessary, it should be removed. For legitimate paths, the principle of least privilege should be adopted."</p><p>After putting controls into place, organizations should test them under realistic conditions to make sure they work well, she adds. This may involve penetration testing – which Bailey adds is important because it gives businesses the chance to identify weaknesses before an attacker does – as well as continuous auditing and monitoring.</p><p>Organizations should also carry out attack exercises to see if the controls set in place actually stop the intended attack path, and that, importantly, things can be quickly rolled back if the attacks disrupt important business processes. </p><p>It's also worth considering escalating the approach. If pre-emptive security works for one service, teams may feel more confident in applying this to more critical services. </p><p>While implementing a new approach to safeguarding your organization, it's also important to remember not to simply ditch or replace old techniques. Coppola tells <em>ITPro</em> that pre-emptive controls can make alerts more meaningful – but don't replace them. Then, when it comes to measuring attack paths, he says: "The question at the end of the quarter should be: what can an attacker with stolen credentials reach now versus 90 days ago? If the answer isn’t shrinking, the program in place is not working, no matter how many products were deployed."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake ChatGPT billing email targets work and home users ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A fake <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a> subscription invoice email is being used as a phishing lure to steal account credentials for users' OpenAI accounts.</p><p>Targeting both work and personal users, the email is headed: 'Urgent: Update Your Payment Method to Avoid Service Interruption', and urges victims to pay an outstanding balance of $23.80 within 48 hours.</p><p>The email, though, comes from a fake email address – support@9527db6e1a.nxcli.io – rather than an official OpenAI domain. And the 'Update Payment Information' button uses a Google API wrapper, which then redirects to a malicious payload via a webpage where a user could make a sign-in attempt.</p><p>The Google API redirect sends the victim to a page that's extremely similar to the genuine ChatGPT sign-in portal, with legitimate logos, text, and icons.</p><p>"With AI growing in popularity over the past few years, it is no surprise that threat actors are beginning to spoof ChatGPT," Josh Varden of the Cofense Phishing Defense Center (PDC) <a href="https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt">said</a>. </p><p>"Utilizing similar tactics to other phishing examples, the threat actors frequently exploit urgency and perceived trustworthiness to manipulate users into taking actions that compromise their security."</p><p>Cofense listed three indicators of compromise, all of which should be fairly easy to spot: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Meanwhile, simply hovering over the address bar to check that it says auth.openai.com would reveal the scam.  </p><p>However, this is just the latest credential-stealing phishing email to impersonate major services.</p><p>"The PDC has identified many other examples of similar credential stealing phish, most commonly spoofing Microsoft, Google, and Adobe. With AI growing in popularity over the past few years, it is no surprise that threat actors are beginning to spoof ChatGPT," said Varden. </p><p>"Utilizing similar tactics to other phishing examples, the threat actors frequently exploit urgency and perceived trustworthiness to manipulate users into taking actions that compromise their security."</p><p>Meanwhile, attackers are increasingly exploiting AI services as phishing lures. This summer, Microsoft Threat Intelligence said it was increasingly seeing similar <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, malvertising, and search engine optimization (SEO)-driven attacks, impersonating the branding of AI platforms including ChatGPT, Microsoft Copilot, <a href="https://www.itpro.com/technology/artificial-intelligence/chinese-ai-firm-deepseek-has-silicon-valley-flustered">DeepSeek</a>, and Anthropic's Claude.</p><p>One campaign, again telling users that they needed to update their payment information, consisted of 4,500 emails sent to targets in South Africa, and was part of a broader campaign delivering as many as 100,000 emails on a single day to targets in Switzerland, Austria, and South Africa.</p><p>Other examples included a phishing campaign impersonating Anthropic-branded services.</p><p>"While AI chatbots are extremely helpful tools in performing repetitive tasks, users need to be aware that, like with all account creation, the threat of credential theft is still persistent," Varden warned. </p><p>"Whether it is a traditional phishing attack... or the use of smishing/vishing, attackers are constantly finding unique pathways through security systems and secure email gateways (SEGs)." </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/phishing/fake-chatgpt-billing-email-targets-work-and-home-users</link>
                                                                            <description>
                            <![CDATA[ Cofense has uncovered a phishing campaign aimed at stealing ChatGPT credentials and payment information ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qypUfAixehee3bWR7y7NSC</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Sep 2026 11:03:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:description>                                                            <media:text><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing concept image showing an email symbol with a fishing hook pierced through, with glowing padlock symbols in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BwgyDzFJ2YV3ja2RZQJT9b-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A fake <a href="https://www.itpro.com/technology/artificial-intelligence-ai/369965/what-is-chatgpt-and-what-does-it-mean-for-businesses">ChatGPT</a> subscription invoice email is being used as a phishing lure to steal account credentials for users' OpenAI accounts.</p><p>Targeting both work and personal users, the email is headed: 'Urgent: Update Your Payment Method to Avoid Service Interruption', and urges victims to pay an outstanding balance of $23.80 within 48 hours.</p><p>The email, though, comes from a fake email address – support@9527db6e1a.nxcli.io – rather than an official OpenAI domain. And the 'Update Payment Information' button uses a Google API wrapper, which then redirects to a malicious payload via a webpage where a user could make a sign-in attempt.</p><p>The Google API redirect sends the victim to a page that's extremely similar to the genuine ChatGPT sign-in portal, with legitimate logos, text, and icons.</p><p>"With AI growing in popularity over the past few years, it is no surprise that threat actors are beginning to spoof ChatGPT," Josh Varden of the Cofense Phishing Defense Center (PDC) <a href="https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt">said</a>. </p><p>"Utilizing similar tactics to other phishing examples, the threat actors frequently exploit urgency and perceived trustworthiness to manipulate users into taking actions that compromise their security."</p><p>Cofense listed three indicators of compromise, all of which should be fairly easy to spot: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Meanwhile, simply hovering over the address bar to check that it says auth.openai.com would reveal the scam.  </p><p>However, this is just the latest credential-stealing phishing email to impersonate major services.</p><p>"The PDC has identified many other examples of similar credential stealing phish, most commonly spoofing Microsoft, Google, and Adobe. With AI growing in popularity over the past few years, it is no surprise that threat actors are beginning to spoof ChatGPT," said Varden. </p><p>"Utilizing similar tactics to other phishing examples, the threat actors frequently exploit urgency and perceived trustworthiness to manipulate users into taking actions that compromise their security."</p><p>Meanwhile, attackers are increasingly exploiting AI services as phishing lures. This summer, Microsoft Threat Intelligence said it was increasingly seeing similar <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, malvertising, and search engine optimization (SEO)-driven attacks, impersonating the branding of AI platforms including ChatGPT, Microsoft Copilot, <a href="https://www.itpro.com/technology/artificial-intelligence/chinese-ai-firm-deepseek-has-silicon-valley-flustered">DeepSeek</a>, and Anthropic's Claude.</p><p>One campaign, again telling users that they needed to update their payment information, consisted of 4,500 emails sent to targets in South Africa, and was part of a broader campaign delivering as many as 100,000 emails on a single day to targets in Switzerland, Austria, and South Africa.</p><p>Other examples included a phishing campaign impersonating Anthropic-branded services.</p><p>"While AI chatbots are extremely helpful tools in performing repetitive tasks, users need to be aware that, like with all account creation, the threat of credential theft is still persistent," Varden warned. </p><p>"Whether it is a traditional phishing attack... or the use of smishing/vishing, attackers are constantly finding unique pathways through security systems and secure email gateways (SEGs)." </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NCSC issues advice on cyber adversary simulation ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre (NCSC)</a> has released guidance on cyber adversary simulation, in the run-up to its launch of a new assured Cyber Adversary Simulation (CyAS) scheme.</p><p>Also known as red teaming, cyber adversary simulation involves testing an organization's defenses by mimicking the actions an adversary is likely to use in a real attack. This can be carried out by either internal or external teams. </p><p>It's not quite the same as <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a>, as it focuses on the effectiveness of an organization's technical controls and detection, rather than identifying technical vulnerabilities.</p><p>The NCSC CyAS scheme will see a number of commercial organizations approved to offer their services, but is still in its early stages, with plans to refine the scheme in light of feedback from partners, buyers and providers.</p><p>When it formally launches in November, there should be a range of approved providers – currently, the NCSC said, the quality of services available across the market can vary significantly.</p><p>These first documents include the <a href="https://www.ncsc.gov.uk/schemes/cyber-adversary-simulation-cyas/introduction/cyas-scheme-documents/cyas-standard">Scheme Standard</a> and <a href="https://www.ncsc.gov.uk/schemes/cyber-adversary-simulation-cyas/introduction/cyas-scheme-documents/cyas-wpd">the Working Practices Document</a>, detailing what potential providers need to do. They cover everything from how services should be set up and managed to security, ethics and technical competence.</p><p>"These documents give an early and transparent view of the standard we will use to assess applicants, including expectations on companies, key role holders, technical delivery and reporting," the NCSC said. </p><p>"As a result, buyers will have a transparent and consistent benchmark for assessing providers, helping them make more informed procurement decisions and giving them greater confidence in the quality of NCSC-assured services."</p><p>The scheme supports two different approaches to evaluating an organization's ability to detect and respond to a cyber attack, depending upon the attacker's starting location.</p><p>A full-spectrum approach starts from outside the network, and evaluates an organization during an end-to-end attack that attempts to breach the perimeter.</p><p>Alternatively, an assumed breach approach starts from a point within the customer network and simulates a threat once an attacker has managed to gain an initial foothold.</p><p>"For organizations with a mature security posture, assumed breach can provide greater value by bypassing the initial access phase and concentrating on the consequences of a successful compromise, specifically whether an attacker can expand their access beyond the initial point of entry and reach high-value targets," the NCSC advised.</p><p>The CyAS scheme is best suited to organizations with a mature understanding of the cyber risks they face – larger firms, or those operating within critical national infrastructure or the UK government. </p><p>To make the most of the services on offer, they should have already identified and assessed their risks, and have well-established mitigations and defences and robust network monitoring and detection systems in place.</p><p>"A carefully scoped adversary simulation engagement will help organizations understand where their defences are working, where they are not, and what needs to improve," the NCSC said. </p><p>"It will also evaluate whether an organization can identify threats early, triage them quickly and appropriately, and escalate where necessary."</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ncsc-issues-advice-on-cyber-adversary-simulation</link>
                                                                            <description>
                            <![CDATA[ The guidance for potential suppliers comes as the cyber authority prepares to launch a formal scheme ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DiELoJJyEdsEXMSzidvD3W</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 18 Sep 2026 09:52:34 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Attacks]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:description>                                                            <media:text><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of the UK&#039;s National Cyber Security Centre (NCSC) pictured on a television screen in London, England. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/upmScpMzZKB4C5Wt2y3h7N-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/tag/national-cyber-security-centre">National Cyber Security Centre (NCSC)</a> has released guidance on cyber adversary simulation, in the run-up to its launch of a new assured Cyber Adversary Simulation (CyAS) scheme.</p><p>Also known as red teaming, cyber adversary simulation involves testing an organization's defenses by mimicking the actions an adversary is likely to use in a real attack. This can be carried out by either internal or external teams. </p><p>It's not quite the same as <a href="https://www.itpro.com/penetration-testing/33981/what-is-penetration-testing">penetration testing</a>, as it focuses on the effectiveness of an organization's technical controls and detection, rather than identifying technical vulnerabilities.</p><p>The NCSC CyAS scheme will see a number of commercial organizations approved to offer their services, but is still in its early stages, with plans to refine the scheme in light of feedback from partners, buyers and providers.</p><p>When it formally launches in November, there should be a range of approved providers – currently, the NCSC said, the quality of services available across the market can vary significantly.</p><p>These first documents include the <a href="https://www.ncsc.gov.uk/schemes/cyber-adversary-simulation-cyas/introduction/cyas-scheme-documents/cyas-standard">Scheme Standard</a> and <a href="https://www.ncsc.gov.uk/schemes/cyber-adversary-simulation-cyas/introduction/cyas-scheme-documents/cyas-wpd">the Working Practices Document</a>, detailing what potential providers need to do. They cover everything from how services should be set up and managed to security, ethics and technical competence.</p><p>"These documents give an early and transparent view of the standard we will use to assess applicants, including expectations on companies, key role holders, technical delivery and reporting," the NCSC said. </p><p>"As a result, buyers will have a transparent and consistent benchmark for assessing providers, helping them make more informed procurement decisions and giving them greater confidence in the quality of NCSC-assured services."</p><p>The scheme supports two different approaches to evaluating an organization's ability to detect and respond to a cyber attack, depending upon the attacker's starting location.</p><p>A full-spectrum approach starts from outside the network, and evaluates an organization during an end-to-end attack that attempts to breach the perimeter.</p><p>Alternatively, an assumed breach approach starts from a point within the customer network and simulates a threat once an attacker has managed to gain an initial foothold.</p><p>"For organizations with a mature security posture, assumed breach can provide greater value by bypassing the initial access phase and concentrating on the consequences of a successful compromise, specifically whether an attacker can expand their access beyond the initial point of entry and reach high-value targets," the NCSC advised.</p><p>The CyAS scheme is best suited to organizations with a mature understanding of the cyber risks they face – larger firms, or those operating within critical national infrastructure or the UK government. </p><p>To make the most of the services on offer, they should have already identified and assessed their risks, and have well-established mitigations and defences and robust network monitoring and detection systems in place.</p><p>"A carefully scoped adversary simulation engagement will help organizations understand where their defences are working, where they are not, and what needs to improve," the NCSC said. </p><p>"It will also evaluate whether an organization can identify threats early, triage them quickly and appropriately, and escalate where necessary."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Spain says it has seen first AI agent hack ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Spain has seen its first official data breach due to an <a href="https://www.itpro.com/technology/artificial-intelligence/nine-seconds-was-all-it-took-for-an-ai-agent-to-wipe-a-startups-database-experts-warn-its-a-glimpse-into-the-future-challenges-of-identity-security">AI agent</a>. </p><p>The Spanish Data Protection Agency said in a blog post that it had received the first notification of a data breach that was apparently carried out by an AI agent using a known <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">large language model (LLM)</a>. </p><p>The revelation comes amid a wider discussion about the safety of AI, in particular agents, following a series of incidents in which OpenAI and Anthropic agents went "rogue" and targeted external organisations during evaluation tests. OpenAI admitted in July that its <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident">agents infiltrated the Hugging Face repository</a>, and Anthropic followed suit shortly afterwards with its own admission of misaligned behaviour. </p><p>Francisco Pérez Bes, the head of the Agencia Espanola Proteccion Datos (AEPD), said in a <a href="https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia">blog post</a> that the information on the attack comes entirely via the impacted organisation, with further investigation required. </p><p>But what it does show is that agentic <a href="https://www.itpro.com/security/generative-ai-attacks-are-accelerating-at-an-alarming-rate">AI attacks</a> "have ceased to be a theoretical risk," Pérez Bes said, according to an automatically translated version of the blog post. </p><p>While AI has long been used to write phishing messages, translate fraudulent campaigns, and help search for flaws to exploit, Pérez Bes said the "emergence of AI agents... introduces a qualitative change," as it can plan tasks, execute code, and modify its actions autonomously. </p><p>He added: "It's important to remember that AI doesn't create new threats. But it does increase the speed, scale, and adaptability of existing malicious techniques, reducing the time available to detect and contain them.</p><p>His comments echo warnings from the security industry, with <a href="https://www.itpro.com/security/ai-is-now-a-standard-part-of-the-attacker-toolkit">Forescout saying</a> earlier this year that AI is now a "standard part of the attacker toolkit" and Anthropic adding that <a href="https://www.itpro.com/security/anthropic-warns-ai-is-helping-lower-the-bar-for-up-and-coming-hackers">AI is helping to lower the bar</a> for hackers. </p><h2 id="what-happened">What happened? </h2><p>According to the blog post, the hackers managed to log into the compromised system, setting loose an autonomous agent to look for vulnerabilities in the application, which then allowed them to modify personal data and access invoices. </p><p>Pérez Bes stressed that there was no indication that the AI model used or its infrastructure had been compromised, and that the agent used wasn't necessarily designed to carry out such activities. </p><p>The victim of the attack hasn't been revealed, nor has the maker of the LLM itself – or any details on the hackers responsible. </p><h2 id="what-next">What next? </h2><p>Pérez Bes said the purpose of issuing the notification was to warn organizations to boost their security practices to answer the new threat of AI agents, calling it a sign to act.</p><p>"The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models," he said, according to the translated post. </p><p>He called for organizations to include AI-assisted or AI-driven attacks in their risk analysis, reconsider response times as procedures designed for manual attacks won't be able to keep pace with autonomous agents, and to take measures to protect digital identities and credentials to keep AI agents from slipping in via accounts, API keys or <a href="https://www.itpro.com/technology/artificial-intelligence/what-were-seeing-right-now-is-just-rapid-escalation-in-ai-token-spend-accenture-tells-staff-to-stop-using-ai-for-unnecessary-tasks-amid-surging-costs">tokens</a> with excessive permissions. </p><p>Pérez Bes said manual intervention is no longer enough when it comes to security. "Human supervision remains essential, but it must be supported by detection, containment, and response mechanisms capable of operating quickly enough," he said. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/spain-says-it-has-seen-first-ai-agent-hack</link>
                                                                            <description>
                            <![CDATA[ Spanish data authorities warns organisations to step up their security as AI attacks were no longer a "theoretical risk" ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HfbgqE5v98JayZ9Ay6p43E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/icLubMqY6LFfbTQiTdvfVc-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Sep 2026 11:24:43 +0000</pubDate>                                                                                                                                <updated>Thu, 17 Sep 2026 13:22:04 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/icLubMqY6LFfbTQiTdvfVc-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Spanish icons on a keyboard]]></media:description>                                                            <media:text><![CDATA[Spanish icons on a keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[Spanish icons on a keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/icLubMqY6LFfbTQiTdvfVc-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Spain has seen its first official data breach due to an <a href="https://www.itpro.com/technology/artificial-intelligence/nine-seconds-was-all-it-took-for-an-ai-agent-to-wipe-a-startups-database-experts-warn-its-a-glimpse-into-the-future-challenges-of-identity-security">AI agent</a>. </p><p>The Spanish Data Protection Agency said in a blog post that it had received the first notification of a data breach that was apparently carried out by an AI agent using a known <a href="https://www.itpro.com/technology/artificial-intelligence/generative-ai-vs-large-language-models">large language model (LLM)</a>. </p><p>The revelation comes amid a wider discussion about the safety of AI, in particular agents, following a series of incidents in which OpenAI and Anthropic agents went "rogue" and targeted external organisations during evaluation tests. OpenAI admitted in July that its <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident">agents infiltrated the Hugging Face repository</a>, and Anthropic followed suit shortly afterwards with its own admission of misaligned behaviour. </p><p>Francisco Pérez Bes, the head of the Agencia Espanola Proteccion Datos (AEPD), said in a <a href="https://www.aepd.es/prensa-y-comunicacion/blog/primera-notiviacion-brecha-datos-personales-causada-por-ataque-ejecutado-mediante-agente-ia">blog post</a> that the information on the attack comes entirely via the impacted organisation, with further investigation required. </p><p>But what it does show is that agentic <a href="https://www.itpro.com/security/generative-ai-attacks-are-accelerating-at-an-alarming-rate">AI attacks</a> "have ceased to be a theoretical risk," Pérez Bes said, according to an automatically translated version of the blog post. </p><p>While AI has long been used to write phishing messages, translate fraudulent campaigns, and help search for flaws to exploit, Pérez Bes said the "emergence of AI agents... introduces a qualitative change," as it can plan tasks, execute code, and modify its actions autonomously. </p><p>He added: "It's important to remember that AI doesn't create new threats. But it does increase the speed, scale, and adaptability of existing malicious techniques, reducing the time available to detect and contain them.</p><p>His comments echo warnings from the security industry, with <a href="https://www.itpro.com/security/ai-is-now-a-standard-part-of-the-attacker-toolkit">Forescout saying</a> earlier this year that AI is now a "standard part of the attacker toolkit" and Anthropic adding that <a href="https://www.itpro.com/security/anthropic-warns-ai-is-helping-lower-the-bar-for-up-and-coming-hackers">AI is helping to lower the bar</a> for hackers. </p><h2 id="what-happened">What happened? </h2><p>According to the blog post, the hackers managed to log into the compromised system, setting loose an autonomous agent to look for vulnerabilities in the application, which then allowed them to modify personal data and access invoices. </p><p>Pérez Bes stressed that there was no indication that the AI model used or its infrastructure had been compromised, and that the agent used wasn't necessarily designed to carry out such activities. </p><p>The victim of the attack hasn't been revealed, nor has the maker of the LLM itself – or any details on the hackers responsible. </p><h2 id="what-next">What next? </h2><p>Pérez Bes said the purpose of issuing the notification was to warn organizations to boost their security practices to answer the new threat of AI agents, calling it a sign to act.</p><p>"The arrival of AI agents in the offensive arena should prompt an immediate review of security and data protection models," he said, according to the translated post. </p><p>He called for organizations to include AI-assisted or AI-driven attacks in their risk analysis, reconsider response times as procedures designed for manual attacks won't be able to keep pace with autonomous agents, and to take measures to protect digital identities and credentials to keep AI agents from slipping in via accounts, API keys or <a href="https://www.itpro.com/technology/artificial-intelligence/what-were-seeing-right-now-is-just-rapid-escalation-in-ai-token-spend-accenture-tells-staff-to-stop-using-ai-for-unnecessary-tasks-amid-surging-costs">tokens</a> with excessive permissions. </p><p>Pérez Bes said manual intervention is no longer enough when it comes to security. "Human supervision remains essential, but it must be supported by detection, containment, and response mechanisms capable of operating quickly enough," he said. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI reveals six more rogue AI incidents  ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI has revealed six more incidents of "unexpected or concerning model behaviour", adding to the constant flow of reports of <a href="https://www.itpro.com/security/anthropic-resumes-model-testing-after-recent-cyber-incidents-but-its-introduced-new-rules-to-improve-security">rogue AI</a> amid a wider debate about the technology's safety. </p><p>Alongside the incident reports, OpenAI unveiled a framework for disclosing such misalignment issues to the public, rather than ad hoc revelations. </p><p>The report comes as the AI industry and wider stakeholders discuss how to address the risks of misalignment, following an Anthropic employee quitting to warn about safety and potentially existential risks to humanity that could arise. </p><p>In a <a href="https://openai.com/index/model-misalignment-reporting-framework/">blog post</a>, OpenAI admitted that the AI industry had not solved the alignment issue that became clear this summer amid a <a href="https://www.itpro.com/security/anthropic-joins-openai-in-admitting-loss-of-control-in-cybersecurity-tests">series of cyber incidents</a> with AI agents, and was not monitoring enough to continue scaling the technology at pace. </p><p>"Decisions about how AI development should proceed in the months and years to come need to draw on evidence that people outside the companies building frontier models can examine for themselves," the company said in the post. </p><h2 id="six-new-problems">Six new problems</h2><p>The post detailed six examples of misalignment, when the AI model or agent takes actions that humans didn't intend, such as when OpenAI's <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident">agents hacked the Hugging Face AI repository</a> in order to solve a test question. </p><p>OpenAI released detailed reports about the six new examples, but added: "These are reports of individual instances, and shouldn't be considered reflective of how often misalignment occurs across our models."</p><p>The first two cases involved altering summaries to hide mistakes or behaviour. In one case, an as-yet-unreleased model changed its own instructions, altering summaries used to continue its work, in order to "disregard its normal constraints." OpenAI said it spotted 27 instances of summary editing. The second example was similar: during training, GPT-5.6 Sol altered summaries to cover up mistakes or misaligned behaviour from users. </p><p>The third and fourth cases were about information sourcing. In one instance, a model searched for exposed API keys and then used them without authorisation – as part of a basic request to dig out earnings figures. "When it still wasn't able to retrieve the requested figures, it fabricated them and presented them as data from the requested source," the post said.</p><p>In the next instance, the model found an answer to a query about lake sizes via Python, but the user asked for a source, so it uploaded the file to be able to cite it, without telling the user. </p><p>The last two new cases had echoes of the Hugging Face incident. In one, models used a software repository as a message board to share information, and in the second, agents working together used a public file hosting website to share files online, despite the task's requirement to only use local files. </p><h2 id="sharing-misalignment">Sharing misalignment</h2><p>OpenAI said it had previously attempted to make all findings about misalignment public. "But without a systematic approach to reporting these findings, our disclosures have been ad hoc and less frequent than ideal: we've often waited until we could collate several instances into one report, or added them to system cards for newly released models," the company noted. </p><p>Because of that, the company has developed a new framework to make it easier and faster to publish misalignment reports, even if the behaviour hasn't been fully solved. </p><p>Under the new framework, any OpenAI employee can flag misalignment for investigation and request it be shared via public disclosure – though of course it's down to technical staff whether that happens. </p><p>If published, a report will include details about what happened, any harms, how the misalignment was discovered, and what OpenAI will be doing next to mitigate. </p><p>"At the moment, there is no industry-wide framework with explicit standards for how AI developers should disclose examples of misalignment in their models," the blog post added. "We hope that the framework we're outlining today is a first step toward creating such standards, setting out which misalignment instances developers should disclose and what their reports should contain."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/openai-reveals-six-more-rogue-ai-incidents</link>
                                                                            <description>
                            <![CDATA[ AI developer unveils plans for misalignment disclosure framework alongside six more incidents ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VgAr6AEiRhfuRhZwPocskS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uj3zdTMMxN4rDq4n8QC4kb-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 17 Sep 2026 09:34:52 +0000</pubDate>                                                                                                                                <updated>Thu, 17 Sep 2026 12:57:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uj3zdTMMxN4rDq4n8QC4kb-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Close-up image of OpenAI logo and branding in white coloring against a black background.]]></media:description>                                                            <media:text><![CDATA[Close-up image of OpenAI logo and branding in white coloring against a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Close-up image of OpenAI logo and branding in white coloring against a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uj3zdTMMxN4rDq4n8QC4kb-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI has revealed six more incidents of "unexpected or concerning model behaviour", adding to the constant flow of reports of <a href="https://www.itpro.com/security/anthropic-resumes-model-testing-after-recent-cyber-incidents-but-its-introduced-new-rules-to-improve-security">rogue AI</a> amid a wider debate about the technology's safety. </p><p>Alongside the incident reports, OpenAI unveiled a framework for disclosing such misalignment issues to the public, rather than ad hoc revelations. </p><p>The report comes as the AI industry and wider stakeholders discuss how to address the risks of misalignment, following an Anthropic employee quitting to warn about safety and potentially existential risks to humanity that could arise. </p><p>In a <a href="https://openai.com/index/model-misalignment-reporting-framework/">blog post</a>, OpenAI admitted that the AI industry had not solved the alignment issue that became clear this summer amid a <a href="https://www.itpro.com/security/anthropic-joins-openai-in-admitting-loss-of-control-in-cybersecurity-tests">series of cyber incidents</a> with AI agents, and was not monitoring enough to continue scaling the technology at pace. </p><p>"Decisions about how AI development should proceed in the months and years to come need to draw on evidence that people outside the companies building frontier models can examine for themselves," the company said in the post. </p><h2 id="six-new-problems">Six new problems</h2><p>The post detailed six examples of misalignment, when the AI model or agent takes actions that humans didn't intend, such as when OpenAI's <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident">agents hacked the Hugging Face AI repository</a> in order to solve a test question. </p><p>OpenAI released detailed reports about the six new examples, but added: "These are reports of individual instances, and shouldn't be considered reflective of how often misalignment occurs across our models."</p><p>The first two cases involved altering summaries to hide mistakes or behaviour. In one case, an as-yet-unreleased model changed its own instructions, altering summaries used to continue its work, in order to "disregard its normal constraints." OpenAI said it spotted 27 instances of summary editing. The second example was similar: during training, GPT-5.6 Sol altered summaries to cover up mistakes or misaligned behaviour from users. </p><p>The third and fourth cases were about information sourcing. In one instance, a model searched for exposed API keys and then used them without authorisation – as part of a basic request to dig out earnings figures. "When it still wasn't able to retrieve the requested figures, it fabricated them and presented them as data from the requested source," the post said.</p><p>In the next instance, the model found an answer to a query about lake sizes via Python, but the user asked for a source, so it uploaded the file to be able to cite it, without telling the user. </p><p>The last two new cases had echoes of the Hugging Face incident. In one, models used a software repository as a message board to share information, and in the second, agents working together used a public file hosting website to share files online, despite the task's requirement to only use local files. </p><h2 id="sharing-misalignment">Sharing misalignment</h2><p>OpenAI said it had previously attempted to make all findings about misalignment public. "But without a systematic approach to reporting these findings, our disclosures have been ad hoc and less frequent than ideal: we've often waited until we could collate several instances into one report, or added them to system cards for newly released models," the company noted. </p><p>Because of that, the company has developed a new framework to make it easier and faster to publish misalignment reports, even if the behaviour hasn't been fully solved. </p><p>Under the new framework, any OpenAI employee can flag misalignment for investigation and request it be shared via public disclosure – though of course it's down to technical staff whether that happens. </p><p>If published, a report will include details about what happened, any harms, how the misalignment was discovered, and what OpenAI will be doing next to mitigate. </p><p>"At the moment, there is no industry-wide framework with explicit standards for how AI developers should disclose examples of misalignment in their models," the blog post added. "We hope that the framework we're outlining today is a first step toward creating such standards, setting out which misalignment instances developers should disclose and what their reports should contain."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Salesforce doubles down on forward deployed engineers in UK Agentforce push ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Senior Salesforce figures have revealed plans to expand forward deployed engineering (FDE) capabilities in the UK as the CRM giant targets agentic AI adoption gains. </p><p>Speaking to assembled media at <a href="https://www.itpro.com/business/live/dreamforce-2026-live-all-the-news-updates-and-announcements-from-day-one">Dreamforce 2026</a>, Paul O’ Sullivan, SVP of Solutions Engineering at Salesforce UK, said the company plans to double the number of FDEs operating across the UK.  </p><p>“We’re going to double the size of the [FDE unit] capacity,” he said. “It strengthens our position in the UK and it shows the bigger investment that we’re making as well.” </p><p>O’Sullivan told <em>ITPro </em>this will take the total number of FDEs across the UK to “about 95”. These specialist engineers will be embedded with Salesforce customers, helping staff to use the company’s agentic AI tools and to build custom agents. </p><p>The company's <a href="https://www.salesforce.com/company/careers/jobs/?search=FDE&page=1" target="_blank">career portal</a> shows it's currently hiring for FDEs spanning core products, including Agentforce and Data 360. </p><p>FDEs act as consultants embedded directly within enterprises, offering technical guidance and working alongside internal teams to build custom AI solutions. </p><p>“The primary purpose is two-fold,” he said in response to a follow-up question from <em>Diginomica</em>. “We’re going to help you build your agents that are going to link directly to business value.”</p><p>“That’s going to allow you to then think about where you can drive better customer experience, more loyalty, improvement on service. That plays into exactly how agents can deliver value more widely.”</p><h2 id="salesforce-eyes-easy-agent-gains">Salesforce eyes easy agent gains</h2><p>The move builds on a broader push by Salesforce across the UK and Ireland, with the company accelerating skills-related investment and engagement with enterprise customers. </p><p>Notably, Salesforce already has a professional services organization designed to support adoption of its various services. While FDEs sit separate from this, Salesforce UKI CEO Zahra Bahrololoumi said they form part of a larger effort to “skill up and enable customers”. </p><p>“The more fluent our customer base is, the more they’ll get out of the platform,” she told assembled media. </p><p>“Our FDE capacity and our FDE capability has been sized at the moment to ensure that, based on what we see on where our customers are, we can get them up and running with agents and consuming and learning and tuning.”</p><p>O’Sullivan added that the FDE team is also connected to the wider engineering function at Salesforce, offering broader engineering expertise for customers. </p><p>“When we think about 95 as a growth number, we’re actually connected to an existing team that’s 330,” he said. “So the combined function will unlock more scale and more opportunity.”</p><h2 id="fdes-in-the-spotlight">FDEs in the spotlight</h2><p>Salesforce isn’t alone in its FDE focus. As <em>ITPro </em>reported in July, a host of hyperscalers and leading AI providers have expanded capabilities on this front over the last year, with the primary aim of streamlining AI deployments. </p><p>In late June, Amazon Web Services (AWS) announced plans to invest $1 billion in its Forward Deployed Engineering division. </p><p>Just days later, Microsoft unveiled the Microsoft Frontier Company as part of a $2.5 billion investment, with the long-term aim of hiring and deploying up to 6,000 AI experts and engineers inside customer organizations. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/salesforce-doubles-down-on-forward-deployed-engineers-in-uk-agentforce-push</link>
                                                                            <description>
                            <![CDATA[ Specialist Salesforce engineers will be embedded within customer teams ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">R4a4KshjREagtWWKLuqFGn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dBk72cVyHkiroDkyErb6y-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 18:00:16 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Sep 2026 18:01:07 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dBk72cVyHkiroDkyErb6y-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Salesforce logo pictured on a sign at the company&#039;s headquarters in San Francisco, USA. ]]></media:description>                                                            <media:text><![CDATA[Salesforce logo pictured on a sign at the company&#039;s headquarters in San Francisco, USA. ]]></media:text>
                                <media:title type="plain"><![CDATA[Salesforce logo pictured on a sign at the company&#039;s headquarters in San Francisco, USA. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dBk72cVyHkiroDkyErb6y-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Senior Salesforce figures have revealed plans to expand forward deployed engineering (FDE) capabilities in the UK as the CRM giant targets agentic AI adoption gains. </p><p>Speaking to assembled media at <a href="https://www.itpro.com/business/live/dreamforce-2026-live-all-the-news-updates-and-announcements-from-day-one">Dreamforce 2026</a>, Paul O’ Sullivan, SVP of Solutions Engineering at Salesforce UK, said the company plans to double the number of FDEs operating across the UK.  </p><p>“We’re going to double the size of the [FDE unit] capacity,” he said. “It strengthens our position in the UK and it shows the bigger investment that we’re making as well.” </p><p>O’Sullivan told <em>ITPro </em>this will take the total number of FDEs across the UK to “about 95”. These specialist engineers will be embedded with Salesforce customers, helping staff to use the company’s agentic AI tools and to build custom agents. </p><p>The company's <a href="https://www.salesforce.com/company/careers/jobs/?search=FDE&page=1" target="_blank">career portal</a> shows it's currently hiring for FDEs spanning core products, including Agentforce and Data 360. </p><p>FDEs act as consultants embedded directly within enterprises, offering technical guidance and working alongside internal teams to build custom AI solutions. </p><p>“The primary purpose is two-fold,” he said in response to a follow-up question from <em>Diginomica</em>. “We’re going to help you build your agents that are going to link directly to business value.”</p><p>“That’s going to allow you to then think about where you can drive better customer experience, more loyalty, improvement on service. That plays into exactly how agents can deliver value more widely.”</p><h2 id="salesforce-eyes-easy-agent-gains">Salesforce eyes easy agent gains</h2><p>The move builds on a broader push by Salesforce across the UK and Ireland, with the company accelerating skills-related investment and engagement with enterprise customers. </p><p>Notably, Salesforce already has a professional services organization designed to support adoption of its various services. While FDEs sit separate from this, Salesforce UKI CEO Zahra Bahrololoumi said they form part of a larger effort to “skill up and enable customers”. </p><p>“The more fluent our customer base is, the more they’ll get out of the platform,” she told assembled media. </p><p>“Our FDE capacity and our FDE capability has been sized at the moment to ensure that, based on what we see on where our customers are, we can get them up and running with agents and consuming and learning and tuning.”</p><p>O’Sullivan added that the FDE team is also connected to the wider engineering function at Salesforce, offering broader engineering expertise for customers. </p><p>“When we think about 95 as a growth number, we’re actually connected to an existing team that’s 330,” he said. “So the combined function will unlock more scale and more opportunity.”</p><h2 id="fdes-in-the-spotlight">FDEs in the spotlight</h2><p>Salesforce isn’t alone in its FDE focus. As <em>ITPro </em>reported in July, a host of hyperscalers and leading AI providers have expanded capabilities on this front over the last year, with the primary aim of streamlining AI deployments. </p><p>In late June, Amazon Web Services (AWS) announced plans to invest $1 billion in its Forward Deployed Engineering division. </p><p>Just days later, Microsoft unveiled the Microsoft Frontier Company as part of a $2.5 billion investment, with the long-term aim of hiring and deploying up to 6,000 AI experts and engineers inside customer organizations. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ UK SMBs are the most vulnerable to cyber attacks ]]></title>
                                                                                                <dc:content><![CDATA[ <p>British small businesses (SMBs) are more likely to be hit by <a href="https://www.itpro.com/security/cyber-attacks/how-cyber-attacks-damage-mental-health">cyber attacks </a>than those in other countries, with two in five falling victim last year.</p><p>Globally, 29% of organizations have been hit by a successful cyber attack in the past year, according to the tenth annual <a href="https://www.hiscoxgroup.com/hiscox-cyber-readiness-report-2026">Hiscox Cyber Readiness Report</a>. However, for UK businesses, the figure's substantially higher, at 38% – making it the most-affected country worldwide.</p><p>UK SMBs are spending less to <a href="https://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk">remediate</a> these attacks, with an average cost per attack of $35,908, compared with $52,000 globally. On average, incidents caused around 32 hours of operational disruption.</p><p>But, commented Jamie Akhtar, CEO and co-founder of Cybersmart, "While the average cost of an individual attack in the UK may be lower than the global average, the higher proportion of businesses being successfully compromised means many more firms are being exposed to those costs in the first place."</p><p>Meanwhile, small UK firms are failing to insure themselves adequately against cyber attacks, according to Hiscox, with only four-in-ten having cyber coverage, compared with around 63% of medium-sized firms and seven-in-ten FTSE 100 companies.</p><p>UK firms are actually spending more than average on cyber resilience, at $59,700 – the third-highest spend – compared with a global average investment of $51,000. Just over half of firms are adopting new technology, with 55% investing in specialist staff and 62% updating employee training.</p><p>The reasons for the greater vulnerability of UK firms aren't apparent.</p><p>"These are some concerning results, and it's not clear why the UK is suffering a larger volume of attacks compared to other countries," said Keven Knight, CEO of Talion Cyber Security. </p><p>"It could be as a result of geopolitical instability, or it could be because of the wave of attacks against retailers from last year, which might have spurred attackers to target businesses in the region."  </p><p>However, there also appears to be a link between <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> performance and executive compensation: globally, 32% of firms said executive pay is now linked to cybersecurity performance, while the figure was just 25% for UK firms.</p><p>Overall, cyber attacks are costing small businesses dear, with 32% saying they have delayed growth and expansion plans, and 31% that incidents have increased staffing costs. Three-in-ten said they'd experienced financial damage and 29% that they'd lost business opportunities. Even more – 48% – cited reputation and customer trust as the most significant cyber-related risk. </p><p>"It's never just about containing an incident initially and moving on, that's naive and unrealistic. It's the aftermath of an attack, where organisations have to work through the financial losses and operational downtime, that causes the greatest damage," said Knight.</p><p>"Downtime doesn't just mean being locked out of computers, it means disruption to service, disruption to employees and their ability to perform their jobs, plus disruption to customers because they are unable to access the services or goods an organisation provides to them. Every second of downtime costs the business money."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/uk-smbs-are-the-most-vulnerable-to-cyber-attacks</link>
                                                                            <description>
                            <![CDATA[ Organizations cite delayed growth and expansion plans, financial damage and missed business opportunities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jcwjU4V8fMkHeWiaAYkccg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HfCpGUG6E8K2iiarJuNM4L-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 11:19:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Attacks]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HfCpGUG6E8K2iiarJuNM4L-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital Union Jack flag ]]></media:description>                                                            <media:text><![CDATA[A digital Union Jack flag ]]></media:text>
