<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.itpro.com/security/feed" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from ITPro ]]></title>
                <link>https://www.itpro.com/security/feed</link>
        <description><![CDATA[ All the latest content from the ITPro team ]]></description>
                                    <lastBuildDate>Tue, 08 Sep 2026 09:48:14 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Samsung backs Mistral in record-breaking €3 billion funding round as French AI firm targets sovereign AI gains ]]></title>
                                                                                                <dc:content><![CDATA[ <p>French AI giant Mistral has raised €3 billion to support frontier model research and development of sovereign, <a href="https://www.itpro.com/software/open-source/the-pros-and-cons-of-open-source-ai-for-business">open-weight systems</a>. </p><p>The funding, led by Samsung Electronics and Scaleup Europe Fund, is the largest equity round by a European tech company and values Mistral at €21 billion. </p><p>The aim is to train "bigger and faster models", CEO Arthur Mensch told <a href="https://www.cnbc.com/2026/09/08/mistral-ai-funding-valuation-samsung.html" target="_blank"><u><em>CNBC</em></u></a>, but Mistral also said in a blog post that its focus was <a href="https://www.itpro.com/technology/artificial-intelligence/big-tech-faces-an-adapt-or-die-predicament-with-open-weight-ai-models"><u>open-weight models</u></a> built and run in Europe that allow companies to keep hold of their data. </p><p>"During the first wave of generative AI, the central question was who could build the most powerful model," the company said in a blog post. </p><p>"Organizations and governments are now asking a different one: how to harness the power of AI for their mission-critical needs without surrendering control over the infrastructure and intelligence loop."</p><p>Mistral added that demand for a “combination of performance and control, choice, and independence” is growing globally. </p><p>The company said enterprises are governments alike are now weighing up long-term tech dependencies, governance requirements and “deployment choices that come with any AI investment”. </p><h2 id="mistral-eyes-sovereign-ai-gains">Mistral eyes sovereign AI gains</h2><p>The importance of <a href="https://www.itpro.com/technology/artificial-intelligence/can-europe-achieve-ai-sovereignty"><u>sovereign AI</u></a> was made clear earlier this year when Anthropic's security models were <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-suspends-fabel-and-mythos-systems-for-all-users-after-us-government-claims-jailbreak-risk"><u>temporarily hit by an export ban</u></a>. </p><p>More generally, <a href="https://www.itpro.com/infrastructure/sovereign-infrastructure-spend-to-triple-in-europe-as-fifth-of-workloads-stay-local"><u>countries like France</u></a> and <a href="https://www.windowscentral.com/microsoft/microsoft-office/switzerland-testing-alternatives-to-microsoft-365-digital-sovereignty" target="_blank"><u>Switzerland are pushing away</u></a> from American technology firms for their own versions of software and services for government use. </p><p>Mistral in particular has positioned itself as an alternative not only to American dominance, but also the <a href="https://www.itpro.com/technology/artificial-intelligence/should-businesses-consider-using-chinese-ai-models"><u>open-weight models developed in China</u></a>. </p><p>"The fact that the EU or Europe have to have their own kind of AI provider in the game is important," chief financial officer Johan Bergqvist told <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u><em>Reuters</em></u></a><em>.</em></p><p>"We ​have seen in the past ​that there is ⁠politics involved in the access of these solutions, and it's important that you make sure that you maintain access and do not compromise your kind of supply ​chain,” he added. </p><p>That said, Mistral <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u>noted</u></a> that it was seeing particular growth in Asia and North America, with more than 125 global enterprises as customers based in 20 countries. </p><p>"The round reflects a strategic endorsement from investors across Europe, Asia and North America," Mistral said in the blog post. </p><p>"It brings together a world-class syndicate of strategic and financial investors, including global technology leaders, growth investors and existing shareholders that have supported Mistral’s development to date."</p><h2 id="paying-for-the-ai-rollout">Paying for the AI rollout</h2><p>Beyond investing in frontier research, the funding round will be used to boost AI infrastructure available to Mistral, Mensch said. </p><p>"Long term, the plan is to fully rely on capacity that we are building ourselves, and so that means that the amount of compute that we own is going to grow ... around 100% in the next five years," Mensch told <em>CNBC</em>. </p><p>Speaking to the <a href="https://www.ft.com/content/adbf5262-c4d5-4312-a9b8-4d3cf30c9e00?syn-25a6b1a6=1" target="_blank"><u><em>Financial Times</em></u></a>, Mensch added that the funding will allow Mistral to reach an "amount of compute that is very comparable to what the Chinese labs have."</p><p>However, the investment is small compared to the figures coming out of the US, with <a href="https://www.itpro.com/security/open-weight-models-are-closing-the-capability-gap-with-frontier-models-at-a-fraction-of-the-cost-cheap-chinese-ai-models-could-spell-trouble-for-us-big-tech"><u>$1trn set to be spent on AI infrastructure this year alone</u></a>, and rivals such as Anthropic and OpenAI <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u>valued</u></a> at $965bn and $852bn ahead of looming IPOs. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/samsung-backs-mistral-in-record-breaking-eur3-billion-funding-round-as-french-ai-firm-targets-sovereign-ai-gains</link>
                                                                            <description>
                            <![CDATA[ The French AI company breaks European records, but still trails American rivals with a €21bn valuation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4rnA6QqviqpvUNJaWBhFmL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fVKmsVEFVJ8unyV6qir3Mh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 09:48:14 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fVKmsVEFVJ8unyV6qir3Mh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mistral AI founder Arthur Mensch speaks at the ai-Pulse conference at Station F technology campus in Paris, France, on Friday, Nov. 17, 2023]]></media:description>                                                            <media:text><![CDATA[Mistral AI founder Arthur Mensch speaks at the ai-Pulse conference at Station F technology campus in Paris, France, on Friday, Nov. 17, 2023]]></media:text>