                                <media:title type="plain"><![CDATA[A digital Union Jack flag ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HfCpGUG6E8K2iiarJuNM4L-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>British small businesses (SMBs) are more likely to be hit by <a href="https://www.itpro.com/security/cyber-attacks/how-cyber-attacks-damage-mental-health">cyber attacks </a>than those in other countries, with two in five falling victim last year.</p><p>Globally, 29% of organizations have been hit by a successful cyber attack in the past year, according to the tenth annual <a href="https://www.hiscoxgroup.com/hiscox-cyber-readiness-report-2026">Hiscox Cyber Readiness Report</a>. However, for UK businesses, the figure's substantially higher, at 38% – making it the most-affected country worldwide.</p><p>UK SMBs are spending less to <a href="https://www.itpro.com/security/patch-management-why-firms-ignore-vulnerabilities-at-their-own-risk">remediate</a> these attacks, with an average cost per attack of $35,908, compared with $52,000 globally. On average, incidents caused around 32 hours of operational disruption.</p><p>But, commented Jamie Akhtar, CEO and co-founder of Cybersmart, "While the average cost of an individual attack in the UK may be lower than the global average, the higher proportion of businesses being successfully compromised means many more firms are being exposed to those costs in the first place."</p><p>Meanwhile, small UK firms are failing to insure themselves adequately against cyber attacks, according to Hiscox, with only four-in-ten having cyber coverage, compared with around 63% of medium-sized firms and seven-in-ten FTSE 100 companies.</p><p>UK firms are actually spending more than average on cyber resilience, at $59,700 – the third-highest spend – compared with a global average investment of $51,000. Just over half of firms are adopting new technology, with 55% investing in specialist staff and 62% updating employee training.</p><p>The reasons for the greater vulnerability of UK firms aren't apparent.</p><p>"These are some concerning results, and it's not clear why the UK is suffering a larger volume of attacks compared to other countries," said Keven Knight, CEO of Talion Cyber Security. </p><p>"It could be as a result of geopolitical instability, or it could be because of the wave of attacks against retailers from last year, which might have spurred attackers to target businesses in the region."  </p><p>However, there also appears to be a link between <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity</a> performance and executive compensation: globally, 32% of firms said executive pay is now linked to cybersecurity performance, while the figure was just 25% for UK firms.</p><p>Overall, cyber attacks are costing small businesses dear, with 32% saying they have delayed growth and expansion plans, and 31% that incidents have increased staffing costs. Three-in-ten said they'd experienced financial damage and 29% that they'd lost business opportunities. Even more – 48% – cited reputation and customer trust as the most significant cyber-related risk. </p><p>"It's never just about containing an incident initially and moving on, that's naive and unrealistic. It's the aftermath of an attack, where organisations have to work through the financial losses and operational downtime, that causes the greatest damage," said Knight.</p><p>"Downtime doesn't just mean being locked out of computers, it means disruption to service, disruption to employees and their ability to perform their jobs, plus disruption to customers because they are unable to access the services or goods an organisation provides to them. Every second of downtime costs the business money."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dreamforce 2026 showed AI safety is the new big tech battleground ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-open-source-ai-models">AI safety risks</a> were the big talking point on the opening day of <a href="https://www.itpro.com/business/live/dreamforce-2026-live-all-the-news-updates-and-announcements-from-day-one">Dreamforce 2026</a>, with the annual conference’s star-studded line-up bringing the topic to the fore. </p><p>Anthropic CEO Dario Amodei joined Salesforce chief Marc Benioff during the opening keynote to discuss the company’s Claudeforce launch. Recent comments on the concerning pace of AI development dominated the discussion, however. </p><p>With companies such as Anthropic rolling out increasingly powerful models, Amodei told Benioff that the industry needs to have a candid discussion about development timelines, AI safety, and the introduction of more robust guardrails. </p><p>“We can always be better, let’s make our practices better, let’s recommit to transparency,” he told the Salesforce CEO. “Let’s invest more in safety, then let’s organize the rest of the industry and say ‘what can we do to set standards for everyone?’.”</p><p>Amodei’s comments came after he published a <a href="https://darioamodei.com/post/we-must-pace-the-frontier#embedded-evaluators" target="_blank"><u>lengthy essay</u></a> on 12 September arguing that the AI industry needs to slow down the pace of AI development to counter potential harms. This call for “pacing the frontier” was echoed by OpenAI CEO Sam Altman and xAI chief Elon Musk online. </p><h2 id="why-the-focus-on-ai-safety">Why the focus on AI safety?</h2><p>The topic of AI safety has been thrust into the spotlight after a series of high profile security incidents involving agents at OpenAI, Anthropic, and Meta. These incidents saw agents escape testing environments and <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident">breach third-party companies such as Hugging Face</a>. </p><p>Combined with <a href="https://www.nbcnews.com/tech/security/anthropic-whistleblower-congress-ai-companies-regulation-rcna597465" target="_blank">whistle blower claims</a> that AI could severely harm humanity in recent days, the topic appears to have reached boiling point. </p><p>Speaking during a fireside chat with Benioff later in the day, Altman said the Hugging Face debacle “triggered a real rest, not just in our own company, but in the world”. </p><p>“I think people also feel the speed with which things are moving,” he told Benioff. “There have been things like the Hugging Face accidents, other accidents in the field.”</p><p>Altman added that he is confident both in the ability of the industry and OpenAI itself to slow down the pace of development and sharpen the focus on AI safety. </p><h2 id="individual-responsibility">Individual responsibility</h2><p>While Altman and Amodei have called for an international effort to slow down the pace of AI development, Nvidia CEO Jensen Huang thinks the responsibility rests firmly on individual companies – not erecting new barriers. </p><p>“We don’t need any new laws, we don’t need any new regulations,” he told Benioff. </p><p>Huang is by no means calling for a Wild West approach to AI development, rather arguing that the onus must be placed on developers that are rolling out products they feel they cannot adequately contain.</p><p>“Safety is paramount,” he said. “Safety is an engineering problem. We’re developing software after all, we’re developing computing systems after all. It’s complicated computing systems, but ultimately it’s a computing system.”</p><p>Huang said that testing environments need to be “built in a good way” to avoid repeats of the incidents involving Meta, OpenAI, and Anthropic. That responsibility lies with them, not by insisting the rest of the industry adheres to their playbook. </p><p>As <em>ITPro </em>reported in August, all three companies involved in ‘rogue AI’ incidents <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents">worked with the same testing company</a> before agents escaped their sandbox environments. </p><p>“If we're not confident about the safety of the products, like all companies … if you build a product or a service and you're not confident in its functionality, capability, or safety, then don't release it,” he said. </p><p>“That's a very obvious thing to do. You pace yourself until you are confident you're releasing something that the market would appreciate.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/dreamforce-2026-showed-ai-safety-is-the-new-big-tech-battleground</link>
                                                                            <description>
                            <![CDATA[ Differing outlooks on AI safety risks have become clear as leading tech figures hit an impasse on responsible development ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWUo82ZPQF9o28rP5bnnHN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XiQrnUdJUNB2DzzeV4T7Xb-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 16 Sep 2026 00:02:37 +0000</pubDate>                                                                                                                                <updated>Wed, 16 Sep 2026 18:02:37 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XiQrnUdJUNB2DzzeV4T7Xb-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Anthropic CEO Dario Amodei pictured with Salesforce CEO Marc Benioff during a discussion on AI safety at Dreamforce 2026 in San Francisco, USA.]]></media:description>                                                            <media:text><![CDATA[Anthropic CEO Dario Amodei pictured with Salesforce CEO Marc Benioff during a discussion on AI safety at Dreamforce 2026 in San Francisco, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[Anthropic CEO Dario Amodei pictured with Salesforce CEO Marc Benioff during a discussion on AI safety at Dreamforce 2026 in San Francisco, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XiQrnUdJUNB2DzzeV4T7Xb-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-open-source-ai-models">AI safety risks</a> were the big talking point on the opening day of <a href="https://www.itpro.com/business/live/dreamforce-2026-live-all-the-news-updates-and-announcements-from-day-one">Dreamforce 2026</a>, with the annual conference’s star-studded line-up bringing the topic to the fore. </p><p>Anthropic CEO Dario Amodei joined Salesforce chief Marc Benioff during the opening keynote to discuss the company’s Claudeforce launch. Recent comments on the concerning pace of AI development dominated the discussion, however. </p><p>With companies such as Anthropic rolling out increasingly powerful models, Amodei told Benioff that the industry needs to have a candid discussion about development timelines, AI safety, and the introduction of more robust guardrails. </p><p>“We can always be better, let’s make our practices better, let’s recommit to transparency,” he told the Salesforce CEO. “Let’s invest more in safety, then let’s organize the rest of the industry and say ‘what can we do to set standards for everyone?’.”</p><p>Amodei’s comments came after he published a <a href="https://darioamodei.com/post/we-must-pace-the-frontier#embedded-evaluators" target="_blank"><u>lengthy essay</u></a> on 12 September arguing that the AI industry needs to slow down the pace of AI development to counter potential harms. This call for “pacing the frontier” was echoed by OpenAI CEO Sam Altman and xAI chief Elon Musk online. </p><h2 id="why-the-focus-on-ai-safety">Why the focus on AI safety?</h2><p>The topic of AI safety has been thrust into the spotlight after a series of high profile security incidents involving agents at OpenAI, Anthropic, and Meta. These incidents saw agents escape testing environments and <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident">breach third-party companies such as Hugging Face</a>. </p><p>Combined with <a href="https://www.nbcnews.com/tech/security/anthropic-whistleblower-congress-ai-companies-regulation-rcna597465" target="_blank">whistle blower claims</a> that AI could severely harm humanity in recent days, the topic appears to have reached boiling point. </p><p>Speaking during a fireside chat with Benioff later in the day, Altman said the Hugging Face debacle “triggered a real rest, not just in our own company, but in the world”. </p><p>“I think people also feel the speed with which things are moving,” he told Benioff. “There have been things like the Hugging Face accidents, other accidents in the field.”</p><p>Altman added that he is confident both in the ability of the industry and OpenAI itself to slow down the pace of development and sharpen the focus on AI safety. </p><h2 id="individual-responsibility">Individual responsibility</h2><p>While Altman and Amodei have called for an international effort to slow down the pace of AI development, Nvidia CEO Jensen Huang thinks the responsibility rests firmly on individual companies – not erecting new barriers. </p><p>“We don’t need any new laws, we don’t need any new regulations,” he told Benioff. </p><p>Huang is by no means calling for a Wild West approach to AI development, rather arguing that the onus must be placed on developers that are rolling out products they feel they cannot adequately contain.</p><p>“Safety is paramount,” he said. “Safety is an engineering problem. We’re developing software after all, we’re developing computing systems after all. It’s complicated computing systems, but ultimately it’s a computing system.”</p><p>Huang said that testing environments need to be “built in a good way” to avoid repeats of the incidents involving Meta, OpenAI, and Anthropic. That responsibility lies with them, not by insisting the rest of the industry adheres to their playbook. </p><p>As <em>ITPro </em>reported in August, all three companies involved in ‘rogue AI’ incidents <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents">worked with the same testing company</a> before agents escaped their sandbox environments. </p><p>“If we're not confident about the safety of the products, like all companies … if you build a product or a service and you're not confident in its functionality, capability, or safety, then don't release it,” he said. </p><p>“That's a very obvious thing to do. You pace yourself until you are confident you're releasing something that the market would appreciate.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Gartner: here's how AI will remake business in the next three years ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cost exhaustion attacks, disposable applications, and evidence custodians – these are the ideas businesses need to prepare for within the next three years or less. </p><p>That's according to analyst house Gartner, which laid out a list of ten predictions for 2027 to 2030, many of which are focused on <a href="https://www.itpro.com/technology/artificial-intelligence">AI</a> and its potential business impacts. </p><p>That includes physical AI or robots, agent swarms clogging up public services or running down budgets, and unpicking how to actually manage AI costs, providers, and risks. </p><p>"Many of the systems we take for granted today, from public services to software, energy and workforce models, will be fundamentally transformed by AI over the next decade," said Daryl Plummer, distinguished VP analyst and Gartner fellow. </p><p>"The most successful organizations will be those that balance innovation with responsibility, building the capabilities needed to manage both the opportunities and the unintended consequences of an AI-driven world," Plummer added. </p><h2 id="ai-risks-on-the-horizon">AI risks on the horizon</h2><p>The analyst firm predicted that more than ten billion <a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-the-age-of-agentic-ai">autonomous agents </a>will be clogging up public services by 2030. Those agents will have been made by people, companies, and even governments in order to take on basic tasks for users. But that will lead to a sharp increase in the number of applications and other transactions, putting pressure on the government to keep up. </p><p>To prepare, Gartner called on governments to modernise their digital infrastructure and strengthen verification, though they'll only have a few years to do so. </p><p>Alongside that, organisations will face a new type of cybersecurity risk: <a href="https://www.itpro.com/security/the-hidden-cost-of-ransomware-is-more-painful-than-many-realize">cost exhaustion attacks</a>. These are like a denial of service attack, but focused on driving up the cost of AI used by the company. </p><p>"The rise of public-facing AI is creating a new cybersecurity risk called cost exhaustion attacks, where malicious actors deliberately drive excessive AI usage to increase operational costs," Gartner said in a statement. </p><p>To avoid this, companies should consider AI usage patterns and token consumption as security concerns, ensuring both are monitored, saying eight in ten companies will face these attacks within the next few years. </p><h2 id="ai-business">AI business</h2><p>Gartner also predicts that by 2030, 80% of front-line employees working for global companies will be working alongside or with physical AI, such as robots, drones, autonomous vehicles, or "other embodied systems that sense, interact with, and influence their surroundings." </p><p>By 2029, most applications will become disposable – on purpose. These disposable apps will be used for less than one year, with employees using AI app development in order to meet short-term needs, ditching the tool when it's no longer needed. Gartner warned that will spark governance and security challenges. </p><p>Beyond AI-generated apps, Gartner also forecasts the rise of AI-powered products, which will allow companies to introduce "customised, efficient and scalable offerings," leaving behind those who haven't gotten to grips with the tech. Gartner also predicted more firms will find themselves generating power, selling it back to grids or to AI data centres.</p><h2 id="watching-ai-and-its-cost">Watching AI – and its cost</h2><p>To help manage the rise of AI, companies will create a new role or corporate function dedicated to managing AI costs and mapping it to value or profit, with 60% of the largest companies embedding financial operations controls at inference, leading to real-time optimisation and cost governance. <a href="https://www.itpro.com/business/business-strategy/why-legacy-tech-is-stifling-cios-dreams-of-global-growth">CIOs</a>, meanwhile, will become the "evidence custodian" for AI accountability in businesses, ensuring guardrails are in place. </p><p>Alongside that, Gartner predicted that insurers will drive AI governance in organizations, rather than regulators, with policy-based AI built into systems and workflows to address the growing concerns around risks and liabilities associated with the technology. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/gartner-heres-how-ai-will-remake-business-in-the-next-three-years</link>
                                                                            <description>
                            <![CDATA[ You've got three years to prep for these new attacks and challenges thanks to AI, says Gartner ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5u2ArvcsqjTUNnS5YP3sbH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/44bS4XVWGfXnqLkeywEJkm-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Sep 2026 12:28:48 +0000</pubDate>                                                                                                                                <updated>Tue, 15 Sep 2026 12:29:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Artificial Intelligence]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/44bS4XVWGfXnqLkeywEJkm-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A visualization of machine identities, shown as blue nodes in the shape of the world with code surrounding them, against a black background.]]></media:description>                                                            <media:text><![CDATA[A visualization of machine identities, shown as blue nodes in the shape of the world with code surrounding them, against a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[A visualization of machine identities, shown as blue nodes in the shape of the world with code surrounding them, against a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/44bS4XVWGfXnqLkeywEJkm-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cost exhaustion attacks, disposable applications, and evidence custodians – these are the ideas businesses need to prepare for within the next three years or less. </p><p>That's according to analyst house Gartner, which laid out a list of ten predictions for 2027 to 2030, many of which are focused on <a href="https://www.itpro.com/technology/artificial-intelligence">AI</a> and its potential business impacts. </p><p>That includes physical AI or robots, agent swarms clogging up public services or running down budgets, and unpicking how to actually manage AI costs, providers, and risks. </p><p>"Many of the systems we take for granted today, from public services to software, energy and workforce models, will be fundamentally transformed by AI over the next decade," said Daryl Plummer, distinguished VP analyst and Gartner fellow. </p><p>"The most successful organizations will be those that balance innovation with responsibility, building the capabilities needed to manage both the opportunities and the unintended consequences of an AI-driven world," Plummer added. </p><h2 id="ai-risks-on-the-horizon">AI risks on the horizon</h2><p>The analyst firm predicted that more than ten billion <a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-the-age-of-agentic-ai">autonomous agents </a>will be clogging up public services by 2030. Those agents will have been made by people, companies, and even governments in order to take on basic tasks for users. But that will lead to a sharp increase in the number of applications and other transactions, putting pressure on the government to keep up. </p><p>To prepare, Gartner called on governments to modernise their digital infrastructure and strengthen verification, though they'll only have a few years to do so. </p><p>Alongside that, organisations will face a new type of cybersecurity risk: <a href="https://www.itpro.com/security/the-hidden-cost-of-ransomware-is-more-painful-than-many-realize">cost exhaustion attacks</a>. These are like a denial of service attack, but focused on driving up the cost of AI used by the company. </p><p>"The rise of public-facing AI is creating a new cybersecurity risk called cost exhaustion attacks, where malicious actors deliberately drive excessive AI usage to increase operational costs," Gartner said in a statement. </p><p>To avoid this, companies should consider AI usage patterns and token consumption as security concerns, ensuring both are monitored, saying eight in ten companies will face these attacks within the next few years. </p><h2 id="ai-business">AI business</h2><p>Gartner also predicts that by 2030, 80% of front-line employees working for global companies will be working alongside or with physical AI, such as robots, drones, autonomous vehicles, or "other embodied systems that sense, interact with, and influence their surroundings." </p><p>By 2029, most applications will become disposable – on purpose. These disposable apps will be used for less than one year, with employees using AI app development in order to meet short-term needs, ditching the tool when it's no longer needed. Gartner warned that will spark governance and security challenges. </p><p>Beyond AI-generated apps, Gartner also forecasts the rise of AI-powered products, which will allow companies to introduce "customised, efficient and scalable offerings," leaving behind those who haven't gotten to grips with the tech. Gartner also predicted more firms will find themselves generating power, selling it back to grids or to AI data centres.</p><h2 id="watching-ai-and-its-cost">Watching AI – and its cost</h2><p>To help manage the rise of AI, companies will create a new role or corporate function dedicated to managing AI costs and mapping it to value or profit, with 60% of the largest companies embedding financial operations controls at inference, leading to real-time optimisation and cost governance. <a href="https://www.itpro.com/business/business-strategy/why-legacy-tech-is-stifling-cios-dreams-of-global-growth">CIOs</a>, meanwhile, will become the "evidence custodian" for AI accountability in businesses, ensuring guardrails are in place. </p><p>Alongside that, Gartner predicted that insurers will drive AI governance in organizations, rather than regulators, with policy-based AI built into systems and workflows to address the growing concerns around risks and liabilities associated with the technology. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Two-thirds of cyber threats still require manual resolution ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Automation and agents in Security Operations Centers (SOCs) aren't easing the job of security analysts, with teams overwhelmingly stuck having to resolve problems manually. </p><p>Security analysts are forced to spend 68% of their day on reactive alert triage and manual data gathering, leaving little time for proactive threat hunting. Meanwhile, 68% of all threat detections still require manual human intervention to resolve, a new report from network intelligence form ExaHop has revealed in a new <a href="https://cloud-assets.extrahop.com/resources/ebooks/extrahop-global-threat-landscape-report-2026.pdf">report</a>.</p><p>"Security teams are facing a crisis in dealing with <a href="https://www.itpro.com/technology/artificial-intelligence/ai-powered-ddos-attacks-are-changing-the-threat-landscape">AI-powered threats,</a>" said Jamie Moles, Senior Technical Manager, ExtraHop.</p><p>"To solve this, security teams are diligently working towards achieving an agentic SOC that drastically expedites the entire security response cycle while eliminating the burden and fatigue analysts have been experiencing."</p><p>When asked which elements of the attack surface they believe represent the most significant cybersecurity risk, 55% of survey respondents cited <a href="https://www.itpro.com/technology/artificial-intelligence/compromised-ai-agents-could-make-living-off-the-land-attacks-much-more-dangerous-says-crowdstrike-field-cto">AI agents</a> and generative AI applications, followed by public cloud services at 45% and third-party services and integrations at 35%.</p><p>However, the researchers said the timeline to identify threats has lengthened, with 49% of organizations only identifying <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> activity after it reached the data exfiltration or later stages – up from less than a third in 2025.</p><p>Nearly 15% failed to recognize that they were being targeted until a ransom demand was issued, up from 6% the previous year. </p><p>When asked which factors delayed a critical alert from being detected or investigated, 41% cited the use of encrypted channels to bypass detection. Meanwhile, 38% said that attacker activity mirrored legitimate, authorized workflows and processes, and 34% noted that valid, high-privilege account permissions were used in the attack.</p><p>As a result, SOC workflows remain heavily manual, with most respondents reporting mid-to-high levels of manual intervention across the threat lifecycle. Investigation was the most manual stage, requiring manual intervention about 50% of the time.</p><p>SOC analysts are limited to spending just 44% of their time on proactive efforts, such as threat hunting and detection engineering.</p><p>The problem, the firm said, extends across all SOC-adjacent job roles and organizations of all sizes. While larger companies show a slight trend toward spending more time on proactive efforts, the increase isn't proportional to the size of the company, showing that scale doesn't solve the problem.</p><p>In order to make the most of AI models and reduce the burden on human analysts, said ExaHop, organizations need a base-level layer of contextual intelligence that allows agents to act decisively and quickly.</p><p>"A well-trained AI model has the reasoning and processing capabilities to analyse environment-wide anomalies instantly, doing in seconds what would take a human analyst hours. But these powerful models must be implemented with the right safeguards in place, sitting atop a layer of intelligence that can be easily accessed and acted upon," said Moles. </p><p>"Automated security will be the standard, but without the right underlying foundation, organizations will continue struggling to keep up with high-velocity threats."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/two-thirds-of-cyber-threats-still-require-manual-resolution</link>
                                                                            <description>
                            <![CDATA[ Security teams are spending most of their time on reactive alert triage and manual data gathering, with little left over for proactive threat hunting ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">d9K526METbuuGqQptokWiD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9bG39dHepwjdwTbjrttSV7-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Sep 2026 12:18:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Attacks]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9bG39dHepwjdwTbjrttSV7-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A businessperson&#039;s hands using a laptop, with overlaid red and yellow, holographic warning symbols indicating a cyber scam and fraud.]]></media:description>                                                            <media:text><![CDATA[A businessperson&#039;s hands using a laptop, with overlaid red and yellow, holographic warning symbols indicating a cyber scam and fraud.]]></media:text>
                                <media:title type="plain"><![CDATA[A businessperson&#039;s hands using a laptop, with overlaid red and yellow, holographic warning symbols indicating a cyber scam and fraud.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9bG39dHepwjdwTbjrttSV7-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Automation and agents in Security Operations Centers (SOCs) aren't easing the job of security analysts, with teams overwhelmingly stuck having to resolve problems manually. </p><p>Security analysts are forced to spend 68% of their day on reactive alert triage and manual data gathering, leaving little time for proactive threat hunting. Meanwhile, 68% of all threat detections still require manual human intervention to resolve, a new report from network intelligence form ExaHop has revealed in a new <a href="https://cloud-assets.extrahop.com/resources/ebooks/extrahop-global-threat-landscape-report-2026.pdf">report</a>.</p><p>"Security teams are facing a crisis in dealing with <a href="https://www.itpro.com/technology/artificial-intelligence/ai-powered-ddos-attacks-are-changing-the-threat-landscape">AI-powered threats,</a>" said Jamie Moles, Senior Technical Manager, ExtraHop.</p><p>"To solve this, security teams are diligently working towards achieving an agentic SOC that drastically expedites the entire security response cycle while eliminating the burden and fatigue analysts have been experiencing."</p><p>When asked which elements of the attack surface they believe represent the most significant cybersecurity risk, 55% of survey respondents cited <a href="https://www.itpro.com/technology/artificial-intelligence/compromised-ai-agents-could-make-living-off-the-land-attacks-much-more-dangerous-says-crowdstrike-field-cto">AI agents</a> and generative AI applications, followed by public cloud services at 45% and third-party services and integrations at 35%.</p><p>However, the researchers said the timeline to identify threats has lengthened, with 49% of organizations only identifying <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware</a> activity after it reached the data exfiltration or later stages – up from less than a third in 2025.</p><p>Nearly 15% failed to recognize that they were being targeted until a ransom demand was issued, up from 6% the previous year. </p><p>When asked which factors delayed a critical alert from being detected or investigated, 41% cited the use of encrypted channels to bypass detection. Meanwhile, 38% said that attacker activity mirrored legitimate, authorized workflows and processes, and 34% noted that valid, high-privilege account permissions were used in the attack.</p><p>As a result, SOC workflows remain heavily manual, with most respondents reporting mid-to-high levels of manual intervention across the threat lifecycle. Investigation was the most manual stage, requiring manual intervention about 50% of the time.</p><p>SOC analysts are limited to spending just 44% of their time on proactive efforts, such as threat hunting and detection engineering.</p><p>The problem, the firm said, extends across all SOC-adjacent job roles and organizations of all sizes. While larger companies show a slight trend toward spending more time on proactive efforts, the increase isn't proportional to the size of the company, showing that scale doesn't solve the problem.</p><p>In order to make the most of AI models and reduce the burden on human analysts, said ExaHop, organizations need a base-level layer of contextual intelligence that allows agents to act decisively and quickly.</p><p>"A well-trained AI model has the reasoning and processing capabilities to analyse environment-wide anomalies instantly, doing in seconds what would take a human analyst hours. But these powerful models must be implemented with the right safeguards in place, sitting atop a layer of intelligence that can be easily accessed and acted upon," said Moles. </p><p>"Automated security will be the standard, but without the right underlying foundation, organizations will continue struggling to keep up with high-velocity threats."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Patch Tuesday inadvertently takes down copy and paste in Excel ]]></title>
                                                                                                <dc:content><![CDATA[ <p>If you're having trouble with copy and paste in Excel, you're not doing it wrong; it's simply been disabled by Microsoft's latest Patch Tuesday update. </p><p>Unfortunately, it's going to be like that for some time, as there isn't a fix, at the time of writing. </p><p><a href="https://www.itpro.com/629377/microsoft-plans-mega-patch-tuesday">Patch Tuesday</a> is a monthly update from Microsoft where it fixes and updates various parts of its software. Much of it focuses on <a href="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review">Windows</a> security and improvements to its suite of applications. </p><p>However, these fixes sometimes cause problems elsewhere. Case in point: the latest security patch for Excel has taken down the copy-paste function. Users first reported issues with Excel 2016 after the update, known as KB5002914, was installed. Soon after, users reported the issue in other versions of <a href="https://www.itpro.com/business-operations/productivity/363979/google-sheets-vs-microsoft-excel">Excel</a>, and Microsoft has acknowledged it and said it is working on a fix. </p><p>Under 'known issues', Microsoft <a href="https://support.microsoft.com/en-us/servicing/office/hotfix/excel/5002914">posted</a>: "In Microsoft Excel 2024, 2021, 2019, and 2016, the paste operation might fail silently. Although users try to paste content, the source remains selected, and the destination is unmodified. When this issue occurs, users receive no indication of the failure, such as a beep or error message. Microsoft is researching the issue and will post more information in this article when the information becomes available."</p><p>Bugs and issues are expected when updating a sprawling software stack like Microsoft's, and the company's Patch Tuesday releases have been known to come with some downsides. In May, bugs where images would not display inside mail were <a href="https://www.neowin.net/news/microsoft-admits-one-of-the-most-basic-useful-outlook-features-is-broken/">reported</a>, and in June, the main email messages were <a href="https://www.neowin.net/news/microsoft-admits-one-of-the-most-crucial-outlook-features-is-currently-broken/">hidden</a>. Both were a result of monthly updates. </p><p>Thankfully, Microsoft has spotted and acknowledged this issue introduced by KB5002914. Unfortunately, it has yet to come back with a fix, so there isn't anything you can do except painstakingly type out everything in Excel. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/microsoft-patch-tuesday-inadvertently-takes-down-copy-and-paste-in-excel-and-theres-no-way-to-fix-it-yet</link>
                                                                            <description>
                            <![CDATA[ The bug in release KB5002914 affects Excel 2016, 2019, 2021, and 2024 ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qxTWxRpNYGtadzEwDLbTWQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K7tNdPzpXATX5n9r6wvMmQ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 15 Sep 2026 09:48:18 +0000</pubDate>                                                                                                                                <updated>Tue, 15 Sep 2026 10:13:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Microsoft Office]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                    <category><![CDATA[Microsoft]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Bobby Hellard) ]]></author>                    <dc:creator><![CDATA[ Bobby Hellard ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/bsR2tHSyVKUoyXZF5pNsDA-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Bobby Hellard&amp;nbsp;is&amp;nbsp;ITPro&#039;s Reviews Editor and has worked on&amp;nbsp;CloudPro and ChannelPro since 2018. In his time at ITPro, Bobby has covered stories for all the major technology companies, such as Apple, Microsoft, Amazon and Facebook, and regularly attends industry-leading events such as AWS Re:Invent and Google Cloud Next.&lt;/p&gt;
&lt;p&gt;Bobby mainly covers hardware reviews, but you will also recognize him as the face of many of our video reviews of laptops and smartphones.&lt;/p&gt;
&lt;p&gt;He has been a journalist for ten years, originally covering sports, before moving into business technology with ITPro. He has bylines in The Independent, Vice and The Business Briefing. Contact him at &lt;a href=&quot;mailto:bobby.hellard@futurenet.com&quot;&gt;bobby.hellard@futurenet.com&lt;/a&gt; or find him on Twitter: &lt;a href=&quot;https://twitter.com/bobbyhellard&quot;&gt;@bobbyhellard&lt;/a&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/K7tNdPzpXATX5n9r6wvMmQ-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up of cells on a spreadsheet ]]></media:description>                                                            <media:text><![CDATA[A close up of cells on a spreadsheet ]]></media:text>
                                <media:title type="plain"><![CDATA[A close up of cells on a spreadsheet ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K7tNdPzpXATX5n9r6wvMmQ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you're having trouble with copy and paste in Excel, you're not doing it wrong; it's simply been disabled by Microsoft's latest Patch Tuesday update. </p><p>Unfortunately, it's going to be like that for some time, as there isn't a fix, at the time of writing. </p><p><a href="https://www.itpro.com/629377/microsoft-plans-mega-patch-tuesday">Patch Tuesday</a> is a monthly update from Microsoft where it fixes and updates various parts of its software. Much of it focuses on <a href="https://www.itpro.com/operating-systems/microsoft-windows/360105/windows-11-review">Windows</a> security and improvements to its suite of applications. </p><p>However, these fixes sometimes cause problems elsewhere. Case in point: the latest security patch for Excel has taken down the copy-paste function. Users first reported issues with Excel 2016 after the update, known as KB5002914, was installed. Soon after, users reported the issue in other versions of <a href="https://www.itpro.com/business-operations/productivity/363979/google-sheets-vs-microsoft-excel">Excel</a>, and Microsoft has acknowledged it and said it is working on a fix. </p><p>Under 'known issues', Microsoft <a href="https://support.microsoft.com/en-us/servicing/office/hotfix/excel/5002914">posted</a>: "In Microsoft Excel 2024, 2021, 2019, and 2016, the paste operation might fail silently. Although users try to paste content, the source remains selected, and the destination is unmodified. When this issue occurs, users receive no indication of the failure, such as a beep or error message. Microsoft is researching the issue and will post more information in this article when the information becomes available."</p><p>Bugs and issues are expected when updating a sprawling software stack like Microsoft's, and the company's Patch Tuesday releases have been known to come with some downsides. In May, bugs where images would not display inside mail were <a href="https://www.neowin.net/news/microsoft-admits-one-of-the-most-basic-useful-outlook-features-is-broken/">reported</a>, and in June, the main email messages were <a href="https://www.neowin.net/news/microsoft-admits-one-of-the-most-crucial-outlook-features-is-currently-broken/">hidden</a>. Both were a result of monthly updates. </p><p>Thankfully, Microsoft has spotted and acknowledged this issue introduced by KB5002914. Unfortunately, it has yet to come back with a fix, so there isn't anything you can do except painstakingly type out everything in Excel. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Revolut hands over customer data after fake government request ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Digital bank Revolut has been fooled into handing over detailed and highly sensitive customer data via a <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing attack</a> that used a legitimate government email domain.</p><p>The company has <a href="https://x.com/mzeller/status/2098662798158954690?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E2098662798158954690%7Ctwgr%5Edf46d082cbbc6373b4e0f28696a4050426f38650%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fcybernews.com%2Fnews%2Frevolut-customer-data-breach%2F">emailed</a> affected customers warning that a wide range of information may have been shared. This includes name, date of birth, postal and email addresses – but also identity documents such as passports or driver's licenses and the facial verification image that customers used to sign up.</p><p>What's more, account statements, including IBAN, account status, the date accounts were opened, wallet reference number, withdrawal records, and full transaction history, including Bitcoin, were also shared.</p><p>One Telegram user, ZachXBT, has <a href="https://t.me/investigations/363">suggested</a> that the incident was targeted in particular at individuals with high net worth.</p><p>Internal systems and customer funds remain completely unaffected, the company said, and it has blocked the unauthorized email source and notified the appropriate authorities. </p><p>However, the leaked data will represent a treasure trove for scammers launching <a href="https://www.itpro.com/security/phishing/the-inbox-is-no-longer-the-only-frontline-phishing-attacks-are-evolving-as-cyber-criminals-ramp-up-multi-channel-campaigns-over-email-and-microsoft-teams">phishing attacks</a> or using the identity information to attempt to open other financial accounts elsewhere.</p><p>The breach arose via fraudulent requests from an unauthorized email account created directly within an unnamed official government authority's domain infrastructure, according to <a href="https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/"><em>Reuters.</em></a> This meant that it carried valid domain-authentication credentials and therefore wasn't picked up as fraudulent.</p><p>"What makes this particularly worrying is that the requests came from a legitimate government email account, making them far harder to spot as a phishing email," said  Jake Moore, global cybersecurity advisor at ESET. </p><p>"The threat actors were able to cleverly disguise themselves as a genuine organization and simply request the information from Revolut." </p><p>There's no information on exactly which government department – or, indeed, which government – was being impersonated, nor the purported reason for the request. It's possible, though, that other banks or cryptocurrency exchanges have been approached in the same way.</p><p>"Increasingly, cybercriminals don't need to break through the technical security controls of a final target if they can impersonate a trusted source," said Moore.</p><p>"The big lesson for organizations is that a genuine email address doesn't always mean a genuine request. Safeguards against this can apply, but need to be enforced in ways where sensitive data requests require verification through a separate trusted channel."</p><p>UK-based Revolut has more than 80 million customers around the world and operates as a bank in more than 30 countries, online rather than via physical branches. It recently received permission to set up as a national bank across the US, expected to launch during the first half of next year. It's also believed to be considering s a potential public listing that could value it at as much as $200 billion.</p><p><em>ITPro has approached Revolut for comment.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-breaches/revolut-hands-over-customer-data-after-fake-government-request</link>
                                                                            <description>
                            <![CDATA[ The online bank is warning customers that a broad range of sensitive data may have been shared ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3LqWz25f9hJeG3jCRMLHzG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kczjbfu3BKp57BPLStKjEH-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 14 Sep 2026 10:45:22 +0000</pubDate>                                                                                                                                <updated>Mon, 14 Sep 2026 13:06:25 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kczjbfu3BKp57BPLStKjEH-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Revolute headquaters ]]></media:description>                                                            <media:text><![CDATA[The Revolute headquaters ]]></media:text>
                                <media:title type="plain"><![CDATA[The Revolute headquaters ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kczjbfu3BKp57BPLStKjEH-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Digital bank Revolut has been fooled into handing over detailed and highly sensitive customer data via a <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing attack</a> that used a legitimate government email domain.</p><p>The company has <a href="https://x.com/mzeller/status/2098662798158954690?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E2098662798158954690%7Ctwgr%5Edf46d082cbbc6373b4e0f28696a4050426f38650%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fcybernews.com%2Fnews%2Frevolut-customer-data-breach%2F">emailed</a> affected customers warning that a wide range of information may have been shared. This includes name, date of birth, postal and email addresses – but also identity documents such as passports or driver's licenses and the facial verification image that customers used to sign up.</p><p>What's more, account statements, including IBAN, account status, the date accounts were opened, wallet reference number, withdrawal records, and full transaction history, including Bitcoin, were also shared.</p><p>One Telegram user, ZachXBT, has <a href="https://t.me/investigations/363">suggested</a> that the incident was targeted in particular at individuals with high net worth.</p><p>Internal systems and customer funds remain completely unaffected, the company said, and it has blocked the unauthorized email source and notified the appropriate authorities. </p><p>However, the leaked data will represent a treasure trove for scammers launching <a href="https://www.itpro.com/security/phishing/the-inbox-is-no-longer-the-only-frontline-phishing-attacks-are-evolving-as-cyber-criminals-ramp-up-multi-channel-campaigns-over-email-and-microsoft-teams">phishing attacks</a> or using the identity information to attempt to open other financial accounts elsewhere.</p><p>The breach arose via fraudulent requests from an unauthorized email account created directly within an unnamed official government authority's domain infrastructure, according to <a href="https://www.reuters.com/legal/litigation/revolut-confirms-sensitive-customer-data-breach-falling-fake-government-requests-2026-09-12/"><em>Reuters.</em></a> This meant that it carried valid domain-authentication credentials and therefore wasn't picked up as fraudulent.</p><p>"What makes this particularly worrying is that the requests came from a legitimate government email account, making them far harder to spot as a phishing email," said  Jake Moore, global cybersecurity advisor at ESET. </p><p>"The threat actors were able to cleverly disguise themselves as a genuine organization and simply request the information from Revolut." </p><p>There's no information on exactly which government department – or, indeed, which government – was being impersonated, nor the purported reason for the request. It's possible, though, that other banks or cryptocurrency exchanges have been approached in the same way.</p><p>"Increasingly, cybercriminals don't need to break through the technical security controls of a final target if they can impersonate a trusted source," said Moore.</p><p>"The big lesson for organizations is that a genuine email address doesn't always mean a genuine request. Safeguards against this can apply, but need to be enforced in ways where sensitive data requests require verification through a separate trusted channel."</p><p>UK-based Revolut has more than 80 million customers around the world and operates as a bank in more than 30 countries, online rather than via physical branches. It recently received permission to set up as a national bank across the US, expected to launch during the first half of next year. It's also believed to be considering s a potential public listing that could value it at as much as $200 billion.</p><p><em>ITPro has approached Revolut for comment.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US accuses Chinese firms of ‘aggressively’ copying frontier models ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The US has accused Chinese companies of stealing AI capabilities via "aggressive, malicious and targeted" distillation at an industrial scale. </p><p>Distillation is a technique by which one model is trained on the outputs of a stronger or better model, but it can be abused to extract features and capabilities more quickly and at a lower cost than doing the work from the ground up. </p><p>A joint advisory from the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation warns that China is abusing this technical capability to unpick AI models, saying that distillation of US systems is core to the country's AI development strategy. </p><p>"While 'distillation' is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models," the advisory noted. </p><p>OpenAI <a href="https://www.itpro.com/technology/artificial-intelligence/deepseek-accused-of-training-its-models-on-openais-content"><u>accused DeepSeek of model distillation</u></a> back in January 2025, just weeks after<a href="https://www.itpro.com/technology/artificial-intelligence/the-deepseek-bombshell-has-been-a-wakeup-call-for-us-tech-giants"><u> DeepSeek made waves</u></a> when it arrived with an AI model that cost significantly less to develop. </p><p>Anthropic raised the issue <a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks"><u> in February of this year</u></a>, accusing three AI labs – all also named in the new American alert, including DeepSeek – of extracting capabilities from Claude via distillation. </p><h2 id="industrial-scale-ai-distillation">Industrial-scale AI distillation</h2><p>The American agencies said that DeepSeek, Alibaba, and other Chinese AI developers had extracted billions of tokens across millions of queries from frontier AI models, including those from Anthropic, OpenAI, Google and xAI since late 2024. </p><p>The advisory suggested that was "likely with Chinese government awareness."</p><p>Distillation runs via multiple pathways, including making use of APIs, cloud providers, and third-party aggregators to avoid being detected. </p><p>"China-based AI companies achieve cost savings for their industrial-scale distillation campaigns through bulk procurement of the US AI companies’ premium subscriptions shared across teams of developers," the alert explained. </p><p>The purpose is to speed up development while reducing costs, the agencies said. </p><p>"China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model," the document noted. </p><p>The alert urged US AI companies to fight back by rolling out detection and mitigation systems to spot malicious distillation behavior, disrupt the benefits of these attacks by altering responses, and sharing information across the industry to better spot such campaigns. </p><h2 id="china-39-s-response">China's response</h2><p>The Chinese commerce ministry denied the allegations, but also countered that the US had "extensively distilled Chinese models," according to a <a href="https://www.reuters.com/technology/us-accuses-chinese-ai-firms-industrial-scale-theft-ai-technology-2026-09-08/" target="_blank"><u><em>Reuters </em></u></a>report. </p><p>A spokesperson for the Chinese foreign ministry told the news agency: "We hope the US will earnestly implement the important consensus reached by the leaders of both countries and refrain from making false ​accusations and smearing China."</p><p>This isn't the first time the American government has accused China of stealing AI from its own companies, with the issue raised repeatedly earlier this year, but comes ahead of the Chinese president Xi Jinping visiting the US later this month. </p><h2 id="does-distillation-matter">Does distillation matter? </h2><p>One expert said the distillation debate highlights the commodification of AI. </p><p>“This isn't about someone copying the smart kids' homework, it's what they chose to copy: coding, software engineering, reasoning, and agentic capabilities," said Cris Thomas, Security Advocate at Semgrep. </p><p>"That's why you shouldn't build your security strategy around who has the smartest model this week. Models will get better, cheaper, copied, distilled, and commoditized."</p><p>He added: "The interesting question isn't who owns the model, it's what you can make that model do when you give it deep code context, deterministic analysis, and a way to check its own work. The model is increasingly becoming a commodity. Knowing how to turn it into a security tool is not."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/what-is-ai-distillation-the-new-threat-facing-western-tech-giants-as-us-accuses-chinese-firms-of-aggressively-copying-frontier-models</link>
                                                                            <description>
                            <![CDATA[ A host of Chinese tech companies have been accused of ‘AI distillation’ practices to keep pace with US rivals ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vBT6sK53QWFYp2xhuDSTqK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JkLKkVM8Vr8TZqeykFqYDH-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 11 Sep 2026 08:33:13 +0000</pubDate>                                                                                                                                <updated>Fri, 11 Sep 2026 11:30:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JkLKkVM8Vr8TZqeykFqYDH-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI distillation concept image showing chemistry distillation apparatus, including flasks and a spiral condenser for liquid separation and purification.]]></media:description>                                                            <media:text><![CDATA[AI distillation concept image showing chemistry distillation apparatus, including flasks and a spiral condenser for liquid separation and purification.]]></media:text>
                                <media:title type="plain"><![CDATA[AI distillation concept image showing chemistry distillation apparatus, including flasks and a spiral condenser for liquid separation and purification.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JkLKkVM8Vr8TZqeykFqYDH-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The US has accused Chinese companies of stealing AI capabilities via "aggressive, malicious and targeted" distillation at an industrial scale. </p><p>Distillation is a technique by which one model is trained on the outputs of a stronger or better model, but it can be abused to extract features and capabilities more quickly and at a lower cost than doing the work from the ground up. </p><p>A joint advisory from the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation warns that China is abusing this technical capability to unpick AI models, saying that distillation of US systems is core to the country's AI development strategy. </p><p>"While 'distillation' is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models," the advisory noted. </p><p>OpenAI <a href="https://www.itpro.com/technology/artificial-intelligence/deepseek-accused-of-training-its-models-on-openais-content"><u>accused DeepSeek of model distillation</u></a> back in January 2025, just weeks after<a href="https://www.itpro.com/technology/artificial-intelligence/the-deepseek-bombshell-has-been-a-wakeup-call-for-us-tech-giants"><u> DeepSeek made waves</u></a> when it arrived with an AI model that cost significantly less to develop. </p><p>Anthropic raised the issue <a href="https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks"><u> in February of this year</u></a>, accusing three AI labs – all also named in the new American alert, including DeepSeek – of extracting capabilities from Claude via distillation. </p><h2 id="industrial-scale-ai-distillation">Industrial-scale AI distillation</h2><p>The American agencies said that DeepSeek, Alibaba, and other Chinese AI developers had extracted billions of tokens across millions of queries from frontier AI models, including those from Anthropic, OpenAI, Google and xAI since late 2024. </p><p>The advisory suggested that was "likely with Chinese government awareness."</p><p>Distillation runs via multiple pathways, including making use of APIs, cloud providers, and third-party aggregators to avoid being detected. </p><p>"China-based AI companies achieve cost savings for their industrial-scale distillation campaigns through bulk procurement of the US AI companies’ premium subscriptions shared across teams of developers," the alert explained. </p><p>The purpose is to speed up development while reducing costs, the agencies said. </p><p>"China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model," the document noted. </p><p>The alert urged US AI companies to fight back by rolling out detection and mitigation systems to spot malicious distillation behavior, disrupt the benefits of these attacks by altering responses, and sharing information across the industry to better spot such campaigns. </p><h2 id="china-39-s-response">China's response</h2><p>The Chinese commerce ministry denied the allegations, but also countered that the US had "extensively distilled Chinese models," according to a <a href="https://www.reuters.com/technology/us-accuses-chinese-ai-firms-industrial-scale-theft-ai-technology-2026-09-08/" target="_blank"><u><em>Reuters </em></u></a>report. </p><p>A spokesperson for the Chinese foreign ministry told the news agency: "We hope the US will earnestly implement the important consensus reached by the leaders of both countries and refrain from making false ​accusations and smearing China."</p><p>This isn't the first time the American government has accused China of stealing AI from its own companies, with the issue raised repeatedly earlier this year, but comes ahead of the Chinese president Xi Jinping visiting the US later this month. </p><h2 id="does-distillation-matter">Does distillation matter? </h2><p>One expert said the distillation debate highlights the commodification of AI. </p><p>“This isn't about someone copying the smart kids' homework, it's what they chose to copy: coding, software engineering, reasoning, and agentic capabilities," said Cris Thomas, Security Advocate at Semgrep. </p><p>"That's why you shouldn't build your security strategy around who has the smartest model this week. Models will get better, cheaper, copied, distilled, and commoditized."</p><p>He added: "The interesting question isn't who owns the model, it's what you can make that model do when you give it deep code context, deterministic analysis, and a way to check its own work. The model is increasingly becoming a commodity. Knowing how to turn it into a security tool is not."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber researchers issue warning over 'phishing pages that exist only inside the victim’s browser' ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Barracuda has uncovered an email phishing campaign that lures victims with a phishing page generated directly inside the victim's browser.</p><p>Rather than building a traditional phishing website, the <a href="https://blog.barracuda.com/2026/09/09/browser-based-phishing-blob-urls-microsoft-redirects" target="_blank"><u>campaign</u></a> creates a fake page in the browser with a blob URL - a temporary address that points to content held in local memory rather than on a public web server.</p><p>Victims are routed through legitimate Microsoft services, including Microsoft OAuth and Microsoft Teams, making the site appear trustworthy and reducing common warning signs.</p><p>"This campaign demonstrates how phishing is evolving beyond fake websites and suspicious domains, removing many of the indicators that security teams have traditionally relied on for detection," said Ashitosh Deshnur, associate threat analyst at Barracuda.</p><h2 id="how-the-phishing-attack-works">How the phishing attack works</h2><p>The attack begins with a DocuSign-themed email with a calendar invite attached. It doesn't appear malicious, because it points to a legitimate <a href="https://www.itpro.com/security/phishing/362065/microsoft-warns-of-phishing-campaign-targeting-oauth-tokens">Microsoft OAuth</a> endpoint; it's there just to add legitimacy.</p><p>A crafted redirect then routes the user to Microsoft Teams, which  loads an external resource hosted on cdn.bloom[.]io. The browser converts this content into a blob URL that renders the phishing page locally within the browser.</p><p>Once the blob-based phishing page loads, it registers a service worker – a browser component that can manage network requests and page behavior in the background. </p><p>Part of the workflow is also executed inside a sandboxed iframe: an isolated browser window embedded within the page. Together, these elements help control navigation, manage requests and coordinate the phishing experience without the need for a conventional phishing website.</p><h2 id="a-hard-to-tackle-campaign">A hard to tackle campaign</h2><p>It's a worrying technique, Barracuda warned. There's no phishing page to block, and therefore no persistent phishing URL for security tools to retrieve, analyze or blocklist in advance.</p><p><a href="https://www.itpro.com/security/cyber-attacks/a-notorious-ransomware-group-is-spreading-fake-microsoft-teams-ads-to-snare-victims">Trusted Microsoft services</a> are abused throughout the attack chain, making the attack harder to spot, and the calendar invitation file makes the message look like routine business communication.</p><p>The phishing workflow receives instructions from backend infrastructure using browser messaging mechanisms; and, because the attack is controlled dynamically rather than through hardcoded redirects, operators can modify destinations and behavior in real time. </p><p>This gives them a level of flexibility and evasiveness that's not typically seen in static phishing pages.</p><h2 id="new-scanning-techniques-are-needed">New scanning techniques are needed</h2><p>The campaign shows that detection approaches built around scanning for known malicious URLs are no longer good enough, said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress. </p><p>"Traditional email security tools, URL scanners, and web filters are looking for malicious destinations. This approach removes the destination entirely; the attack surface exists only inside the target's browser for the duration of the session, then disappears," he said. </p><p>Patel said blob URLs mean detection needs to “shift toward behavioral monitoring of what the browser is actually doing” – such as URL creation in “unusual contexts” and “anomalous behaviour following calendar invite interactions”. </p><p>“These are detectable patterns, but they require endpoint-level visibility rather than network or email gateway scanning.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/phishing/cyber-researchers-issue-warning-over-phishing-pages-that-exist-only-inside-the-victims-browser</link>
                                                                            <description>
                            <![CDATA[ A blob URL renders and delivers the phishing page inside the target’s own browser, making it harder for security scanners to spot ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NYeeGH84tsJ6tX6v8ifo2L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 10:21:39 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:description>                                                            <media:text><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing email attack concept image showing email with warning symbol on a laptop screen with a fishing hook attached.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iLr5eH4Tgk7GAiwMDELMzG-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Barracuda has uncovered an email phishing campaign that lures victims with a phishing page generated directly inside the victim's browser.</p><p>Rather than building a traditional phishing website, the <a href="https://blog.barracuda.com/2026/09/09/browser-based-phishing-blob-urls-microsoft-redirects" target="_blank"><u>campaign</u></a> creates a fake page in the browser with a blob URL - a temporary address that points to content held in local memory rather than on a public web server.</p><p>Victims are routed through legitimate Microsoft services, including Microsoft OAuth and Microsoft Teams, making the site appear trustworthy and reducing common warning signs.</p><p>"This campaign demonstrates how phishing is evolving beyond fake websites and suspicious domains, removing many of the indicators that security teams have traditionally relied on for detection," said Ashitosh Deshnur, associate threat analyst at Barracuda.</p><h2 id="how-the-phishing-attack-works">How the phishing attack works</h2><p>The attack begins with a DocuSign-themed email with a calendar invite attached. It doesn't appear malicious, because it points to a legitimate <a href="https://www.itpro.com/security/phishing/362065/microsoft-warns-of-phishing-campaign-targeting-oauth-tokens">Microsoft OAuth</a> endpoint; it's there just to add legitimacy.</p><p>A crafted redirect then routes the user to Microsoft Teams, which  loads an external resource hosted on cdn.bloom[.]io. The browser converts this content into a blob URL that renders the phishing page locally within the browser.</p><p>Once the blob-based phishing page loads, it registers a service worker – a browser component that can manage network requests and page behavior in the background. </p><p>Part of the workflow is also executed inside a sandboxed iframe: an isolated browser window embedded within the page. Together, these elements help control navigation, manage requests and coordinate the phishing experience without the need for a conventional phishing website.</p><h2 id="a-hard-to-tackle-campaign">A hard to tackle campaign</h2><p>It's a worrying technique, Barracuda warned. There's no phishing page to block, and therefore no persistent phishing URL for security tools to retrieve, analyze or blocklist in advance.</p><p><a href="https://www.itpro.com/security/cyber-attacks/a-notorious-ransomware-group-is-spreading-fake-microsoft-teams-ads-to-snare-victims">Trusted Microsoft services</a> are abused throughout the attack chain, making the attack harder to spot, and the calendar invitation file makes the message look like routine business communication.</p><p>The phishing workflow receives instructions from backend infrastructure using browser messaging mechanisms; and, because the attack is controlled dynamically rather than through hardcoded redirects, operators can modify destinations and behavior in real time. </p><p>This gives them a level of flexibility and evasiveness that's not typically seen in static phishing pages.</p><h2 id="new-scanning-techniques-are-needed">New scanning techniques are needed</h2><p>The campaign shows that detection approaches built around scanning for known malicious URLs are no longer good enough, said Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress. </p><p>"Traditional email security tools, URL scanners, and web filters are looking for malicious destinations. This approach removes the destination entirely; the attack surface exists only inside the target's browser for the duration of the session, then disappears," he said. </p><p>Patel said blob URLs mean detection needs to “shift toward behavioral monitoring of what the browser is actually doing” – such as URL creation in “unusual contexts” and “anomalous behaviour following calendar invite interactions”. </p><p>“These are detectable patterns, but they require endpoint-level visibility rather than network or email gateway scanning.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI and Anthropic admit rogue AI agents did more than first thought ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI and Anthropic have both admitted that rogue AI incidents went further than first reported.</p><p>In July, OpenAI said its AI agents had gone r<a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime"><u>ogue and breached Hugging Face systems</u></a>. Anthropic later admitted its own similar incidents, saying its models had escaped a testing sandbox too, with the UK AI Security Institute <a href="https://www.itpro.com/security/cyber-attacks/anthropics-mythos-ai-tried-to-dupe-devs-in-social-engineering-attack-collaborated-with-other-agents"><u>reporting other alarming behavior</u></a>. </p><p>Last week, both companies published <a href="https://www.itpro.com/security/anthropic-resumes-model-testing-after-recent-cyber-incidents-but-its-introduced-new-rules-to-improve-security"><u>reports</u></a> with details of what happened in those incidents, with much of the blame pinned on minor operational mistakes that enabled online access, as well as tasking agents with overly difficult or impossible problems that drove them to "cheat". </p><p>That included abusing systems in order to build their own messaging boards in order to collaborate and communicate. </p><p>Since then, further incidents have been exposed, including the use of a German wiki site for communications. Now, <a href="https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/" target="_blank"><u><em>Reuters</em></u></a><em> </em>has reported that OpenAI's agents had made use of ten further websites for communication, based on reports from six independent investigators. </p><h2 id="chatty-ai-agents">Chatty AI agents</h2><p>The report notes that the websites weren't hacked, but more akin to spam, with the agents making use of comment boards to communicate with each other, contrary to instructions in the evaluation they were undertaking. </p><p>Alongside one university's link shortener tool, the websites used by OpenAI's agents were often wiki-style sites that could be used as message boards for the misbehaving AI agents. </p><p>These included a high-school teacher's chemistry site and personal websites of Polish technology workers, <em>Reuters </em>said. The agents made edits in comments in order to leave data for other agents. </p><p>“If these ⁠models were told only to read, they’ve got to get clever in terms of leaving information behind,” Kenneth Russell DeGraff, a software developer and former congressional aide, <a href="https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/" target="_blank"><u>told</u></a> the news agency. </p><h2 id="openai-39-s-response">OpenAI's response</h2><p>OpenAI told <em>ITPro </em>that its investigation was ongoing, but stressed that the Hugging Face incident remained the most serious to date. </p><p>"As we said in July, the Hugging Face incident prompted a broader review of agent activity, and that work remains ongoing," a spokesperson said in an emailed statement. </p><p>"We are prioritizing review based on the type of impact on a third party and its severity, such as some of the other third parties we have notified following Hugging Face as we have previously shared. We are also examining lower-severity abuse such as spam-like activity. To date, we have not identified other activity matching the severity or scale of Hugging Face. "</p><p>The spokesperson added: "The AI community does not yet have a clear standard for reporting misalignment across training, evaluation, and deployment, and we're developing a framework to share soon." </p><h2 id="another-anthropic-incident">Another Anthropic incident</h2><p>Rival AI developer Anthropic admitted an additional rogue agent incident, the fourth after three previous ones were revealed over the summer. </p><p>In a blog post, the company said it had spotted the first three incidents via a scan of 141,000 transcripts following an evaluation – admitting it had missed the fourth after relying on AI. </p><p>"Given the volume of transcripts and our desire to disclose incidents quickly, our scan relied on an agentic search," Anthropic post noted. "This missed a set of transcripts that also turned out to have internet access; we identified these in August while assembling transcripts to share with METR."</p><p>This fourth incident happened in January and involved its Claude Opus 4.6 model in a "capture the flag" test. </p><p>"The model accidentally broke its target by assigning it a conflicting IP address with another machine, thus making the target unreachable and the task impossible to solve," the post noted. "Recognizing this, the model attempted to abort the task using a command but was unsuccessful due to a misconfiguration in our evaluation harness."</p><p>The model then attempted to reach the target by escaping the testing environment and targeting a third-party machine, finding a password that it used to gain admin access, and continuing to harvest further credentials and modifying settings for access. </p><p>This continued until its token budget ran out and it stopped, the company revealed. </p><p>Anthropic said the impacted parties have been notified and suggested the fourth incident wasn't a new sort of AI misalignment, but in keeping with the previous behavior. </p><p>"Taken together, our assessment is that these incidents are serious. Our production models took harmful actions against real systems over long trajectories, which included biased reasoning,” the company said. </p><p>“The behaviors in these incidents are more severe than those we had previously observed and reported in our system cards. However, we do not believe these incidents represent a new kind of misalignment." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/openai-and-anthropic-admit-rogue-ai-agents-did-more-than-first-thought</link>
                                                                            <description>
                            <![CDATA[ The two companies have shared additional details on agent misbehavior ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SmMRsMTLvLj9FUQymdHuab</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U9hrKDAwa6SaJDCirzgjra-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 10 Sep 2026 10:10:10 +0000</pubDate>                                                                                                                                <updated>Thu, 10 Sep 2026 15:46:13 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U9hrKDAwa6SaJDCirzgjra-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[App symbols for ChatGPT and Claude, developed by OpenAI and Anthropic, pictured on a smartphone screen, with Google Gemini app symbol also featured.]]></media:description>                                                            <media:text><![CDATA[App symbols for ChatGPT and Claude, developed by OpenAI and Anthropic, pictured on a smartphone screen, with Google Gemini app symbol also featured.]]></media:text>
                                <media:title type="plain"><![CDATA[App symbols for ChatGPT and Claude, developed by OpenAI and Anthropic, pictured on a smartphone screen, with Google Gemini app symbol also featured.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U9hrKDAwa6SaJDCirzgjra-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI and Anthropic have both admitted that rogue AI incidents went further than first reported.</p><p>In July, OpenAI said its AI agents had gone r<a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime"><u>ogue and breached Hugging Face systems</u></a>. Anthropic later admitted its own similar incidents, saying its models had escaped a testing sandbox too, with the UK AI Security Institute <a href="https://www.itpro.com/security/cyber-attacks/anthropics-mythos-ai-tried-to-dupe-devs-in-social-engineering-attack-collaborated-with-other-agents"><u>reporting other alarming behavior</u></a>. </p><p>Last week, both companies published <a href="https://www.itpro.com/security/anthropic-resumes-model-testing-after-recent-cyber-incidents-but-its-introduced-new-rules-to-improve-security"><u>reports</u></a> with details of what happened in those incidents, with much of the blame pinned on minor operational mistakes that enabled online access, as well as tasking agents with overly difficult or impossible problems that drove them to "cheat". </p><p>That included abusing systems in order to build their own messaging boards in order to collaborate and communicate. </p><p>Since then, further incidents have been exposed, including the use of a German wiki site for communications. Now, <a href="https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/" target="_blank"><u><em>Reuters</em></u></a><em> </em>has reported that OpenAI's agents had made use of ten further websites for communication, based on reports from six independent investigators. </p><h2 id="chatty-ai-agents">Chatty AI agents</h2><p>The report notes that the websites weren't hacked, but more akin to spam, with the agents making use of comment boards to communicate with each other, contrary to instructions in the evaluation they were undertaking. </p><p>Alongside one university's link shortener tool, the websites used by OpenAI's agents were often wiki-style sites that could be used as message boards for the misbehaving AI agents. </p><p>These included a high-school teacher's chemistry site and personal websites of Polish technology workers, <em>Reuters </em>said. The agents made edits in comments in order to leave data for other agents. </p><p>“If these ⁠models were told only to read, they’ve got to get clever in terms of leaving information behind,” Kenneth Russell DeGraff, a software developer and former congressional aide, <a href="https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/" target="_blank"><u>told</u></a> the news agency. </p><h2 id="openai-39-s-response">OpenAI's response</h2><p>OpenAI told <em>ITPro </em>that its investigation was ongoing, but stressed that the Hugging Face incident remained the most serious to date. </p><p>"As we said in July, the Hugging Face incident prompted a broader review of agent activity, and that work remains ongoing," a spokesperson said in an emailed statement. </p><p>"We are prioritizing review based on the type of impact on a third party and its severity, such as some of the other third parties we have notified following Hugging Face as we have previously shared. We are also examining lower-severity abuse such as spam-like activity. To date, we have not identified other activity matching the severity or scale of Hugging Face. "</p><p>The spokesperson added: "The AI community does not yet have a clear standard for reporting misalignment across training, evaluation, and deployment, and we're developing a framework to share soon." </p><h2 id="another-anthropic-incident">Another Anthropic incident</h2><p>Rival AI developer Anthropic admitted an additional rogue agent incident, the fourth after three previous ones were revealed over the summer. </p><p>In a blog post, the company said it had spotted the first three incidents via a scan of 141,000 transcripts following an evaluation – admitting it had missed the fourth after relying on AI. </p><p>"Given the volume of transcripts and our desire to disclose incidents quickly, our scan relied on an agentic search," Anthropic post noted. "This missed a set of transcripts that also turned out to have internet access; we identified these in August while assembling transcripts to share with METR."</p><p>This fourth incident happened in January and involved its Claude Opus 4.6 model in a "capture the flag" test. </p><p>"The model accidentally broke its target by assigning it a conflicting IP address with another machine, thus making the target unreachable and the task impossible to solve," the post noted. "Recognizing this, the model attempted to abort the task using a command but was unsuccessful due to a misconfiguration in our evaluation harness."</p><p>The model then attempted to reach the target by escaping the testing environment and targeting a third-party machine, finding a password that it used to gain admin access, and continuing to harvest further credentials and modifying settings for access. </p><p>This continued until its token budget ran out and it stopped, the company revealed. </p><p>Anthropic said the impacted parties have been notified and suggested the fourth incident wasn't a new sort of AI misalignment, but in keeping with the previous behavior. </p><p>"Taken together, our assessment is that these incidents are serious. Our production models took harmful actions against real systems over long trajectories, which included biased reasoning,” the company said. </p><p>“The behaviors in these incidents are more severe than those we had previously observed and reported in our system cards. However, we do not believe these incidents represent a new kind of misalignment." </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google cyber researchers warn hackers are ramping up automated attacks ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Attackers used AI agents to compromise a cloud resource and then plan, build, and carry out a mass credential harvesting campaign earlier this year – and all in less than six hours.</p><p>That’s according to new <a href="https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai" target="_blank"><u>research </u></a>from Google Threat Intelligence Group (GTIG), with recent analysis showing threat actors are flocking to agentic AI and automation to conduct sophisticated attacks. </p><p>“At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited," said John Hultquist, chief analyst at Google Threat Intelligence Group. </p><p>"Like everyone else, we’re concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary. Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to."</p><p>In this example, a financially motivated threat actor compromised an organization’s cloud infrastructure to deploy an autonomous, multi-agent attack framework, allowing them to operate at the sort of scale and speed that's usually associated with larger and more resource-heavy groups. </p><p>In less than six hours, the attacker was able to leverage an AI coding chatbot, a simple prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign. </p><p>Using preconfigured markdown instruction sets as operational playbooks, GTIG said the threat actor carried out automated scanning and credential harvesting, compromising thousands of third-party credentials. </p><p>The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute IP rotation logic without manual intervention. </p><p>Operating from the victim cloud infrastructure also allowed the threat actor route attack traffic through legitimate IP addresses.</p><h2 id="state-backed-groups-are-flocking-to-ai">State-backed groups are flocking to AI</h2><p>GTIG said it has observed state-linked groups broadening their use of AI. In one example, PRC-nexus threat actor UNC6508 carried out a major intrusion campaign against US medical facilities, using compromised cloud environments to host a local model.</p><p>In April, meanwhile, Mandiant spotted a threat actor leveraging AI infrastructure access which was then used to sustain unauthorized AI workloads, utilizing hijacked cloud environments to provision high-performance GPU compute instances at the victim's expense.</p><p>Notably, <a href="https://www.itpro.com/security/litellm-pypi-compromise-everything-we-know-so-far">TeamPCP </a>has focused heavily on the AI supply chain, using malware designed to take advantage of emerging AI systems, and including malicious prompts that were used to execute commands surreptitiously. </p><p>The group has even poisoned open source package metadata to trick AI assistants, resulting in malicious dependencies being recommended to developers. </p><p>"The challenge for defenders is that these risks are evolving faster than many organizations can quantify, measure, and govern," said Ronald Lewis, head of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>governance at Black Duck. </p><p>"Security teams are no longer protecting only applications, users, and infrastructure. They must now secure <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-open-source-ai-models">AI models</a>, agents, prompts, data pipelines, and an increasingly complex AI supply chain while also defending against adversaries using AI to accelerate attacks.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-crime/we-can-assume-that-all-threat-actors-are-using-ai-in-some-capacity-google-cyber-researchers-warn-hackers-are-ramping-up-automated-attacks</link>
                                                                            <description>
                            <![CDATA[ Google Threat Intelligence Group has issued a warning over the increased threats posed by hackers using agentic AI tools ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sWhJ4d98MpUEhSrqv8PtWU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 17:00:00 +0000</pubDate>                                                                                                                                <updated>Thu, 10 Sep 2026 11:28:05 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1920-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:description>                                                            <media:text><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Attackers used AI agents to compromise a cloud resource and then plan, build, and carry out a mass credential harvesting campaign earlier this year – and all in less than six hours.</p><p>That’s according to new <a href="https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai" target="_blank"><u>research </u></a>from Google Threat Intelligence Group (GTIG), with recent analysis showing threat actors are flocking to agentic AI and automation to conduct sophisticated attacks. </p><p>“At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited," said John Hultquist, chief analyst at Google Threat Intelligence Group. </p><p>"Like everyone else, we’re concerned about the vulnerability problem, but AI is being applied to several other areas, and it will be especially challenging as it is applied agentically, creating a scaled, faster adversary. Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to."</p><p>In this example, a financially motivated threat actor compromised an organization’s cloud infrastructure to deploy an autonomous, multi-agent attack framework, allowing them to operate at the sort of scale and speed that's usually associated with larger and more resource-heavy groups. </p><p>In less than six hours, the attacker was able to leverage an AI coding chatbot, a simple prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign. </p><p>Using preconfigured markdown instruction sets as operational playbooks, GTIG said the threat actor carried out automated scanning and credential harvesting, compromising thousands of third-party credentials. </p><p>The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute IP rotation logic without manual intervention. </p><p>Operating from the victim cloud infrastructure also allowed the threat actor route attack traffic through legitimate IP addresses.</p><h2 id="state-backed-groups-are-flocking-to-ai">State-backed groups are flocking to AI</h2><p>GTIG said it has observed state-linked groups broadening their use of AI. In one example, PRC-nexus threat actor UNC6508 carried out a major intrusion campaign against US medical facilities, using compromised cloud environments to host a local model.</p><p>In April, meanwhile, Mandiant spotted a threat actor leveraging AI infrastructure access which was then used to sustain unauthorized AI workloads, utilizing hijacked cloud environments to provision high-performance GPU compute instances at the victim's expense.</p><p>Notably, <a href="https://www.itpro.com/security/litellm-pypi-compromise-everything-we-know-so-far">TeamPCP </a>has focused heavily on the AI supply chain, using malware designed to take advantage of emerging AI systems, and including malicious prompts that were used to execute commands surreptitiously. </p><p>The group has even poisoned open source package metadata to trick AI assistants, resulting in malicious dependencies being recommended to developers. </p><p>"The challenge for defenders is that these risks are evolving faster than many organizations can quantify, measure, and govern," said Ronald Lewis, head of <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>governance at Black Duck. </p><p>"Security teams are no longer protecting only applications, users, and infrastructure. They must now secure <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-open-source-ai-models">AI models</a>, agents, prompts, data pipelines, and an increasingly complex AI supply chain while also defending against adversaries using AI to accelerate attacks.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is Shai-Hulud back? Researchers spot 'wormy boy' slipping past npm malware scanning features ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The <a href="https://www.itpro.com/security/malware/shai-hulud-here-we-go-again-thousands-of-npm-packages-compromised-in-chaindrop-malware-campaign-where-hackers-taunt-victims">Shai-Hulud</a> npm worm is back several months after everyone assumed it was dead.</p><p>Back in May, a compromised maintainer account pushed 639 malicious versions of @antv packages to npm in a single hour, although the attack was swiftly halted.</p><p>However, while npm has since introduced publish-time malware scanning, researchers at Aikido Security spotted a “wormy boy” slipped through a triage queue. </p><p>“It had the same hash as the @AntV wave. Same payload,” Aikido Security’s Charlie Eriksen noted in a recent <a href="https://www.aikido.dev/blog/shai-hulud-npm-resurfaces" target="_blank"><u>blog post</u></a>. </p><p>Eriksen said four packages were uploaded within the space of an hour after a 111-day gap - and bypassing npm's new publish-time malware scanning, which sees every package held for five to 15 minutes while an automated system checks it before it becomes installable. </p><p>This marks a concerning new development in terms of Shai-Hulud-related risks, according to Eriksen. </p><p>While the scanners shouldn't be expected to catch everything, a worm payload with a public hash, extensive vendor write-ups, and months of detection coverage should not be slipping through the net on a registry that now markets itself as scanning every publish.</p><p>"That gap between what registry-level scanning claims to do and what a hash-identical reactivation shows it actually caught is the real story here," he said. </p><p>"Signature matching against known-malicious artifacts is the single easiest bar to clear in this industry, and it's the bar we should all be most alarmed to see missed."</p><p>The four packages concerned were:</p><ul><li>feishu-docx-mcp@0.3.2</li><li>bmc-i18n-extract-cli@1.1.1</li><li>blueai-cli@0.7.0</li><li>bmc-translate-utils@1.1.1all</li></ul><h2 id="keep-an-eye-out-for-shai-hulud">Keep an eye out for Shai-Hulud</h2><p>According to Aikido, teams should be looking out for these and the command-and-control domain associated with the original May wave, t[.]m-kosche[.]com.</p><p>Other indicators of compromise include the hash of the reused malicious payload, e37e3ddeeaaa9e0c4fdbcb829b4895a6521031c80053fc436625b61e6ee5b1a6, the index.js root-level payload file ,and the command executed by the preinstall script, bun run index.js, along with the persistence files .vscode/tasks.json and claude/settings.json.</p><p>Behavioral indicators include outbound validation calls against npm registry using stolen tokens, tarball download, payload injection, version bump, republish cycle, and the mass creation of GitHub repositories with Dune-themed naming and reversed "Shai-Hulud" strings in descriptions.</p><p>“A file hash match is a lookup, not a hard problem. It requires no behavioral analysis, sandboxing, or reasoning about obfuscated code’s intent,” Erikson commented. </p><p>“And this payload wasn't novel, repacked, or even lightly modified to dodge signature matching. It was the same 64 hex characters that had been on file since May."</p><p>While the likes of multi-stage loaders, dependency confusion, and runtime-triggered payloads are genuinely hard problems, he said an exact hash match to a worm that made international security news four months ago isn't.</p><p>"That's the floor of what publish-time scanning is supposed to catch, and it got missed," he said.</p><p><em>ITPro </em>approached npm for comment, but did not receive a response by time of publication. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/malware/is-shai-hulud-back-researchers-spot-wormy-boy-slipping-past-npm-malware-scanning-features</link>
                                                                            <description>
                            <![CDATA[ After a 111-day hiatus, Aikido detected a previously-documented Shai-Hulud worm payload in four npm package releases published this week ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bK5y7PZZzSJJWkKd4m42PJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S2kXYxtTBgGXo79HoNmvZZ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 08:13:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Malware]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S2kXYxtTBgGXo79HoNmvZZ-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dune Shai-Hulud concept image showing man standing on rock with giant sandworm breaching out of the sand. ]]></media:description>                                                            <media:text><![CDATA[Dune Shai-Hulud concept image showing man standing on rock with giant sandworm breaching out of the sand. ]]></media:text>
                                <media:title type="plain"><![CDATA[Dune Shai-Hulud concept image showing man standing on rock with giant sandworm breaching out of the sand. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S2kXYxtTBgGXo79HoNmvZZ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.itpro.com/security/malware/shai-hulud-here-we-go-again-thousands-of-npm-packages-compromised-in-chaindrop-malware-campaign-where-hackers-taunt-victims">Shai-Hulud</a> npm worm is back several months after everyone assumed it was dead.</p><p>Back in May, a compromised maintainer account pushed 639 malicious versions of @antv packages to npm in a single hour, although the attack was swiftly halted.</p><p>However, while npm has since introduced publish-time malware scanning, researchers at Aikido Security spotted a “wormy boy” slipped through a triage queue. </p><p>“It had the same hash as the @AntV wave. Same payload,” Aikido Security’s Charlie Eriksen noted in a recent <a href="https://www.aikido.dev/blog/shai-hulud-npm-resurfaces" target="_blank"><u>blog post</u></a>. </p><p>Eriksen said four packages were uploaded within the space of an hour after a 111-day gap - and bypassing npm's new publish-time malware scanning, which sees every package held for five to 15 minutes while an automated system checks it before it becomes installable. </p><p>This marks a concerning new development in terms of Shai-Hulud-related risks, according to Eriksen. </p><p>While the scanners shouldn't be expected to catch everything, a worm payload with a public hash, extensive vendor write-ups, and months of detection coverage should not be slipping through the net on a registry that now markets itself as scanning every publish.</p><p>"That gap between what registry-level scanning claims to do and what a hash-identical reactivation shows it actually caught is the real story here," he said. </p><p>"Signature matching against known-malicious artifacts is the single easiest bar to clear in this industry, and it's the bar we should all be most alarmed to see missed."</p><p>The four packages concerned were:</p><ul><li>feishu-docx-mcp@0.3.2</li><li>bmc-i18n-extract-cli@1.1.1</li><li>blueai-cli@0.7.0</li><li>bmc-translate-utils@1.1.1all</li></ul><h2 id="keep-an-eye-out-for-shai-hulud">Keep an eye out for Shai-Hulud</h2><p>According to Aikido, teams should be looking out for these and the command-and-control domain associated with the original May wave, t[.]m-kosche[.]com.</p><p>Other indicators of compromise include the hash of the reused malicious payload, e37e3ddeeaaa9e0c4fdbcb829b4895a6521031c80053fc436625b61e6ee5b1a6, the index.js root-level payload file ,and the command executed by the preinstall script, bun run index.js, along with the persistence files .vscode/tasks.json and claude/settings.json.</p><p>Behavioral indicators include outbound validation calls against npm registry using stolen tokens, tarball download, payload injection, version bump, republish cycle, and the mass creation of GitHub repositories with Dune-themed naming and reversed "Shai-Hulud" strings in descriptions.</p><p>“A file hash match is a lookup, not a hard problem. It requires no behavioral analysis, sandboxing, or reasoning about obfuscated code’s intent,” Erikson commented. </p><p>“And this payload wasn't novel, repacked, or even lightly modified to dodge signature matching. It was the same 64 hex characters that had been on file since May."</p><p>While the likes of multi-stage loaders, dependency confusion, and runtime-triggered payloads are genuinely hard problems, he said an exact hash match to a worm that made international security news four months ago isn't.</p><p>"That's the floor of what publish-time scanning is supposed to catch, and it got missed," he said.</p><p><em>ITPro </em>approached npm for comment, but did not receive a response by time of publication. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What happens to consent when the keys are handed to machines? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In June, Google disabled a feature in its Analytics platform that stopped personal data from being shared with Google Ads. </p><p>Launched just after <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a> in 2018, Google Signals gave businesses veto over whether Google’s ad network could see their visitor activity. Even if a user consented to being tracked, the final decision lay with the business, and many used it as an extra guardrail, with Google’s Consent Mode, to prevent falling foul of privacy laws. Then in June, Google Signals was gone. </p><p>You could assume the change was minor, especially because Consent Mode was still there to protect a user’s cookie consent choice. Yet straight after the switch, compliance failures across the world's biggest websites increased. </p><p>In the US, <a href="https://www.privado.ai/the-state-of-google-consent-mode-june-15"><u>87% of sites</u></a> were found to be ignoring a user's opt-out signal, up from 81% before the change. In Europe, 56% kept tracking users even after they'd rejected cookies, up from 52%. One vendor changed one setting and elements of an already brittle consent framework began to unravel. </p><p>"If a single vendor can make this change which affects everybody's privacy compliance docket without most noticing,” says Vaibhav Antil, CEO and co-founder of Privado. “Imagine what happens when agents are deployed?" </p><h2 id="handing-the-keys-to-the-machine">Handing the keys to the machine</h2><p>Bot web traffic has already overtaken human web traffic, according to <a href="https://radar.cloudflare.com/traffic#bot-vs-human"><u>Cloudflare’s traffic radar</u></a>, and the number of non-human identities inside organizations outnumber humans by <a href="https://www.businesswire.com/news/home/20250423817886/en/Machine-Identities-Outnumber-Humans-by-More-Than-80-to-1-New-Report-Exposes-the-Exponential-Threats-of-Fragmented-Identity-Security"><u>more than 80 to 1</u></a>. </p><p>These agents are on the web comparing prices, filling in forms and booking appointments. They’re embedded in products, sifting job applications, querying databases, moving money, updating records, and increasingly making decisions that used to need a person to sign off on. Gartner expects <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027"><u>15% of day-to-day work decisions</u></a> will be made autonomously by AI agents by 2028.</p><p>Yet the approval and consent process behind it all still largely consists of cookie banners, DSAR portals, and preference centres; tools built for a human ticking one box, once, and that consent holding until they say otherwise. AI actors are capable of acting thousands of times a second, or chaining several tools together to complete a single instruction. They need their permission checked before every move, and their actions can leave businesses unable to say, with confidence, what they did, when.</p><p>“A person with too much access is limited by habit, their training, and by their job,” adds Marcus Tommy, co-founder of MALTO Cyber. “An agent has none of that.”</p><h2 id="the-fan-out">The fan-out</h2><p>Take, for example, someone who asks an agent to find out why sales have dropped. “The system can choose an analysis, run it, and generate SQL to investigate it,” explains Maurice Sikkink, CTO at Stormly. It might even reach into an external system for market data. Technically, a human approved the question, but they didn’t explicitly approve every step the agent took to answer it.</p><p>This becomes more stark when agents start connecting systems together. One linked agent might have permission to read customer records in a CRM, and permission to write to a marketing platform – both individually authorized. Yet the moment it starts moving a customer's data between them, it presents a new use of that person's data nobody explicitly consented to.</p><p>And then there’s the issue of revocation and re-authorisation. Revoking permissions can be done for several reasons, from policy changes to someone leaving a job. If an agent's session token or API key is valid for hours after the revocation kicks in, the underlying permission isn’t always automatically revoked. </p><p>"Those credentials haven’t necessarily been stolen," Harry Varatharasan, chief product officer at ComplyCube, says. "The agent might not be malicious. The identity behind them might be perfectly genuine, but the authority is stale.”</p><h2 id="auditability-by-design">Auditability by design</h2><p>Antil's answer, for copilots at least, is what he calls permission inheritance: "If you, the user, are not able to edit settings, then your copilot shouldn't be able to either.” When permission inheritance isn't enough, continues Antil, enterprise IT needs to decide what counts as dangerous, regardless of whether a single employee has permission to perform the task. </p><p>“A business might disable an email-to-Claude connector, for instance, because it's a common route for prompt injection attacks,” he adds.  </p><p>However, even where access is logged and overseen, most systems can prove who had permission to ask the agent to act but not <em>why</em> the agent did what it did once inside. </p><p>Sikkink says this is where the industry is furthest behind. "Authentication tells me someone had access to the project. Attribution tells me that they asked the agent to do it.” What’s missing, he argues, “is a common way of carrying the identity of an original request through the entire chain.” </p><p>Varatharasan calls this idea of carrying identity and authority through the chain as “binding.” "Issuing the credential is only half the problem. Knowing whether you should still trust it is arguably the more important half,” he says. "I don't think the future is simply 'continuously identifying the agent ’. It’s the continuous assurance over the relationship between the individual, the agent, its credentials, its delegated authority and its behaviour." </p><p>Sikkink agrees: “[Not] every intermediate step needs another consent popup. That would make agents almost pointless. The important thing is that the agent stays inside a clearly defined boundary, and that we can reconstruct how it got from the user's request to the result.”</p><h2 id="a-push-for-clarity">A push for clarity</h2><p>From a technical point of view, Tommy argues that what’s needed to fix this largely already exists. “Cloud audit logs record the actor and the action. Token systems know the scope. Append-only log structures are proven technology; they run the public certificate transparency system. What’s missing is the join.”</p><p>In the UK, the <a href="https://www.gov.uk/government/collections/uk-digital-verification-services-trust-framework"><u>Digital Verification Services Trust Framework</u></a> is one attempt to build this join. It sets out guidance on proving delegated authority: what was granted, when and by whom, plus plans for cryptographic checks on signing keys. Under new <a href="https://cppa.ca.gov/announcements/2025/20250923.html"><u>California Consumer Privacy Act regulations</u></a>, businesses using AI for significant decisions must give consumers a pre-use notice, a working opt-out, and the right to ask what the system did and why. </p><p>Antil calls these a step in the right direction, even if they don’t fully cover agentic workflows. Varatharasan adds that these frameworks have the right building blocks but fall short of addressing the bigger, lifecycle issues around revocation, re-authorisation, and continuous risk. </p><p>Ultimately though, Antil expects consent in the age of machines to resolve the way SaaS governance did. First, by applying existing regulations to the problem; second, through the rise of new regulations; and third, he expects “we’ll see a major public failure which will push enterprises to demand more controls and guardrails from vendors.” </p><p>There’s also a future when the governance itself will be automated. “Because agents and copilots have agency, act at machine speed around the clock, and are prone to hallucinations, enterprises will need to match that speed from a governance perspective," concludes Antil.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/what-happens-to-consent-when-the-keys-are-handed-to-machines</link>
                                                                            <description>
                            <![CDATA[ Access is under the spotlight, and things are definitely more complicated in the AI era... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QsfnoD3wzkXnBJKLTJN2fW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 09 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 09 Sep 2026 10:20:32 +0000</updated>
                                                                                                                                            <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Privacy]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Victoria Woollaston ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:description>                                                            <media:text><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:text>