                                <media:title type="plain"><![CDATA[Mistral AI founder Arthur Mensch speaks at the ai-Pulse conference at Station F technology campus in Paris, France, on Friday, Nov. 17, 2023]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fVKmsVEFVJ8unyV6qir3Mh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>French AI giant Mistral has raised €3 billion to support frontier model research and development of sovereign, <a href="https://www.itpro.com/software/open-source/the-pros-and-cons-of-open-source-ai-for-business">open-weight systems</a>. </p><p>The funding, led by Samsung Electronics and Scaleup Europe Fund, is the largest equity round by a European tech company and values Mistral at €21 billion. </p><p>The aim is to train "bigger and faster models", CEO Arthur Mensch told <a href="https://www.cnbc.com/2026/09/08/mistral-ai-funding-valuation-samsung.html" target="_blank"><u><em>CNBC</em></u></a>, but Mistral also said in a blog post that its focus was <a href="https://www.itpro.com/technology/artificial-intelligence/big-tech-faces-an-adapt-or-die-predicament-with-open-weight-ai-models"><u>open-weight models</u></a> built and run in Europe that allow companies to keep hold of their data. </p><p>"During the first wave of generative AI, the central question was who could build the most powerful model," the company said in a blog post. </p><p>"Organizations and governments are now asking a different one: how to harness the power of AI for their mission-critical needs without surrendering control over the infrastructure and intelligence loop."</p><p>Mistral added that demand for a “combination of performance and control, choice, and independence” is growing globally. </p><p>The company said enterprises are governments alike are now weighing up long-term tech dependencies, governance requirements and “deployment choices that come with any AI investment”. </p><h2 id="mistral-eyes-sovereign-ai-gains">Mistral eyes sovereign AI gains</h2><p>The importance of <a href="https://www.itpro.com/technology/artificial-intelligence/can-europe-achieve-ai-sovereignty"><u>sovereign AI</u></a> was made clear earlier this year when Anthropic's security models were <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-suspends-fabel-and-mythos-systems-for-all-users-after-us-government-claims-jailbreak-risk"><u>temporarily hit by an export ban</u></a>. </p><p>More generally, <a href="https://www.itpro.com/infrastructure/sovereign-infrastructure-spend-to-triple-in-europe-as-fifth-of-workloads-stay-local"><u>countries like France</u></a> and <a href="https://www.windowscentral.com/microsoft/microsoft-office/switzerland-testing-alternatives-to-microsoft-365-digital-sovereignty" target="_blank"><u>Switzerland are pushing away</u></a> from American technology firms for their own versions of software and services for government use. </p><p>Mistral in particular has positioned itself as an alternative not only to American dominance, but also the <a href="https://www.itpro.com/technology/artificial-intelligence/should-businesses-consider-using-chinese-ai-models"><u>open-weight models developed in China</u></a>. </p><p>"The fact that the EU or Europe have to have their own kind of AI provider in the game is important," chief financial officer Johan Bergqvist told <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u><em>Reuters</em></u></a><em>.</em></p><p>"We ​have seen in the past ​that there is ⁠politics involved in the access of these solutions, and it's important that you make sure that you maintain access and do not compromise your kind of supply ​chain,” he added. </p><p>That said, Mistral <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u>noted</u></a> that it was seeing particular growth in Asia and North America, with more than 125 global enterprises as customers based in 20 countries. </p><p>"The round reflects a strategic endorsement from investors across Europe, Asia and North America," Mistral said in the blog post. </p><p>"It brings together a world-class syndicate of strategic and financial investors, including global technology leaders, growth investors and existing shareholders that have supported Mistral’s development to date."</p><h2 id="paying-for-the-ai-rollout">Paying for the AI rollout</h2><p>Beyond investing in frontier research, the funding round will be used to boost AI infrastructure available to Mistral, Mensch said. </p><p>"Long term, the plan is to fully rely on capacity that we are building ourselves, and so that means that the amount of compute that we own is going to grow ... around 100% in the next five years," Mensch told <em>CNBC</em>. </p><p>Speaking to the <a href="https://www.ft.com/content/adbf5262-c4d5-4312-a9b8-4d3cf30c9e00?syn-25a6b1a6=1" target="_blank"><u><em>Financial Times</em></u></a>, Mensch added that the funding will allow Mistral to reach an "amount of compute that is very comparable to what the Chinese labs have."</p><p>However, the investment is small compared to the figures coming out of the US, with <a href="https://www.itpro.com/security/open-weight-models-are-closing-the-capability-gap-with-frontier-models-at-a-fraction-of-the-cost-cheap-chinese-ai-models-could-spell-trouble-for-us-big-tech"><u>$1trn set to be spent on AI infrastructure this year alone</u></a>, and rivals such as Anthropic and OpenAI <a href="https://www.reuters.com/world/europe/french-ai-company-mistral-hits-24-billion-valuation-funding-round-2026-09-08/" target="_blank"><u>valued</u></a> at $965bn and $852bn ahead of looming IPOs. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The hidden cost of tool sprawl on the channel ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The cybersecurity industry is awash with products.</p><p>Every time a new attack technique is discovered, vendors will rush to develop a product to address the challenge. </p><p>Whether it be malware prevention, privileged access management, next-generation firewalls, or email security platforms, the industry is flooded with platforms promising to improve defences and make it harder for attackers to infiltrate systems.</p><p>But in reality, this has made security very noisy. </p><p>Instead of improving security, the volume of tools organisations must manage has actually amplified risks.</p><p>There are too many alerts coming in to understand and identify threats quickly. Too many platforms to manage, which overburdens resources and amplifies costs, and too many interfaces to navigate, which makes managing security far from seamless.</p><p>Overall, while the objective of the platforms is to strengthen security, the products can actually jeopardise it.</p><p>However, these problems are significantly worse when it comes to Managed Service Providers (MSPs).</p><h2 id="tool-sprawl-in-the-channel">Tool sprawl in the channel</h2><p>Consider an MSP delivering security services to 50 customers.</p><p>One customer may use Microsoft security technologies, another CrowdStrike, while others could have different SIEM, vulnerability management, ticketing, and endpoint security platforms.</p><p>However, the MSP is often forced to operate them all. </p><p>All simultaneously, and all expertly, knowing the capabilities of each platform and how to operate them.</p><p>The MSP must maintain the knowledge, processes, and integrations required to operate across all of the platforms they manage for their clients. However, not only does this create resourcing challenges it also amplifies costs.</p><p>There is the cost of purchasing each platform that clients depend on, plus there is the cost of employees to manage the platforms.</p><p>Furthermore, with MSP staff continually navigating between platform interfaces, this wastes valuable time, reduces productivity, and can make managing security for clients more cumbersome.</p><p>Individually, these delays can appear insignificant. However, across hundreds or thousands of incidents, tickets, and customer interactions, they quickly accumulate.</p><p>Plus, as an MSP grows its customer base, the challenges can become even harder to manage.</p><h2 id="when-growth-introduces-more-complexity">When growth introduces more complexity</h2><p>Every business wants to grow its customer base, but for an MSP this can also mean introducing more tools into their environments.