                                <media:title type="plain"><![CDATA[AI agent concept image showing a digitized human face disintegrating into hundreds of small individual blocks.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/44ktQKgRvmq93jKSBo3pnB-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In June, Google disabled a feature in its Analytics platform that stopped personal data from being shared with Google Ads. </p><p>Launched just after <a href="https://www.itpro.com/it-legislation/27814/what-is-gdpr-everything-you-need-to-know"><u>GDPR</u></a> in 2018, Google Signals gave businesses veto over whether Google’s ad network could see their visitor activity. Even if a user consented to being tracked, the final decision lay with the business, and many used it as an extra guardrail, with Google’s Consent Mode, to prevent falling foul of privacy laws. Then in June, Google Signals was gone. </p><p>You could assume the change was minor, especially because Consent Mode was still there to protect a user’s cookie consent choice. Yet straight after the switch, compliance failures across the world's biggest websites increased. </p><p>In the US, <a href="https://www.privado.ai/the-state-of-google-consent-mode-june-15"><u>87% of sites</u></a> were found to be ignoring a user's opt-out signal, up from 81% before the change. In Europe, 56% kept tracking users even after they'd rejected cookies, up from 52%. One vendor changed one setting and elements of an already brittle consent framework began to unravel. </p><p>"If a single vendor can make this change which affects everybody's privacy compliance docket without most noticing,” says Vaibhav Antil, CEO and co-founder of Privado. “Imagine what happens when agents are deployed?" </p><h2 id="handing-the-keys-to-the-machine">Handing the keys to the machine</h2><p>Bot web traffic has already overtaken human web traffic, according to <a href="https://radar.cloudflare.com/traffic#bot-vs-human"><u>Cloudflare’s traffic radar</u></a>, and the number of non-human identities inside organizations outnumber humans by <a href="https://www.businesswire.com/news/home/20250423817886/en/Machine-Identities-Outnumber-Humans-by-More-Than-80-to-1-New-Report-Exposes-the-Exponential-Threats-of-Fragmented-Identity-Security"><u>more than 80 to 1</u></a>. </p><p>These agents are on the web comparing prices, filling in forms and booking appointments. They’re embedded in products, sifting job applications, querying databases, moving money, updating records, and increasingly making decisions that used to need a person to sign off on. Gartner expects <a href="https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027"><u>15% of day-to-day work decisions</u></a> will be made autonomously by AI agents by 2028.</p><p>Yet the approval and consent process behind it all still largely consists of cookie banners, DSAR portals, and preference centres; tools built for a human ticking one box, once, and that consent holding until they say otherwise. AI actors are capable of acting thousands of times a second, or chaining several tools together to complete a single instruction. They need their permission checked before every move, and their actions can leave businesses unable to say, with confidence, what they did, when.</p><p>“A person with too much access is limited by habit, their training, and by their job,” adds Marcus Tommy, co-founder of MALTO Cyber. “An agent has none of that.”</p><h2 id="the-fan-out">The fan-out</h2><p>Take, for example, someone who asks an agent to find out why sales have dropped. “The system can choose an analysis, run it, and generate SQL to investigate it,” explains Maurice Sikkink, CTO at Stormly. It might even reach into an external system for market data. Technically, a human approved the question, but they didn’t explicitly approve every step the agent took to answer it.</p><p>This becomes more stark when agents start connecting systems together. One linked agent might have permission to read customer records in a CRM, and permission to write to a marketing platform – both individually authorized. Yet the moment it starts moving a customer's data between them, it presents a new use of that person's data nobody explicitly consented to.</p><p>And then there’s the issue of revocation and re-authorisation. Revoking permissions can be done for several reasons, from policy changes to someone leaving a job. If an agent's session token or API key is valid for hours after the revocation kicks in, the underlying permission isn’t always automatically revoked. </p><p>"Those credentials haven’t necessarily been stolen," Harry Varatharasan, chief product officer at ComplyCube, says. "The agent might not be malicious. The identity behind them might be perfectly genuine, but the authority is stale.”</p><h2 id="auditability-by-design">Auditability by design</h2><p>Antil's answer, for copilots at least, is what he calls permission inheritance: "If you, the user, are not able to edit settings, then your copilot shouldn't be able to either.” When permission inheritance isn't enough, continues Antil, enterprise IT needs to decide what counts as dangerous, regardless of whether a single employee has permission to perform the task. </p><p>“A business might disable an email-to-Claude connector, for instance, because it's a common route for prompt injection attacks,” he adds.  </p><p>However, even where access is logged and overseen, most systems can prove who had permission to ask the agent to act but not <em>why</em> the agent did what it did once inside. </p><p>Sikkink says this is where the industry is furthest behind. "Authentication tells me someone had access to the project. Attribution tells me that they asked the agent to do it.” What’s missing, he argues, “is a common way of carrying the identity of an original request through the entire chain.” </p><p>Varatharasan calls this idea of carrying identity and authority through the chain as “binding.” "Issuing the credential is only half the problem. Knowing whether you should still trust it is arguably the more important half,” he says. "I don't think the future is simply 'continuously identifying the agent ’. It’s the continuous assurance over the relationship between the individual, the agent, its credentials, its delegated authority and its behaviour." </p><p>Sikkink agrees: “[Not] every intermediate step needs another consent popup. That would make agents almost pointless. The important thing is that the agent stays inside a clearly defined boundary, and that we can reconstruct how it got from the user's request to the result.”</p><h2 id="a-push-for-clarity">A push for clarity</h2><p>From a technical point of view, Tommy argues that what’s needed to fix this largely already exists. “Cloud audit logs record the actor and the action. Token systems know the scope. Append-only log structures are proven technology; they run the public certificate transparency system. What’s missing is the join.”</p><p>In the UK, the <a href="https://www.gov.uk/government/collections/uk-digital-verification-services-trust-framework"><u>Digital Verification Services Trust Framework</u></a> is one attempt to build this join. It sets out guidance on proving delegated authority: what was granted, when and by whom, plus plans for cryptographic checks on signing keys. Under new <a href="https://cppa.ca.gov/announcements/2025/20250923.html"><u>California Consumer Privacy Act regulations</u></a>, businesses using AI for significant decisions must give consumers a pre-use notice, a working opt-out, and the right to ask what the system did and why. </p><p>Antil calls these a step in the right direction, even if they don’t fully cover agentic workflows. Varatharasan adds that these frameworks have the right building blocks but fall short of addressing the bigger, lifecycle issues around revocation, re-authorisation, and continuous risk. </p><p>Ultimately though, Antil expects consent in the age of machines to resolve the way SaaS governance did. First, by applying existing regulations to the problem; second, through the rise of new regulations; and third, he expects “we’ll see a major public failure which will push enterprises to demand more controls and guardrails from vendors.” </p><p>There’s also a future when the governance itself will be automated. “Because agents and copilots have agency, act at machine speed around the clock, and are prone to hallucinations, enterprises will need to match that speed from a governance perspective," concludes Antil.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The NCSC is calling for a crackdown on shadow AI ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The widespread use of shadow AI is putting British businesses at risk, according to the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u>.</a></p><p>The use of unapproved AI tools is on the rise, with <a href="https://ukstories.microsoft.com/features/rise-in-shadow-ai-tools-raising-security-concerns-for-uk/" target="_blank"><u>research</u></a> from Microsoft late last year revealing that 71% of UK employees have used unapproved consumer AI tools at work, with more than half saying they do so every week.</p><p>While the NCSC said AI can help people complete tasks more quickly, improve decision-making, cut costs and increase productivity, organizations are falling short when it comes to policy and guidance. </p><p>In a new <a href="https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai" target="_blank"><u>briefing document</u></a>, the security agency said enterprises need to tighten up practices on this front and crack down on unapproved use. </p><p>"Rather than preventing them from using AI, this can mean employees turn to using <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> that have not been approved by their organization, introducing new cybersecurity risks that can be hard to identify,” the document reads. </p><p>"Where <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>policies cannot meet business needs, organizations are likely to continue seeing their employees adopt new AI services before they have had time to assess them and provide approved alternatives. This trend is likely to be reinforced as AI capabilities become increasingly affordable and readily available."</p><h2 id="the-rise-of-shadow-ai">The rise of shadow AI</h2><p>Some of the biggest concerns associated with shadow AI is the risk of data breaches, the loss of intellectual property, and failure to meet regulatory requirements.</p><p>If employees transfer sensitive or proprietary information to consumer AI services, there's a strong chance that this information might be stored, retained, or used to improve the service – outside established security and governance arrangements – unless specific privacy controls are in place.</p><p>This can reduce the organization's visibility and control over that information. </p><p>Similarly, the use of <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-shadow-ai-and-what-leaders-can-do-to-prevent-it">shadow AI</a> can also create a wealth of new opportunities for attackers, according to the NCSC. If hackers successfully exploit a vulnerability, they can gain access to the same data, services, and privileges that the agent has legitimate access to.</p><p>Attackers are highly likely to use agents with looser guardrails to exploit any vulnerabilities or misconfigurations in the wider corporate IT system.</p><p>"The NCSC is not recommending that individuals stop using AI – but when turning to these tools for assistance with a work task, think carefully about which apps and services you are using before you share data," said the NCSC.</p><p>"It may feel natural to stick with using the same AI service that you are familiar with from your personal life – but using systems that are not corporately approved can present real problems for your employer."</p><h2 id="stronger-controls-are-needed">Stronger controls are needed</h2><p>The NCSC said organizations need to introduce policies that reflect the real world, with the aim of reducing risk rather than assuming it can be eliminated.</p><p>This means adopting a positive <a href="https://www.itpro.com/security/357406/four-tips-for-building-effective-security-awareness-training">cybersecurity culture</a> and encouraging open communication about security issues. Once organizations understand why people are using shadow AI, it becomes much easier to identify risks, provide secure alternatives, and support innovation safely.</p><p>The guidance echoes <a href="https://www.itpro.com/technology/artificial-intelligence/gartner-says-40-percent-of-enterprises-will-experience-shadow-ai-breaches-by-2030-educating-staff-is-the-key-to-avoiding-disaster"><u>analysis</u></a> by Gartner last year that found nearly half of enterprises could face serious security or compliance-related incidents as a result of shadow AI by 2030.</p><p>"You cannot manage what you do not know," the NCSC guidance noted. "By raising awareness of the risks of shadow AI use within your organisation and understanding the needs of employees, you can help them get the benefits of new technologies while using them securely."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/you-cannot-manage-what-you-do-not-know-the-ncsc-is-calling-for-a-crackdown-on-shadow-ai</link>
                                                                            <description>
                            <![CDATA[ Organizations are urged to identify shadow AI use and tighten up security procedures ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JGSziwnG6iXiZqTSekauVX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 09:57:12 +0000</pubDate>                                                                                                                                <updated>Tue, 08 Sep 2026 10:03:06 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:description>                                                            <media:text><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:text>
                                <media:title type="plain"><![CDATA[Insider threat hacker concept image showing man typing on keyboard in a dimly lit room. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UjWjTqk5HiFp2xWB4yo93k-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The widespread use of shadow AI is putting British businesses at risk, according to the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u>.</a></p><p>The use of unapproved AI tools is on the rise, with <a href="https://ukstories.microsoft.com/features/rise-in-shadow-ai-tools-raising-security-concerns-for-uk/" target="_blank"><u>research</u></a> from Microsoft late last year revealing that 71% of UK employees have used unapproved consumer AI tools at work, with more than half saying they do so every week.</p><p>While the NCSC said AI can help people complete tasks more quickly, improve decision-making, cut costs and increase productivity, organizations are falling short when it comes to policy and guidance. </p><p>In a new <a href="https://www.ncsc.gov.uk/blogs/the-hidden-risks-of-shadow-ai" target="_blank"><u>briefing document</u></a>, the security agency said enterprises need to tighten up practices on this front and crack down on unapproved use. </p><p>"Rather than preventing them from using AI, this can mean employees turn to using <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> that have not been approved by their organization, introducing new cybersecurity risks that can be hard to identify,” the document reads. </p><p>"Where <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>policies cannot meet business needs, organizations are likely to continue seeing their employees adopt new AI services before they have had time to assess them and provide approved alternatives. This trend is likely to be reinforced as AI capabilities become increasingly affordable and readily available."</p><h2 id="the-rise-of-shadow-ai">The rise of shadow AI</h2><p>Some of the biggest concerns associated with shadow AI is the risk of data breaches, the loss of intellectual property, and failure to meet regulatory requirements.</p><p>If employees transfer sensitive or proprietary information to consumer AI services, there's a strong chance that this information might be stored, retained, or used to improve the service – outside established security and governance arrangements – unless specific privacy controls are in place.</p><p>This can reduce the organization's visibility and control over that information. </p><p>Similarly, the use of <a href="https://www.itpro.com/technology/artificial-intelligence/the-risks-of-shadow-ai-and-what-leaders-can-do-to-prevent-it">shadow AI</a> can also create a wealth of new opportunities for attackers, according to the NCSC. If hackers successfully exploit a vulnerability, they can gain access to the same data, services, and privileges that the agent has legitimate access to.</p><p>Attackers are highly likely to use agents with looser guardrails to exploit any vulnerabilities or misconfigurations in the wider corporate IT system.</p><p>"The NCSC is not recommending that individuals stop using AI – but when turning to these tools for assistance with a work task, think carefully about which apps and services you are using before you share data," said the NCSC.</p><p>"It may feel natural to stick with using the same AI service that you are familiar with from your personal life – but using systems that are not corporately approved can present real problems for your employer."</p><h2 id="stronger-controls-are-needed">Stronger controls are needed</h2><p>The NCSC said organizations need to introduce policies that reflect the real world, with the aim of reducing risk rather than assuming it can be eliminated.</p><p>This means adopting a positive <a href="https://www.itpro.com/security/357406/four-tips-for-building-effective-security-awareness-training">cybersecurity culture</a> and encouraging open communication about security issues. Once organizations understand why people are using shadow AI, it becomes much easier to identify risks, provide secure alternatives, and support innovation safely.</p><p>The guidance echoes <a href="https://www.itpro.com/technology/artificial-intelligence/gartner-says-40-percent-of-enterprises-will-experience-shadow-ai-breaches-by-2030-educating-staff-is-the-key-to-avoiding-disaster"><u>analysis</u></a> by Gartner last year that found nearly half of enterprises could face serious security or compliance-related incidents as a result of shadow AI by 2030.</p><p>"You cannot manage what you do not know," the NCSC guidance noted. "By raising awareness of the risks of shadow AI use within your organisation and understanding the needs of employees, you can help them get the benefits of new technologies while using them securely."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Samsung backs Mistral in record-breaking €3 billion funding round ]]></title>
                                                                                                <dc:content><![CDATA[ <p>French AI giant Mistral has raised €3 billion to support frontier model research and development of sovereign, <a href="https://www.itpro.com/software/open-source/the-pros-and-cons-of-open-source-ai-for-business">open-weight systems</a>. </p><p>The funding, led by Samsung Electronics and Scaleup Europe Fund, is the largest equity round by a European tech company and values Mistral at €21 billion. </p><p>The aim is to train "bigger and faster models", CEO Arthur Mensch told <a href="https://www.cnbc.com/2026/09/08/mistral-ai-funding-valuation-samsung.html" target="_blank"><u><em>CNBC</em></u></a>, but Mistral also said in a blog post that its focus was <a href="https://www.itpro.com/technology/artificial-intelligence/big-tech-faces-an-adapt-or-die-predicament-with-open-weight-ai-models"><u>open-weight models</u></a> built and run in Europe that allow companies to keep hold of their data. </p><p>"During the first wave of generative AI, the central question was who could build the most powerful model," the company said in a blog post. </p><p>"Organizations and governments are now asking a different one: how to harness the power of AI for their mission-critical needs without surrendering control over the infrastructure and intelligence loop."</p><p>Mistral added that demand for a “combination of performance and control, choice, and independence” is growing globally. </p><p>The company said enterprises are governments alike are now weighing up long-term tech dependencies, governance requirements and “deployment choices that come with any AI investment”. </p><h2 id="mistral-eyes-sovereign-ai-gains">Mistral eyes sovereign AI gains</h2><p>The importance of <a href="https://www.itpro.com/technology/artificial-intelligence/can-europe-achieve-ai-sovereignty"><u>sovereign AI</u></a> was made clear earlier this year when Anthropic's security models were <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-suspends-fabel-and-mythos-systems-for-all-users-after-us-government-claims-jailbreak-risk"><u>temporarily hit by an export ban</u></a>. </p><p>More generally, <a href="https://www.itpro.com/infrastructure/sovereign-infrastructure-spend-to-triple-in-europe-as-fifth-of-workloads-stay-local"><u>countries like France</u></a> and <a href="https://www.windowscentral.com/microsoft/microsoft-office/switzerland-testing-alternatives-to-microsoft-365-digital-sovereignty" target="_blank"><u>Switzerland are pushing away</u></a> from American technology firms for their own versions of software and services for government use. </p><p>Mistral in particular has positioned itself as an alternative not only to American dominance, but also the <a href="https://www.itpro.com/technology/artificial-intelligence/should-businesses-consider-using-chinese-ai-models"><u>open-weight models developed in China</u></a>. </p><p>"The fact that the EU or Europe have to have their own kind of AI provider in the game is important," chief financial officer Johan Bergqvist told <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u><em>Reuters</em></u></a><em>.</em></p><p>"We ​have seen in the past ​that there is ⁠politics involved in the access of these solutions, and it's important that you make sure that you maintain access and do not compromise your kind of supply ​chain,” he added. </p><p>That said, Mistral <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u>noted</u></a> that it was seeing particular growth in Asia and North America, with more than 125 global enterprises as customers based in 20 countries. </p><p>"The round reflects a strategic endorsement from investors across Europe, Asia and North America," Mistral said in the blog post. </p><p>"It brings together a world-class syndicate of strategic and financial investors, including global technology leaders, growth investors and existing shareholders that have supported Mistral’s development to date."</p><h2 id="paying-for-the-ai-rollout">Paying for the AI rollout</h2><p>Beyond investing in frontier research, the funding round will be used to boost AI infrastructure available to Mistral, Mensch said. </p><p>"Long term, the plan is to fully rely on capacity that we are building ourselves, and so that means that the amount of compute that we own is going to grow ... around 100% in the next five years," Mensch told <em>CNBC</em>. </p><p>Speaking to the <a href="https://www.ft.com/content/adbf5262-c4d5-4312-a9b8-4d3cf30c9e00?syn-25a6b1a6=1" target="_blank"><u><em>Financial Times</em></u></a>, Mensch added that the funding will allow Mistral to reach an "amount of compute that is very comparable to what the Chinese labs have."</p><p>However, the investment is small compared to the figures coming out of the US, with <a href="https://www.itpro.com/security/open-weight-models-are-closing-the-capability-gap-with-frontier-models-at-a-fraction-of-the-cost-cheap-chinese-ai-models-could-spell-trouble-for-us-big-tech"><u>$1trn set to be spent on AI infrastructure this year alone</u></a>, and rivals such as Anthropic and OpenAI <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u>valued</u></a> at $965bn and $852bn ahead of looming IPOs. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/samsung-backs-mistral-in-record-breaking-eur3-billion-funding-round-as-french-ai-firm-targets-sovereign-ai-gains</link>
                                                                            <description>
                            <![CDATA[ The French AI company breaks European records, but still trails American rivals with a €21bn valuation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4rnA6QqviqpvUNJaWBhFmL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fVKmsVEFVJ8unyV6qir3Mh-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 09:48:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fVKmsVEFVJ8unyV6qir3Mh-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mistral AI founder Arthur Mensch speaks at the ai-Pulse conference at Station F technology campus in Paris, France, on Friday, Nov. 17, 2023]]></media:description>                                                            <media:text><![CDATA[Mistral AI founder Arthur Mensch speaks at the ai-Pulse conference at Station F technology campus in Paris, France, on Friday, Nov. 17, 2023]]></media:text>
                                <media:title type="plain"><![CDATA[Mistral AI founder Arthur Mensch speaks at the ai-Pulse conference at Station F technology campus in Paris, France, on Friday, Nov. 17, 2023]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fVKmsVEFVJ8unyV6qir3Mh-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>French AI giant Mistral has raised €3 billion to support frontier model research and development of sovereign, <a href="https://www.itpro.com/software/open-source/the-pros-and-cons-of-open-source-ai-for-business">open-weight systems</a>. </p><p>The funding, led by Samsung Electronics and Scaleup Europe Fund, is the largest equity round by a European tech company and values Mistral at €21 billion. </p><p>The aim is to train "bigger and faster models", CEO Arthur Mensch told <a href="https://www.cnbc.com/2026/09/08/mistral-ai-funding-valuation-samsung.html" target="_blank"><u><em>CNBC</em></u></a>, but Mistral also said in a blog post that its focus was <a href="https://www.itpro.com/technology/artificial-intelligence/big-tech-faces-an-adapt-or-die-predicament-with-open-weight-ai-models"><u>open-weight models</u></a> built and run in Europe that allow companies to keep hold of their data. </p><p>"During the first wave of generative AI, the central question was who could build the most powerful model," the company said in a blog post. </p><p>"Organizations and governments are now asking a different one: how to harness the power of AI for their mission-critical needs without surrendering control over the infrastructure and intelligence loop."</p><p>Mistral added that demand for a “combination of performance and control, choice, and independence” is growing globally. </p><p>The company said enterprises are governments alike are now weighing up long-term tech dependencies, governance requirements and “deployment choices that come with any AI investment”. </p><h2 id="mistral-eyes-sovereign-ai-gains">Mistral eyes sovereign AI gains</h2><p>The importance of <a href="https://www.itpro.com/technology/artificial-intelligence/can-europe-achieve-ai-sovereignty"><u>sovereign AI</u></a> was made clear earlier this year when Anthropic's security models were <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-suspends-fabel-and-mythos-systems-for-all-users-after-us-government-claims-jailbreak-risk"><u>temporarily hit by an export ban</u></a>. </p><p>More generally, <a href="https://www.itpro.com/infrastructure/sovereign-infrastructure-spend-to-triple-in-europe-as-fifth-of-workloads-stay-local"><u>countries like France</u></a> and <a href="https://www.windowscentral.com/microsoft/microsoft-office/switzerland-testing-alternatives-to-microsoft-365-digital-sovereignty" target="_blank"><u>Switzerland are pushing away</u></a> from American technology firms for their own versions of software and services for government use. </p><p>Mistral in particular has positioned itself as an alternative not only to American dominance, but also the <a href="https://www.itpro.com/technology/artificial-intelligence/should-businesses-consider-using-chinese-ai-models"><u>open-weight models developed in China</u></a>. </p><p>"The fact that the EU or Europe have to have their own kind of AI provider in the game is important," chief financial officer Johan Bergqvist told <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u><em>Reuters</em></u></a><em>.</em></p><p>"We ​have seen in the past ​that there is ⁠politics involved in the access of these solutions, and it's important that you make sure that you maintain access and do not compromise your kind of supply ​chain,” he added. </p><p>That said, Mistral <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u>noted</u></a> that it was seeing particular growth in Asia and North America, with more than 125 global enterprises as customers based in 20 countries. </p><p>"The round reflects a strategic endorsement from investors across Europe, Asia and North America," Mistral said in the blog post. </p><p>"It brings together a world-class syndicate of strategic and financial investors, including global technology leaders, growth investors and existing shareholders that have supported Mistral’s development to date."</p><h2 id="paying-for-the-ai-rollout">Paying for the AI rollout</h2><p>Beyond investing in frontier research, the funding round will be used to boost AI infrastructure available to Mistral, Mensch said. </p><p>"Long term, the plan is to fully rely on capacity that we are building ourselves, and so that means that the amount of compute that we own is going to grow ... around 100% in the next five years," Mensch told <em>CNBC</em>. </p><p>Speaking to the <a href="https://www.ft.com/content/adbf5262-c4d5-4312-a9b8-4d3cf30c9e00?syn-25a6b1a6=1" target="_blank"><u><em>Financial Times</em></u></a>, Mensch added that the funding will allow Mistral to reach an "amount of compute that is very comparable to what the Chinese labs have."</p><p>However, the investment is small compared to the figures coming out of the US, with <a href="https://www.itpro.com/security/open-weight-models-are-closing-the-capability-gap-with-frontier-models-at-a-fraction-of-the-cost-cheap-chinese-ai-models-could-spell-trouble-for-us-big-tech"><u>$1trn set to be spent on AI infrastructure this year alone</u></a>, and rivals such as Anthropic and OpenAI <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u>valued</u></a> at $965bn and $852bn ahead of looming IPOs. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The hidden cost of tool sprawl on the channel ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The cybersecurity industry is awash with products.</p><p>Every time a new attack technique is discovered, vendors will rush to develop a product to address the challenge. </p><p>Whether it be malware prevention, privileged access management, next-generation firewalls, or email security platforms, the industry is flooded with platforms promising to improve defences and make it harder for attackers to infiltrate systems.</p><p>But in reality, this has made security very noisy. </p><p>Instead of improving security, the volume of tools organisations must manage has actually amplified risks.</p><p>There are too many alerts coming in to understand and identify threats quickly. Too many platforms to manage, which overburdens resources and amplifies costs, and too many interfaces to navigate, which makes managing security far from seamless.</p><p>Overall, while the objective of the platforms is to strengthen security, the products can actually jeopardise it.</p><p>However, these problems are significantly worse when it comes to Managed Service Providers (MSPs).</p><h2 id="tool-sprawl-in-the-channel">Tool sprawl in the channel</h2><p>Consider an MSP delivering security services to 50 customers.</p><p>One customer may use Microsoft security technologies, another CrowdStrike, while others could have different SIEM, vulnerability management, ticketing, and endpoint security platforms.</p><p>However, the MSP is often forced to operate them all. </p><p>All simultaneously, and all expertly, knowing the capabilities of each platform and how to operate them.</p><p>The MSP must maintain the knowledge, processes, and integrations required to operate across all of the platforms they manage for their clients. However, not only does this create resourcing challenges it also amplifies costs.</p><p>There is the cost of purchasing each platform that clients depend on, plus there is the cost of employees to manage the platforms.</p><p>Furthermore, with MSP staff continually navigating between platform interfaces, this wastes valuable time, reduces productivity, and can make managing security for clients more cumbersome.</p><p>Individually, these delays can appear insignificant. However, across hundreds or thousands of incidents, tickets, and customer interactions, they quickly accumulate.</p><p>Plus, as an MSP grows its customer base, the challenges can become even harder to manage.</p><h2 id="when-growth-introduces-more-complexity">When growth introduces more complexity</h2><p>Every business wants to grow its customer base, but for an MSP this can also mean introducing more tools into their environments.</p><p>If every new customer introduces another combination of technologies, integrations and processes, onboarding customers also introduces additional operational complexity.</p><p>Providers can find themselves in a position where growing the business requires continually adding more people to manage the additional workload.</p><p>This has obvious implications for margins, but it can also put pressure on existing teams. </p><p>Skilled cyber security professionals are already difficult and expensive to recruit. Using their time to perform repetitive administrative tasks or manually move between disconnected platforms is neither efficient nor sustainable.</p><p>Ultimately, the channel therefore needs to look beyond simply adding more technology and consider how existing technologies are operated.</p><p>There will always be customers that want or need different technologies. Channel providers therefore need to find ways to embrace this diversity without allowing it to dictate how efficiently they operate.</p><p>But how can this be achieved?</p><h2 id="the-importance-of-technology-agnostic-platforms">The importance of technology-agnostic platforms</h2><p>One of the best ways to overcome this challenge is by working with partners that deliver technology-agnostic platforms that simplify the management of security for MSPs.</p><p>These platforms can seamlessly integrate with the security platforms MSPs rely on for their customers, but they can be managed via a single dashboard.</p><p>This allows an MSP to more efficiently manage security, but without having to navigate across multiple platforms.</p><p>These platforms can deliver everything a partner needs to track, monitor, and manage the security of their customers, without overburdening resources or amplifying costs.</p><p>Instead, everything can be managed via a single unified platform, reducing complexity and cutting out the chaos of managing multiple solutions.</p><p>A technology-agnostic platform doesn't replace customer investments; it provides a common operational layer across them. </p><p>Analysts can investigate incidents, automate workflows, manage tickets, and monitor security posture from one interface while still supporting whichever technologies each customer has chosen.</p><p>The channel doesn't need fewer security technologies; it needs a better way to operate them. </p><p>MSPs that standardize their operations across diverse customer environments will reduce costs, improve analyst productivity, and deliver a more consistent service. </p><p>In an increasingly competitive market, operational efficiency isn't just an internal advantage; ultimately, it's a differentiator that leads to better security outcomes for customers and healthier margins for MSPs.  </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/the-hidden-cost-of-tool-sprawl-on-the-channel</link>
                                                                            <description>
                            <![CDATA[ Tool sprawl represents major challenges for MSPs, so how can the issue be tackled? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kcT4H7H39wP47bAapK2amh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ihZG9rnw3t3ZGBiY82SzAN-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gemma Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pKcnhWn69jhSZfdbR4f9xC-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ihZG9rnw3t3ZGBiY82SzAN-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software sprawl concept image showing multiple applications all in siloed positions on a digital interace.]]></media:description>                                                            <media:text><![CDATA[Software sprawl concept image showing multiple applications all in siloed positions on a digital interace.]]></media:text>
                                <media:title type="plain"><![CDATA[Software sprawl concept image showing multiple applications all in siloed positions on a digital interace.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ihZG9rnw3t3ZGBiY82SzAN-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The cybersecurity industry is awash with products.</p><p>Every time a new attack technique is discovered, vendors will rush to develop a product to address the challenge. </p><p>Whether it be malware prevention, privileged access management, next-generation firewalls, or email security platforms, the industry is flooded with platforms promising to improve defences and make it harder for attackers to infiltrate systems.</p><p>But in reality, this has made security very noisy. </p><p>Instead of improving security, the volume of tools organisations must manage has actually amplified risks.</p><p>There are too many alerts coming in to understand and identify threats quickly. Too many platforms to manage, which overburdens resources and amplifies costs, and too many interfaces to navigate, which makes managing security far from seamless.</p><p>Overall, while the objective of the platforms is to strengthen security, the products can actually jeopardise it.</p><p>However, these problems are significantly worse when it comes to Managed Service Providers (MSPs).</p><h2 id="tool-sprawl-in-the-channel">Tool sprawl in the channel</h2><p>Consider an MSP delivering security services to 50 customers.</p><p>One customer may use Microsoft security technologies, another CrowdStrike, while others could have different SIEM, vulnerability management, ticketing, and endpoint security platforms.</p><p>However, the MSP is often forced to operate them all. </p><p>All simultaneously, and all expertly, knowing the capabilities of each platform and how to operate them.</p><p>The MSP must maintain the knowledge, processes, and integrations required to operate across all of the platforms they manage for their clients. However, not only does this create resourcing challenges it also amplifies costs.</p><p>There is the cost of purchasing each platform that clients depend on, plus there is the cost of employees to manage the platforms.</p><p>Furthermore, with MSP staff continually navigating between platform interfaces, this wastes valuable time, reduces productivity, and can make managing security for clients more cumbersome.</p><p>Individually, these delays can appear insignificant. However, across hundreds or thousands of incidents, tickets, and customer interactions, they quickly accumulate.</p><p>Plus, as an MSP grows its customer base, the challenges can become even harder to manage.</p><h2 id="when-growth-introduces-more-complexity">When growth introduces more complexity</h2><p>Every business wants to grow its customer base, but for an MSP this can also mean introducing more tools into their environments.</p><p>If every new customer introduces another combination of technologies, integrations and processes, onboarding customers also introduces additional operational complexity.</p><p>Providers can find themselves in a position where growing the business requires continually adding more people to manage the additional workload.</p><p>This has obvious implications for margins, but it can also put pressure on existing teams. </p><p>Skilled cyber security professionals are already difficult and expensive to recruit. Using their time to perform repetitive administrative tasks or manually move between disconnected platforms is neither efficient nor sustainable.</p><p>Ultimately, the channel therefore needs to look beyond simply adding more technology and consider how existing technologies are operated.</p><p>There will always be customers that want or need different technologies. Channel providers therefore need to find ways to embrace this diversity without allowing it to dictate how efficiently they operate.</p><p>But how can this be achieved?</p><h2 id="the-importance-of-technology-agnostic-platforms">The importance of technology-agnostic platforms</h2><p>One of the best ways to overcome this challenge is by working with partners that deliver technology-agnostic platforms that simplify the management of security for MSPs.</p><p>These platforms can seamlessly integrate with the security platforms MSPs rely on for their customers, but they can be managed via a single dashboard.</p><p>This allows an MSP to more efficiently manage security, but without having to navigate across multiple platforms.</p><p>These platforms can deliver everything a partner needs to track, monitor, and manage the security of their customers, without overburdening resources or amplifying costs.</p><p>Instead, everything can be managed via a single unified platform, reducing complexity and cutting out the chaos of managing multiple solutions.</p><p>A technology-agnostic platform doesn't replace customer investments; it provides a common operational layer across them. </p><p>Analysts can investigate incidents, automate workflows, manage tickets, and monitor security posture from one interface while still supporting whichever technologies each customer has chosen.</p><p>The channel doesn't need fewer security technologies; it needs a better way to operate them. </p><p>MSPs that standardize their operations across diverse customer environments will reduce costs, improve analyst productivity, and deliver a more consistent service. </p><p>In an increasingly competitive market, operational efficiency isn't just an internal advantage; ultimately, it's a differentiator that leads to better security outcomes for customers and healthier margins for MSPs.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iran power plant closure is a warning to all businesses: How to respond ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In August, it emerged that a small UK power plant was shut down for four days following a <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>cyber attack</u></a> attributed to <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat"><u>Iranian hackers</u></a>. It follows multiple <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn"><u>attacks on water facilities</u></a> in the US, which reports indicate are linked to the latest incident.</p><p>Not much is known about the UK power plant breach, with the government declining to reveal exactly where it took place. It has confirmed the incident involved a small-scale generator, and that the wider energy system was never at risk.</p><p>But a key technical detail is still withheld about whether control systems were directly affected, or if the plant was disconnected merely as a precaution while IT contained the infiltration.</p><p>After the first of its kind attack, the government has written to businesses with advice on the steps they should take to protect themselves. How big is the risk, who does it impact, and how should firms react?</p><h2 id="major-escalation">Major escalation </h2><p>The latest attack is “a major escalation” from the recent campaign targeting water facilities in the US, says Markus Mueller, field CISO at Nozomi Networks. </p><p>He says attacks on peaker plants like this – which are designed to provide power when needed – can be more dangerous because “things happen fast, there is no buffer, and there can be major impacts”.</p><p>Critical national infrastructure is also vulnerable because it often uses legacy technology never meant to be connected to the internet. In the latest incident, the attack path involved a <a href="https://www.itpro.com/security/cyber-attacks/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories"><u>programmable logic controller</u></a> (PLC) that was not secured following basic best practices. </p><p>“If current reporting is correct, this was a publicly exposed PLC that was impacted similarly to what we have seen at US water utilities, where the threat group scans the internet for exposed PLCs using AI-generated scripts,” Mueller tells <em>ITPro</em>.</p><p>The attacker then logs into the PLCs using default credentials and proceeds to take them offline by resetting the programming and changing the password and IP address, “making it inaccessible”, explains Mueller. </p><h2 id="a-risk-beyond-cni">A risk beyond CNI</h2><p>The risk goes beyond critical sectors, into the supply chain, other industries, and to firms that rely on the breached organization.</p><p>While this incident occurred at a power plant, this is also “a clear warning” for “non-utility commercial sectors”, says Mueller. </p><p>He points out that automated scanning scripts used by adversaries “do not differentiate between a power generator, a manufacturing plant, a logistics warehouse, or smart building management systems”. </p><p>Any business relying on connected physical systems or industrial controls is at risk. At the same time, <a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight"><u>supply chain</u></a> partners and third-party maintenance contractors with remote access into operational technology (OT) environments represent “a major attack vector that adversaries are actively targeting to move laterally into enterprise networks”, says Mueller.</p><p>The risk extends “well beyond” large, regulated energy operators, agrees Martin Riley, CTO at Bridewell. </p><p>He describes how the UK’s energy system is becoming more distributed, with growing reliance on smaller peaker plants, renewable generators, battery storage and other remotely operated assets. </p><p>“Individually, these facilities may represent a small proportion of national capacity, but collectively they are becoming an essential part of how the grid operates,” says Riley.</p><p>“That creates a particular challenge because smaller operators and suppliers may fall outside the regulatory thresholds applied to traditional critical infrastructure, while still having connectivity into systems and services the country depends on.”</p><p>At the same time, James Neilson, SVP of global at OPSWAT, says it is “a lucky escape” that this attack happened at a small power plant and didn’t impact the UK’s wider energy system. </p><p>“<a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>Hostile actors</u></a> now routinely target the UK using cyber attacks, undermining security, the economy and public trust. This form of grey-zone warfare has been present for at least a decade, but sub-threshold activity has increased sharply in recent years.”</p><h2 id="resilience-measures">Resilience measures</h2><p>Following the power plant attack, the UK government and National Cyber Security Center have actively urged organizations running critical infrastructure and industrial facilities to audit internet-facing devices and enforce cyber hygiene. </p><p>“The guidance emphasizes immediately identifying and pulling exposed OT and PLCs off the public internet, eliminating default vendor passwords and enforcing <a href="https://www.itpro.com/technology/how-to-choose-the-best-mfa-methods"><u>multi-factor authentication</u></a> for remote management connections,” explains Mueller.</p><p>At this stage, the most important lesson is “understanding asset exposure, attack paths, and the operational consequences of unauthorized access to industrial control systems”, according to Mueller.</p><p><a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>Resilience</u></a> starts with “understanding how an attacker could move through the organization” and “ensuring a compromise in one part of the environment cannot easily reach systems responsible for physical operations”, says Riley. </p><p>For operational environments, that means strong IT and OT segmentation, tightly controlled remote access and “security controls proportionate to the potential consequences of an incident”, he advises.</p><p>Organizations also need visibility across IT and OT. “If security monitoring operates separately, an attacker may be able to establish themselves in the corporate environment before moving towards operational systems without anyone seeing the complete picture,” warns Riley.</p><p>Know what exposed interfaces you have and harden these by using technology and architecture, advises Ian Thornton-Trump, CISO at Inversion6. </p><p>At the same time, use firewalls with access control and whitelisting capabilities to “ensure any exposed interfaces can only be connected to by specific IP addresses”, he adds.</p><p>Meanwhile, Thornton-Trump advises deploying deception technology to detect the early stages of an attack, including honeypots, as well as taking advantage of the <a href="https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning?utm_source=Google&utm_medium=cpc&utm_campaign=NCSC+Always+On+Search+26&utm_content=EW&gad_source=1&gad_campaignid=24164180098&gbraid=0AAAAACafkIXIMz0NdMPIRtnIL5_4yCA2v&gclid=Cj0KCQjwteTUBhD4ARIsAEYjs3rKYgHyvnTCO_nwP-kaaKHA4eL9O7kDuYTVsEqS606SpC6YLLx_80UaArqYEALw_wcB"><u>NCSC’s early warning</u></a> service.</p><p>It’s also important to know the enemy you are facing. For example, Iranian and other nation-state groups will often hunt out default credentials immediately to achieve “rapid, low-noise access”, says Neilson. </p><p>With this in mind, he advises “assessing and hardening critical systems and infrastructure considering the latest attacks”.</p><p>Firms should train for incident response using tabletop exercises at all levels of operations and management, Thornton-Trump adds. “Have a plan that includes cyber-incident responders on retainer and cybersecurity contacts in other companies in your industry vertical – and identify reinforcements and additional resources if you need them. Prolonged downtime of any sort – cyber or otherwise – is avoidable, predictable, and recoverable.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/iran-power-plant-closure-is-a-warning-to-all-businesses-how-to-respond</link>
                                                                            <description>
                            <![CDATA[ After the first attack of its kind, how big is the risk, who does it impact, and how should firms react? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fa9Y6as2Cis8apnLttdDXF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Tue, 08 Sep 2026 10:07:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:description>                                                            <media:text><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:text>