</p><p>If every new customer introduces another combination of technologies, integrations and processes, onboarding customers also introduces additional operational complexity.</p><p>Providers can find themselves in a position where growing the business requires continually adding more people to manage the additional workload.</p><p>This has obvious implications for margins, but it can also put pressure on existing teams. </p><p>Skilled cyber security professionals are already difficult and expensive to recruit. Using their time to perform repetitive administrative tasks or manually move between disconnected platforms is neither efficient nor sustainable.</p><p>Ultimately, the channel therefore needs to look beyond simply adding more technology and consider how existing technologies are operated.</p><p>There will always be customers that want or need different technologies. Channel providers therefore need to find ways to embrace this diversity without allowing it to dictate how efficiently they operate.</p><p>But how can this be achieved?</p><h2 id="the-importance-of-technology-agnostic-platforms">The importance of technology-agnostic platforms</h2><p>One of the best ways to overcome this challenge is by working with partners that deliver technology-agnostic platforms that simplify the management of security for MSPs.</p><p>These platforms can seamlessly integrate with the security platforms MSPs rely on for their customers, but they can be managed via a single dashboard.</p><p>This allows an MSP to more efficiently manage security, but without having to navigate across multiple platforms.</p><p>These platforms can deliver everything a partner needs to track, monitor, and manage the security of their customers, without overburdening resources or amplifying costs.</p><p>Instead, everything can be managed via a single unified platform, reducing complexity and cutting out the chaos of managing multiple solutions.</p><p>A technology-agnostic platform doesn't replace customer investments; it provides a common operational layer across them. </p><p>Analysts can investigate incidents, automate workflows, manage tickets, and monitor security posture from one interface while still supporting whichever technologies each customer has chosen.</p><p>The channel doesn't need fewer security technologies; it needs a better way to operate them. </p><p>MSPs that standardize their operations across diverse customer environments will reduce costs, improve analyst productivity, and deliver a more consistent service. </p><p>In an increasingly competitive market, operational efficiency isn't just an internal advantage; ultimately, it's a differentiator that leads to better security outcomes for customers and healthier margins for MSPs.  </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/the-hidden-cost-of-tool-sprawl-on-the-channel</link>
                                                                            <description>
                            <![CDATA[ Tool sprawl represents major challenges for MSPs, so how can the issue be tackled? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kcT4H7H39wP47bAapK2amh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ihZG9rnw3t3ZGBiY82SzAN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Software]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gemma Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/pKcnhWn69jhSZfdbR4f9xC.png ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ihZG9rnw3t3ZGBiY82SzAN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software sprawl concept image showing multiple applications all in siloed positions on a digital interace.]]></media:description>                                                            <media:text><![CDATA[Software sprawl concept image showing multiple applications all in siloed positions on a digital interace.]]></media:text>
                                <media:title type="plain"><![CDATA[Software sprawl concept image showing multiple applications all in siloed positions on a digital interace.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ihZG9rnw3t3ZGBiY82SzAN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The cybersecurity industry is awash with products.</p><p>Every time a new attack technique is discovered, vendors will rush to develop a product to address the challenge. </p><p>Whether it be malware prevention, privileged access management, next-generation firewalls, or email security platforms, the industry is flooded with platforms promising to improve defences and make it harder for attackers to infiltrate systems.</p><p>But in reality, this has made security very noisy. </p><p>Instead of improving security, the volume of tools organisations must manage has actually amplified risks.</p><p>There are too many alerts coming in to understand and identify threats quickly. Too many platforms to manage, which overburdens resources and amplifies costs, and too many interfaces to navigate, which makes managing security far from seamless.</p><p>Overall, while the objective of the platforms is to strengthen security, the products can actually jeopardise it.</p><p>However, these problems are significantly worse when it comes to Managed Service Providers (MSPs).</p><h2 id="tool-sprawl-in-the-channel">Tool sprawl in the channel</h2><p>Consider an MSP delivering security services to 50 customers.</p><p>One customer may use Microsoft security technologies, another CrowdStrike, while others could have different SIEM, vulnerability management, ticketing, and endpoint security platforms.</p><p>However, the MSP is often forced to operate them all. </p><p>All simultaneously, and all expertly, knowing the capabilities of each platform and how to operate them.</p><p>The MSP must maintain the knowledge, processes, and integrations required to operate across all of the platforms they manage for their clients. However, not only does this create resourcing challenges it also amplifies costs.</p><p>There is the cost of purchasing each platform that clients depend on, plus there is the cost of employees to manage the platforms.</p><p>Furthermore, with MSP staff continually navigating between platform interfaces, this wastes valuable time, reduces productivity, and can make managing security for clients more cumbersome.</p><p>Individually, these delays can appear insignificant. However, across hundreds or thousands of incidents, tickets, and customer interactions, they quickly accumulate.</p><p>Plus, as an MSP grows its customer base, the challenges can become even harder to manage.</p><h2 id="when-growth-introduces-more-complexity">When growth introduces more complexity</h2><p>Every business wants to grow its customer base, but for an MSP this can also mean introducing more tools into their environments.</p><p>If every new customer introduces another combination of technologies, integrations and processes, onboarding customers also introduces additional operational complexity.</p><p>Providers can find themselves in a position where growing the business requires continually adding more people to manage the additional workload.</p><p>This has obvious implications for margins, but it can also put pressure on existing teams. </p><p>Skilled cyber security professionals are already difficult and expensive to recruit. Using their time to perform repetitive administrative tasks or manually move between disconnected platforms is neither efficient nor sustainable.</p><p>Ultimately, the channel therefore needs to look beyond simply adding more technology and consider how existing technologies are operated.</p><p>There will always be customers that want or need different technologies. Channel providers therefore need to find ways to embrace this diversity without allowing it to dictate how efficiently they operate.</p><p>But how can this be achieved?</p><h2 id="the-importance-of-technology-agnostic-platforms">The importance of technology-agnostic platforms</h2><p>One of the best ways to overcome this challenge is by working with partners that deliver technology-agnostic platforms that simplify the management of security for MSPs.</p><p>These platforms can seamlessly integrate with the security platforms MSPs rely on for their customers, but they can be managed via a single dashboard.</p><p>This allows an MSP to more efficiently manage security, but without having to navigate across multiple platforms.</p><p>These platforms can deliver everything a partner needs to track, monitor, and manage the security of their customers, without overburdening resources or amplifying costs.</p><p>Instead, everything can be managed via a single unified platform, reducing complexity and cutting out the chaos of managing multiple solutions.</p><p>A technology-agnostic platform doesn't replace customer investments; it provides a common operational layer across them. </p><p>Analysts can investigate incidents, automate workflows, manage tickets, and monitor security posture from one interface while still supporting whichever technologies each customer has chosen.</p><p>The channel doesn't need fewer security technologies; it needs a better way to operate them. </p><p>MSPs that standardize their operations across diverse customer environments will reduce costs, improve analyst productivity, and deliver a more consistent service. </p><p>In an increasingly competitive market, operational efficiency isn't just an internal advantage; ultimately, it's a differentiator that leads to better security outcomes for customers and healthier margins for MSPs.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iran power plant closure is a warning to all businesses: How to respond ]]></title>
                                                                                                <dc:content><![CDATA[ <p>In August, it emerged that a small UK power plant was shut down for four days following a <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>cyber attack</u></a> attributed to <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat"><u>Iranian hackers</u></a>. It follows multiple <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn"><u>attacks on water facilities</u></a> in the US, which reports indicate are linked to the latest incident.</p><p>Not much is known about the UK power plant breach, with the government declining to reveal exactly where it took place. It has confirmed the incident involved a small-scale generator, and that the wider energy system was never at risk.</p><p>But a key technical detail is still withheld about whether control systems were directly affected, or if the plant was disconnected merely as a precaution while IT contained the infiltration.</p><p>After the first of its kind attack, the government has written to businesses with advice on the steps they should take to protect themselves. How big is the risk, who does it impact, and how should firms react?</p><h2 id="major-escalation">Major escalation </h2><p>The latest attack is “a major escalation” from the recent campaign targeting water facilities in the US, says Markus Mueller, field CISO at Nozomi Networks. </p><p>He says attacks on peaker plants like this – which are designed to provide power when needed – can be more dangerous because “things happen fast, there is no buffer, and there can be major impacts”.</p><p>Critical national infrastructure is also vulnerable because it often uses legacy technology never meant to be connected to the internet. In the latest incident, the attack path involved a <a href="https://www.itpro.com/security/cyber-attacks/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories"><u>programmable logic controller</u></a> (PLC) that was not secured following basic best practices. </p><p>“If current reporting is correct, this was a publicly exposed PLC that was impacted similarly to what we have seen at US water utilities, where the threat group scans the internet for exposed PLCs using AI-generated scripts,” Mueller tells <em>ITPro</em>.</p><p>The attacker then logs into the PLCs using default credentials and proceeds to take them offline by resetting the programming and changing the password and IP address, “making it inaccessible”, explains Mueller. </p><h2 id="a-risk-beyond-cni">A risk beyond CNI</h2><p>The risk goes beyond critical sectors, into the supply chain, other industries, and to firms that rely on the breached organization.</p><p>While this incident occurred at a power plant, this is also “a clear warning” for “non-utility commercial sectors”, says Mueller. </p><p>He points out that automated scanning scripts used by adversaries “do not differentiate between a power generator, a manufacturing plant, a logistics warehouse, or smart building management systems”. </p><p>Any business relying on connected physical systems or industrial controls is at risk. At the same time, <a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight"><u>supply chain</u></a> partners and third-party maintenance contractors with remote access into operational technology (OT) environments represent “a major attack vector that adversaries are actively targeting to move laterally into enterprise networks”, says Mueller.</p><p>The risk extends “well beyond” large, regulated energy operators, agrees Martin Riley, CTO at Bridewell. </p><p>He describes how the UK’s energy system is becoming more distributed, with growing reliance on smaller peaker plants, renewable generators, battery storage and other remotely operated assets. </p><p>“Individually, these facilities may represent a small proportion of national capacity, but collectively they are becoming an essential part of how the grid operates,” says Riley.</p><p>“That creates a particular challenge because smaller operators and suppliers may fall outside the regulatory thresholds applied to traditional critical infrastructure, while still having connectivity into systems and services the country depends on.”</p><p>At the same time, James Neilson, SVP of global at OPSWAT, says it is “a lucky escape” that this attack happened at a small power plant and didn’t impact the UK’s wider energy system. </p><p>“<a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>Hostile actors</u></a> now routinely target the UK using cyber attacks, undermining security, the economy and public trust. This form of grey-zone warfare has been present for at least a decade, but sub-threshold activity has increased sharply in recent years.”</p><h2 id="resilience-measures">Resilience measures</h2><p>Following the power plant attack, the UK government and National Cyber Security Center have actively urged organizations running critical infrastructure and industrial facilities to audit internet-facing devices and enforce cyber hygiene. </p><p>“The guidance emphasizes immediately identifying and pulling exposed OT and PLCs off the public internet, eliminating default vendor passwords and enforcing <a href="https://www.itpro.com/technology/how-to-choose-the-best-mfa-methods"><u>multi-factor authentication</u></a> for remote management connections,” explains Mueller.</p><p>At this stage, the most important lesson is “understanding asset exposure, attack paths, and the operational consequences of unauthorized access to industrial control systems”, according to Mueller.