                                <media:title type="plain"><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In August, it emerged that a small UK power plant was shut down for four days following a <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>cyber attack</u></a> attributed to <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat"><u>Iranian hackers</u></a>. It follows multiple <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn"><u>attacks on water facilities</u></a> in the US, which reports indicate are linked to the latest incident.</p><p>Not much is known about the UK power plant breach, with the government declining to reveal exactly where it took place. It has confirmed the incident involved a small-scale generator, and that the wider energy system was never at risk.</p><p>But a key technical detail is still withheld about whether control systems were directly affected, or if the plant was disconnected merely as a precaution while IT contained the infiltration.</p><p>After the first of its kind attack, the government has written to businesses with advice on the steps they should take to protect themselves. How big is the risk, who does it impact, and how should firms react?</p><h2 id="major-escalation">Major escalation </h2><p>The latest attack is “a major escalation” from the recent campaign targeting water facilities in the US, says Markus Mueller, field CISO at Nozomi Networks. </p><p>He says attacks on peaker plants like this – which are designed to provide power when needed – can be more dangerous because “things happen fast, there is no buffer, and there can be major impacts”.</p><p>Critical national infrastructure is also vulnerable because it often uses legacy technology never meant to be connected to the internet. In the latest incident, the attack path involved a <a href="https://www.itpro.com/security/cyber-attacks/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories"><u>programmable logic controller</u></a> (PLC) that was not secured following basic best practices. </p><p>“If current reporting is correct, this was a publicly exposed PLC that was impacted similarly to what we have seen at US water utilities, where the threat group scans the internet for exposed PLCs using AI-generated scripts,” Mueller tells <em>ITPro</em>.</p><p>The attacker then logs into the PLCs using default credentials and proceeds to take them offline by resetting the programming and changing the password and IP address, “making it inaccessible”, explains Mueller. </p><h2 id="a-risk-beyond-cni">A risk beyond CNI</h2><p>The risk goes beyond critical sectors, into the supply chain, other industries, and to firms that rely on the breached organization.</p><p>While this incident occurred at a power plant, this is also “a clear warning” for “non-utility commercial sectors”, says Mueller. </p><p>He points out that automated scanning scripts used by adversaries “do not differentiate between a power generator, a manufacturing plant, a logistics warehouse, or smart building management systems”. </p><p>Any business relying on connected physical systems or industrial controls is at risk. At the same time, <a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight"><u>supply chain</u></a> partners and third-party maintenance contractors with remote access into operational technology (OT) environments represent “a major attack vector that adversaries are actively targeting to move laterally into enterprise networks”, says Mueller.</p><p>The risk extends “well beyond” large, regulated energy operators, agrees Martin Riley, CTO at Bridewell. </p><p>He describes how the UK’s energy system is becoming more distributed, with growing reliance on smaller peaker plants, renewable generators, battery storage and other remotely operated assets. </p><p>“Individually, these facilities may represent a small proportion of national capacity, but collectively they are becoming an essential part of how the grid operates,” says Riley.</p><p>“That creates a particular challenge because smaller operators and suppliers may fall outside the regulatory thresholds applied to traditional critical infrastructure, while still having connectivity into systems and services the country depends on.”</p><p>At the same time, James Neilson, SVP of global at OPSWAT, says it is “a lucky escape” that this attack happened at a small power plant and didn’t impact the UK’s wider energy system. </p><p>“<a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>Hostile actors</u></a> now routinely target the UK using cyber attacks, undermining security, the economy and public trust. This form of grey-zone warfare has been present for at least a decade, but sub-threshold activity has increased sharply in recent years.”</p><h2 id="resilience-measures">Resilience measures</h2><p>Following the power plant attack, the UK government and National Cyber Security Center have actively urged organizations running critical infrastructure and industrial facilities to audit internet-facing devices and enforce cyber hygiene. </p><p>“The guidance emphasizes immediately identifying and pulling exposed OT and PLCs off the public internet, eliminating default vendor passwords and enforcing <a href="https://www.itpro.com/technology/how-to-choose-the-best-mfa-methods"><u>multi-factor authentication</u></a> for remote management connections,” explains Mueller.</p><p>At this stage, the most important lesson is “understanding asset exposure, attack paths, and the operational consequences of unauthorized access to industrial control systems”, according to Mueller.</p><p><a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>Resilience</u></a> starts with “understanding how an attacker could move through the organization” and “ensuring a compromise in one part of the environment cannot easily reach systems responsible for physical operations”, says Riley. </p><p>For operational environments, that means strong IT and OT segmentation, tightly controlled remote access and “security controls proportionate to the potential consequences of an incident”, he advises.</p><p>Organizations also need visibility across IT and OT. “If security monitoring operates separately, an attacker may be able to establish themselves in the corporate environment before moving towards operational systems without anyone seeing the complete picture,” warns Riley.</p><p>Know what exposed interfaces you have and harden these by using technology and architecture, advises Ian Thornton-Trump, CISO at Inversion6. </p><p>At the same time, use firewalls with access control and whitelisting capabilities to “ensure any exposed interfaces can only be connected to by specific IP addresses”, he adds.</p><p>Meanwhile, Thornton-Trump advises deploying deception technology to detect the early stages of an attack, including honeypots, as well as taking advantage of the <a href="https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning?utm_source=Google&utm_medium=cpc&utm_campaign=NCSC+Always+On+Search+26&utm_content=EW&gad_source=1&gad_campaignid=24164180098&gbraid=0AAAAACafkIXIMz0NdMPIRtnIL5_4yCA2v&gclid=Cj0KCQjwteTUBhD4ARIsAEYjs3rKYgHyvnTCO_nwP-kaaKHA4eL9O7kDuYTVsEqS606SpC6YLLx_80UaArqYEALw_wcB"><u>NCSC’s early warning</u></a> service.</p><p>It’s also important to know the enemy you are facing. For example, Iranian and other nation-state groups will often hunt out default credentials immediately to achieve “rapid, low-noise access”, says Neilson. </p><p>With this in mind, he advises “assessing and hardening critical systems and infrastructure considering the latest attacks”.</p><p>Firms should train for incident response using tabletop exercises at all levels of operations and management, Thornton-Trump adds. “Have a plan that includes cyber-incident responders on retainer and cybersecurity contacts in other companies in your industry vertical – and identify reinforcements and additional resources if you need them. Prolonged downtime of any sort – cyber or otherwise – is avoidable, predictable, and recoverable.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber criminals are adapting ASCII smuggling for mass phishing campaigns ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft has warned that ASCII smuggling, the use of invisible Unicode characters to trick AI models, is now being used by cyber criminals to supercharge phishing campaigns. </p><p>Over the past year, ASCII smuggling has become a recurring technique for <a href="https://www.itpro.com/security/ncsc-issues-urgent-warning-over-growing-ai-prompt-injection-risks-heres-what-you-need-to-know">prompt injection</a> and cross-prompt injection (XPIA), allowing an attacker to hide instructions inside invisible tag characters embedded in a web page, document, email, or other content.</p><p>While human beings - and many user interfaces - see nothing unusual, an AI assistant that ingests the raw text registers the hidden characters, decodes them as text, and can be induced to carry out unauthorized instructions, including data exposure.</p><p>The most abused range is the Unicode Tags block, U+E0000 to U+E007F, which contains a shadow copy of the printable ASCII characters. For example, U+E0041 mirrors ‘A’, U+E0061 mirrors ‘a’). The block was originally intended for language tagging and is now largely deprecated.</p><p><a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank"><u>According to Microsoft</u></a>, hits on a hunting signature designed to detect ASCII smuggling increased sharply on February 9, and stayed high on weekdays for the next three months. </p><p>This time, though, the technique appears to be in use as part of a broader <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign that was identified by Fortra this time last year. </p><p>"When we looked at a sampling of the flagged messages, the surprise was there were no smuggled instructions to an AI assistant. Instead, the invisible tag characters were inserted inside common financial keywords, splitting them apart so that a literal signature or keyword match would fail," the researchers said.</p><p>"For example, a finance lure term that appeared normal to the recipient could be transmitted with an invisible tag character in the middle: funding became 'fun⟨U+E0020⟩ding'.</p><p>To the recipient, and to parsing pipelines that drop or normalize these characters, the word still reads as 'funding'. Microsoft warned that unless a filtering system takes a picture of a message and does OCR extraction over the visual image, it may miss this type of attack. </p><h2 id="ascii-smuggling-campaign-hit-hundreds-of-domains">ASCII smuggling campaign hit hundreds of domains</h2><p>According to Microsoft, the campaign ran on hundreds of disposable, finance-themed sender domains with lures that resembled business loan, line-of-credit, and advance-funding phishing patterns often associated with fraud or credential-harvesting funnels. </p><p>This pattern accounted for roughly 96% of the volume flagged by the hunting signature. The emails in question were relayed through infrastructure associated with the legitimate email-marketing platform, ActiveCampaign.</p><p>"We appreciate Microsoft’s research and welcome collaboration with the security community to combat this activity. We take abuse, fraud, and security extremely seriously," said an ActiveCampaign spokesperson. </p><p>"We tested the specific technique described in this research against our content-moderation systems: messages containing invisible Unicode characters receive the same moderation verdicts as their unobfuscated equivalents, and heavy use of the technique is itself treated as a suspicious signal."</p><h2 id="how-to-protect-yourself-against-ascii-smuggling">How to protect yourself against ASCII smuggling</h2><p>To stay safe, Microsoft said organizations should strip or normalize Unicode tag characters (U+E0000-U+E007F) – and other zero-width / invisible code points – from email subject and body text before applying spam and phishing content signatures. </p><p>The presence of tag-block characters should be seen as a strong red flag: they're rare in ordinary mail and can be a high-value anomaly signal.</p><p>They should also look for the behavioral fingerprint: bulk volume from churning, finance-themed disposable domains, on a strict weekday-on/weekend-off schedule.</p><p>Elsewhere, businesses are advised to apply the same normalization upstream of AI ingestion: the same control that defeats this evasion also reduces XPIA / ASCII-smuggling exposure for AI assistants that ingest email content, Microsoft said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-crime/cyber-criminals-are-adapting-ascii-smuggling-for-mass-phishing-campaigns</link>
                                                                            <description>
                            <![CDATA[ Usually known for its use in prompt injection attacks, ASCII smuggling is now being used to evade spam filters on email platforms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HNXUSnXZNthhAuqNLv4NmM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 10:54:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has warned that ASCII smuggling, the use of invisible Unicode characters to trick AI models, is now being used by cyber criminals to supercharge phishing campaigns. </p><p>Over the past year, ASCII smuggling has become a recurring technique for <a href="https://www.itpro.com/security/ncsc-issues-urgent-warning-over-growing-ai-prompt-injection-risks-heres-what-you-need-to-know">prompt injection</a> and cross-prompt injection (XPIA), allowing an attacker to hide instructions inside invisible tag characters embedded in a web page, document, email, or other content.</p><p>While human beings - and many user interfaces - see nothing unusual, an AI assistant that ingests the raw text registers the hidden characters, decodes them as text, and can be induced to carry out unauthorized instructions, including data exposure.</p><p>The most abused range is the Unicode Tags block, U+E0000 to U+E007F, which contains a shadow copy of the printable ASCII characters. For example, U+E0041 mirrors ‘A’, U+E0061 mirrors ‘a’). The block was originally intended for language tagging and is now largely deprecated.</p><p><a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank"><u>According to Microsoft</u></a>, hits on a hunting signature designed to detect ASCII smuggling increased sharply on February 9, and stayed high on weekdays for the next three months. </p><p>This time, though, the technique appears to be in use as part of a broader <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign that was identified by Fortra this time last year. </p><p>"When we looked at a sampling of the flagged messages, the surprise was there were no smuggled instructions to an AI assistant. Instead, the invisible tag characters were inserted inside common financial keywords, splitting them apart so that a literal signature or keyword match would fail," the researchers said.</p><p>"For example, a finance lure term that appeared normal to the recipient could be transmitted with an invisible tag character in the middle: funding became 'fun⟨U+E0020⟩ding'.</p><p>To the recipient, and to parsing pipelines that drop or normalize these characters, the word still reads as 'funding'. Microsoft warned that unless a filtering system takes a picture of a message and does OCR extraction over the visual image, it may miss this type of attack. </p><h2 id="ascii-smuggling-campaign-hit-hundreds-of-domains">ASCII smuggling campaign hit hundreds of domains</h2><p>According to Microsoft, the campaign ran on hundreds of disposable, finance-themed sender domains with lures that resembled business loan, line-of-credit, and advance-funding phishing patterns often associated with fraud or credential-harvesting funnels. </p><p>This pattern accounted for roughly 96% of the volume flagged by the hunting signature. The emails in question were relayed through infrastructure associated with the legitimate email-marketing platform, ActiveCampaign.</p><p>"We appreciate Microsoft’s research and welcome collaboration with the security community to combat this activity. We take abuse, fraud, and security extremely seriously," said an ActiveCampaign spokesperson. </p><p>"We tested the specific technique described in this research against our content-moderation systems: messages containing invisible Unicode characters receive the same moderation verdicts as their unobfuscated equivalents, and heavy use of the technique is itself treated as a suspicious signal."</p><h2 id="how-to-protect-yourself-against-ascii-smuggling">How to protect yourself against ASCII smuggling</h2><p>To stay safe, Microsoft said organizations should strip or normalize Unicode tag characters (U+E0000-U+E007F) – and other zero-width / invisible code points – from email subject and body text before applying spam and phishing content signatures. </p><p>The presence of tag-block characters should be seen as a strong red flag: they're rare in ordinary mail and can be a high-value anomaly signal.</p><p>They should also look for the behavioral fingerprint: bulk volume from churning, finance-themed disposable domains, on a strict weekday-on/weekend-off schedule.</p><p>Elsewhere, businesses are advised to apply the same normalization upstream of AI ingestion: the same control that defeats this evasion also reduces XPIA / ASCII-smuggling exposure for AI assistants that ingest email content, Microsoft said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ G7 sounds alarm on quantum cyber threats ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The G7 Cybersecurity Working Group has issued a <a href="https://oos.cloudgouv-eu-west-1.outscale.com/sitesconformes-prd-osc-cgw1-s3-cybergouvfr/sf-cyber/documents/G7_preparing_for_the_qost_quantum_era_a_call_to_action.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=4KPMC6G57D6727LM7P5K%2F20260907%2Fcloudgouv-eu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20260907T080129Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Signature=d900d8fefb5e833c18f23c30fa64c9a368c5c3441f5586dddeef625a2762499b" target="_blank"><u>joint advisory</u></a> urging organizations to get moving on <a href="https://www.itpro.com/business/post-quantum-cryptography-is-now-top-of-mind-for-cybersecurity-leaders">post-quantum cryptography (PQC)</a>.</p><p>The advisory specifically highlights the risk that <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a> poses to public-key cryptography, stressing that it's a near-term threat that needs addressing across all sectors, not just critical infrastructure.</p><p>"Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms and threaten the security of digital infrastructures," it said.</p><p>The big threat from cryptographically relevant quantum computers (CRQCs) is that they will be able to carry out '<a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them">harvest now, decrypt later</a>' attacks. </p><p>This involves collecting and storing encrypted data protected by public-key cryptography that threat actors will be able to decrypt at a later date. </p><p>"Malicious cyber actors with access to CRQCs will also be able to target authentication mechanisms that help provide assurance and help protect the integrity of data between communicating parties and the integrity of devices," the advisory said. </p><p>"This capability could allow malicious cyber actors to impersonate trusted entities, compromise equipment, forge trusted data, or access confidential data, therefore undermining confidence in secure communications or contractual agreements."</p><h2 id="quantum-preparations">Quantum preparations</h2><p>Organizations should adopt a phased and risk-based strategy, prioritizing the most sensitive data and assets. This means carrying out an inventory of their cryptographic assets, mapping their dependencies, and developing a transition plan. </p><p>To keep costs down, they should acquire products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule - this, the advisory noted, could result in lower migration costs overall. </p><p>Worryingly, the report said the quantum threat remains off the radar for many organizations and as such is under-resourced, with other security concerns taking precedence.</p><p>"Yet a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk," the report warns. </p><p>Raising awareness of the stakes involved will be critical, according to the working group. National strategies aimed at transitioning to PQC should aim to attain an adequate supply of PQC hardware and software products, and encourage users to adopt them.</p><p>Research and development efforts also need to be ramped up, with more cooperation between government, industry, and academia, and the introduction of specific requirements within the framework of public procurement.</p><p>"Tackling the risks that the impending quantum computing era poses to current cryptographic systems, and ultimately organizations in which they are embedded, requires a coordinated global effort to transition to PQC," the report concluded. </p><p>"To strengthen collective resilience and safeguard confidential data, supply chains, and critical systems, public and private organizations must jointly act now. The transition to PQC is the key foundation to help build a secure and resilient digital future."</p><h2 id="still-a-long-way-to-go">Still a long way to go</h2><p>The advice from the working group might not resonate with enterprises, however. A <a href="https://www.itpro.com/security/post-quantum-encryption-enterprise-preparation-juniper-research"><u>study</u></a> by Juniper Research earlier this year found that only 27% of global businesses are set to be using PQC by 2030.</p><p>Those figures come despite recent predictions from Google that computers capable of breaking existing encryption could be here within just three years.</p><p>"The most important part of the G7’s message is the recognition that quantum can no longer be treated as a distant technology problem. Organizations are being told to start their PQC transition now, but transition and protection are not the same thing," said Simon Pamplin, CTO at Certes.</p><p>"The real challenge will be legacy infrastructure. Replacing cryptography embedded across decades of applications, supply chains and interconnected systems is not something organisations can achieve overnight. </p><p>"Security therefore needs to be abstracted away from individual applications and infrastructure and attached directly to the data, allowing the cryptography protecting it to change without repeatedly rebuilding the systems underneath."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/g7-sounds-alarm-on-quantum-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ The risk of 'harvest now, decrypt later' attacks is a leading concern for security agencies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WAybbV5PecR96nnaqek739</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GFpMfj9q29UoFDQyuwcQuh-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 09:19:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GFpMfj9q29UoFDQyuwcQuh-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[&#039;Q-Day&#039; quantum computing attack showing a data storage container with encryption key unlocked, placed on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[&#039;Q-Day&#039; quantum computing attack showing a data storage container with encryption key unlocked, placed on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[&#039;Q-Day&#039; quantum computing attack showing a data storage container with encryption key unlocked, placed on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GFpMfj9q29UoFDQyuwcQuh-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The G7 Cybersecurity Working Group has issued a <a href="https://oos.cloudgouv-eu-west-1.outscale.com/sitesconformes-prd-osc-cgw1-s3-cybergouvfr/sf-cyber/documents/G7_preparing_for_the_qost_quantum_era_a_call_to_action.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=4KPMC6G57D6727LM7P5K%2F20260907%2Fcloudgouv-eu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20260907T080129Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Signature=d900d8fefb5e833c18f23c30fa64c9a368c5c3441f5586dddeef625a2762499b" target="_blank"><u>joint advisory</u></a> urging organizations to get moving on <a href="https://www.itpro.com/business/post-quantum-cryptography-is-now-top-of-mind-for-cybersecurity-leaders">post-quantum cryptography (PQC)</a>.</p><p>The advisory specifically highlights the risk that <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a> poses to public-key cryptography, stressing that it's a near-term threat that needs addressing across all sectors, not just critical infrastructure.</p><p>"Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms and threaten the security of digital infrastructures," it said.</p><p>The big threat from cryptographically relevant quantum computers (CRQCs) is that they will be able to carry out '<a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them">harvest now, decrypt later</a>' attacks. </p><p>This involves collecting and storing encrypted data protected by public-key cryptography that threat actors will be able to decrypt at a later date. </p><p>"Malicious cyber actors with access to CRQCs will also be able to target authentication mechanisms that help provide assurance and help protect the integrity of data between communicating parties and the integrity of devices," the advisory said. </p><p>"This capability could allow malicious cyber actors to impersonate trusted entities, compromise equipment, forge trusted data, or access confidential data, therefore undermining confidence in secure communications or contractual agreements."</p><h2 id="quantum-preparations">Quantum preparations</h2><p>Organizations should adopt a phased and risk-based strategy, prioritizing the most sensitive data and assets. This means carrying out an inventory of their cryptographic assets, mapping their dependencies, and developing a transition plan. </p><p>To keep costs down, they should acquire products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule - this, the advisory noted, could result in lower migration costs overall. </p><p>Worryingly, the report said the quantum threat remains off the radar for many organizations and as such is under-resourced, with other security concerns taking precedence.</p><p>"Yet a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk," the report warns. </p><p>Raising awareness of the stakes involved will be critical, according to the working group. National strategies aimed at transitioning to PQC should aim to attain an adequate supply of PQC hardware and software products, and encourage users to adopt them.</p><p>Research and development efforts also need to be ramped up, with more cooperation between government, industry, and academia, and the introduction of specific requirements within the framework of public procurement.</p><p>"Tackling the risks that the impending quantum computing era poses to current cryptographic systems, and ultimately organizations in which they are embedded, requires a coordinated global effort to transition to PQC," the report concluded. </p><p>"To strengthen collective resilience and safeguard confidential data, supply chains, and critical systems, public and private organizations must jointly act now. The transition to PQC is the key foundation to help build a secure and resilient digital future."</p><h2 id="still-a-long-way-to-go">Still a long way to go</h2><p>The advice from the working group might not resonate with enterprises, however. A <a href="https://www.itpro.com/security/post-quantum-encryption-enterprise-preparation-juniper-research"><u>study</u></a> by Juniper Research earlier this year found that only 27% of global businesses are set to be using PQC by 2030.</p><p>Those figures come despite recent predictions from Google that computers capable of breaking existing encryption could be here within just three years.</p><p>"The most important part of the G7’s message is the recognition that quantum can no longer be treated as a distant technology problem. Organizations are being told to start their PQC transition now, but transition and protection are not the same thing," said Simon Pamplin, CTO at Certes.</p><p>"The real challenge will be legacy infrastructure. Replacing cryptography embedded across decades of applications, supply chains and interconnected systems is not something organisations can achieve overnight. </p><p>"Security therefore needs to be abstracted away from individual applications and infrastructure and attached directly to the data, allowing the cryptography protecting it to change without repeatedly rebuilding the systems underneath."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the MSSP model is broken, and how to fix it ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Can small Managed Security Service Providers (MSSPs) outcompete the world’s biggest Systems Integrators (SIs)? It might sound like a fool’s errand. But SIs have a glaring weakness: a generic, heavily standardized approach that fails to move in step with the rapidly evolving threat landscape. There’s an opportunity for smaller, more agile MSSPs, if they’re bold enough to take it.</p><p>Unfortunately, many are failing to take advantage. In fact, they’re making it harder for CISOs to differentiate their offerings by citing inaccurate metrics. These do nothing but confuse prospective customers. But for those MSSPs willing to go against the status quo, the market is there for the taking.</p><h2 id="why-bigger-doesn-t-mean-better-in-cybersecurity">Why bigger doesn’t mean better in cybersecurity</h2><p>The threat landscape stands still for no one. Over the past couple of years, we’ve witnessed an unprecedented weaponization of new technologies by threat actors. AI is being used in victim reconnaissance, social engineering, malware generation, and vulnerability research and exploit development. </p><p>According to <a href="https://www.verizon.com/business/resources/T1f0/reports/2026-dbir-data-breach-investigations-report.pdf"><u>Verizon</u></a>, the median threat actor researched or used AI assistance in 15 different documented techniques last year, with some using as many as 50. <a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-collapsing-exploit-window-ai-mtte-20260411-cs/"><u>Researchers are warning</u></a> that the exploitation window is collapsing as a result. <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"><u>Google’s most recent M-Trends report</u></a> puts mean-time-to-exploitation at less than seven days. </p><p>This means that SecOps teams live in a world of constant flux. One in which continuous improvements need to be made to the SOC — to swap in and out services and evaluate and reevaluate vendors in order to maintain a good security posture. Now think of a typical SI. They may have deep domain knowledge and plenty of smart people on the books. But their business model is scale, not agility. In fact, they tend to charge punitive fees for any change requests outside the original scope of work.</p><p>Rigid contracts and multiple management layers are a recipe for inertia. That’s bad news for CISO customers at a time when IT infrastructure and threat actor innovation are moving at pace. If you can’t afford to mitigate new risks around agentic AI data leakage or prompt injection, what do you do? Delay investment in the technology? Or accept increased risk? There are no good options.  </p><h2 id="missing-an-open-goal">Missing an open goal</h2><p>This business opportunity should be an open goal for MSSPs. But the truth is that many also adopt a cookie-cutter approach in order to efficiently service as wide a bank of customers as possible. This ultimately erodes the value of a potentially powerful differentiator.</p><p>They make things worse by resorting to disingenuous tricks to outcompete their rivals. They might claim to respond to alerts within 30 minutes, for example. But in reality, that metric is only applied to critical-severity alerts. Those deemed less urgent may take many more hours to respond to. That’s not only insincere. It could be a major security risk at a time when attackers go to deliberate lengths to hide in low-level activity. It’s critically important to spot and stop living-off-the-land techniques like these before they escalate.</p><p>There’s more. It’s also become accepted industry practice today for MSSPs to include automatically assigned and closed alerts when working out Mean Time to Acknowledge (MTTA) and Mean Time to Close (MTTC) — artificially shrinking these values. MSSPs may exclude alerts that weren’t handled within SLA parameters, like those at the weekend. And they may even reset the clock when an alert is escalated between tiers, to make it appear as if SLA targets were met.</p><p>This isn’t just bad practice. It means CISOs can no longer trust the sales pitch. That’s bad news for those who operate differently.</p><h2 id="honesty-and-agility">Honesty and agility</h2><p>Yet if they can get their message out, there is an opportunity for more dynamic MSSPs. They must be honest about SLAs, clearly define the terminology they use, and resist the urge to manipulate metrics. But just as importantly, they should offer services that move in step with the needs of their customers and the changing nature of the threat landscape, to outcompete their larger SI rivals.</p><p>It can be done. Think: red teaming for rogue behavior. Continuous risk reporting that maps findings to best-practice compliance standards. And AI posture management that integrates with SOC playbooks and exposure management dashboards to mitigate risk across the AI attack surface.</p><p>There are some fantastic solution providers out there offering cutting-edge capabilities—from real-time runtime detection to observability and model provenance checks. But no single vendor offers the whole package a SOC needs. That’s where the MSSP can add value. It’s about continuously evaluating what’s out there on the market, and integrating it into a seamless, 24/7 managed service offering. </p><h2 id="protection-for-today-and-tomorrow">Protection for today and tomorrow</h2><p>The MSSP space has never been more important for customers. The accelerating pace of industry regulation, infrastructure, and threat innovation is a testament to that. </p><p>For IT security leaders, the question to ask is not just whether your service provider is good enough right now. It’s whether they have a convincing vision of where security is heading in the future. </p><p>For many organizations, that’s not going to be an SI where only 80% of what they do might be “good enough.” In cyber, 80% is no longer good enough. CISOs need a more dynamic partner to protect their business: for today and tomorrow.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/why-the-mssp-model-is-broken-and-how-to-fix-it</link>
                                                                            <description>
                            <![CDATA[ CISOs are struggling to differentiate between MSSPs due to confusing metrics and SLAs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WMGQNfGDo8Dv973X4k2ap7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 21:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Martin Jakobsen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5WF2fD8fctFhUR7Zg5UeNm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Martin Jakobsen is the managing director of Cybanetix and brings over 20 years of experience delivering NOC and SOC services to a wide range of customers. &lt;/p&gt;&lt;p&gt;At Cybanetix, Martin has overseen the company’s growth into a trusted MDR specialist supporting clients across multiple sectors, including large-scale enterprises and public sector organizations. Martin remains focused on expanding Cybanetix’s capabilities and its use of advanced, AI-enabled security operations to deliver practical, intelligence-driven services. &lt;/p&gt;&lt;p&gt;Before Cybanetix, Martin served as managing director of Capita Cyber Security and holds board positions at KonsensIT A/S and CapMon A/S, contributing his expertise in governance and strategic growth.  &lt;/p&gt;&lt;p&gt;He has played a central role in the design and build of some of the UK’s largest government networks and has provided outsourced security operations to multinational enterprises. His combination of technical expertise and leadership has enabled organizations to strengthen their defences and run more resilient security operations. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:description>                                                            <media:text><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Can small Managed Security Service Providers (MSSPs) outcompete the world’s biggest Systems Integrators (SIs)? It might sound like a fool’s errand. But SIs have a glaring weakness: a generic, heavily standardized approach that fails to move in step with the rapidly evolving threat landscape. There’s an opportunity for smaller, more agile MSSPs, if they’re bold enough to take it.</p><p>Unfortunately, many are failing to take advantage. In fact, they’re making it harder for CISOs to differentiate their offerings by citing inaccurate metrics. These do nothing but confuse prospective customers. But for those MSSPs willing to go against the status quo, the market is there for the taking.</p><h2 id="why-bigger-doesn-t-mean-better-in-cybersecurity">Why bigger doesn’t mean better in cybersecurity</h2><p>The threat landscape stands still for no one. Over the past couple of years, we’ve witnessed an unprecedented weaponization of new technologies by threat actors. AI is being used in victim reconnaissance, social engineering, malware generation, and vulnerability research and exploit development. </p><p>According to <a href="https://www.verizon.com/business/resources/T1f0/reports/2026-dbir-data-breach-investigations-report.pdf"><u>Verizon</u></a>, the median threat actor researched or used AI assistance in 15 different documented techniques last year, with some using as many as 50. <a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-collapsing-exploit-window-ai-mtte-20260411-cs/"><u>Researchers are warning</u></a> that the exploitation window is collapsing as a result. <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"><u>Google’s most recent M-Trends report</u></a> puts mean-time-to-exploitation at less than seven days. </p><p>This means that SecOps teams live in a world of constant flux. One in which continuous improvements need to be made to the SOC — to swap in and out services and evaluate and reevaluate vendors in order to maintain a good security posture. Now think of a typical SI. They may have deep domain knowledge and plenty of smart people on the books. But their business model is scale, not agility. In fact, they tend to charge punitive fees for any change requests outside the original scope of work.</p><p>Rigid contracts and multiple management layers are a recipe for inertia. That’s bad news for CISO customers at a time when IT infrastructure and threat actor innovation are moving at pace. If you can’t afford to mitigate new risks around agentic AI data leakage or prompt injection, what do you do? Delay investment in the technology? Or accept increased risk? There are no good options.  </p><h2 id="missing-an-open-goal">Missing an open goal</h2><p>This business opportunity should be an open goal for MSSPs. But the truth is that many also adopt a cookie-cutter approach in order to efficiently service as wide a bank of customers as possible. This ultimately erodes the value of a potentially powerful differentiator.</p><p>They make things worse by resorting to disingenuous tricks to outcompete their rivals. They might claim to respond to alerts within 30 minutes, for example. But in reality, that metric is only applied to critical-severity alerts. Those deemed less urgent may take many more hours to respond to. That’s not only insincere. It could be a major security risk at a time when attackers go to deliberate lengths to hide in low-level activity. It’s critically important to spot and stop living-off-the-land techniques like these before they escalate.</p><p>There’s more. It’s also become accepted industry practice today for MSSPs to include automatically assigned and closed alerts when working out Mean Time to Acknowledge (MTTA) and Mean Time to Close (MTTC) — artificially shrinking these values. MSSPs may exclude alerts that weren’t handled within SLA parameters, like those at the weekend. And they may even reset the clock when an alert is escalated between tiers, to make it appear as if SLA targets were met.</p><p>This isn’t just bad practice. It means CISOs can no longer trust the sales pitch. That’s bad news for those who operate differently.</p><h2 id="honesty-and-agility">Honesty and agility</h2><p>Yet if they can get their message out, there is an opportunity for more dynamic MSSPs. They must be honest about SLAs, clearly define the terminology they use, and resist the urge to manipulate metrics. But just as importantly, they should offer services that move in step with the needs of their customers and the changing nature of the threat landscape, to outcompete their larger SI rivals.</p><p>It can be done. Think: red teaming for rogue behavior. Continuous risk reporting that maps findings to best-practice compliance standards. And AI posture management that integrates with SOC playbooks and exposure management dashboards to mitigate risk across the AI attack surface.</p><p>There are some fantastic solution providers out there offering cutting-edge capabilities—from real-time runtime detection to observability and model provenance checks. But no single vendor offers the whole package a SOC needs. That’s where the MSSP can add value. It’s about continuously evaluating what’s out there on the market, and integrating it into a seamless, 24/7 managed service offering. </p><h2 id="protection-for-today-and-tomorrow">Protection for today and tomorrow</h2><p>The MSSP space has never been more important for customers. The accelerating pace of industry regulation, infrastructure, and threat innovation is a testament to that. </p><p>For IT security leaders, the question to ask is not just whether your service provider is good enough right now. It’s whether they have a convincing vision of where security is heading in the future. </p><p>For many organizations, that’s not going to be an SI where only 80% of what they do might be “good enough.” In cyber, 80% is no longer good enough. CISOs need a more dynamic partner to protect their business: for today and tomorrow.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ DDoS attacks might be dwindling, but they’re intensifying ]]></title>
                                                                                                <dc:content><![CDATA[ <p>While the number of <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS) attacks</a> on European organizations is falling, attacks have become more targeted and intense. </p><p>Findings from Link11's <a href="https://www.link11.com/en/download/european-cyber-report-midyear-2026/" target="_blank"><u><em>European Cyber Report</em></u></a> for the first half of 2026 show that the number of attacks was down by 42%, but revealed new highs for attack intensity across bandwidth, packet rate, and cumulative data volume.</p><p>The highest measured bandwidth attack reached 2.3 Tbit/s – 85% higher than the previous peak of 1.2 Tbit/s in the first half of 2025.</p><p>The packet rate followed the same pattern, reaching a new peak of 322 million packets per second — up 56% from 207 million packets per second a year earlier. </p><p>Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period — a 61% increase.</p><p>“Attacks are shorter, but the total volume that we had to mitigate is higher than ever," said Karsten Desler, Link11 <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO</a>. "Attackers are steering their botnets with greater precision and control, generating more traffic in less time.”</p><h2 id="law-enforcement-takedowns-are-working">Law enforcement takedowns are working</h2><p>The drop in the number of attacks is down to sustained pressure from international law enforcement, including the takedown of pro-Russian group NoName057(16)'s infrastructure in July 2025. </p><p>Similarly, the takedown in March of the command-and-control servers of four major <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">IoT botnets</a> has played a key role. These controlled more than three million devices between them.</p><p>Despite positive gains by law enforcement, a rise in super-botnets such as Aisuru and its successor, Kimwolf, as well as a growing number of hijacked cloud servers, has increased the intensity of attacks. </p><p>Unlike a private IoT camera with just a few Mbit/s of upload bandwidth, a compromised server in a data center has a connection in the Gbit/s range - meaning that just a few thousand hacked cloud instances can easily eclipse the attack potential of an IoT botnet with millions of end devices.</p><p>“These numbers show that the threat isn't shrinking; it's shifting from breadth to peak intensity,” said Jens-Philipp Jung, CEO of Link11. “Organizations that size their defenses based on last year's attack count are underestimating how quickly a single incident can escalate today.”</p><h2 id="no-reprieve-for-victims">No reprieve for victims</h2><p>Notably, the report found that getting hit once makes it more likely that you'll get hit again: 56% fell victim to a second attack within 30 days of the first, compared with 46% a year earlier.</p><p>Link11 said the most dangerous attacks aren't always the most visible ones. In one case, attackers used a traffic spike against two domains as cover while quietly running SQL injection and cross-site scripting (XSS) probes behind it. </p><p>The attack was only spotted because the attackers used the same IP addresses for both.</p><p>"The most dangerous attacks we deal with are rarely the loudest ones anymore,” said Jag Bains, VP solution engineering, at Link11. “If you're only watching bandwidth and known signatures, you'll miss the attacks designed to do the most damage, because they're built to stay unnoticed.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/attackers-are-steering-their-botnets-with-greater-precision-and-control-ddos-attack-numbers-might-be-dwindling-but-theyre-intensifying</link>
                                                                            <description>
                            <![CDATA[ While law enforcement efforts have had their effect, the rise in super-botnets and hijacked cloud servers has increased the intensity of attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uhcoePthCZXTsAMeLrja3S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JNx6cDAorJmPFmr2saspoG-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 10:36:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JNx6cDAorJmPFmr2saspoG-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[DDoS attack concept image showing data terminals distributed in several different global locations, all interlinked with red glowing lights.]]></media:description>                                                            <media:text><![CDATA[DDoS attack concept image showing data terminals distributed in several different global locations, all interlinked with red glowing lights.]]></media:text>
                                <media:title type="plain"><![CDATA[DDoS attack concept image showing data terminals distributed in several different global locations, all interlinked with red glowing lights.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JNx6cDAorJmPFmr2saspoG-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While the number of <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS) attacks</a> on European organizations is falling, attacks have become more targeted and intense. </p><p>Findings from Link11's <a href="https://www.link11.com/en/download/european-cyber-report-midyear-2026/" target="_blank"><u><em>European Cyber Report</em></u></a> for the first half of 2026 show that the number of attacks was down by 42%, but revealed new highs for attack intensity across bandwidth, packet rate, and cumulative data volume.</p><p>The highest measured bandwidth attack reached 2.3 Tbit/s – 85% higher than the previous peak of 1.2 Tbit/s in the first half of 2025.</p><p>The packet rate followed the same pattern, reaching a new peak of 322 million packets per second — up 56% from 207 million packets per second a year earlier. </p><p>Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period — a 61% increase.</p><p>“Attacks are shorter, but the total volume that we had to mitigate is higher than ever," said Karsten Desler, Link11 <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO</a>. "Attackers are steering their botnets with greater precision and control, generating more traffic in less time.”</p><h2 id="law-enforcement-takedowns-are-working">Law enforcement takedowns are working</h2><p>The drop in the number of attacks is down to sustained pressure from international law enforcement, including the takedown of pro-Russian group NoName057(16)'s infrastructure in July 2025. </p><p>Similarly, the takedown in March of the command-and-control servers of four major <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">IoT botnets</a> has played a key role. These controlled more than three million devices between them.</p><p>Despite positive gains by law enforcement, a rise in super-botnets such as Aisuru and its successor, Kimwolf, as well as a growing number of hijacked cloud servers, has increased the intensity of attacks. </p><p>Unlike a private IoT camera with just a few Mbit/s of upload bandwidth, a compromised server in a data center has a connection in the Gbit/s range - meaning that just a few thousand hacked cloud instances can easily eclipse the attack potential of an IoT botnet with millions of end devices.</p><p>“These numbers show that the threat isn't shrinking; it's shifting from breadth to peak intensity,” said Jens-Philipp Jung, CEO of Link11. “Organizations that size their defenses based on last year's attack count are underestimating how quickly a single incident can escalate today.”</p><h2 id="no-reprieve-for-victims">No reprieve for victims</h2><p>Notably, the report found that getting hit once makes it more likely that you'll get hit again: 56% fell victim to a second attack within 30 days of the first, compared with 46% a year earlier.</p><p>Link11 said the most dangerous attacks aren't always the most visible ones. In one case, attackers used a traffic spike against two domains as cover while quietly running SQL injection and cross-site scripting (XSS) probes behind it. </p><p>The attack was only spotted because the attackers used the same IP addresses for both.</p><p>"The most dangerous attacks we deal with are rarely the loudest ones anymore,” said Jag Bains, VP solution engineering, at Link11. “If you're only watching bandwidth and known signatures, you'll miss the attacks designed to do the most damage, because they're built to stay unnoticed.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Yesterday’s triple AI outage should be a wake-up call for enterprises ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A simultaneous outage affecting OpenAI, Anthropic and xAI should act as a wake-up call for enterprises, analysts have told <em>ITPro</em>. </p><p>All three providers reported service disruption starting at about 6.30am Pacific Time on 3 September. While the outages were resolved within two-to-three, Charlie Dai, VP principal analyst at Forrester, said the incident puts the growing reliance of enterprises on <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> in the spotlight. </p><p>“The near-simultaneous disruptions highlight that AI is increasingly becoming operational infrastructure rather than a productivity add-on,” he told <em>ITPro</em>. </p><p>“Enterprises should treat AI availability as a resilience issue, implementing multi-model strategies, fallback workflows, and business continuity plans instead of assuming frontier AI services will always be available.”</p><p><a href="https://www.itpro.com/security/downtime-hits-hard-as-organizations-battle-hidden-costs">Downtime </a>of any kind can be highly damaging for businesses, impacting finances, consumer trust, and operational efficiency. With OpenAI and Anthropic ranking among the most popular AI providers on the market, any outage raises the stakes. </p><p>“Downtime can quickly translate into lost revenue, reduced employee productivity, delayed decisions, operational disruptions, SLA breaches, and customer dissatisfaction,” Dai said. </p><p>“As AI becomes embedded in customer service, software development, knowledge management, and business processes, even short interruptions can create cascading impacts across multiple teams and customer touchpoints.</p><h2 id="openai-anthropic-and-xai-outage-timeline">OpenAI, Anthropic, and xAI outage timeline</h2><p>OpenAI, Anthropic, and xAI first reported issues between 6.23 am and 7.45 am Pacific time yesterday. </p><p>Anthropic <a href="https://status.claude.com/" target="_blank"><u>confirmed </u></a>“elevated errors on requests” for Mythos 5.1, Claude Fable 5.1, and Claude Opus 5 at 6.23 am PT. </p><p>OpenAI, meanwhile, <a href="https://status.openai.com/incidents/01M1KWEDH417T2CF44YYHZDFCR" target="_blank"><u>reported </u></a>“elevated errors” across <a href="https://www.itpro.com/technology/artificial-intelligence/openai-just-revealed-what-people-really-use-chatgpt-for-and-70-percent-of-queries-have-nothing-to-do-with-work">ChatGPT </a>and <a href="https://www.itpro.com/technology/artificial-intelligence/openais-codex-app-is-now-available-on-macos-and-its-free-for-some-chatgpt-users-for-a-limited-time">Codex</a>. xAI also confirmed Grok was “experiencing issues”. </p><p>Based on respective status updates, all three providers resolved the issues within two-to-three hours: OpenAI marked the case as resolved at 9.15 am, while Anthropic and xAI reported fixes at 9.16 am and 10.05 am respectively.</p><h2 id="the-mystery-source">The mystery source</h2><p>With all three providers all experiencing outages in tandem, speculation over a common source was rife. Initial suggestions that a cloud or networking provider was behind the outages fell flat, however. </p><p>Neither Amazon Web Services (AWS), Microsoft Azure, nor Google Cloud reported downtime yesterday. Cloudflare, meanwhile, told <em>ITPro </em>that services were operating as expected at the time. </p><p>“Cloudflare is not experiencing any significant service disruptions at this time,” the company said. “Our services are operating normally, and any reporting that deviates from this is incorrect.”</p><p>In a <a href="https://x.com/SpaceXAI/status/2095597264043717014?s=20" target="_blank"><u>statement via X</u></a>, however, SpaceX revealed an outage at the company’s Memphis data center yesterday morning impacted Grok services. </p><p>“We are sorry for the issues you may have experienced with Grok following an outage at our Memphis compute center this morning,” the company said. </p><p>“We’d also like to apologize to our impacted compute partners. All systems have now been restored and are functioning nominally.”</p><p>As <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal"><u><em>ITPro </em></u><u>reported in May</u></a>, Anthropic signed a multi-billion dollar deal with SpaceX to rent out “<a href="https://www.anthropic.com/news/higher-limits-spacex" target="_blank"><u>all of the compute capacity</u></a>” at the company’s Colossus 1 data center. The company also relies on infrastructure provided by Amazon, Google, Broadcom, Microsoft.</p><p>Some users on X have <a href="https://x.com/mark_k/status/2095782755577610614?s=20" target="_blank"><u>pointed to a potential domino effect situation</u></a> unfolding in the wake of the SpaceX outage. With Grok and Claude down, users may have flocked to OpenAI as a backup. </p><p>A spokesperson for OpenAI told <a href="https://www.wired.com/story/nobody-is-saying-why-openai-and-anthropic-had-outages-today/" target="_blank"><u><em>Wired </em></u></a>that a “routing error” started at around 7.43 am PT. <em>ITPro </em>approached OpenAI for comment, but did not receive a response by time of publication.</p><p>Dai said that the lack of clarity from each of the providers should raise concerns for enterprises and reinforces the need for greater vendor transparency. </p><p>When multiple major providers experience overlapping failures without a clearly established common cause, enterprises cannot accurately assess systemic risk, dependency concentration, or recurrence likelihood,” he told <em>ITPro</em>. </p><p>“This reinforces the importance of vendor transparency, dependency mapping, and risk assessments that extend beyond individual AI providers to the underlying infrastructure ecosystem.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ai-is-increasingly-becoming-operational-infrastructure-rather-than-a-productivity-add-on-yesterdays-triple-ai-outage-should-be-a-wake-up-call-for-enterprises</link>