</p><p><a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>Resilience</u></a> starts with “understanding how an attacker could move through the organization” and “ensuring a compromise in one part of the environment cannot easily reach systems responsible for physical operations”, says Riley. </p><p>For operational environments, that means strong IT and OT segmentation, tightly controlled remote access and “security controls proportionate to the potential consequences of an incident”, he advises.</p><p>Organizations also need visibility across IT and OT. “If security monitoring operates separately, an attacker may be able to establish themselves in the corporate environment before moving towards operational systems without anyone seeing the complete picture,” warns Riley.</p><p>Know what exposed interfaces you have and harden these by using technology and architecture, advises Ian Thornton-Trump, CISO at Inversion6. </p><p>At the same time, use firewalls with access control and whitelisting capabilities to “ensure any exposed interfaces can only be connected to by specific IP addresses”, he adds.</p><p>Meanwhile, Thornton-Trump advises deploying deception technology to detect the early stages of an attack, including honeypots, as well as taking advantage of the <a href="https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning?utm_source=Google&utm_medium=cpc&utm_campaign=NCSC+Always+On+Search+26&utm_content=EW&gad_source=1&gad_campaignid=24164180098&gbraid=0AAAAACafkIXIMz0NdMPIRtnIL5_4yCA2v&gclid=Cj0KCQjwteTUBhD4ARIsAEYjs3rKYgHyvnTCO_nwP-kaaKHA4eL9O7kDuYTVsEqS606SpC6YLLx_80UaArqYEALw_wcB"><u>NCSC’s early warning</u></a> service.</p><p>It’s also important to know the enemy you are facing. For example, Iranian and other nation-state groups will often hunt out default credentials immediately to achieve “rapid, low-noise access”, says Neilson. </p><p>With this in mind, he advises “assessing and hardening critical systems and infrastructure considering the latest attacks”.</p><p>Firms should train for incident response using tabletop exercises at all levels of operations and management, Thornton-Trump adds. “Have a plan that includes cyber-incident responders on retainer and cybersecurity contacts in other companies in your industry vertical – and identify reinforcements and additional resources if you need them. Prolonged downtime of any sort – cyber or otherwise – is avoidable, predictable, and recoverable.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/iran-power-plant-closure-is-a-warning-to-all-businesses-how-to-respond</link>
                                                                            <description>
                            <![CDATA[ After the first attack of its kind, how big is the risk, who does it impact, and how should firms react? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fa9Y6as2Cis8apnLttdDXF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 08 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:description>                                                            <media:text><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:text>
                                <media:title type="plain"><![CDATA[Neon blue padlock with code flowing over it, floating above small plinths raised at different heights, each with code underneath their platforms]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gAZQGXquzahjQHwSbSp9WN-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In August, it emerged that a small UK power plant was shut down for four days following a <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>cyber attack</u></a> attributed to <a href="https://www.itpro.com/security/cyber-attacks/the-iran-cyber-threat"><u>Iranian hackers</u></a>. It follows multiple <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn"><u>attacks on water facilities</u></a> in the US, which reports indicate are linked to the latest incident.</p><p>Not much is known about the UK power plant breach, with the government declining to reveal exactly where it took place. It has confirmed the incident involved a small-scale generator, and that the wider energy system was never at risk.</p><p>But a key technical detail is still withheld about whether control systems were directly affected, or if the plant was disconnected merely as a precaution while IT contained the infiltration.</p><p>After the first of its kind attack, the government has written to businesses with advice on the steps they should take to protect themselves. How big is the risk, who does it impact, and how should firms react?</p><h2 id="major-escalation">Major escalation </h2><p>The latest attack is “a major escalation” from the recent campaign targeting water facilities in the US, says Markus Mueller, field CISO at Nozomi Networks. </p><p>He says attacks on peaker plants like this – which are designed to provide power when needed – can be more dangerous because “things happen fast, there is no buffer, and there can be major impacts”.</p><p>Critical national infrastructure is also vulnerable because it often uses legacy technology never meant to be connected to the internet. In the latest incident, the attack path involved a <a href="https://www.itpro.com/security/cyber-attacks/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories"><u>programmable logic controller</u></a> (PLC) that was not secured following basic best practices. </p><p>“If current reporting is correct, this was a publicly exposed PLC that was impacted similarly to what we have seen at US water utilities, where the threat group scans the internet for exposed PLCs using AI-generated scripts,” Mueller tells <em>ITPro</em>.</p><p>The attacker then logs into the PLCs using default credentials and proceeds to take them offline by resetting the programming and changing the password and IP address, “making it inaccessible”, explains Mueller. </p><h2 id="a-risk-beyond-cni">A risk beyond CNI</h2><p>The risk goes beyond critical sectors, into the supply chain, other industries, and to firms that rely on the breached organization.</p><p>While this incident occurred at a power plant, this is also “a clear warning” for “non-utility commercial sectors”, says Mueller. </p><p>He points out that automated scanning scripts used by adversaries “do not differentiate between a power generator, a manufacturing plant, a logistics warehouse, or smart building management systems”. </p><p>Any business relying on connected physical systems or industrial controls is at risk. At the same time, <a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight"><u>supply chain</u></a> partners and third-party maintenance contractors with remote access into operational technology (OT) environments represent “a major attack vector that adversaries are actively targeting to move laterally into enterprise networks”, says Mueller.</p><p>The risk extends “well beyond” large, regulated energy operators, agrees Martin Riley, CTO at Bridewell. </p><p>He describes how the UK’s energy system is becoming more distributed, with growing reliance on smaller peaker plants, renewable generators, battery storage and other remotely operated assets. </p><p>“Individually, these facilities may represent a small proportion of national capacity, but collectively they are becoming an essential part of how the grid operates,” says Riley.</p><p>“That creates a particular challenge because smaller operators and suppliers may fall outside the regulatory thresholds applied to traditional critical infrastructure, while still having connectivity into systems and services the country depends on.”