                                                                            <description>
                            <![CDATA[ Greater vendor transparency is needed in the wake of outages at OpenAI, Anthropic, and xAI ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VvAMFenFjr62ETLTm2pEc6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eyFHeH5jjDEbUmBZf8PrHJ-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 10:07:16 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Sep 2026 07:17:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eyFHeH5jjDEbUmBZf8PrHJ-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Smartphone screen with selection of AI apps pictured in a dedicated folder titled &#039;Artificial Intelligence&#039;, including ChatGPT, Claude, Grok, Gemini and DeepSeek app symbols.]]></media:description>                                                            <media:text><![CDATA[Smartphone screen with selection of AI apps pictured in a dedicated folder titled &#039;Artificial Intelligence&#039;, including ChatGPT, Claude, Grok, Gemini and DeepSeek app symbols.]]></media:text>
                                <media:title type="plain"><![CDATA[Smartphone screen with selection of AI apps pictured in a dedicated folder titled &#039;Artificial Intelligence&#039;, including ChatGPT, Claude, Grok, Gemini and DeepSeek app symbols.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eyFHeH5jjDEbUmBZf8PrHJ-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A simultaneous outage affecting OpenAI, Anthropic and xAI should act as a wake-up call for enterprises, analysts have told <em>ITPro</em>. </p><p>All three providers reported service disruption starting at about 6.30am Pacific Time on 3 September. While the outages were resolved within two-to-three, Charlie Dai, VP principal analyst at Forrester, said the incident puts the growing reliance of enterprises on <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> in the spotlight. </p><p>“The near-simultaneous disruptions highlight that AI is increasingly becoming operational infrastructure rather than a productivity add-on,” he told <em>ITPro</em>. </p><p>“Enterprises should treat AI availability as a resilience issue, implementing multi-model strategies, fallback workflows, and business continuity plans instead of assuming frontier AI services will always be available.”</p><p><a href="https://www.itpro.com/security/downtime-hits-hard-as-organizations-battle-hidden-costs">Downtime </a>of any kind can be highly damaging for businesses, impacting finances, consumer trust, and operational efficiency. With OpenAI and Anthropic ranking among the most popular AI providers on the market, any outage raises the stakes. </p><p>“Downtime can quickly translate into lost revenue, reduced employee productivity, delayed decisions, operational disruptions, SLA breaches, and customer dissatisfaction,” Dai said. </p><p>“As AI becomes embedded in customer service, software development, knowledge management, and business processes, even short interruptions can create cascading impacts across multiple teams and customer touchpoints.</p><h2 id="openai-anthropic-and-xai-outage-timeline">OpenAI, Anthropic, and xAI outage timeline</h2><p>OpenAI, Anthropic, and xAI first reported issues between 6.23 am and 7.45 am Pacific time yesterday. </p><p>Anthropic <a href="https://status.claude.com/" target="_blank"><u>confirmed </u></a>“elevated errors on requests” for Mythos 5.1, Claude Fable 5.1, and Claude Opus 5 at 6.23 am PT. </p><p>OpenAI, meanwhile, <a href="https://status.openai.com/incidents/01M1KWEDH417T2CF44YYHZDFCR" target="_blank"><u>reported </u></a>“elevated errors” across <a href="https://www.itpro.com/technology/artificial-intelligence/openai-just-revealed-what-people-really-use-chatgpt-for-and-70-percent-of-queries-have-nothing-to-do-with-work">ChatGPT </a>and <a href="https://www.itpro.com/technology/artificial-intelligence/openais-codex-app-is-now-available-on-macos-and-its-free-for-some-chatgpt-users-for-a-limited-time">Codex</a>. xAI also confirmed Grok was “experiencing issues”. </p><p>Based on respective status updates, all three providers resolved the issues within two-to-three hours: OpenAI marked the case as resolved at 9.15 am, while Anthropic and xAI reported fixes at 9.16 am and 10.05 am respectively.</p><h2 id="the-mystery-source">The mystery source</h2><p>With all three providers all experiencing outages in tandem, speculation over a common source was rife. Initial suggestions that a cloud or networking provider was behind the outages fell flat, however. </p><p>Neither Amazon Web Services (AWS), Microsoft Azure, nor Google Cloud reported downtime yesterday. Cloudflare, meanwhile, told <em>ITPro </em>that services were operating as expected at the time. </p><p>“Cloudflare is not experiencing any significant service disruptions at this time,” the company said. “Our services are operating normally, and any reporting that deviates from this is incorrect.”</p><p>In a <a href="https://x.com/SpaceXAI/status/2095597264043717014?s=20" target="_blank"><u>statement via X</u></a>, however, SpaceX revealed an outage at the company’s Memphis data center yesterday morning impacted Grok services. </p><p>“We are sorry for the issues you may have experienced with Grok following an outage at our Memphis compute center this morning,” the company said. </p><p>“We’d also like to apologize to our impacted compute partners. All systems have now been restored and are functioning nominally.”</p><p>As <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal"><u><em>ITPro </em></u><u>reported in May</u></a>, Anthropic signed a multi-billion dollar deal with SpaceX to rent out “<a href="https://www.anthropic.com/news/higher-limits-spacex" target="_blank"><u>all of the compute capacity</u></a>” at the company’s Colossus 1 data center. The company also relies on infrastructure provided by Amazon, Google, Broadcom, Microsoft.</p><p>Some users on X have <a href="https://x.com/mark_k/status/2095782755577610614?s=20" target="_blank"><u>pointed to a potential domino effect situation</u></a> unfolding in the wake of the SpaceX outage. With Grok and Claude down, users may have flocked to OpenAI as a backup. </p><p>A spokesperson for OpenAI told <a href="https://www.wired.com/story/nobody-is-saying-why-openai-and-anthropic-had-outages-today/" target="_blank"><u><em>Wired </em></u></a>that a “routing error” started at around 7.43 am PT. <em>ITPro </em>approached OpenAI for comment, but did not receive a response by time of publication.</p><p>Dai said that the lack of clarity from each of the providers should raise concerns for enterprises and reinforces the need for greater vendor transparency. </p><p>When multiple major providers experience overlapping failures without a clearly established common cause, enterprises cannot accurately assess systemic risk, dependency concentration, or recurrence likelihood,” he told <em>ITPro</em>. </p><p>“This reinforces the importance of vendor transparency, dependency mapping, and risk assessments that extend beyond individual AI providers to the underlying infrastructure ecosystem.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaseya announces new compliance and Apple device management tools for Datto RMM ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Kaseya has launched two major enhancements to its Datto RMM platform, in a move designed to help MSPs and IT teams strengthen their compliance capabilities and simplify management of Apple devices.</p><p>Unveiled during the vendor’s <em>Kaseya Connect Edge</em> event, the updates will introduce FIPS 140-3 validated cryptography and native <a href="https://www.itpro.com/business-operations/business-management/361508/apple-unveils-business-essentials-for-smbs">Apple mobile device management</a> (MDM) capabilities to the firm’s cloud-based remote monitoring and management platform from October.</p><p>With the FIPS 140-3 update, the company is aiming to help organizations meet evolving compliance requirements in regulated sectors, while the native Apple MDM will enable users to manage iOS, iPadOS, and <a href="https://www.itpro.com/technology/artificial-intelligence/openais-codex-app-is-now-available-on-macos-and-its-free-for-some-chatgpt-users-for-a-limited-time">macOS </a>devices alongside other endpoints from within Datto RMM.</p><p>"As regulatory requirements continue to evolve, MSPs and IT teams shouldn't have to choose between compliance and operational efficiency," said Kaseya chief technology officer Pratik Wadher in an announcement.</p><p>"At Kaseya, we're making it easier for organizations to pursue opportunities in highly regulated industries while continuing to leverage the automation, visibility and security capabilities they rely on every day.”</p><h2 id="fips-140-3-compliance">FIPS 140-3 compliance</h2><p>Starting in October, Datto RMM will add FIPS 140-3 validated cryptography at no additional cost to customers.</p><p>The capability uses a NIST-validated cryptographic module to secure the platform’s core communication channels and can be enabled through a single account-wide setting. Kaseya said its inclusion will enable organizations to adopt the new standard on their own timeline, with the feature switched off by default.</p><p>Existing <a href="https://www.itpro.com/technology/datto-rmm-a-security-first-solution">Datto RMM</a> capabilities – including patch management, automation, monitoring, and remote control – will remain available when the setting is enabled, with audit-ready logging built in to reduce audit and legal exposure.</p><p>The company added that the move aims to help partners pursue opportunities in regulated industries such as government, healthcare, finance, and defense, as organizations transition toward the FIPS 140-3 standard.</p><h2 id="native-apple-mdm">Native Apple MDM</h2><p>Datto RMM is also gaining native Apple MDM capabilities from early October, which will give MSPs and IT teams a centralized way to manage Apple devices without relying on a separate mobile device management platform.</p><p>According to Kaseya, the update will help reduce the cost, complexity, and visibility gaps involved with managing mobile devices through separate MDM tools.</p><p>Users will be able to enroll iOS, iPadOS, and macOS devices individually or in bulk via Apple Business Manager, configure security and compliance policies, deploy applications, and take remote actions directly within Datto RMM.</p><p>Apple devices will also appear alongside other managed endpoints across the platform’s existing dashboards, filters, and compliance reports, which Kaseya said will provide technicians with a more unified view of their customers’ environments.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-protection/kaseya-announces-new-compliance-and-apple-device-management-tools-for-datto-rmm</link>
                                                                            <description>
                            <![CDATA[ The enhancements will introduce FIPS 140-3 validated cryptography and native Apple MDM to the remote monitoring and management platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Lin7pGXoVrmevnfHF6JCbm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QDVrTGUP6HsSVNuiHY5oe6-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 08:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QDVrTGUP6HsSVNuiHY5oe6-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaseya company logo pictured on a smartphone screen with company branding blurred in background.]]></media:description>                                                            <media:text><![CDATA[Kaseya company logo pictured on a smartphone screen with company branding blurred in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Kaseya company logo pictured on a smartphone screen with company branding blurred in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QDVrTGUP6HsSVNuiHY5oe6-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaseya has launched two major enhancements to its Datto RMM platform, in a move designed to help MSPs and IT teams strengthen their compliance capabilities and simplify management of Apple devices.</p><p>Unveiled during the vendor’s <em>Kaseya Connect Edge</em> event, the updates will introduce FIPS 140-3 validated cryptography and native <a href="https://www.itpro.com/business-operations/business-management/361508/apple-unveils-business-essentials-for-smbs">Apple mobile device management</a> (MDM) capabilities to the firm’s cloud-based remote monitoring and management platform from October.</p><p>With the FIPS 140-3 update, the company is aiming to help organizations meet evolving compliance requirements in regulated sectors, while the native Apple MDM will enable users to manage iOS, iPadOS, and <a href="https://www.itpro.com/technology/artificial-intelligence/openais-codex-app-is-now-available-on-macos-and-its-free-for-some-chatgpt-users-for-a-limited-time">macOS </a>devices alongside other endpoints from within Datto RMM.</p><p>"As regulatory requirements continue to evolve, MSPs and IT teams shouldn't have to choose between compliance and operational efficiency," said Kaseya chief technology officer Pratik Wadher in an announcement.</p><p>"At Kaseya, we're making it easier for organizations to pursue opportunities in highly regulated industries while continuing to leverage the automation, visibility and security capabilities they rely on every day.”</p><h2 id="fips-140-3-compliance">FIPS 140-3 compliance</h2><p>Starting in October, Datto RMM will add FIPS 140-3 validated cryptography at no additional cost to customers.</p><p>The capability uses a NIST-validated cryptographic module to secure the platform’s core communication channels and can be enabled through a single account-wide setting. Kaseya said its inclusion will enable organizations to adopt the new standard on their own timeline, with the feature switched off by default.</p><p>Existing <a href="https://www.itpro.com/technology/datto-rmm-a-security-first-solution">Datto RMM</a> capabilities – including patch management, automation, monitoring, and remote control – will remain available when the setting is enabled, with audit-ready logging built in to reduce audit and legal exposure.</p><p>The company added that the move aims to help partners pursue opportunities in regulated industries such as government, healthcare, finance, and defense, as organizations transition toward the FIPS 140-3 standard.</p><h2 id="native-apple-mdm">Native Apple MDM</h2><p>Datto RMM is also gaining native Apple MDM capabilities from early October, which will give MSPs and IT teams a centralized way to manage Apple devices without relying on a separate mobile device management platform.</p><p>According to Kaseya, the update will help reduce the cost, complexity, and visibility gaps involved with managing mobile devices through separate MDM tools.</p><p>Users will be able to enroll iOS, iPadOS, and macOS devices individually or in bulk via Apple Business Manager, configure security and compliance policies, deploy applications, and take remote actions directly within Datto RMM.</p><p>Apple devices will also appear alongside other managed endpoints across the platform’s existing dashboards, filters, and compliance reports, which Kaseya said will provide technicians with a more unified view of their customers’ environments.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cheap Chinese AI models could spell trouble for US big tech ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The rising quality of <a href="https://www.itpro.com/technology/artificial-intelligence/should-businesses-consider-using-chinese-ai-models">cheaper Chinese AI models</a> could wreak havoc on the US tech industry, according to Juniper Research. </p><p><a href="https://www.juniperresearch.com/resources/free-research/beyond-the-headlines-what-the-ai-bubble-really-means/" target="_blank"><u>Analysis from the consultancy</u></a> suggests leading US tech giants could find themselves losing out to Chinese rivals offering alternatives in a bid to break the industry’s global dominance. </p><p>Juniper Research pointed to figures from OpenRouter, which show that just 30% of the work on that platform was through AI models offered by leading providers such as OpenAI, Google, or Anthropic. That marks a steep fall from 70% last year. </p><p>The report noted that Chinese models typically run 60% to 90% cheaper than rivals from Anthropic and OpenAI. The pricing challenge from China was first faced last year when <a href="https://www.itpro.com/technology/artificial-intelligence/chinese-ai-firm-deepseek-has-silicon-valley-flustered"><u>DeepSeek hit the market</u></a>, tanking tech stocks briefly by offering high-level performance at a much lower cost. </p><p>This year, Alibaba's <a href="https://www.itpro.com/technology/artificial-intelligence/three-open-source-large-language-models-you-can-use-today">Qwen models</a> had overtaken Meta's Llama as the most downloaded open model system, the report noted. </p><p>February marked the "real crossover into cheaper inference", Juniper added, with Chinese models processing 4.12 trillion tokens on OpenRouter vs 2.94 trillion for American models. </p><p>That's all down to lower prices for capable-enough open models, the consultancy noted.</p><p>“Open weight models are closing the capability gap with frontier models at a fraction of the cost," said Juniper Senior Analyst Jawad Jahan.</p><p>The trend is also being aided by more efficient designs, such as Mixture of Experts (MoE) models, which only use necessary parameters for a given query. </p><p>"This cuts compute-per-query without shrinking the model’s capability," the report noted. "DeepSeek is the cleanest example of this. Its V3 models carry 671 billion parameters in total, but only 37 billion of them fire for any given token. This led to a cut of V3.2’s price by more than half, as a result of lowering the cost of long-context inference."</p><h2 id="cutting-costs-with-chinese-ai-models">Cutting costs with Chinese AI models</h2><p>According to Juniper, DeepSeek's V4 Flash cost $0.14 per million input tokens against $5.00 for <a href="https://www.itpro.com/security/openai-expands-daybreak-cyber-program-new-tools-partnerships-and-a-cyber-focused-gpt-5-5-aim-to-help-patch-the-world">OpenAI’s GPT-5.5</a>, while Claude Opus 4.8 was at the time charging about $5 for input and $25 for output per million tokens. </p><p>"This pricing gap has existed ever since the release of the first Chinese open-sourced model that was able to rival frontier organizations in the West," the report noted. </p><p>Shifting demand has altered the picture, however, with programming rising from 11% to more than half of OpenRouter's token volume. Agentic workloads also account for the majority of output, Juniper said. </p><p>"Given the large call frequency for agentic workloads, per-token pricing starts to become a real budget consideration and constraint," the report noted.</p><h2 id="funding-the-ai-roll-out">Funding the AI roll-out</h2><p>That raises a problem, one that Juniper refers to as an "existential risk": can we afford all the borrowed billions being spent on data centers via "complex financing agreements" if customers stop paying for the very best models and instead choose cheaper Chinese options? </p><p>The firm argued that if the price of running AI falls too low, companies will lose the ability to make revenue from it to pay for all this investment. </p><p>That concern isn't new, either. Investors have been <a href="https://www.itpro.com/business/business-strategy/google-clouds-record-results-cant-quiet-concerns-on-ai-spending-and-model-release-timelines"><u>questioning the massive spending on data centers</u></a>, with Juniper noting that the four major hyperscalers are expected to spend $725 billion on capital expenditure this year, up by 77% compared to the year prior.</p><p>Beyond the raw figures, Juniper pointed to the convoluted ways American companies are gathering the funds to pay for such projects, largely spurred by the AI infrastructure spending outpacing available cashflow and revenue. </p><p>The firm noted that this year the top five hyperscalers will spend more than a trillion dollars on infrastructure for AI. </p><p>"This figure exceeds their combined earnings and free cashflow," the report said. </p><p>Juniper claimed this has driven a rise in "off balance sheet financing" — in which companies don't borrow directly but build standalone legal entities to carry debt, later leasing the infrastructure back to the hyperscaler.</p><p>Circular financing is also a concern, which Juniper defines as a supplier investing in a company with the understanding the recipient will spend those funds buying the supplier's products. </p><p>The consultancy pointed to OpenAI's deals with Oracle and Nvidia as prime examples.</p><h2 id="chinese-challenge-to-funding-structures">Chinese challenge to funding structures</h2><p>If revenue from AI starts to shift to China, these spending levels and funding structures could prove problematic, the analyst firm noted. </p><p>"If this trend continues, the inference revenue underwriting the Western datacentre build-out weakens, and, correspondingly, the financing structures resting on that revenue,” Jahan commented.</p><p>That's exacerbated by the fact Chinese companies don't face the same issues, with funding either so far provided by external financial businesses, particularly in the case of DeepSeek. </p><p>Similarly, they aren’t beholden to a business model that sees cloud providers like Alibaba and Baidu effectively give the model away, then sell the compute to make use of it. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/open-weight-models-are-closing-the-capability-gap-with-frontier-models-at-a-fraction-of-the-cost-cheap-chinese-ai-models-could-spell-trouble-for-us-big-tech</link>
                                                                            <description>
                            <![CDATA[ Powerful new open weight models from Chinese providers could undercut AI revenues and unbalance funding models for big tech's infrastructure rollout ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">94ag4G4VKN5objAr8n2hnk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/B2K9HhHgVDEXtjMsMYMowg-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 15:20:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/B2K9HhHgVDEXtjMsMYMowg-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The flag of the People&#039;s Republic of China (PRC) and United States pictured side-by-side.]]></media:description>                                                            <media:text><![CDATA[The flag of the People&#039;s Republic of China (PRC) and United States pictured side-by-side.]]></media:text>
                                <media:title type="plain"><![CDATA[The flag of the People&#039;s Republic of China (PRC) and United States pictured side-by-side.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/B2K9HhHgVDEXtjMsMYMowg-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The rising quality of <a href="https://www.itpro.com/technology/artificial-intelligence/should-businesses-consider-using-chinese-ai-models">cheaper Chinese AI models</a> could wreak havoc on the US tech industry, according to Juniper Research. </p><p><a href="https://www.juniperresearch.com/resources/free-research/beyond-the-headlines-what-the-ai-bubble-really-means/" target="_blank"><u>Analysis from the consultancy</u></a> suggests leading US tech giants could find themselves losing out to Chinese rivals offering alternatives in a bid to break the industry’s global dominance. </p><p>Juniper Research pointed to figures from OpenRouter, which show that just 30% of the work on that platform was through AI models offered by leading providers such as OpenAI, Google, or Anthropic. That marks a steep fall from 70% last year. </p><p>The report noted that Chinese models typically run 60% to 90% cheaper than rivals from Anthropic and OpenAI. The pricing challenge from China was first faced last year when <a href="https://www.itpro.com/technology/artificial-intelligence/chinese-ai-firm-deepseek-has-silicon-valley-flustered"><u>DeepSeek hit the market</u></a>, tanking tech stocks briefly by offering high-level performance at a much lower cost. </p><p>This year, Alibaba's <a href="https://www.itpro.com/technology/artificial-intelligence/three-open-source-large-language-models-you-can-use-today">Qwen models</a> had overtaken Meta's Llama as the most downloaded open model system, the report noted. </p><p>February marked the "real crossover into cheaper inference", Juniper added, with Chinese models processing 4.12 trillion tokens on OpenRouter vs 2.94 trillion for American models. </p><p>That's all down to lower prices for capable-enough open models, the consultancy noted.</p><p>“Open weight models are closing the capability gap with frontier models at a fraction of the cost," said Juniper Senior Analyst Jawad Jahan.</p><p>The trend is also being aided by more efficient designs, such as Mixture of Experts (MoE) models, which only use necessary parameters for a given query. </p><p>"This cuts compute-per-query without shrinking the model’s capability," the report noted. "DeepSeek is the cleanest example of this. Its V3 models carry 671 billion parameters in total, but only 37 billion of them fire for any given token. This led to a cut of V3.2’s price by more than half, as a result of lowering the cost of long-context inference."</p><h2 id="cutting-costs-with-chinese-ai-models">Cutting costs with Chinese AI models</h2><p>According to Juniper, DeepSeek's V4 Flash cost $0.14 per million input tokens against $5.00 for <a href="https://www.itpro.com/security/openai-expands-daybreak-cyber-program-new-tools-partnerships-and-a-cyber-focused-gpt-5-5-aim-to-help-patch-the-world">OpenAI’s GPT-5.5</a>, while Claude Opus 4.8 was at the time charging about $5 for input and $25 for output per million tokens. </p><p>"This pricing gap has existed ever since the release of the first Chinese open-sourced model that was able to rival frontier organizations in the West," the report noted. </p><p>Shifting demand has altered the picture, however, with programming rising from 11% to more than half of OpenRouter's token volume. Agentic workloads also account for the majority of output, Juniper said. </p><p>"Given the large call frequency for agentic workloads, per-token pricing starts to become a real budget consideration and constraint," the report noted.</p><h2 id="funding-the-ai-roll-out">Funding the AI roll-out</h2><p>That raises a problem, one that Juniper refers to as an "existential risk": can we afford all the borrowed billions being spent on data centers via "complex financing agreements" if customers stop paying for the very best models and instead choose cheaper Chinese options? </p><p>The firm argued that if the price of running AI falls too low, companies will lose the ability to make revenue from it to pay for all this investment. </p><p>That concern isn't new, either. Investors have been <a href="https://www.itpro.com/business/business-strategy/google-clouds-record-results-cant-quiet-concerns-on-ai-spending-and-model-release-timelines"><u>questioning the massive spending on data centers</u></a>, with Juniper noting that the four major hyperscalers are expected to spend $725 billion on capital expenditure this year, up by 77% compared to the year prior.</p><p>Beyond the raw figures, Juniper pointed to the convoluted ways American companies are gathering the funds to pay for such projects, largely spurred by the AI infrastructure spending outpacing available cashflow and revenue. </p><p>The firm noted that this year the top five hyperscalers will spend more than a trillion dollars on infrastructure for AI. </p><p>"This figure exceeds their combined earnings and free cashflow," the report said. </p><p>Juniper claimed this has driven a rise in "off balance sheet financing" — in which companies don't borrow directly but build standalone legal entities to carry debt, later leasing the infrastructure back to the hyperscaler.</p><p>Circular financing is also a concern, which Juniper defines as a supplier investing in a company with the understanding the recipient will spend those funds buying the supplier's products. </p><p>The consultancy pointed to OpenAI's deals with Oracle and Nvidia as prime examples.</p><h2 id="chinese-challenge-to-funding-structures">Chinese challenge to funding structures</h2><p>If revenue from AI starts to shift to China, these spending levels and funding structures could prove problematic, the analyst firm noted. </p><p>"If this trend continues, the inference revenue underwriting the Western datacentre build-out weakens, and, correspondingly, the financing structures resting on that revenue,” Jahan commented.</p><p>That's exacerbated by the fact Chinese companies don't face the same issues, with funding either so far provided by external financial businesses, particularly in the case of DeepSeek. </p><p>Similarly, they aren’t beholden to a business model that sees cloud providers like Alibaba and Baidu effectively give the model away, then sell the compute to make use of it. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber insurance ‘should not be treated as a get-out-of-jail-free card’  ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Just one in five UK business leaders believe their <a href="https://www.itpro.com/security/cyber-security/368458/what-is-cyber-insurance"><u>cyber insurance</u></a> will provide adequate protection in the event of a breach, according to new research from Cohesity. </p><p>In a survey conducted by the firm, only 22% of respondents believe cyber insurance policies will cover the costs and revenue losses associated with a cyber attack.</p><p>Cohesity said the survey highlights growing anxiety among business leaders given the heightened threats enterprises face. Concerns over losses in the wake of an attack are also growing, the survey noted. </p><p>CEOs estimate that a cyber attack could cut their organization’s revenue by 15.17% on average. </p><p>These figures are a ballpark estimate, however. One in five reveal that their business has “never undertaken business impact modelling to understand the potential cost of an attack”. </p><p>Without modelling, Cohesity warned that enterprises might never know the true scale of their potential insurance shortfalls, and this could come back to bite them. </p><p>Fraser Hutchison, VP UKI at Cohesity, said the study shows cyber insurance “should not be treated as a get-out-of-jail-free card”. </p><p>“As the threat landscape becomes increasingly complex, organizations cannot treat an insurance policy as a substitute for resilience,” he said. </p><p>“Organizations need to understand exactly what their policies will and will not cover, model the potential impact of different attack scenarios and prepare for losses that may fall outside their policies.”</p><h2 id="cyber-insurance-in-the-spotlight">Cyber insurance in the spotlight</h2><p><a href="https://www.itpro.com/security/why-your-business-needs-cyber-insurance"><u>Cyber insurance is now viewed as a critical fallback for enterprises </u></a>due to rising global security threats, yet research from the UK government’s <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025"><u>Cyber Security Breaches</u></a> survey found half of firms across the country have no policy at all. </p><p>Awareness is rising, however. <a href="https://www.itpro.com/security/cyber-attacks/cyber-insurance-payouts-are-skyrocketing"><u>Analysis from the Association of British Insurers (ABI)</u></a> in November last year showed 17% more policies were taken out across 2025 than in the year prior. </p><p>Speaking at the time, Jonathan Fong, head of general insurance policy at the ABI, said cyber insurance is “more than just a financial safety net” and now forms a key component of broader resilience strategies. </p><p>“The right policy not only supports businesses in the aftermath of an incident, but can also help prevent attacks through access to expert advice, threat monitoring, and incident response planning,” he said. </p><p>That study from ABI found cyber insurance payouts skyrocketed in 2025, with £197 million paid out across the year. </p><p>ABI pointed to Marks & Spencer (M&S), which <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack"><u>recovered £100 million from insurers</u></a> after a devastating attack disrupted operations in April 2025. </p><h2 id="knowing-your-policy">Knowing your policy</h2><p>Cohesity urged UK business leaders to improve their understanding of cyber insurance policies, including what they’re entitled to in the event of a cyber attack. </p><p>First and foremost, firms need to understand their full financial exposure, modeling the “direct and indirect consequences of different attack scenarios”. </p><p>This includes potential revenue losses, downtime, remediation costs, customer attrition, reputational damage, and lost productivity. All these metrics are crucial when measuring the broader impact of an attack. </p><p>Similarly, understanding what insurers <em>will and will not</em> cover is vital. According to Cohesity, business leaders “need clarity” on areas such as policy limits, exclusions, and conditions, as well as the losses the organization itself needs to absorb. </p><h2 id="focus-on-resilience">Focus on resilience</h2><p>According to Hutchison, the best approach for enterprises is to bolster cyber resilience capabilities to avoid any difficult conversations in the event of an attack. </p><p>“Cyber insurance can mitigate some of the financial risk, but the only way to truly bounce back from a cyber attack is by embedding genuine resilience into operations,” he said. </p><p>Hutchison added that enterprises need to identify systems and data that are critical to keeping the lights on in the event of a breach. </p><p>Elsewhere, assigning “clear responsibility” for recovery decisions is vital, as is regular testing to establish whether critical services can be restored in a timely fashion. </p><p>Improving cyber resilience also has a tangible impact on the cost of cyber insurance, research shows. </p><p>As <a href="https://www.itpro.com/security/want-cheaper-cyber-insurance-security-leaders-say-improving-resilience-has-helped-them-save-on-coverage"><em>ITPro </em>previously reported</a>, research from Sophos found enterprises that improved security capabilities were able to push down cyber insurance coverage rates. </p><p>A whopping 97% of respondents told the security firm that they had invested in cyber resilience with the explicit goal of improving insurance rates. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/security-experts-warn-cyber-insurance-should-not-be-treated-as-a-get-out-of-jail-free-card</link>
                                                                            <description>
                            <![CDATA[ Cyber insurance might alleviate financial losses after an attack, but building resilience is still the best defense ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZTZuVQnT4G3yN5vEF9hwhF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L2yET6pYuZAKmcRAwtxBWV-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:18:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L2yET6pYuZAKmcRAwtxBWV-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber Insurance concept image showing stacked dollar bills placed upon a cliff edge.]]></media:description>                                                            <media:text><![CDATA[Cyber Insurance concept image showing stacked dollar bills placed upon a cliff edge.]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber Insurance concept image showing stacked dollar bills placed upon a cliff edge.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L2yET6pYuZAKmcRAwtxBWV-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Just one in five UK business leaders believe their <a href="https://www.itpro.com/security/cyber-security/368458/what-is-cyber-insurance"><u>cyber insurance</u></a> will provide adequate protection in the event of a breach, according to new research from Cohesity. </p><p>In a survey conducted by the firm, only 22% of respondents believe cyber insurance policies will cover the costs and revenue losses associated with a cyber attack.</p><p>Cohesity said the survey highlights growing anxiety among business leaders given the heightened threats enterprises face. Concerns over losses in the wake of an attack are also growing, the survey noted. </p><p>CEOs estimate that a cyber attack could cut their organization’s revenue by 15.17% on average. </p><p>These figures are a ballpark estimate, however. One in five reveal that their business has “never undertaken business impact modelling to understand the potential cost of an attack”. </p><p>Without modelling, Cohesity warned that enterprises might never know the true scale of their potential insurance shortfalls, and this could come back to bite them. </p><p>Fraser Hutchison, VP UKI at Cohesity, said the study shows cyber insurance “should not be treated as a get-out-of-jail-free card”. </p><p>“As the threat landscape becomes increasingly complex, organizations cannot treat an insurance policy as a substitute for resilience,” he said. </p><p>“Organizations need to understand exactly what their policies will and will not cover, model the potential impact of different attack scenarios and prepare for losses that may fall outside their policies.”</p><h2 id="cyber-insurance-in-the-spotlight">Cyber insurance in the spotlight</h2><p><a href="https://www.itpro.com/security/why-your-business-needs-cyber-insurance"><u>Cyber insurance is now viewed as a critical fallback for enterprises </u></a>due to rising global security threats, yet research from the UK government’s <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025"><u>Cyber Security Breaches</u></a> survey found half of firms across the country have no policy at all. </p><p>Awareness is rising, however. <a href="https://www.itpro.com/security/cyber-attacks/cyber-insurance-payouts-are-skyrocketing"><u>Analysis from the Association of British Insurers (ABI)</u></a> in November last year showed 17% more policies were taken out across 2025 than in the year prior. </p><p>Speaking at the time, Jonathan Fong, head of general insurance policy at the ABI, said cyber insurance is “more than just a financial safety net” and now forms a key component of broader resilience strategies. </p><p>“The right policy not only supports businesses in the aftermath of an incident, but can also help prevent attacks through access to expert advice, threat monitoring, and incident response planning,” he said. </p><p>That study from ABI found cyber insurance payouts skyrocketed in 2025, with £197 million paid out across the year. </p><p>ABI pointed to Marks & Spencer (M&S), which <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack"><u>recovered £100 million from insurers</u></a> after a devastating attack disrupted operations in April 2025. </p><h2 id="knowing-your-policy">Knowing your policy</h2><p>Cohesity urged UK business leaders to improve their understanding of cyber insurance policies, including what they’re entitled to in the event of a cyber attack. </p><p>First and foremost, firms need to understand their full financial exposure, modeling the “direct and indirect consequences of different attack scenarios”. </p><p>This includes potential revenue losses, downtime, remediation costs, customer attrition, reputational damage, and lost productivity. All these metrics are crucial when measuring the broader impact of an attack. </p><p>Similarly, understanding what insurers <em>will and will not</em> cover is vital. According to Cohesity, business leaders “need clarity” on areas such as policy limits, exclusions, and conditions, as well as the losses the organization itself needs to absorb. </p><h2 id="focus-on-resilience">Focus on resilience</h2><p>According to Hutchison, the best approach for enterprises is to bolster cyber resilience capabilities to avoid any difficult conversations in the event of an attack. </p><p>“Cyber insurance can mitigate some of the financial risk, but the only way to truly bounce back from a cyber attack is by embedding genuine resilience into operations,” he said. </p><p>Hutchison added that enterprises need to identify systems and data that are critical to keeping the lights on in the event of a breach. </p><p>Elsewhere, assigning “clear responsibility” for recovery decisions is vital, as is regular testing to establish whether critical services can be restored in a timely fashion. </p><p>Improving cyber resilience also has a tangible impact on the cost of cyber insurance, research shows. </p><p>As <a href="https://www.itpro.com/security/want-cheaper-cyber-insurance-security-leaders-say-improving-resilience-has-helped-them-save-on-coverage"><em>ITPro </em>previously reported</a>, research from Sophos found enterprises that improved security capabilities were able to push down cyber insurance coverage rates. </p><p>A whopping 97% of respondents told the security firm that they had invested in cyber resilience with the explicit goal of improving insurance rates. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Popular’ AI use cases aren’t those delivering results. Gartner says focus on the basics for success and easy wins ]]></title>
                                                                                                <dc:content><![CDATA[ <p>IT leaders need to get back to basics and prioritize AI integration in areas where it can deliver real impact, according to Gartner, and that requires a more considered approach to adoption. </p><p>Tina Nunno, distinguished vice president and Gartner fellow, told <em>ITPro </em>that many IT leaders are still falling into a trap of following hype when it comes to <a href="https://www.itpro.com/technology/artificial-intelligence">AI</a>, and it’s hampering success. </p><p>“We’re human beings, and we follow hype,” she said. “We're curious about what we last saw published, or in a keynote, or we're curious about what the vendors are talking about.”</p><p>“But we still have to have, I think, a reasonable balance and need to think about what’s the business case? Some of the basics still really matter here.”</p><p>Nunno’s comments come after a Gartner survey found the most <a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-real-world-stories-of-the-sectors-ai-is-changing">popular AI use cases</a> are rarely the ones that deliver real business impact and value. </p><p>The survey of C-suite executives warned that adoption projects are being influenced by “heavily hyped” applications of the technology over those that actually generate value.</p><p>“We calculated what the most common use cases were, and then we compared them to the ones where they were getting the most reliable rates of return, and they didn't match,” Nunno told <em>ITPro</em>. “There wasn't even a lot of overlap.”</p><h2 id="choosing-the-popular-ai-use-cases-doesn-t-always-work">Choosing the ‘popular’ AI use cases doesn’t always work</h2><p>Gartner’s survey found that the three most popular AI use cases included <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>threat detection and response, identified by 54% of respondents, alongside IT service desk automation (54%), and <a href="https://www.itpro.com/software/development/ai-generated-code-software-developer-security-risk">automated code generation</a> and refactoring (44%). </p><p>Yet only the latter of these use cases ranked among the use cases that delivered positive operational or financial returns. </p><p>Intelligent IT asset and cost optimization (40%), <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-synthetic-data">synthetic data generation</a> (28%) and automated code generation and refactoring (23%) all ranked as the most successful use cases. </p><p>While hype is a key factor behind this disparity, Nunno told <em>ITPro </em>that it shows some ‘high performers’ are taking a more surgical approach to integrating the technology. </p><p>These businesses are focusing on overhauling or streamlining specific processes in a highly strategic manner, rather than taking a slap-dash approach and seeing what works. </p><p>“When we look at what’s most common, sometimes they’re more foundational AI implementations,” she explained. They’re not specific to the business unit. They’re not specific to the specific function that they’re attempting to perform.”</p><p>Nunno added that approaching adoption with a degree of generality rarely delivers tangible returns. It’s why having a clear-cut goal from the get-go is critical. </p><p>“There was a bit more specific nature in those that actually were showing returns,” she said. “They appeared to be more targeted, and as a result, because they were more targeted, they seem much more likely to deliver”. </p><p>Gartner’s findings align closely with recent <a href="https://www.itpro.com/business/business-strategy/flexibility-is-a-huge-advantage-for-small-businesses-adopting-ai-but-clear-strategy-and-bold-leadership-is-critical">research from Dell Technologies</a>, which also highlighted the importance of clear goals when it comes to AI adoption. </p><p>More than half (52%) of AI ‘front runners’ – those Dell identified as having the most success with the technology - had “clearly defined specific AI use cases”.</p><h2 id="be-prepared">Be prepared</h2><p>A lack of clear objectives and strategies is having a direct impact on scaling of AI across the enterprise, Gartner found. Indeed, just 22% of respondents said they’ve successfully scaled the technology across multiple business units. </p><p>Nunno told <em>ITPro </em>that this reinforces the importance of laying solid foundations before even embarking on projects. <a href="https://www.itpro.com/business/business-strategy/a-striking-finding-this-year-is-the-gap-between-individual-gains-and-enterprise-impact-mckinsey-says-ai-is-finally-paying-off-for-enterprises-but-rising-costs-and-constrained-efficiency-boosts-are-still-a-major-hurdle">Building maturity is critical</a>. </p><p>“For some organizations, we've seen there's a very strong correlation between the maturity of the organization and their ability to take advantage of AI,” she said. </p><p>“They haven't yet grown the AI skill sets that they need to bring the AI to scale, and that can be anything from the current state of their data, for example.”</p><p>Nunno admitted that this is often easier said than done. Basic foundational tasks like getting data in good shape and order are “a lot of work”. </p><p>“There’s still a very real investment that many of our clients are telling us they’re putting in to build those foundations to actually scale AI in the way that they would like,” she said. </p><p>“There’s a lot of heavy lifting that sometimes has to happen.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/popular-ai-use-cases-arent-those-delivering-results-gartner-says-focus-on-the-basics-for-success-and-easy-wins</link>
                                                                            <description>
                            <![CDATA[ Focusing on hype-driven AI use cases rarely delivers, so it’s important to start with the basics and build  from there ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SPBUe3TQ7BBzC57xucVLA6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wHyq8nVFtPiG8vKPhbvPqG-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:09:20 +0000</pubDate>                                                                                                                                <updated>Thu, 03 Sep 2026 10:10:20 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wHyq8nVFtPiG8vKPhbvPqG-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital transformation concept image showing male technologist in casual work wear standing in an office with glowing walls of data on either side.]]></media:description>                                                            <media:text><![CDATA[Digital transformation concept image showing male technologist in casual work wear standing in an office with glowing walls of data on either side.]]></media:text>