</p><p>At the same time, James Neilson, SVP of global at OPSWAT, says it is “a lucky escape” that this attack happened at a small power plant and didn’t impact the UK’s wider energy system. </p><p>“<a href="https://www.itpro.com/security/cyber-attacks/crink-attacks-nation-state-hackers--threat-2026"><u>Hostile actors</u></a> now routinely target the UK using cyber attacks, undermining security, the economy and public trust. This form of grey-zone warfare has been present for at least a decade, but sub-threshold activity has increased sharply in recent years.”</p><h2 id="resilience-measures">Resilience measures</h2><p>Following the power plant attack, the UK government and National Cyber Security Center have actively urged organizations running critical infrastructure and industrial facilities to audit internet-facing devices and enforce cyber hygiene. </p><p>“The guidance emphasizes immediately identifying and pulling exposed OT and PLCs off the public internet, eliminating default vendor passwords and enforcing <a href="https://www.itpro.com/technology/how-to-choose-the-best-mfa-methods"><u>multi-factor authentication</u></a> for remote management connections,” explains Mueller.</p><p>At this stage, the most important lesson is “understanding asset exposure, attack paths, and the operational consequences of unauthorized access to industrial control systems”, according to Mueller.</p><p><a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>Resilience</u></a> starts with “understanding how an attacker could move through the organization” and “ensuring a compromise in one part of the environment cannot easily reach systems responsible for physical operations”, says Riley. </p><p>For operational environments, that means strong IT and OT segmentation, tightly controlled remote access and “security controls proportionate to the potential consequences of an incident”, he advises.</p><p>Organizations also need visibility across IT and OT. “If security monitoring operates separately, an attacker may be able to establish themselves in the corporate environment before moving towards operational systems without anyone seeing the complete picture,” warns Riley.</p><p>Know what exposed interfaces you have and harden these by using technology and architecture, advises Ian Thornton-Trump, CISO at Inversion6. </p><p>At the same time, use firewalls with access control and whitelisting capabilities to “ensure any exposed interfaces can only be connected to by specific IP addresses”, he adds.</p><p>Meanwhile, Thornton-Trump advises deploying deception technology to detect the early stages of an attack, including honeypots, as well as taking advantage of the <a href="https://www.ncsc.gov.uk/section/active-cyber-defence/early-warning?utm_source=Google&utm_medium=cpc&utm_campaign=NCSC+Always+On+Search+26&utm_content=EW&gad_source=1&gad_campaignid=24164180098&gbraid=0AAAAACafkIXIMz0NdMPIRtnIL5_4yCA2v&gclid=Cj0KCQjwteTUBhD4ARIsAEYjs3rKYgHyvnTCO_nwP-kaaKHA4eL9O7kDuYTVsEqS606SpC6YLLx_80UaArqYEALw_wcB"><u>NCSC’s early warning</u></a> service.</p><p>It’s also important to know the enemy you are facing. For example, Iranian and other nation-state groups will often hunt out default credentials immediately to achieve “rapid, low-noise access”, says Neilson. </p><p>With this in mind, he advises “assessing and hardening critical systems and infrastructure considering the latest attacks”.</p><p>Firms should train for incident response using tabletop exercises at all levels of operations and management, Thornton-Trump adds. “Have a plan that includes cyber-incident responders on retainer and cybersecurity contacts in other companies in your industry vertical – and identify reinforcements and additional resources if you need them. Prolonged downtime of any sort – cyber or otherwise – is avoidable, predictable, and recoverable.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cyber criminals are adapting ASCII smuggling for mass phishing campaigns ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Microsoft has warned that ASCII smuggling, the use of invisible Unicode characters to trick AI models, is now being used by cyber criminals to supercharge phishing campaigns. </p><p>Over the past year, ASCII smuggling has become a recurring technique for <a href="https://www.itpro.com/security/ncsc-issues-urgent-warning-over-growing-ai-prompt-injection-risks-heres-what-you-need-to-know">prompt injection</a> and cross-prompt injection (XPIA), allowing an attacker to hide instructions inside invisible tag characters embedded in a web page, document, email, or other content.</p><p>While human beings - and many user interfaces - see nothing unusual, an AI assistant that ingests the raw text registers the hidden characters, decodes them as text, and can be induced to carry out unauthorized instructions, including data exposure.</p><p>The most abused range is the Unicode Tags block, U+E0000 to U+E007F, which contains a shadow copy of the printable ASCII characters. For example, U+E0041 mirrors ‘A’, U+E0061 mirrors ‘a’). The block was originally intended for language tagging and is now largely deprecated.</p><p><a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank"><u>According to Microsoft</u></a>, hits on a hunting signature designed to detect ASCII smuggling increased sharply on February 9, and stayed high on weekdays for the next three months. </p><p>This time, though, the technique appears to be in use as part of a broader <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign that was identified by Fortra this time last year. </p><p>"When we looked at a sampling of the flagged messages, the surprise was there were no smuggled instructions to an AI assistant. Instead, the invisible tag characters were inserted inside common financial keywords, splitting them apart so that a literal signature or keyword match would fail," the researchers said.</p><p>"For example, a finance lure term that appeared normal to the recipient could be transmitted with an invisible tag character in the middle: funding became 'fun⟨U+E0020⟩ding'.</p><p>To the recipient, and to parsing pipelines that drop or normalize these characters, the word still reads as 'funding'. Microsoft warned that unless a filtering system takes a picture of a message and does OCR extraction over the visual image, it may miss this type of attack. </p><h2 id="ascii-smuggling-campaign-hit-hundreds-of-domains">ASCII smuggling campaign hit hundreds of domains</h2><p>According to Microsoft, the campaign ran on hundreds of disposable, finance-themed sender domains with lures that resembled business loan, line-of-credit, and advance-funding phishing patterns often associated with fraud or credential-harvesting funnels. </p><p>This pattern accounted for roughly 96% of the volume flagged by the hunting signature. The emails in question were relayed through infrastructure associated with the legitimate email-marketing platform, ActiveCampaign.</p><p>"We appreciate Microsoft’s research and welcome collaboration with the security community to combat this activity. We take abuse, fraud, and security extremely seriously," said an ActiveCampaign spokesperson. </p><p>"We tested the specific technique described in this research against our content-moderation systems: messages containing invisible Unicode characters receive the same moderation verdicts as their unobfuscated equivalents, and heavy use of the technique is itself treated as a suspicious signal."</p><h2 id="how-to-protect-yourself-against-ascii-smuggling">How to protect yourself against ASCII smuggling</h2><p>To stay safe, Microsoft said organizations should strip or normalize Unicode tag characters (U+E0000-U+E007F) – and other zero-width / invisible code points – from email subject and body text before applying spam and phishing content signatures. </p><p>The presence of tag-block characters should be seen as a strong red flag: they're rare in ordinary mail and can be a high-value anomaly signal.</p><p>They should also look for the behavioral fingerprint: bulk volume from churning, finance-themed disposable domains, on a strict weekday-on/weekend-off schedule.</p><p>Elsewhere, businesses are advised to apply the same normalization upstream of AI ingestion: the same control that defeats this evasion also reduces XPIA / ASCII-smuggling exposure for AI assistants that ingest email content, Microsoft said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-crime/cyber-criminals-are-adapting-ascii-smuggling-for-mass-phishing-campaigns</link>
                                                                            <description>
                            <![CDATA[ Usually known for its use in prompt injection attacks, ASCII smuggling is now being used to evade spam filters on email platforms ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HNXUSnXZNthhAuqNLv4NmM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 10:54:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Microsoft has warned that ASCII smuggling, the use of invisible Unicode characters to trick AI models, is now being used by cyber criminals to supercharge phishing campaigns. </p><p>Over the past year, ASCII smuggling has become a recurring technique for <a href="https://www.itpro.com/security/ncsc-issues-urgent-warning-over-growing-ai-prompt-injection-risks-heres-what-you-need-to-know">prompt injection</a> and cross-prompt injection (XPIA), allowing an attacker to hide instructions inside invisible tag characters embedded in a web page, document, email, or other content.</p><p>While human beings - and many user interfaces - see nothing unusual, an AI assistant that ingests the raw text registers the hidden characters, decodes them as text, and can be induced to carry out unauthorized instructions, including data exposure.</p><p>The most abused range is the Unicode Tags block, U+E0000 to U+E007F, which contains a shadow copy of the printable ASCII characters. For example, U+E0041 mirrors ‘A’, U+E0061 mirrors ‘a’). The block was originally intended for language tagging and is now largely deprecated.</p><p><a href="https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/" target="_blank"><u>According to Microsoft</u></a>, hits on a hunting signature designed to detect ASCII smuggling increased sharply on February 9, and stayed high on weekdays for the next three months. </p><p>This time, though, the technique appears to be in use as part of a broader <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaign that was identified by Fortra this time last year. </p><p>"When we looked at a sampling of the flagged messages, the surprise was there were no smuggled instructions to an AI assistant. Instead, the invisible tag characters were inserted inside common financial keywords, splitting them apart so that a literal signature or keyword match would fail," the researchers said.</p><p>"For example, a finance lure term that appeared normal to the recipient could be transmitted with an invisible tag character in the middle: funding became 'fun⟨U+E0020⟩ding'.</p><p>To the recipient, and to parsing pipelines that drop or normalize these characters, the word still reads as 'funding'. Microsoft warned that unless a filtering system takes a picture of a message and does OCR extraction over the visual image, it may miss this type of attack. </p><h2 id="ascii-smuggling-campaign-hit-hundreds-of-domains">ASCII smuggling campaign hit hundreds of domains</h2><p>According to Microsoft, the campaign ran on hundreds of disposable, finance-themed sender domains with lures that resembled business loan, line-of-credit, and advance-funding phishing patterns often associated with fraud or credential-harvesting funnels. </p><p>This pattern accounted for roughly 96% of the volume flagged by the hunting signature. The emails in question were relayed through infrastructure associated with the legitimate email-marketing platform, ActiveCampaign.</p><p>"We appreciate Microsoft’s research and welcome collaboration with the security community to combat this activity. We take abuse, fraud, and security extremely seriously," said an ActiveCampaign spokesperson. </p><p>"We tested the specific technique described in this research against our content-moderation systems: messages containing invisible Unicode characters receive the same moderation verdicts as their unobfuscated equivalents, and heavy use of the technique is itself treated as a suspicious signal."</p><h2 id="how-to-protect-yourself-against-ascii-smuggling">How to protect yourself against ASCII smuggling</h2><p>To stay safe, Microsoft said organizations should strip or normalize Unicode tag characters (U+E0000-U+E007F) – and other zero-width / invisible code points – from email subject and body text before applying spam and phishing content signatures. </p><p>The presence of tag-block characters should be seen as a strong red flag: they're rare in ordinary mail and can be a high-value anomaly signal.</p><p>They should also look for the behavioral fingerprint: bulk volume from churning, finance-themed disposable domains, on a strict weekday-on/weekend-off schedule.</p><p>Elsewhere, businesses are advised to apply the same normalization upstream of AI ingestion: the same control that defeats this evasion also reduces XPIA / ASCII-smuggling exposure for AI assistants that ingest email content, Microsoft said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ G7 sounds alarm on quantum cyber threats ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The G7 Cybersecurity Working Group has issued a <a href="https://oos.cloudgouv-eu-west-1.outscale.com/sitesconformes-prd-osc-cgw1-s3-cybergouvfr/sf-cyber/documents/G7_preparing_for_the_qost_quantum_era_a_call_to_action.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=4KPMC6G57D6727LM7P5K%2F20260907%2Fcloudgouv-eu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20260907T080129Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Signature=d900d8fefb5e833c18f23c30fa64c9a368c5c3441f5586dddeef625a2762499b" target="_blank"><u>joint advisory</u></a> urging organizations to get moving on <a href="https://www.itpro.com/business/post-quantum-cryptography-is-now-top-of-mind-for-cybersecurity-leaders">post-quantum cryptography (PQC)</a>.</p><p>The advisory specifically highlights the risk that <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a> poses to public-key cryptography, stressing that it's a near-term threat that needs addressing across all sectors, not just critical infrastructure.</p><p>"Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms and threaten the security of digital infrastructures," it said.</p><p>The big threat from cryptographically relevant quantum computers (CRQCs) is that they will be able to carry out '<a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them">harvest now, decrypt later</a>' attacks. </p><p>This involves collecting and storing encrypted data protected by public-key cryptography that threat actors will be able to decrypt at a later date. </p><p>"Malicious cyber actors with access to CRQCs will also be able to target authentication mechanisms that help provide assurance and help protect the integrity of data between communicating parties and the integrity of devices," the advisory said. </p><p>"This capability could allow malicious cyber actors to impersonate trusted entities, compromise equipment, forge trusted data, or access confidential data, therefore undermining confidence in secure communications or contractual agreements."