                                <media:title type="plain"><![CDATA[Digital transformation concept image showing male technologist in casual work wear standing in an office with glowing walls of data on either side.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wHyq8nVFtPiG8vKPhbvPqG-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT leaders need to get back to basics and prioritize AI integration in areas where it can deliver real impact, according to Gartner, and that requires a more considered approach to adoption. </p><p>Tina Nunno, distinguished vice president and Gartner fellow, told <em>ITPro </em>that many IT leaders are still falling into a trap of following hype when it comes to <a href="https://www.itpro.com/technology/artificial-intelligence">AI</a>, and it’s hampering success. </p><p>“We’re human beings, and we follow hype,” she said. “We're curious about what we last saw published, or in a keynote, or we're curious about what the vendors are talking about.”</p><p>“But we still have to have, I think, a reasonable balance and need to think about what’s the business case? Some of the basics still really matter here.”</p><p>Nunno’s comments come after a Gartner survey found the most <a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-real-world-stories-of-the-sectors-ai-is-changing">popular AI use cases</a> are rarely the ones that deliver real business impact and value. </p><p>The survey of C-suite executives warned that adoption projects are being influenced by “heavily hyped” applications of the technology over those that actually generate value.</p><p>“We calculated what the most common use cases were, and then we compared them to the ones where they were getting the most reliable rates of return, and they didn't match,” Nunno told <em>ITPro</em>. “There wasn't even a lot of overlap.”</p><h2 id="choosing-the-popular-ai-use-cases-doesn-t-always-work">Choosing the ‘popular’ AI use cases doesn’t always work</h2><p>Gartner’s survey found that the three most popular AI use cases included <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>threat detection and response, identified by 54% of respondents, alongside IT service desk automation (54%), and <a href="https://www.itpro.com/software/development/ai-generated-code-software-developer-security-risk">automated code generation</a> and refactoring (44%). </p><p>Yet only the latter of these use cases ranked among the use cases that delivered positive operational or financial returns. </p><p>Intelligent IT asset and cost optimization (40%), <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-synthetic-data">synthetic data generation</a> (28%) and automated code generation and refactoring (23%) all ranked as the most successful use cases. </p><p>While hype is a key factor behind this disparity, Nunno told <em>ITPro </em>that it shows some ‘high performers’ are taking a more surgical approach to integrating the technology. </p><p>These businesses are focusing on overhauling or streamlining specific processes in a highly strategic manner, rather than taking a slap-dash approach and seeing what works. </p><p>“When we look at what’s most common, sometimes they’re more foundational AI implementations,” she explained. They’re not specific to the business unit. They’re not specific to the specific function that they’re attempting to perform.”</p><p>Nunno added that approaching adoption with a degree of generality rarely delivers tangible returns. It’s why having a clear-cut goal from the get-go is critical. </p><p>“There was a bit more specific nature in those that actually were showing returns,” she said. “They appeared to be more targeted, and as a result, because they were more targeted, they seem much more likely to deliver”. </p><p>Gartner’s findings align closely with recent <a href="https://www.itpro.com/business/business-strategy/flexibility-is-a-huge-advantage-for-small-businesses-adopting-ai-but-clear-strategy-and-bold-leadership-is-critical">research from Dell Technologies</a>, which also highlighted the importance of clear goals when it comes to AI adoption. </p><p>More than half (52%) of AI ‘front runners’ – those Dell identified as having the most success with the technology - had “clearly defined specific AI use cases”.</p><h2 id="be-prepared">Be prepared</h2><p>A lack of clear objectives and strategies is having a direct impact on scaling of AI across the enterprise, Gartner found. Indeed, just 22% of respondents said they’ve successfully scaled the technology across multiple business units. </p><p>Nunno told <em>ITPro </em>that this reinforces the importance of laying solid foundations before even embarking on projects. <a href="https://www.itpro.com/business/business-strategy/a-striking-finding-this-year-is-the-gap-between-individual-gains-and-enterprise-impact-mckinsey-says-ai-is-finally-paying-off-for-enterprises-but-rising-costs-and-constrained-efficiency-boosts-are-still-a-major-hurdle">Building maturity is critical</a>. </p><p>“For some organizations, we've seen there's a very strong correlation between the maturity of the organization and their ability to take advantage of AI,” she said. </p><p>“They haven't yet grown the AI skill sets that they need to bring the AI to scale, and that can be anything from the current state of their data, for example.”</p><p>Nunno admitted that this is often easier said than done. Basic foundational tasks like getting data in good shape and order are “a lot of work”. </p><p>“There’s still a very real investment that many of our clients are telling us they’re putting in to build those foundations to actually scale AI in the way that they would like,” she said. </p><p>“There’s a lot of heavy lifting that sometimes has to happen.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Travellers urged to look out for scams as MAG hackers publish stolen data online ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hackers have leaked the personal details of 8.7 million people following an attack on three British airports.</p><p>The incident was first disclosed in late August, impacting travellers at <a href="https://www.itpro.com/security/cyber-attacks/manchester-airports-group-attack-everything-we-know-so-far-as-8-7-million-customers-impacted-in-breach">three locations managed by Manchester Airports Group (MAG)</a>: Stansted, East Midlands, and Manchester airports.</p><p>The criminals behind the attack, believed to be FulcrumSec, published the data online, claiming to have half a terabyte of personally identifiable information. </p><p>However, the hackers <a href="https://www.computerweekly.com/news/366649824/UK-airport-hackers-leak-stolen-customer-data" target="_blank"><u>reportedly said</u></a> they wouldn't be selling "dangerous" data about future travel plans over concerns it would lead to stalking or burglary. </p><p>"This is an expected update, but it’s one none of the victims wanted to hear," said Timon Johnson, principal cyber essentials assessor at Closed Door Security.  </p><p>"It was always unlikely MAG would pay the ransom demand as it is akin to doing business with criminals, and it’s also highly unlikely the data would ever have been returned in full without further exploitation."</p><h2 id="free-release-as-punishment">Free release as punishment</h2><p>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, agreed that MAG made the right call by refusing to pay the ransom. </p><p>However, that decision puts nearly nine million people at risk for mistakes that weren't made by them. </p><p>"The 'free release' model is deliberately designed to maximize harm and reputational damage as a warning to the next target," he said. </p><p>"Publishing almost nine million records for free isn't just punishment for MAG — it's a marketing campaign aimed at every other organization watching. Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost."</p><p>At this point, the airlines group says it has contacted everyone whose data was compromised.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement sent to the <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank"><u><em>BBC</em></u></a>.</p><h2 id="what-happened-2">What happened?</h2><p>The attack is believed to have started over the weekend of 22 August, with the intrusion spotted the following Tuesday by MAG's security team, which promptly shut down further access. The attack was publicly disclosed on Thursday, 27 August. </p><p>FulcrumSec later claimed responsibility for the attack, saying it would publish the data owing to MAG not negotiating a ransom. Yesterday, they followed through with that threat. </p><p>MAG said in a <a href="https://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/" target="_blank"><u>statement</u></a> that the customer data relates to the car park, lounge, and Fast Track bookings at the airports, as well as Wi-Fi signups, stressing there had been no operational disruption and that aviation security had not been compromised.</p><p>The data taken includes email addresses, phone numbers, vehicle registrations, and postcodes, but does not include bank or payment card details. </p><h2 id="what-now">What now? </h2><p>As the data has been published on the open web, the focus now turns to scams against the 8.7 million victims. </p><p>"Now that the data is available for free on the <a href="https://www.itpro.com/security/the-dark-web-is-absolutely-awash-with-stolen-data-on-british-mps">dark web</a>, other criminals will be working to exploit it," says Johnson. "<a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>presents the greatest risk, and all individuals must be vigilant for scams. These could come in via email, phone calls or texts, so all these communication methods must be monitored closely."</p><p>As ever, this means constant vigilance online: be wary of clicking links or opening attachments and don't share any financial or other personal data unless the receiver has been verified, added Johnson. </p><p>The inclusion of travel data exacerbates the risk, according to security expert Kevin Beaumont. </p><p>"The data includes both historical locations and planned future travel, so individuals sensitive to their movements being known may need to take precautions," he told the <em>BBC</em>. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-breaches/manchester-airports-group-attack-millions-of-holidaymakers-urged-to-look-out-for-scams-as-hackers-publish-stolen-data-online</link>
                                                                            <description>
                            <![CDATA[ The Manchester Airports Group attack could lead to fraud and scams, experts warn ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PoLZxGbqtMjx83aVosQkf5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DVmkPfYJrV73rHN98npwDo-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 09:53:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DVmkPfYJrV73rHN98npwDo-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Terminal 2 departures building at Manchester Airport, run by Manchester Airports Group, with passengers queuing at check-in point.]]></media:description>                                                            <media:text><![CDATA[Terminal 2 departures building at Manchester Airport, run by Manchester Airports Group, with passengers queuing at check-in point.]]></media:text>
                                <media:title type="plain"><![CDATA[Terminal 2 departures building at Manchester Airport, run by Manchester Airports Group, with passengers queuing at check-in point.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DVmkPfYJrV73rHN98npwDo-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have leaked the personal details of 8.7 million people following an attack on three British airports.</p><p>The incident was first disclosed in late August, impacting travellers at <a href="https://www.itpro.com/security/cyber-attacks/manchester-airports-group-attack-everything-we-know-so-far-as-8-7-million-customers-impacted-in-breach">three locations managed by Manchester Airports Group (MAG)</a>: Stansted, East Midlands, and Manchester airports.</p><p>The criminals behind the attack, believed to be FulcrumSec, published the data online, claiming to have half a terabyte of personally identifiable information. </p><p>However, the hackers <a href="https://www.computerweekly.com/news/366649824/UK-airport-hackers-leak-stolen-customer-data" target="_blank"><u>reportedly said</u></a> they wouldn't be selling "dangerous" data about future travel plans over concerns it would lead to stalking or burglary. </p><p>"This is an expected update, but it’s one none of the victims wanted to hear," said Timon Johnson, principal cyber essentials assessor at Closed Door Security.  </p><p>"It was always unlikely MAG would pay the ransom demand as it is akin to doing business with criminals, and it’s also highly unlikely the data would ever have been returned in full without further exploitation."</p><h2 id="free-release-as-punishment">Free release as punishment</h2><p>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, agreed that MAG made the right call by refusing to pay the ransom. </p><p>However, that decision puts nearly nine million people at risk for mistakes that weren't made by them. </p><p>"The 'free release' model is deliberately designed to maximize harm and reputational damage as a warning to the next target," he said. </p><p>"Publishing almost nine million records for free isn't just punishment for MAG — it's a marketing campaign aimed at every other organization watching. Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost."</p><p>At this point, the airlines group says it has contacted everyone whose data was compromised.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement sent to the <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank"><u><em>BBC</em></u></a>.</p><h2 id="what-happened-2">What happened?</h2><p>The attack is believed to have started over the weekend of 22 August, with the intrusion spotted the following Tuesday by MAG's security team, which promptly shut down further access. The attack was publicly disclosed on Thursday, 27 August. </p><p>FulcrumSec later claimed responsibility for the attack, saying it would publish the data owing to MAG not negotiating a ransom. Yesterday, they followed through with that threat. </p><p>MAG said in a <a href="https://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/" target="_blank"><u>statement</u></a> that the customer data relates to the car park, lounge, and Fast Track bookings at the airports, as well as Wi-Fi signups, stressing there had been no operational disruption and that aviation security had not been compromised.</p><p>The data taken includes email addresses, phone numbers, vehicle registrations, and postcodes, but does not include bank or payment card details. </p><h2 id="what-now">What now? </h2><p>As the data has been published on the open web, the focus now turns to scams against the 8.7 million victims. </p><p>"Now that the data is available for free on the <a href="https://www.itpro.com/security/the-dark-web-is-absolutely-awash-with-stolen-data-on-british-mps">dark web</a>, other criminals will be working to exploit it," says Johnson. "<a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>presents the greatest risk, and all individuals must be vigilant for scams. These could come in via email, phone calls or texts, so all these communication methods must be monitored closely."</p><p>As ever, this means constant vigilance online: be wary of clicking links or opening attachments and don't share any financial or other personal data unless the receiver has been verified, added Johnson. </p><p>The inclusion of travel data exacerbates the risk, according to security expert Kevin Beaumont. </p><p>"The data includes both historical locations and planned future travel, so individuals sensitive to their movements being known may need to take precautions," he told the <em>BBC</em>. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know about the Dropbox breach so far ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hackers have breached cloud storage provider <a href="https://www.itpro.com/cloud-storage/32814/dropbox-business-advanced-review-first-rate-filesharing">Dropbox </a>via a flaw in Lenovo’s email verification process.</p><p>Around 5,000 accounts are believed to have been compromised during the first three weeks of August, with files viewed or downloaded from around 1,500 of these. It's not known who carried out the attack.</p><p>The breach arose through the <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a> option using Lenovo IDs. Dropbox partners with Lenovo as an identity provider, allowing users to log in to their Dropbox accounts using verified Lenovo IDs.</p><p>However, the process lacked enforced <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA)</a>, meaning that an attacker could gain full access without needing a password. Even users without a pre-existing Lenovo ID were vulnerable.</p><p>The company has now <a href="https://x.com/yonilevy/status/2094521566826541248/photo/1" target="_blank"><u>alerted users</u></a>.</p><p>"While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address," the company said.</p><p>Justin Beals, CEO and founder of Strike Graph, said the incident appears to have derived from a trusted legacy integration between the two firms.</p><p>"This is the same failure mode we keep seeing across every major vendor breach this year. Organizations assess the vendors they contract with directly, then treat every integration that vendor maintains as inherited trust. Nobody re-verifies the third-party connections a trusted platform has already built," he said. </p><p>"Traditional third-party <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">risk management</a> approaches have true positive detection rates below 30%, and a legacy authentication bridge between two major platforms is exactly the kind of dependency that a point-in-time questionnaire was never built to catch."</p><h2 id="dropbox-breach-could-39-ve-been-avoided">Dropbox breach could've been avoided</h2><p>Dropbox has now closed the loophole by expiring all sessions authenticated through Lenovo IDs, cutting any link between Lenovo, and adding the requirement for users to enter their Dropbox account password when attempting to use Lenovo ID authentication.</p><p>A spokesperson for Dropbox told <em>ITPro </em>the company reacted swiftly to the incident and has informed affected users. </p><p>“We emailed users we know were impacted, offered them support, and reported this event to relevant data protection regulators," they said.</p><p>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, suggested that some users only have themselves to blame for not implementing <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a>. </p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap, and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," he said.</p><p>Organizations should periodically audit what third-party services have authentication access to their accounts, he said. </p><p>"OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends,” Patel added.</p><p>Dropbox has been <a href="https://www.itpro.com/security/27169/68-million-dropbox-credentials-leak-online"><u>hit before</u></a>, with a 2012 breach that affected around two-thirds of the company's user base. Four years later, more than 68 million customer usernames and passwords were leaked. </p><p>On that occasion, accounts were compromised through password reuse, Dropbox said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-breaches/everything-we-know-about-the-dropbox-breach-so-far</link>
                                                                            <description>
                            <![CDATA[ The company has confirmed that thousands of accounts connected through Lenovo ID and lacking Dropbox two-factor authentication have been affected ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MXpDKnoTrX5pqNJcEH83ue</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/whouCEvG367mE97QpHjVuF-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 09:42:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/whouCEvG367mE97QpHjVuF-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dropbox logo and branding displayed on a smartphone screen with black background.]]></media:description>                                                            <media:text><![CDATA[Dropbox logo and branding displayed on a smartphone screen with black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Dropbox logo and branding displayed on a smartphone screen with black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/whouCEvG367mE97QpHjVuF-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have breached cloud storage provider <a href="https://www.itpro.com/cloud-storage/32814/dropbox-business-advanced-review-first-rate-filesharing">Dropbox </a>via a flaw in Lenovo’s email verification process.</p><p>Around 5,000 accounts are believed to have been compromised during the first three weeks of August, with files viewed or downloaded from around 1,500 of these. It's not known who carried out the attack.</p><p>The breach arose through the <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a> option using Lenovo IDs. Dropbox partners with Lenovo as an identity provider, allowing users to log in to their Dropbox accounts using verified Lenovo IDs.</p><p>However, the process lacked enforced <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA)</a>, meaning that an attacker could gain full access without needing a password. Even users without a pre-existing Lenovo ID were vulnerable.</p><p>The company has now <a href="https://x.com/yonilevy/status/2094521566826541248/photo/1" target="_blank"><u>alerted users</u></a>.</p><p>"While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address," the company said.</p><p>Justin Beals, CEO and founder of Strike Graph, said the incident appears to have derived from a trusted legacy integration between the two firms.</p><p>"This is the same failure mode we keep seeing across every major vendor breach this year. Organizations assess the vendors they contract with directly, then treat every integration that vendor maintains as inherited trust. Nobody re-verifies the third-party connections a trusted platform has already built," he said. </p><p>"Traditional third-party <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">risk management</a> approaches have true positive detection rates below 30%, and a legacy authentication bridge between two major platforms is exactly the kind of dependency that a point-in-time questionnaire was never built to catch."</p><h2 id="dropbox-breach-could-39-ve-been-avoided">Dropbox breach could've been avoided</h2><p>Dropbox has now closed the loophole by expiring all sessions authenticated through Lenovo IDs, cutting any link between Lenovo, and adding the requirement for users to enter their Dropbox account password when attempting to use Lenovo ID authentication.</p><p>A spokesperson for Dropbox told <em>ITPro </em>the company reacted swiftly to the incident and has informed affected users. </p><p>“We emailed users we know were impacted, offered them support, and reported this event to relevant data protection regulators," they said.</p><p>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, suggested that some users only have themselves to blame for not implementing <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a>. </p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap, and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," he said.</p><p>Organizations should periodically audit what third-party services have authentication access to their accounts, he said. </p><p>"OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends,” Patel added.</p><p>Dropbox has been <a href="https://www.itpro.com/security/27169/68-million-dropbox-credentials-leak-online"><u>hit before</u></a>, with a 2012 breach that affected around two-thirds of the company's user base. Four years later, more than 68 million customer usernames and passwords were leaked. </p><p>On that occasion, accounts were compromised through password reuse, Dropbox said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How MSSPs can deliver continuous pentesting without hiring more security experts ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Managed Security Service Providers (MSSPs) need continuous security testing and faster risk identification. But the cybersecurity talent shortage makes it harder to expand service delivery through hiring alone.</p><p>The challenge is becoming more urgent as cyber threats continue to grow. More than <a href="https://zerothreat.ai/blog/cyberattack-statistics"><u>2,244 cyberattacks occur every day worldwide</u></a>, according to our research. This creates constant pressure for organizations to identify and address security gaps before attackers do.</p><p>More risk and more demand. Traditional approaches and tools simply can’t keep up.</p><p>That reality is forcing MSSPs to change how they scale security services. The good part is that continuous pentesting no longer requires a proportional increase in headcount. With AI-powered automated penetration testing, MSSPs can expand security coverage, increase testing frequency, and serve more clients without continuously adding security specialists.</p><h2 id="why-continuous-security-coverage-is-getting-harder">Why continuous security coverage is getting harder</h2><p>Managing security for clients used to be like checking a box once a year, but that has changed. Each organization needs continuous security coverage to keep up with the updates they are deploying and the growing number of cyber threats.</p><p>The complexity of today’s applications can’t be tackled by traditional methods because:</p><ul><li>Cloud-native apps and APIs change daily, making annual penetration tests obsolete within weeks.</li><li>Hiring more security experts to manually test every environment is not feasible.</li><li>Attackers now use AI to scan and exploit systems continuously, moving far faster than manual audit cycles.</li></ul><p>As a result, many providers are rethinking how they scale offensive security services without continually expanding their security teams.</p><h2 id="why-hiring-more-people-isn-39-t-a-scalable-security-strategy">Why hiring more people isn't a scalable security strategy</h2><p>Hiring more security experts seems like the obvious way to add to continuous pentesting services. But in reality, fluctuating demand, shortage of skills, and other operational costs can make it difficult to sustain.</p><ol start="1"><li><strong>Skilled security talent is hard to find: </strong>The cybersecurity talent gap remains a major challenge across the industry. Recent ISC2 research found that 95% of organizations report at least one cybersecurity skills gap, while 59% face significant or critical skills shortages. Finding experienced pentesters, application security specialists, and offensive security experts is becoming increasingly tough.</li><li><strong>Hiring costs keep increasing: </strong>Recruiting security professionals is expensive, and other than salary, MSSPs need to account for onboarding, training, certifications, and retention efforts. With high demand for application security and threat exposure management skills, the cost of building larger teams rises with it.</li><li><strong>Client growth often outpaces team growth: </strong>Security teams do not scale at the same rate as client demand. As MSSPs add more customers, each new environment introduces additional assets, attack surfaces, vulnerabilities, and testing requirements. Hiring one person at a time rarely keeps pace with the volume of continuous security assessments clients expect.</li><li><strong>Specialized expertise does not scale easily: </strong>Continuous pentesting demands expertise in web applications, APIs, cloud environments, business logic testing, and risk validation. Building teams with every required specialty can easily become impractical for growing MSSPs.</li><li><strong>More people can create operational bottlenecks: </strong>Adding more heads to the team does not mean improved service delivery. Larger teams require coordination, management, quality assurance, and workflow standardization. In many cases, operational complexity grows faster than productivity, reducing the efficiency gains MSSPs expected from hiring more analysts and testers.</li></ol><p>The key problem with hiring more isn’t just about finding more skilled experts; it’s finding a way to offer continuous security coverage while utilizing the resources efficiently.</p><h2 id="how-mssps-can-provide-continuous-pentesting-without-hiring">How MSSPs can provide continuous pentesting without hiring</h2><p>The most practical way to scale continuous pentesting today is to combine security expertise with AI-powered automated penetration testing that increases coverage, testing frequency, and operational efficiency.</p><p><strong>Automate repetitive security testing tasks:</strong> A large portion of pentesting involves reconnaissance, attack surface discovery, vulnerability validation, and retesting. AI-powered pentesting platforms can help you automate these repeatable tasks so that you can focus on higher-value investigations and risk analysis.</p><p><strong>Integrate security testing into existing pipelines: </strong>You should embed automated testing directly into the client delivery process. This ensures that every configuration change is tested immediately rather than waiting for an annual check. It turns security from periodic, labor-intensive work into an automated process.</p><p><strong>Implement multi-tenant management: </strong>Instead of configuring tests for each client individually, use multi-tenant dashboards. This allows your current engineering or SOC team to centrally schedule automated tests, distribute reports, and track remediation across hundreds of client environments simultaneously.</p><p><strong>Prioritize findings based on real risk:</strong> Use modern AI-powered pentesting platforms that help correlate findings, validate exploitability, and highlight the issues most likely to impact the client. This improves remediation efficiency and helps you deliver clearer security outcomes.</p><p><strong>Utilize white-label reseller tools:</strong> The best way to save time and effort on preparing reports is by using a tool that offers white-labeled reports. The reports are generated by AI-powered tools, and you can keep your Logos & URLs, making sure you deliver professional, client-ready documentation without manual formatting.</p><h2 id="what-mssps-should-look-for-in-a-scalable-continuous-pentesting-solution">What MSSPs should look for in a scalable continuous pentesting solution</h2><p>As client environments grow complex, MSSPs need solutions that can expand security coverage without operational burden. The ideal platform should help teams identify risks faster, validate findings more efficiently, and deliver consistent security outcomes across multiple customers.</p><p>When evaluating a solution, focus on capabilities that support long-term scalability:</p><ul><li>Continuous attack surface monitoring</li><li>AI-assisted vulnerability validation</li><li>Web application, API, cloud, and external asset coverage</li><li>Risk-based prioritization of findings</li><li>Automated retesting and remediation tracking</li><li>Multi-tenant management and reporting</li><li>Integration with existing security workflows and ticketing systems</li></ul><p>The right tool helps security teams spend less time on repetitive testing and more time delivering meaningful risk insights. For MSSPs, that balance is what makes continuous pentesting both operationally sustainable and commercially viable.</p><p>Continuous pentesting is the new basic expectation of clients, and that has turned out to be the new challenge for MSSPs. If they rely only on hiring to offer continuous testing services, it is rarely sustainable in a market already facing a cybersecurity skills shortage.</p><p>The most effective path forward is to combine security expertise with AI-powered automation.</p><p>By automating repetitive testing activities and enabling continuous security validation, MSSPs can support more clients, identify risks faster, and scale their services without compromising the quality of protection they deliver.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/how-mssps-can-deliver-continuous-pentesting-without-hiring-more-security-experts</link>
                                                                            <description>
                            <![CDATA[ MSSPs can scale and strengthen their security posture using AI instead of expanding security teams... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7sUn7zuCnbDyeX8LYaxNpK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 22:05:25 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 22:06:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dharmesh Acharya ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/UakkT3isdrj83uFs6V7FiW-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Managed Security Service Providers (MSSPs) need continuous security testing and faster risk identification. But the cybersecurity talent shortage makes it harder to expand service delivery through hiring alone.</p><p>The challenge is becoming more urgent as cyber threats continue to grow. More than <a href="https://zerothreat.ai/blog/cyberattack-statistics"><u>2,244 cyberattacks occur every day worldwide</u></a>, according to our research. This creates constant pressure for organizations to identify and address security gaps before attackers do.</p><p>More risk and more demand. Traditional approaches and tools simply can’t keep up.</p><p>That reality is forcing MSSPs to change how they scale security services. The good part is that continuous pentesting no longer requires a proportional increase in headcount. With AI-powered automated penetration testing, MSSPs can expand security coverage, increase testing frequency, and serve more clients without continuously adding security specialists.</p><h2 id="why-continuous-security-coverage-is-getting-harder">Why continuous security coverage is getting harder</h2><p>Managing security for clients used to be like checking a box once a year, but that has changed. Each organization needs continuous security coverage to keep up with the updates they are deploying and the growing number of cyber threats.</p><p>The complexity of today’s applications can’t be tackled by traditional methods because:</p><ul><li>Cloud-native apps and APIs change daily, making annual penetration tests obsolete within weeks.</li><li>Hiring more security experts to manually test every environment is not feasible.</li><li>Attackers now use AI to scan and exploit systems continuously, moving far faster than manual audit cycles.</li></ul><p>As a result, many providers are rethinking how they scale offensive security services without continually expanding their security teams.</p><h2 id="why-hiring-more-people-isn-39-t-a-scalable-security-strategy">Why hiring more people isn't a scalable security strategy</h2><p>Hiring more security experts seems like the obvious way to add to continuous pentesting services. But in reality, fluctuating demand, shortage of skills, and other operational costs can make it difficult to sustain.</p><ol start="1"><li><strong>Skilled security talent is hard to find: </strong>The cybersecurity talent gap remains a major challenge across the industry. Recent ISC2 research found that 95% of organizations report at least one cybersecurity skills gap, while 59% face significant or critical skills shortages. Finding experienced pentesters, application security specialists, and offensive security experts is becoming increasingly tough.</li><li><strong>Hiring costs keep increasing: </strong>Recruiting security professionals is expensive, and other than salary, MSSPs need to account for onboarding, training, certifications, and retention efforts. With high demand for application security and threat exposure management skills, the cost of building larger teams rises with it.</li><li><strong>Client growth often outpaces team growth: </strong>Security teams do not scale at the same rate as client demand. As MSSPs add more customers, each new environment introduces additional assets, attack surfaces, vulnerabilities, and testing requirements. Hiring one person at a time rarely keeps pace with the volume of continuous security assessments clients expect.</li><li><strong>Specialized expertise does not scale easily: </strong>Continuous pentesting demands expertise in web applications, APIs, cloud environments, business logic testing, and risk validation. Building teams with every required specialty can easily become impractical for growing MSSPs.</li><li><strong>More people can create operational bottlenecks: </strong>Adding more heads to the team does not mean improved service delivery. Larger teams require coordination, management, quality assurance, and workflow standardization. In many cases, operational complexity grows faster than productivity, reducing the efficiency gains MSSPs expected from hiring more analysts and testers.</li></ol><p>The key problem with hiring more isn’t just about finding more skilled experts; it’s finding a way to offer continuous security coverage while utilizing the resources efficiently.</p><h2 id="how-mssps-can-provide-continuous-pentesting-without-hiring">How MSSPs can provide continuous pentesting without hiring</h2><p>The most practical way to scale continuous pentesting today is to combine security expertise with AI-powered automated penetration testing that increases coverage, testing frequency, and operational efficiency.</p><p><strong>Automate repetitive security testing tasks:</strong> A large portion of pentesting involves reconnaissance, attack surface discovery, vulnerability validation, and retesting. AI-powered pentesting platforms can help you automate these repeatable tasks so that you can focus on higher-value investigations and risk analysis.</p><p><strong>Integrate security testing into existing pipelines: </strong>You should embed automated testing directly into the client delivery process. This ensures that every configuration change is tested immediately rather than waiting for an annual check. It turns security from periodic, labor-intensive work into an automated process.</p><p><strong>Implement multi-tenant management: </strong>Instead of configuring tests for each client individually, use multi-tenant dashboards. This allows your current engineering or SOC team to centrally schedule automated tests, distribute reports, and track remediation across hundreds of client environments simultaneously.</p><p><strong>Prioritize findings based on real risk:</strong> Use modern AI-powered pentesting platforms that help correlate findings, validate exploitability, and highlight the issues most likely to impact the client. This improves remediation efficiency and helps you deliver clearer security outcomes.</p><p><strong>Utilize white-label reseller tools:</strong> The best way to save time and effort on preparing reports is by using a tool that offers white-labeled reports. The reports are generated by AI-powered tools, and you can keep your Logos & URLs, making sure you deliver professional, client-ready documentation without manual formatting.</p><h2 id="what-mssps-should-look-for-in-a-scalable-continuous-pentesting-solution">What MSSPs should look for in a scalable continuous pentesting solution</h2><p>As client environments grow complex, MSSPs need solutions that can expand security coverage without operational burden. The ideal platform should help teams identify risks faster, validate findings more efficiently, and deliver consistent security outcomes across multiple customers.</p><p>When evaluating a solution, focus on capabilities that support long-term scalability:</p><ul><li>Continuous attack surface monitoring</li><li>AI-assisted vulnerability validation</li><li>Web application, API, cloud, and external asset coverage</li><li>Risk-based prioritization of findings</li><li>Automated retesting and remediation tracking</li><li>Multi-tenant management and reporting</li><li>Integration with existing security workflows and ticketing systems</li></ul><p>The right tool helps security teams spend less time on repetitive testing and more time delivering meaningful risk insights. For MSSPs, that balance is what makes continuous pentesting both operationally sustainable and commercially viable.</p><p>Continuous pentesting is the new basic expectation of clients, and that has turned out to be the new challenge for MSSPs. If they rely only on hiring to offer continuous testing services, it is rarely sustainable in a market already facing a cybersecurity skills shortage.</p><p>The most effective path forward is to combine security expertise with AI-powered automation.</p><p>By automating repetitive testing activities and enabling continuous security validation, MSSPs can support more clients, identify risks faster, and scale their services without compromising the quality of protection they deliver.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers ran up a $600,000 AI bill after swiping API keys, says METR ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI research non-profit METR has disclosed two security incidents – and while no sensitive information is believed to have been accessed, one of the attacks led to what might have been a massive bill.</p><p><a href="https://metr.org/blog/2026-08-31-security-update/#our-approach-to-security" target="_blank"><u>According to METR</u></a>, attackers stole an API key for inference on public AI models in March, consuming $600,000 worth of credits. Luckily, the model developer had granted them to METR for free. </p><p>A researcher left an <a href="https://www.itpro.com/cloud/370070/what-is-aws-ec2">EC2 </a>instance publicly accessible behind Google authentication, the company said, which contained an API key for METR’s general-access (public models) account. </p><p>METR noted that the <a href="https://www.itpro.com/technology/artificial-intelligence/vibe-coding-security-risks-how-to-mitigate">vibe-coded app</a> included a fail-open vulnerability that silently disabled authentication, exposing the system to the public internet for several days.</p><p>METR reckons the attacker found the instance by looking through recently registered websites to find vibe-coded sites with high-signal keywords relating to LLMs or agents.</p><p>The attacker prompted an agent directly to reveal its model provider API key, added an SSH key for persistent access, and over the course of three weeks used the stolen credentials to consume the API credits.</p><h2 id="why-didn-39-t-metr-notice">Why didn't METR notice?</h2><p>METR noted that because the organisation is “accustomed to running evaluations and experiments that use large volumes of tokens”, the incident flew under the radar. </p><p>The non-profit regularly runs large-scale evaluations with pre-deployment AI models, meaning it typically deals with “lots of weird rate limits and API errors”. </p><p>"At the time of the incident, our internal usage dashboard didn’t show data on rate-limited requests to all users, even if they were occurring,” METR said.</p><p>Notably, because it wasn't actually paying for the tokens there was no natural token spend ceiling, and no way at the time to put a spending limit on keys.</p><h2 id="metr-lifts-lid-on-separate-attack">METR lifts lid on separate attack</h2><p>In another attack in May, METR spotted attackers systematically probing its publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint. </p><p>"We were tipped off that we were being targeted by hackers who appeared to be financially motivated and may have been looking to obtain frontier model access," it said. </p><p>"We observed the attackers systematically probing our publicly accessible infrastructure, with heavy use of agents to automate vulnerability discovery, including by credential stuffing authentication providers, attempting OAuth token grants, scanning newly deployed services, and attempting to phish staff."</p><p>METR said it's now maintaining an isolated public production environment for public-facing applications that's architecturally separated from its internal infrastructure. </p><p>This means a misconfiguration in a public service can't expose internal data. It's also hired a security lead and is expanding security staff further. </p><p>Elsewhere, METR revealed it has shut down legacy infrastructure that was unnecessarily expanding the attack surface and has set up monitoring for unusual API key usage and other abnormal behavior.</p><p>"Although these incidents had limited consequences, we considered them near-misses, and increased our security investment in response," it said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/hackers-ran-up-a-usd600-000-ai-bill-after-swiping-api-keys-says-metr-and-nobody-realized-for-weeks</link>
                                                                            <description>
                            <![CDATA[ Luckily the organization wasn't paying for the tokens; others might not have been so lucky ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iJ8YUwrrj8ciQwd26ZdEZ9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K77LEmNgKcHxRxhEtmnX3W-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 10:19:47 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 14:46:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/K77LEmNgKcHxRxhEtmnX3W-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Concept image showing a US dollar bill burning at the edges with smoke pluming outwards.]]></media:description>                                                            <media:text><![CDATA[Concept image showing a US dollar bill burning at the edges with smoke pluming outwards.]]></media:text>
                                <media:title type="plain"><![CDATA[Concept image showing a US dollar bill burning at the edges with smoke pluming outwards.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K77LEmNgKcHxRxhEtmnX3W-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI research non-profit METR has disclosed two security incidents – and while no sensitive information is believed to have been accessed, one of the attacks led to what might have been a massive bill.</p><p><a href="https://metr.org/blog/2026-08-31-security-update/#our-approach-to-security" target="_blank"><u>According to METR</u></a>, attackers stole an API key for inference on public AI models in March, consuming $600,000 worth of credits. Luckily, the model developer had granted them to METR for free. </p><p>A researcher left an <a href="https://www.itpro.com/cloud/370070/what-is-aws-ec2">EC2 </a>instance publicly accessible behind Google authentication, the company said, which contained an API key for METR’s general-access (public models) account. </p><p>METR noted that the <a href="https://www.itpro.com/technology/artificial-intelligence/vibe-coding-security-risks-how-to-mitigate">vibe-coded app</a> included a fail-open vulnerability that silently disabled authentication, exposing the system to the public internet for several days.</p><p>METR reckons the attacker found the instance by looking through recently registered websites to find vibe-coded sites with high-signal keywords relating to LLMs or agents.</p><p>The attacker prompted an agent directly to reveal its model provider API key, added an SSH key for persistent access, and over the course of three weeks used the stolen credentials to consume the API credits.</p><h2 id="why-didn-39-t-metr-notice">Why didn't METR notice?</h2><p>METR noted that because the organisation is “accustomed to running evaluations and experiments that use large volumes of tokens”, the incident flew under the radar. </p><p>The non-profit regularly runs large-scale evaluations with pre-deployment AI models, meaning it typically deals with “lots of weird rate limits and API errors”. </p><p>"At the time of the incident, our internal usage dashboard didn’t show data on rate-limited requests to all users, even if they were occurring,” METR said.</p><p>Notably, because it wasn't actually paying for the tokens there was no natural token spend ceiling, and no way at the time to put a spending limit on keys.</p><h2 id="metr-lifts-lid-on-separate-attack">METR lifts lid on separate attack</h2><p>In another attack in May, METR spotted attackers systematically probing its publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint. </p><p>"We were tipped off that we were being targeted by hackers who appeared to be financially motivated and may have been looking to obtain frontier model access," it said. </p><p>"We observed the attackers systematically probing our publicly accessible infrastructure, with heavy use of agents to automate vulnerability discovery, including by credential stuffing authentication providers, attempting OAuth token grants, scanning newly deployed services, and attempting to phish staff."</p><p>METR said it's now maintaining an isolated public production environment for public-facing applications that's architecturally separated from its internal infrastructure. </p><p>This means a misconfiguration in a public service can't expose internal data. It's also hired a security lead and is expanding security staff further. </p><p>Elsewhere, METR revealed it has shut down legacy infrastructure that was unnecessarily expanding the attack surface and has set up monitoring for unusual API key usage and other abnormal behavior.</p><p>"Although these incidents had limited consequences, we considered them near-misses, and increased our security investment in response," it said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cato Networks launches SMB FlexPool to help MSPs scale managed SASE services ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cato Networks has cut the ribbon on SMB FlexPool, a new program designed to help MSPs deliver managed <a href="https://www.itpro.com/cloud/cloud-security/what-is-secure-access-service-edge-sase">SASE </a>services to small and midsize businesses at scale.</p><p>Available to both new and existing MSPs and service providers, the initiative offers access to a pool of Cato licenses that can be gradually allocated across eligible SMB customers as demand evolves.</p><p>The model allows partners to create customer accounts, allocate capacity, and activate services through a self-service workflow, while retaining control over customer relationships, service packaging, and support.</p><p>In an announcement, Cato said SMB FlexPool aims to remove the operational overhead associated with separate licensing transactions for every customer deployment, allowing partners to onboard customers faster and reallocate capacity as required.</p><p>"MSPs shouldn't have to slow down customer deployments because of licensing and operational overhead,” said Cato Networks’ global channel chief Karl Soderlund.</p><p>“SMB FlexPool aims to remove that friction with instant provisioning and flexible pooled licensing, enabling partners to activate new customers while maintaining full control of the customer experience."</p><p>Cato Networks provides a converged network and security cloud that brings networking, security and access capabilities together across enterprise environments. The platform offers visibility and control across users, applications, data, and AI interactions.</p><p>The company’s new SMB FlexPool initiative is built on the firm’s managed SASE (MSASE) Partner Platform, which provides <a href="https://www.itpro.com/business/business-strategy/msps-are-burned-out-and-overworked-as-tool-sprawl-and-it-complexity-grows-but-theres-light-on-the-horizon">MSPs </a>with tools, training, and automation across the partner lifecycle.</p><h2 id="pooled-licensing-for-msps">Pooled licensing for MSPs</h2><p>SMB FlexPool’s built-in partner-level capacity and license portability allow MSPs to allocate capacity across eligible SMB customers, as well as reallocate unused capacity as requirements change.</p><p>Cato said this approach aims to give MSPs greater flexibility as their customer base and pipeline develop, allowing them to ramp utilization of their purchased capacity in line with staged customer deployments and go-to-market progress.</p><p>Partners also retain control over key elements of their customer-facing packages, including their commercial offering, support model, and managed services.</p><p>By eliminating the friction associated with individual transactions, Cato said its new partner initiative will help partners move from opportunity to customer-ready service “in seconds.”</p><p>SMB FlexPool can be managed through Cato’s new MSASE dashboard in the MSASE Business Center, giving partners a unified view of customer accounts, orders, license usage, invoices, and customer lifecycle activity across both SMB and enterprise customers.</p><p>Art Nichols, chief technology officer at Uniti Solutions, said Cato’s new partner model will give the MSP a more efficient and scalable way to deliver managed SASE.</p><p>“Instead of managing separate licensing transactions for every new customer, we can provision services in seconds, bring customers online faster, and keep our operations simple as our business expands,” he explained. </p><p>“This means our customers benefit from faster deployment, a smoother onboarding experience, and the confidence that their secure network services can scale seamlessly alongside their business.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cato-networks-launches-smb-flexpool-to-help-msps-scale-managed-sase-services</link>
                                                                            <description>
                            <![CDATA[ The program is designed to remove licensing friction and speed up customer onboarding for partners serving the SMB market ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eGS6xFibmFhFVoQJWJ7uLo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 07:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:description>                                                            <media:text><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:text>
                                <media:title type="plain"><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cato Networks has cut the ribbon on SMB FlexPool, a new program designed to help MSPs deliver managed <a href="https://www.itpro.com/cloud/cloud-security/what-is-secure-access-service-edge-sase">SASE </a>services to small and midsize businesses at scale.</p><p>Available to both new and existing MSPs and service providers, the initiative offers access to a pool of Cato licenses that can be gradually allocated across eligible SMB customers as demand evolves.</p><p>The model allows partners to create customer accounts, allocate capacity, and activate services through a self-service workflow, while retaining control over customer relationships, service packaging, and support.</p><p>In an announcement, Cato said SMB FlexPool aims to remove the operational overhead associated with separate licensing transactions for every customer deployment, allowing partners to onboard customers faster and reallocate capacity as required.</p><p>"MSPs shouldn't have to slow down customer deployments because of licensing and operational overhead,” said Cato Networks’ global channel chief Karl Soderlund.</p><p>“SMB FlexPool aims to remove that friction with instant provisioning and flexible pooled licensing, enabling partners to activate new customers while maintaining full control of the customer experience."</p><p>Cato Networks provides a converged network and security cloud that brings networking, security and access capabilities together across enterprise environments. The platform offers visibility and control across users, applications, data, and AI interactions.</p><p>The company’s new SMB FlexPool initiative is built on the firm’s managed SASE (MSASE) Partner Platform, which provides <a href="https://www.itpro.com/business/business-strategy/msps-are-burned-out-and-overworked-as-tool-sprawl-and-it-complexity-grows-but-theres-light-on-the-horizon">MSPs </a>with tools, training, and automation across the partner lifecycle.</p><h2 id="pooled-licensing-for-msps">Pooled licensing for MSPs</h2><p>SMB FlexPool’s built-in partner-level capacity and license portability allow MSPs to allocate capacity across eligible SMB customers, as well as reallocate unused capacity as requirements change.</p><p>Cato said this approach aims to give MSPs greater flexibility as their customer base and pipeline develop, allowing them to ramp utilization of their purchased capacity in line with staged customer deployments and go-to-market progress.</p><p>Partners also retain control over key elements of their customer-facing packages, including their commercial offering, support model, and managed services.</p><p>By eliminating the friction associated with individual transactions, Cato said its new partner initiative will help partners move from opportunity to customer-ready service “in seconds.”</p><p>SMB FlexPool can be managed through Cato’s new MSASE dashboard in the MSASE Business Center, giving partners a unified view of customer accounts, orders, license usage, invoices, and customer lifecycle activity across both SMB and enterprise customers.</p><p>Art Nichols, chief technology officer at Uniti Solutions, said Cato’s new partner model will give the MSP a more efficient and scalable way to deliver managed SASE.</p><p>“Instead of managing separate licensing transactions for every new customer, we can provision services in seconds, bring customers online faster, and keep our operations simple as our business expands,” he explained. </p><p>“This means our customers benefit from faster deployment, a smoother onboarding experience, and the confidence that their secure network services can scale seamlessly alongside their business.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How seriously is your business taking the 'Q-Day' threat, and can you really be ready by 2029? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>If you can cast your mind back to 1999, the computing world was in a frenzy over the Y2K bug, or Millennium Bug, a coding flaw where systems abbreviated four-digit years to two digits – so, 99 instead of 1999. </p><p>First identified in 1958, the fear was that computers would read '00' as 1900 instead of 2000, potentially crashing global infrastructure. As such, $300 billion (now worth a staggering $600 billion in today's money) was spent to upgrade computers and application programs so they were Y2K-compliant. Because of this monumental effort over many years, the crisis was largely averted.</p><p>In 2026, a similar panic is simmering at a glacial pace. The fear is Q-Day: a hypothetical moment at which quantum computers become so powerful that they can crack encryption algorithms within seconds. Leading industry figures, quantum computing companies, cybersecurity advisors, and even <a href="https://www.govinfo.gov/content/pkg/DCPD-202200355/html/DCPD-202200355.htm"><u>national government agencies</u></a> have been warning about this moment for years — as far back as 1994, when mathematician Peter Shor first published his paper warning about this exact possibility. </p><p>Since then, the threat has felt far away and abstract – with under-pressure businesses spending their precious IT budgets on more immediate threats. </p><p>But in March 2026, Google Quantum AI published research revealing that quantum computers can crack the encryption underpinning Bitcoin using under 500,000 physical qubits. As such, <a href="https://www.itpro.com/security/google-just-revised-its-q-day-timeline-quantum-computers-could-break-existing-encryption-techniques-within-three-years-and-enterprises-are-nowhere-near-ready"><u>Google accelerated its migration timeline</u></a> from the 2030s to 2029. This is simply one example of the industry ramping up the pace of its migration, with another <a href="https://arxiv.org/html/2603.28627v1"><u>March study</u></a> showing quantum computers may need as few as 10,000 qubits to one day break the most secure encryption algorithms. </p><p>But that doesn't seem to have moved the needle very much, with countless businesses still completely unprotected or in the very earliest stages of exploring moves to implement post-quantum cryptography (PQC) or related countermeasures. With the timelines accelerating, why is the business world still so slow to react to these looming threats that lie over the horizon?    </p><h2 id="how-prepared-are-we-for-a-post-quantum-world">How prepared are we for a post-quantum world?</h2><p>Existing research into business preparedness is incredibly bleak. The vast majority (90%) of companies don't have systems in place to defend against quantum security threats, according to <a href="https://www.itpro.com/security/90-percent-of-companies-are-woefully-unprepared-for-quantum-security-threats-analysts-say-they-need-to-get-a-move-on"><u>Bain & Company analysis</u></a>. It's a similar, albeit less extreme, story with <a href="https://www.itpro.com/security/nearly-half-of-enterprises-arent-prepared-for-quantum-cybersecurity-threats"><u>Keyfactor research</u></a> that shows nearly half (48%) aren't ready. </p><p>Juniper Research found that just 27% of global companies will deploy PQC – but only by 2035. Right now, that figure stands at roughly 0.0009%, or just 35,000. Compound these findings with <a href="https://cdn.prod.website-files.com/643b94c382e84463a9e52264/698a5056aa19e254d8105a24_Part_1_2026_Quantum_Readiness_Survey_Report.pdf"><u>QuEra research</u></a> that showed the level of confidence in quantum preparedness actually fell from 65% to 55% between 2025 and 2026, meaning that as the threats become less abstract, businesses are increasingly aware that the measures they've taken may not be sufficient. </p><p>There's a readiness gap – no matter how you interpret the many and various findings. But what does this actually mean in practice and why is there such a large gap? Knowledge is the primary deficit, says Arjun Kudinoor, a doctoral student and NSF Graduate Research Fellow at MIT, as well as quantum security advisor at Protegrity. Many organizations lack the required expertise to understand the risks, prepare existing systems, and identify valuable applications, according to Kudinoor.</p><p>"Businesses must begin developing quantum literacy across technical and executive teams, assessing their exposure to quantum-enabled cybersecurity threats, and identifying problems for which quantum computing could provide a meaningful advantage," he adds. </p><p>But according to Orange Business' quantum-safe network lead and program director of edge computing, Frank de Jong, awareness has increased significantly in the last few years. </p><p>He tells <em>ITPro</em>: "It is impossible to be quantum-ready today, and in my opinion, it is also questionable if you could be completely quantum-safe before 2029. That's why we advise customers to start planning now and prioritize protecting their most valuable assets first. The key is to begin the journey, not to wait for perfect conditions."</p><p>As things stand, some sectors are more prepared than others. The earliest movers were telecoms providers and infrastructure-heavy organizations, with financial services, healthcare and software providers following suit. But it's also true to say that preparedness varies more based on resources and expertise, adds Kudinoor. He explains that firms with strong technical teams, quantum-related budgets, and executives concerned about planning for the threat are moving the fastest.</p><h2 id="avoiding-a-slow-motion-quantum-disaster">Avoiding a slow-motion quantum disaster</h2><p>Quantum computing is difficult to wrap your head around, and it's long been a technology that's some years away from maturation. For that reason, it might be tempting for many to have kicked the issue deep into the long grass. Suja Viswesan, IBM VP of security software, acknowledges this impact. "It can feel overwhelming at the sheer magnitude of possible impact. But the best place to start is by gaining visibility. You can’t fix what you can’t see." </p><p>Businesses, she says, should start small by mapping cryptographic assets – including certificates, secrets and API keys – across their environments. Then, they should prioritize risk and introduce controls such as proxy layers to, as she puts it, "buy time" before full PQC upgrades are available. </p><p>Kohinoor rejects the notion that quantum computing's threats are abstract, telling <em>ITPro</em>: "Much work has been done to estimate the number of qubits, error rates, and error correction methods required to implement such quantum factoring algorithms on quantum hardware." </p><p>The most powerful quantum computers commercially available are only one or two orders of magnitude away from breaking encryption schemes like RSA-2048. Thankfully, he adds, it's "not yet a disaster" because we are still several difficult breakthroughs away from achieving a fault-tolerant cryptographically relevant quantum computer. </p><p>So what's to explain the general malaise in preparing for this eventuality? The answer may lie on the balance sheet – and the IT and security budgets that so many organizations are under pressure to spend on far more immediate threats.</p><p>Although <a href="https://www.itpro.com/infrastructure/gartner-just-revised-its-global-it-spending-projection-for-2026-heres-why"><u>IT spending is expected to hit $6.37 trillion this year</u></a>, 14.2% higher than last year's spend, much of this has been allocated toward either trendier areas or toward more concrete threats. As de Jong puts it, IT budgets are spent "on where the center of attention is".</p><p>"In recent years, this was predominantly AI, and still today, this is where the majority of the “additional” money gets spent," he explains. </p><p>"Transitioning to quantum-safe infrastructure isn't a simple project. It will require substantial, sustained investment over many years. The most urgent call to action for CXOs today is to start planning and allocating substantial budgets for the coming years. This isn't fear-mongering — it's pragmatism. We cannot afford to wait and see."   </p><h2 id="is-it-too-late-to-prepare-for-the-post-quantum-world">Is it too late to prepare for the post-quantum world? </h2><p>The urgency is certainly there, and many experts fear it's far too late to avoid the damage – especially given the rise of <a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them"><u>"harvest now, decrypt later" (HNDL) attacks</u></a> – in which cybercriminals steal encrypted data with the intent of cracking it in the years to come using quantum computers. </p><p>But even if that were the case, there's still far more damage that can be done if businesses are sluggish about getting their defenses sorted. In that vein, the experts we interviewed say it's never too late to prepare.</p><p>"As the saying goes, ‘The best time to plant a tree was 20 years ago. The second-best time is now.’ The challenge with cybersecurity threats is that they may or may not affect you, but the fact that they could is sufficient reason to pay attention," de Jong says, but concedes that many will never be fully prepared. </p><p>"Most organizations face 15 years of work to become quantum-safe, but they may have only three years to do it. This means that they need to prioritize and accept the fact that not every asset can be defended at the same level from the start."</p><p>In the last few years, the mood has certainly shifted away from maximum preparedness to damage limitation as the reality has hit the industry that businesses haven't been moving quickly enough. MIT's Kudinoor advises businesses to upgrade all systems to PQC, beginning with the highest priority and most publicly available systems. </p><p>But the reality is that the threats themselves won't all hit at once – despite the 'Q-Day' label implying there's a single moment in the future beyond which there's no return. As IBM's Viswesan explains: "We’ll see it materialize over time, spanning multiple years as different cryptographic systems become vulnerable at different times." </p><h2 id="quantum-readiness-is-all-about-making-haste-slowly">Quantum readiness is all about making haste slowly</h2><p>Given the gradual and unfolding nature of 'Q-Day',  businesses should avoid rushing their decision-making and adopt a balanced and thoughtful approach, whether that's in assessing their estate or engaging with vendors. </p><p>The name for this dilemma – in which you need to act fast but not so fast that you end up making poor decisions – is "festina lente", a Latin term that roughly translates to "hurry slowly". But that's easier said than done.</p><p>"Organizations shouldn't wait to begin the transformation journey, but they also shouldn't rush into decisions. That’s where crypto-agility comes into play," Viswesan continues. </p><p>"Crypto‑agility is the ability to migrate to post-quantum cryptography (PQC), while maintaining the flexibility to make changes without business disruption. Crypto‑agility allows organizations to scale cryptography‑based data protection with confidence, reduce the operational costs associated with managing cryptography, and meaningfully lower long‑term security risk."</p><p>What about quantum companies themselves? After all, aren't they causing the problem in the first place? As de Jong says, the supply chain is already seeing a lot of countermeasures embedded into products by design, for example, quantum-safe features in the systems that cloud companies provide. </p><p>Pro bono support may also be available to smaller companies without the budgets or expertise to fight this battle. But, he says, the problem is likely to impact the larger companies the most. </p><p>To adequately prepare, the experts also recommend that building quantum literacy among technical teams and executives is essential. These teams should then devise roadmaps, with budgets over the coming years incorporating more quantum line items. </p><p>This transition is new to almost everyone, meaning that it's a journey of discovery and the best practice is still being formulated. There are, however, companies that are further along the journey than others – and organizations should liaise with one another so that everyone can benefit together.</p><p>"The transition to quantum-safe is new for almost everyone," de Jong adds, "so I would advise enterprise CXOs not to try and reinvent the wheel themselves, but rather work with companies that have been working on it for several years, so everyone can benefit from the collective knowledge."</p><p>The timelines are shrinking with each quantum computing breakthrough, and there's a general acceptance among experts that it won't be possible for businesses to be fully quantum-ready by 2029 – especially if you factor in the HNDL attacks that have already happened. </p><p>That said, it's never too late to act to avoid the very worst of it, and businesses should do what they can to get as far ahead of this threat as possible before it's too late – no matter how tempting it is to route budgets into more appealing areas like AI. </p><p>Should more businesses begin to act faster, when 'Q-Day' begins to take hold, there's still every chance, much like the Y2K bug, that this will become yet another amusing anecdote from the annals of tech history about a massive computing threat that was avoided.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/how-seriously-is-your-business-taking-the-q-day-threat-and-can-you-really-be-ready-by-2029</link>
                                                                            <description>
                            <![CDATA[ The pace of progress on quantum computing isn't slowing down, but so many businesses still haven't prepared for the looming threat – with experts now shifting their rhetoric toward damage limitation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GHXSXxUcuJ73QVF6HDKVGA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 11:06:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:description>                                                            <media:text><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you can cast your mind back to 1999, the computing world was in a frenzy over the Y2K bug, or Millennium Bug, a coding flaw where systems abbreviated four-digit years to two digits – so, 99 instead of 1999. </p><p>First identified in 1958, the fear was that computers would read '00' as 1900 instead of 2000, potentially crashing global infrastructure. As such, $300 billion (now worth a staggering $600 billion in today's money) was spent to upgrade computers and application programs so they were Y2K-compliant. Because of this monumental effort over many years, the crisis was largely averted.</p><p>In 2026, a similar panic is simmering at a glacial pace. The fear is Q-Day: a hypothetical moment at which quantum computers become so powerful that they can crack encryption algorithms within seconds. Leading industry figures, quantum computing companies, cybersecurity advisors, and even <a href="https://www.govinfo.gov/content/pkg/DCPD-202200355/html/DCPD-202200355.htm"><u>national government agencies</u></a> have been warning about this moment for years — as far back as 1994, when mathematician Peter Shor first published his paper warning about this exact possibility. </p><p>Since then, the threat has felt far away and abstract – with under-pressure businesses spending their precious IT budgets on more immediate threats. </p><p>But in March 2026, Google Quantum AI published research revealing that quantum computers can crack the encryption underpinning Bitcoin using under 500,000 physical qubits. As such, <a href="https://www.itpro.com/security/google-just-revised-its-q-day-timeline-quantum-computers-could-break-existing-encryption-techniques-within-three-years-and-enterprises-are-nowhere-near-ready"><u>Google accelerated its migration timeline</u></a> from the 2030s to 2029. This is simply one example of the industry ramping up the pace of its migration, with another <a href="https://arxiv.org/html/2603.28627v1"><u>March study</u></a> showing quantum computers may need as few as 10,000 qubits to one day break the most secure encryption algorithms. </p><p>But that doesn't seem to have moved the needle very much, with countless businesses still completely unprotected or in the very earliest stages of exploring moves to implement post-quantum cryptography (PQC) or related countermeasures. With the timelines accelerating, why is the business world still so slow to react to these looming threats that lie over the horizon?    </p><h2 id="how-prepared-are-we-for-a-post-quantum-world">How prepared are we for a post-quantum world?</h2><p>Existing research into business preparedness is incredibly bleak. The vast majority (90%) of companies don't have systems in place to defend against quantum security threats, according to <a href="https://www.itpro.com/security/90-percent-of-companies-are-woefully-unprepared-for-quantum-security-threats-analysts-say-they-need-to-get-a-move-on"><u>Bain & Company analysis</u></a>. It's a similar, albeit less extreme, story with <a href="https://www.itpro.com/security/nearly-half-of-enterprises-arent-prepared-for-quantum-cybersecurity-threats"><u>Keyfactor research</u></a> that shows nearly half (48%) aren't ready. </p><p>Juniper Research found that just 27% of global companies will deploy PQC – but only by 2035. Right now, that figure stands at roughly 0.0009%, or just 35,000. Compound these findings with <a href="https://cdn.prod.website-files.com/643b94c382e84463a9e52264/698a5056aa19e254d8105a24_Part_1_2026_Quantum_Readiness_Survey_Report.pdf"><u>QuEra research</u></a> that showed the level of confidence in quantum preparedness actually fell from 65% to 55% between 2025 and 2026, meaning that as the threats become less abstract, businesses are increasingly aware that the measures they've taken may not be sufficient. </p><p>There's a readiness gap – no matter how you interpret the many and various findings. But what does this actually mean in practice and why is there such a large gap? Knowledge is the primary deficit, says Arjun Kudinoor, a doctoral student and NSF Graduate Research Fellow at MIT, as well as quantum security advisor at Protegrity. Many organizations lack the required expertise to understand the risks, prepare existing systems, and identify valuable applications, according to Kudinoor.</p><p>"Businesses must begin developing quantum literacy across technical and executive teams, assessing their exposure to quantum-enabled cybersecurity threats, and identifying problems for which quantum computing could provide a meaningful advantage," he adds. </p><p>But according to Orange Business' quantum-safe network lead and program director of edge computing, Frank de Jong, awareness has increased significantly in the last few years. </p><p>He tells <em>ITPro</em>: "It is impossible to be quantum-ready today, and in my opinion, it is also questionable if you could be completely quantum-safe before 2029. That's why we advise customers to start planning now and prioritize protecting their most valuable assets first. The key is to begin the journey, not to wait for perfect conditions."</p><p>As things stand, some sectors are more prepared than others. The earliest movers were telecoms providers and infrastructure-heavy organizations, with financial services, healthcare and software providers following suit. But it's also true to say that preparedness varies more based on resources and expertise, adds Kudinoor. He explains that firms with strong technical teams, quantum-related budgets, and executives concerned about planning for the threat are moving the fastest.</p><h2 id="avoiding-a-slow-motion-quantum-disaster">Avoiding a slow-motion quantum disaster</h2><p>Quantum computing is difficult to wrap your head around, and it's long been a technology that's some years away from maturation. For that reason, it might be tempting for many to have kicked the issue deep into the long grass. Suja Viswesan, IBM VP of security software, acknowledges this impact. "It can feel overwhelming at the sheer magnitude of possible impact. But the best place to start is by gaining visibility. You can’t fix what you can’t see." </p><p>Businesses, she says, should start small by mapping cryptographic assets – including certificates, secrets and API keys – across their environments. Then, they should prioritize risk and introduce controls such as proxy layers to, as she puts it, "buy time" before full PQC upgrades are available. </p><p>Kohinoor rejects the notion that quantum computing's threats are abstract, telling <em>ITPro</em>: "Much work has been done to estimate the number of qubits, error rates, and error correction methods required to implement such quantum factoring algorithms on quantum hardware." </p><p>The most powerful quantum computers commercially available are only one or two orders of magnitude away from breaking encryption schemes like RSA-2048. Thankfully, he adds, it's "not yet a disaster" because we are still several difficult breakthroughs away from achieving a fault-tolerant cryptographically relevant quantum computer. </p><p>So what's to explain the general malaise in preparing for this eventuality? The answer may lie on the balance sheet – and the IT and security budgets that so many organizations are under pressure to spend on far more immediate threats.</p><p>Although <a href="https://www.itpro.com/infrastructure/gartner-just-revised-its-global-it-spending-projection-for-2026-heres-why"><u>IT spending is expected to hit $6.37 trillion this year</u></a>, 14.2% higher than last year's spend, much of this has been allocated toward either trendier areas or toward more concrete threats. As de Jong puts it, IT budgets are spent "on where the center of attention is".</p><p>"In recent years, this was predominantly AI, and still today, this is where the majority of the “additional” money gets spent," he explains. </p><p>"Transitioning to quantum-safe infrastructure isn't a simple project. It will require substantial, sustained investment over many years. The most urgent call to action for CXOs today is to start planning and allocating substantial budgets for the coming years. This isn't fear-mongering — it's pragmatism. We cannot afford to wait and see."   </p><h2 id="is-it-too-late-to-prepare-for-the-post-quantum-world">Is it too late to prepare for the post-quantum world? </h2><p>The urgency is certainly there, and many experts fear it's far too late to avoid the damage – especially given the rise of <a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them"><u>"harvest now, decrypt later" (HNDL) attacks</u></a> – in which cybercriminals steal encrypted data with the intent of cracking it in the years to come using quantum computers. </p><p>But even if that were the case, there's still far more damage that can be done if businesses are sluggish about getting their defenses sorted. In that vein, the experts we interviewed say it's never too late to prepare.</p><p>"As the saying goes, ‘The best time to plant a tree was 20 years ago. The second-best time is now.’ The challenge with cybersecurity threats is that they may or may not affect you, but the fact that they could is sufficient reason to pay attention," de Jong says, but concedes that many will never be fully prepared. </p><p>"Most organizations face 15 years of work to become quantum-safe, but they may have only three years to do it. This means that they need to prioritize and accept the fact that not every asset can be defended at the same level from the start."</p><p>In the last few years, the mood has certainly shifted away from maximum preparedness to damage limitation as the reality has hit the industry that businesses haven't been moving quickly enough. MIT's Kudinoor advises businesses to upgrade all systems to PQC, beginning with the highest priority and most publicly available systems. </p><p>But the reality is that the threats themselves won't all hit at once – despite the 'Q-Day' label implying there's a single moment in the future beyond which there's no return. As IBM's Viswesan explains: "We’ll see it materialize over time, spanning multiple years as different cryptographic systems become vulnerable at different times." </p><h2 id="quantum-readiness-is-all-about-making-haste-slowly">Quantum readiness is all about making haste slowly</h2><p>Given the gradual and unfolding nature of 'Q-Day',  businesses should avoid rushing their decision-making and adopt a balanced and thoughtful approach, whether that's in assessing their estate or engaging with vendors. </p><p>The name for this dilemma – in which you need to act fast but not so fast that you end up making poor decisions – is "festina lente", a Latin term that roughly translates to "hurry slowly". But that's easier said than done.</p><p>"Organizations shouldn't wait to begin the transformation journey, but they also shouldn't rush into decisions. That’s where crypto-agility comes into play," Viswesan continues. </p><p>"Crypto‑agility is the ability to migrate to post-quantum cryptography (PQC), while maintaining the flexibility to make changes without business disruption. Crypto‑agility allows organizations to scale cryptography‑based data protection with confidence, reduce the operational costs associated with managing cryptography, and meaningfully lower long‑term security risk."</p><p>What about quantum companies themselves? After all, aren't they causing the problem in the first place? As de Jong says, the supply chain is already seeing a lot of countermeasures embedded into products by design, for example, quantum-safe features in the systems that cloud companies provide. </p><p>Pro bono support may also be available to smaller companies without the budgets or expertise to fight this battle. But, he says, the problem is likely to impact the larger companies the most. </p><p>To adequately prepare, the experts also recommend that building quantum literacy among technical teams and executives is essential. These teams should then devise roadmaps, with budgets over the coming years incorporating more quantum line items. </p><p>This transition is new to almost everyone, meaning that it's a journey of discovery and the best practice is still being formulated. There are, however, companies that are further along the journey than others – and organizations should liaise with one another so that everyone can benefit together.</p><p>"The transition to quantum-safe is new for almost everyone," de Jong adds, "so I would advise enterprise CXOs not to try and reinvent the wheel themselves, but rather work with companies that have been working on it for several years, so everyone can benefit from the collective knowledge."</p><p>The timelines are shrinking with each quantum computing breakthrough, and there's a general acceptance among experts that it won't be possible for businesses to be fully quantum-ready by 2029 – especially if you factor in the HNDL attacks that have already happened. </p><p>That said, it's never too late to act to avoid the very worst of it, and businesses should do what they can to get as far ahead of this threat as possible before it's too late – no matter how tempting it is to route budgets into more appealing areas like AI. </p><p>Should more businesses begin to act faster, when 'Q-Day' begins to take hold, there's still every chance, much like the Y2K bug, that this will become yet another amusing anecdote from the annals of tech history about a massive computing threat that was avoided.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anthropic resumes model testing after recent cyber incidents ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Anthropic is back to testing security models after systems went rogue – and claims the incident wasn’t entirely down to security faults but AI misalignment. </p><p>Back in July, Anthropic revealed its Claude models had slipped out of their apparent bounds to hack third-party systems. Days later, its <a href="https://www.itpro.com/security/cyber-attacks/anthropics-mythos-ai-tried-to-dupe-devs-in-social-engineering-attack-collaborated-with-other-agents"><u>Mythos system was spotted</u></a> with similar alarming behavior by the UK AI Security Institute. </p><p>The incidents followed <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime"><u>OpenAI revealing similar behavior</u></a> from its own security models. </p><p>Last week, <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident"><u>OpenAI reported on its own incident</u></a>, detailing plans to improve security around such models, and Anthropic has followed with its own efforts, including confirmation that it will begin testing again. </p><p>Anthropic noted it was currently conducting a review of what happened and said it is "planning" to work with METR on an independent review; OpenAI has already published an independent METR review into its own incident. </p><p>But Anthropic isn't waiting to make changes. In a <a href="https://www.anthropic.com/news/improving-alignment-security-efforts" target="_blank"><u>blog post</u></a> on 31 August, the firm said it plans to make tweaks to containment and monitoring, introduce new rules for third-party testers, as well as changes to the models. </p><p>Notably, the AI developer revealed it is seconding 150 product engineers to focus primarily on security. </p><p>"We believe the incidents reflect a failure of operational security, as well as two alignment issues: motivated reasoning, and willingness to take harmful actions in pursuit of a narrow task," the company said. </p><h2 id="anthropic-is-back-testing">Anthropic is back testing</h2><p>While the full investigation isn't yet complete, Anthropic said it was removing a "pause" on external <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>evaluations of pre-release models as well as internal tests. </p><p>To avoid similar issues happening again, Anthropic is adding additional layers of security and "hardening" the sandbox where these models are set loose, noting that move was prompted by its own evidence as well as that shared by OpenAI. </p><p>The changes include a system to spot when a model attempts to escape a testing environment or obtains internet access, immediately blocking the activity and alerting people overseeing the task, as well as fixing potential flaws and misconfigurations in the sandbox. </p><p>"We migrated high-risk internal cyber sandboxes to more robust isolation," the post added. "We are also further red-teaming our virtualization stack – that is, tasking pre-release models to try and escape it – to find and patch weaknesses."</p><p>Similar protections have been applied to reinforcement learning environments, with Anthropic adding it plans to expand its monitoring across most other internal frontier agentic usage. </p><p>Beyond testing environments, Anthropic is hardening security across the company, including blocking outbound traffic by default on computing clusters, boosting identity verification on internal services, retiring legacy services, and reducing the number of human and automated accounts that can access model weights or customer data. </p><h2 id="tougher-testing-rules">Tougher testing rules</h2><p>With regard to third-party testing, Anthropic said it will require testers to commit to a fresh set of best practices, noting that the reported incidents all took place in external evaluation environments. </p><p>As <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents"><u><em>ITPro </em></u><u>reported last month</u></a>, Israeli startup Irregular was identified as the external model testing firm involved in all three ‘rogue AI’ incidents involving Anthropic, OpenAI, and Meta. </p><p>The changes include running tests inside hardened sandboxes with no internet access, tasking the model being tested to look for flaws before tests under close human supervision, run monitoring continuously, and confirm whether test tasks are impossible or not. </p><p>"When an evaluation target is offline or a task can’t be completed, agents will often look for other ways to complete a challenge, increasing the chance that they take actions outside the intended scope of the evaluation," the company said. </p><h2 id="unpicking-why">Unpicking why</h2><p>Those operational changes should help prevent models from escaping their sandboxes, but Anthropic said it wants to better understand why its systems took such "dangerous actions" in the first place. </p><p>While the full investigation continues, Anthropic highlighted two challenges with alignment, which refers to ensuring that AI behaves how humans want and expect. </p><p>"One is motivated reasoning: the models were initially told their environments were simulated, but when they later encountered evidence that they were connected to the real internet, they may have interpreted that evidence in a way that allowed them to maintain that belief," the blog post explained. </p><p>"The second is recklessness: the model was willing to take harmful actions on the real internet in pursuit of the narrow goal of solving a cybersecurity evaluation."</p><p>The company noted that poorly designed training environments – including ones that are easy to cheat in or impossible to solve without cheating – can lead to misalignment behavior. </p><p>Anthropic is trying to avoid such issues in the future. The company said work on thie front goes back several months and involves training poorly and training well to try to spot differences – but admitted that the July incidents show "our process isn't perfect and our models aren't perfectly aligned". </p><p>Further details on security improvements are expected in the full report, according to Anthropic. </p><p>Beyond that, the firm also loosely backed calls to develop a framework for safe development of security-focused AI, acknowledging that its own executives had recently signed an open letter demanding better coordination globally. </p><p>Anthropic said it would "say more in the coming weeks" but intended to contribute to such efforts. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/anthropic-resumes-model-testing-after-recent-cyber-incidents-but-its-introduced-new-rules-to-improve-security</link>
                                                                            <description>
                            <![CDATA[ Anthropic has boosted its security and tweaked its training to avoid rogue AI ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">prrkks6bEQDGqqZoVB8jKR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jLZncMSkFV4MARFdHwLLV5-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 14:37:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S-320-70.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jLZncMSkFV4MARFdHwLLV5-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of AI startup Anthropic, developer of the Claude Opus 4 and Sonnet 4 AI models, pictured on a smartphone held in a human hand.]]></media:description>                                                            <media:text><![CDATA[Logo of AI startup Anthropic, developer of the Claude Opus 4 and Sonnet 4 AI models, pictured on a smartphone held in a human hand.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of AI startup Anthropic, developer of the Claude Opus 4 and Sonnet 4 AI models, pictured on a smartphone held in a human hand.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jLZncMSkFV4MARFdHwLLV5-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anthropic is back to testing security models after systems went rogue – and claims the incident wasn’t entirely down to security faults but AI misalignment. </p><p>Back in July, Anthropic revealed its Claude models had slipped out of their apparent bounds to hack third-party systems. Days later, its <a href="https://www.itpro.com/security/cyber-attacks/anthropics-mythos-ai-tried-to-dupe-devs-in-social-engineering-attack-collaborated-with-other-agents"><u>Mythos system was spotted</u></a> with similar alarming behavior by the UK AI Security Institute. </p><p>The incidents followed <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime"><u>OpenAI revealing similar behavior</u></a> from its own security models. </p><p>Last week, <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident"><u>OpenAI reported on its own incident</u></a>, detailing plans to improve security around such models, and Anthropic has followed with its own efforts, including confirmation that it will begin testing again. </p><p>Anthropic noted it was currently conducting a review of what happened and said it is "planning" to work with METR on an independent review; OpenAI has already published an independent METR review into its own incident. </p><p>But Anthropic isn't waiting to make changes. In a <a href="https://www.anthropic.com/news/improving-alignment-security-efforts" target="_blank"><u>blog post</u></a> on 31 August, the firm said it plans to make tweaks to containment and monitoring, introduce new rules for third-party testers, as well as changes to the models. </p><p>Notably, the AI developer revealed it is seconding 150 product engineers to focus primarily on security. </p><p>"We believe the incidents reflect a failure of operational security, as well as two alignment issues: motivated reasoning, and willingness to take harmful actions in pursuit of a narrow task," the company said. </p><h2 id="anthropic-is-back-testing">Anthropic is back testing</h2><p>While the full investigation isn't yet complete, Anthropic said it was removing a "pause" on external <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>evaluations of pre-release models as well as internal tests. </p><p>To avoid similar issues happening again, Anthropic is adding additional layers of security and "hardening" the sandbox where these models are set loose, noting that move was prompted by its own evidence as well as that shared by OpenAI. </p><p>The changes include a system to spot when a model attempts to escape a testing environment or obtains internet access, immediately blocking the activity and alerting people overseeing the task, as well as fixing potential flaws and misconfigurations in the sandbox. </p><p>"We migrated high-risk internal cyber sandboxes to more robust isolation," the post added. "We are also further red-teaming our virtualization stack – that is, tasking pre-release models to try and escape it – to find and patch weaknesses."</p><p>Similar protections have been applied to reinforcement learning environments, with Anthropic adding it plans to expand its monitoring across most other internal frontier agentic usage. </p><p>Beyond testing environments, Anthropic is hardening security across the company, including blocking outbound traffic by default on computing clusters, boosting identity verification on internal services, retiring legacy services, and reducing the number of human and automated accounts that can access model weights or customer data. </p><h2 id="tougher-testing-rules">Tougher testing rules</h2><p>With regard to third-party testing, Anthropic said it will require testers to commit to a fresh set of best practices, noting that the reported incidents all took place in external evaluation environments. </p><p>As <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents"><u><em>ITPro </em></u><u>reported last month</u></a>, Israeli startup Irregular was identified as the external model testing firm involved in all three ‘rogue AI’ incidents involving Anthropic, OpenAI, and Meta. </p><p>The changes include running tests inside hardened sandboxes with no internet access, tasking the model being tested to look for flaws before tests under close human supervision, run monitoring continuously, and confirm whether test tasks are impossible or not. </p><p>"When an evaluation target is offline or a task can’t be completed, agents will often look for other ways to complete a challenge, increasing the chance that they take actions outside the intended scope of the evaluation," the company said. </p><h2 id="unpicking-why">Unpicking why</h2><p>Those operational changes should help prevent models from escaping their sandboxes, but Anthropic said it wants to better understand why its systems took such "dangerous actions" in the first place. </p><p>While the full investigation continues, Anthropic highlighted two challenges with alignment, which refers to ensuring that AI behaves how humans want and expect. </p><p>"One is motivated reasoning: the models were initially told their environments were simulated, but when they later encountered evidence that they were connected to the real internet, they may have interpreted that evidence in a way that allowed them to maintain that belief," the blog post explained. </p><p>"The second is recklessness: the model was willing to take harmful actions on the real internet in pursuit of the narrow goal of solving a cybersecurity evaluation."</p><p>The company noted that poorly designed training environments – including ones that are easy to cheat in or impossible to solve without cheating – can lead to misalignment behavior. </p><p>Anthropic is trying to avoid such issues in the future. The company said work on thie front goes back several months and involves training poorly and training well to try to spot differences – but admitted that the July incidents show "our process isn't perfect and our models aren't perfectly aligned". </p><p>Further details on security improvements are expected in the full report, according to Anthropic. </p><p>Beyond that, the firm also loosely backed calls to develop a framework for safe development of security-focused AI, acknowledging that its own executives had recently signed an open letter demanding better coordination globally. </p><p>Anthropic said it would "say more in the coming weeks" but intended to contribute to such efforts. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security researchers warn of AI-powered PLC attacks in wake of Siemens advisories ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Security researchers have successfully used AI to port a remote code execution (RCE) exploit between two <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn">programmable logic controllers (PLCs)</a>. </p><p>While the experiment still required significant human expertise to negotiate dead ends and false leads, it showed how AI could make it easier to carry out attacks against embedded and industrial systems.</p><p>The team at Forescout’s Vedere Labs used AI to port an RCE exploit between two WAGO PLC models in an exploit that took eight hours and 32 minutes and consumed just $535.74 in API tokens.</p><p>Once code execution was achieved, AI produced multiple working network payloads within minutes, suggesting that post-exploitation could become increasingly automated as models improve.</p><p>The exploit targeted CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus FTP server that allowed arbitrary ARM shellcode to execute on the live PLC without credentials.</p><p>Researchers had already shown that RCE exploits on PLCs can enable Deep Lateral Movement and granular control over safety logic – and reckoned that as AI-assisted exploit development improves, these techniques could become more accessible.</p><h2 id="how-ai-was-used-to-crack-plcs">How AI was used to crack PLCs</h2><p>The AI-assisted exploit development process involved two steps, according to Forescout. First and foremost, this included confirming the vulnerability and writing the payload. </p><p>Each step consisted of interactive sessions between a researcher and <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal">Claude Code</a>, which had access to a terminal, the reference files, analysis tools including Ghidra, and the live target PLC.</p><p>Claude could use those tools directly, generate and test code, and ask the researcher for additional input when needed.</p><p>Researchers noted that Claude decided to confirm the presence of the vulnerability by both probing the live target and carrying out static code analysis. </p><p>It didn't work the first time, however, with one session failing to trace the vulnerable function correctly and producing an invalid exploit. </p><p>According to researchers, the analysis provided useful context for the next session, which used binary searches to map the relevant functions correctly – albeit with researcher input to steer the analysis away from dead ends and provide additional disassembly context where necessary.</p><p>Writing a working RCE exploit took much longer, with initial attempts failing. Claude also wasted a lot of time testing incorrect hypotheses, decompiling unrelated code, and pursuing false leads.</p><p>The researchers had to change to <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-reveals-claude-opus-4-6-enterprise-focused-model-1-million-token-context-window">Claude Opus 4.6</a> with 1M context, and add the prompt: “Ask for my help with disassembly if you are not certain about a firmware detail”, and instruct the AI to the sink of the vulnerability – the point where the attacker-supplied username is copied into memory.</p><p>Claude could then reason about the function call chain leading to the sink and understand that it needed more context about how FTP packets are treated throughout this call chain.</p><h2 id="operational-technology-in-the-crosshairs">Operational technology in the crosshairs</h2><p>Organizations shouldn't dismiss <a href="https://www.itpro.com/security/369739/high-severity-vulnerabilities-uncovered-in-three-quarters-of-operational-technology">operational technology (OT) vulnerabilities</a> because they seem hard to exploit, researchers warned.</p><p>"AI has already lowered the barrier to vulnerability research and exploit development in higher-level software. This experiment suggests that the same progression is beginning to reach low-level embedded systems, although substantial barriers remain," the report noted..</p><p>"As models become more capable and independent, the cost and expertise required to adapt exploits across related embedded targets could fall substantially."</p><p>The advice on mitigation is pretty standard: reduce unnecessary OT device exposure, monitor <a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot">OT environments</a> for early signs of exploitation, exercise incident response against AI-assisted OT attack paths and use AI defensively, but validate its outputs.</p><p>Programmable logic controllers are rapidly emerging as a major risk to critical infrastructure. The US National Security Agency (NSA) issued a <a href="https://www.itpro.com/security/an-evolution-in-threat-actor-capabilities-cisa-warns-hackers-are-targeting-siemens-industrial-controllers-and-theyre-using-ai-generated-code"><u>warning</u></a> last month over an active threat against Siemens PLCs.</p><p>Similarly, in recent months, a series of <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>attacks on US water supply infrastructure</u></a> targeted internet-exposed PLCs, with the attackers remotely changing IP addresses and turning on and setting passwords. </p><p>Several water firms were left unable to view connected equipment, and in some cases it was shut down. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories</link>
                                                                            <description>
                            <![CDATA[ While the exploit required significant human help, Forescout says it could become a significant threat in future ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c7eafuMpjRRyW8X23c4KYM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qXYXXdT4d7pCmVTE7ztgCc-1920-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ-320-70.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qXYXXdT4d7pCmVTE7ztgCc-1920-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Programmable logic controllers (PLCs) pictured inside an industrial cabinet unit with LEDs, power supply, relays, and organized wire ducts.]]></media:description>                                                            <media:text><![CDATA[Programmable logic controllers (PLCs) pictured inside an industrial cabinet unit with LEDs, power supply, relays, and organized wire ducts.]]></media:text>
                                <media:title type="plain"><![CDATA[Programmable logic controllers (PLCs) pictured inside an industrial cabinet unit with LEDs, power supply, relays, and organized wire ducts.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qXYXXdT4d7pCmVTE7ztgCc-1920-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have successfully used AI to port a remote code execution (RCE) exploit between two <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn">programmable logic controllers (PLCs)</a>. </p><p>While the experiment still required significant human expertise to negotiate dead ends and false leads, it showed how AI could make it easier to carry out attacks against embedded and industrial systems.</p><p>The team at Forescout’s Vedere Labs used AI to port an RCE exploit between two WAGO PLC models in an exploit that took eight hours and 32 minutes and consumed just $535.74 in API tokens.</p><p>Once code execution was achieved, AI produced multiple working network payloads within minutes, suggesting that post-exploitation could become increasingly automated as models improve.</p><p>The exploit targeted CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus FTP server that allowed arbitrary ARM shellcode to execute on the live PLC without credentials.</p><p>Researchers had already shown that RCE exploits on PLCs can enable Deep Lateral Movement and granular control over safety logic – and reckoned that as AI-assisted exploit development improves, these techniques could become more accessible.</p><h2 id="how-ai-was-used-to-crack-plcs">How AI was used to crack PLCs</h2><p>The AI-assisted exploit development process involved two steps, according to Forescout. First and foremost, this included confirming the vulnerability and writing the payload. </p><p>Each step consisted of interactive sessions between a researcher and <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal">Claude Code</a>, which had access to a terminal, the reference files, analysis tools including Ghidra, and the live target PLC.</p><p>Claude could use those tools directly, generate and test code, and ask the researcher for additional input when needed.</p><p>Researchers noted that Claude decided to confirm the presence of the vulnerability by both probing the live target and carrying out static code analysis. </p><p>It didn't work the first time, however, with one session failing to trace the vulnerable function correctly and producing an invalid exploit. </p><p>According to researchers, the analysis provided useful context for the next session, which used binary searches to map the relevant functions correctly – albeit with researcher input to steer the analysis away from dead ends and provide additional disassembly context where necessary.</p><p>Writing a working RCE exploit took much longer, with initial attempts failing. Claude also wasted a lot of time testing incorrect hypotheses, decompiling unrelated code, and pursuing false leads.</p><p>The researchers had to change to <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-reveals-claude-opus-4-6-enterprise-focused-model-1-million-token-context-window">Claude Opus 4.6</a> with 1M context, and add the prompt: “Ask for my help with disassembly if you are not certain about a firmware detail”, and instruct the AI to the sink of the vulnerability – the point where the attacker-supplied username is copied into memory.</p><p>Claude could then reason about the function call chain leading to the sink and understand that it needed more context about how FTP packets are treated throughout this call chain.</p><h2 id="operational-technology-in-the-crosshairs">Operational technology in the crosshairs</h2><p>Organizations shouldn't dismiss <a href="https://www.itpro.com/security/369739/high-severity-vulnerabilities-uncovered-in-three-quarters-of-operational-technology">operational technology (OT) vulnerabilities</a> because they seem hard to exploit, researchers warned.</p><p>"AI has already lowered the barrier to vulnerability research and exploit development in higher-level software. This experiment suggests that the same progression is beginning to reach low-level embedded systems, although substantial barriers remain," the report noted..</p><p>"As models become more capable and independent, the cost and expertise required to adapt exploits across related embedded targets could fall substantially."</p><p>The advice on mitigation is pretty standard: reduce unnecessary OT device exposure, monitor <a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot">OT environments</a> for early signs of exploitation, exercise incident response against AI-assisted OT attack paths and use AI defensively, but validate its outputs.</p><p>Programmable logic controllers are rapidly emerging as a major risk to critical infrastructure. The US National Security Agency (NSA) issued a <a href="https://www.itpro.com/security/an-evolution-in-threat-actor-capabilities-cisa-warns-hackers-are-targeting-siemens-industrial-controllers-and-theyre-using-ai-generated-code"><u>warning</u></a> last month over an active threat against Siemens PLCs.</p><p>Similarly, in recent months, a series of <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>attacks on US water supply infrastructure</u></a> targeted internet-exposed PLCs, with the attackers remotely changing IP addresses and turning on and setting passwords. </p><p>Several water firms were left unable to view connected equipment, and in some cases it was shut down. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>