</p><h2 id="quantum-preparations">Quantum preparations</h2><p>Organizations should adopt a phased and risk-based strategy, prioritizing the most sensitive data and assets. This means carrying out an inventory of their cryptographic assets, mapping their dependencies, and developing a transition plan. </p><p>To keep costs down, they should acquire products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule - this, the advisory noted, could result in lower migration costs overall. </p><p>Worryingly, the report said the quantum threat remains off the radar for many organizations and as such is under-resourced, with other security concerns taking precedence.</p><p>"Yet a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk," the report warns. </p><p>Raising awareness of the stakes involved will be critical, according to the working group. National strategies aimed at transitioning to PQC should aim to attain an adequate supply of PQC hardware and software products, and encourage users to adopt them.</p><p>Research and development efforts also need to be ramped up, with more cooperation between government, industry, and academia, and the introduction of specific requirements within the framework of public procurement.</p><p>"Tackling the risks that the impending quantum computing era poses to current cryptographic systems, and ultimately organizations in which they are embedded, requires a coordinated global effort to transition to PQC," the report concluded. </p><p>"To strengthen collective resilience and safeguard confidential data, supply chains, and critical systems, public and private organizations must jointly act now. The transition to PQC is the key foundation to help build a secure and resilient digital future."</p><h2 id="still-a-long-way-to-go">Still a long way to go</h2><p>The advice from the working group might not resonate with enterprises, however. A <a href="https://www.itpro.com/security/post-quantum-encryption-enterprise-preparation-juniper-research"><u>study</u></a> by Juniper Research earlier this year found that only 27% of global businesses are set to be using PQC by 2030.</p><p>Those figures come despite recent predictions from Google that computers capable of breaking existing encryption could be here within just three years.</p><p>"The most important part of the G7’s message is the recognition that quantum can no longer be treated as a distant technology problem. Organizations are being told to start their PQC transition now, but transition and protection are not the same thing," said Simon Pamplin, CTO at Certes.</p><p>"The real challenge will be legacy infrastructure. Replacing cryptography embedded across decades of applications, supply chains and interconnected systems is not something organisations can achieve overnight. </p><p>"Security therefore needs to be abstracted away from individual applications and infrastructure and attached directly to the data, allowing the cryptography protecting it to change without repeatedly rebuilding the systems underneath."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/g7-sounds-alarm-on-quantum-cyber-threats</link>
                                                                            <description>
                            <![CDATA[ The risk of 'harvest now, decrypt later' attacks is a leading concern for security agencies ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WAybbV5PecR96nnaqek739</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GFpMfj9q29UoFDQyuwcQuh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 07 Sep 2026 09:19:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GFpMfj9q29UoFDQyuwcQuh-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[&#039;Q-Day&#039; quantum computing attack showing a data storage container with encryption key unlocked, placed on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[&#039;Q-Day&#039; quantum computing attack showing a data storage container with encryption key unlocked, placed on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[&#039;Q-Day&#039; quantum computing attack showing a data storage container with encryption key unlocked, placed on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GFpMfj9q29UoFDQyuwcQuh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The G7 Cybersecurity Working Group has issued a <a href="https://oos.cloudgouv-eu-west-1.outscale.com/sitesconformes-prd-osc-cgw1-s3-cybergouvfr/sf-cyber/documents/G7_preparing_for_the_qost_quantum_era_a_call_to_action.pdf?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=4KPMC6G57D6727LM7P5K%2F20260907%2Fcloudgouv-eu-west-1%2Fs3%2Faws4_request&X-Amz-Date=20260907T080129Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Signature=d900d8fefb5e833c18f23c30fa64c9a368c5c3441f5586dddeef625a2762499b" target="_blank"><u>joint advisory</u></a> urging organizations to get moving on <a href="https://www.itpro.com/business/post-quantum-cryptography-is-now-top-of-mind-for-cybersecurity-leaders">post-quantum cryptography (PQC)</a>.</p><p>The advisory specifically highlights the risk that <a href="https://www.itpro.com/technology/31818/what-is-quantum-computing">quantum computing</a> poses to public-key cryptography, stressing that it's a near-term threat that needs addressing across all sectors, not just critical infrastructure.</p><p>"Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms and threaten the security of digital infrastructures," it said.</p><p>The big threat from cryptographically relevant quantum computers (CRQCs) is that they will be able to carry out '<a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them">harvest now, decrypt later</a>' attacks. </p><p>This involves collecting and storing encrypted data protected by public-key cryptography that threat actors will be able to decrypt at a later date. </p><p>"Malicious cyber actors with access to CRQCs will also be able to target authentication mechanisms that help provide assurance and help protect the integrity of data between communicating parties and the integrity of devices," the advisory said. </p><p>"This capability could allow malicious cyber actors to impersonate trusted entities, compromise equipment, forge trusted data, or access confidential data, therefore undermining confidence in secure communications or contractual agreements."</p><h2 id="quantum-preparations">Quantum preparations</h2><p>Organizations should adopt a phased and risk-based strategy, prioritizing the most sensitive data and assets. This means carrying out an inventory of their cryptographic assets, mapping their dependencies, and developing a transition plan. </p><p>To keep costs down, they should acquire products that integrate PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule - this, the advisory noted, could result in lower migration costs overall. </p><p>Worryingly, the report said the quantum threat remains off the radar for many organizations and as such is under-resourced, with other security concerns taking precedence.</p><p>"Yet a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk," the report warns. </p><p>Raising awareness of the stakes involved will be critical, according to the working group. National strategies aimed at transitioning to PQC should aim to attain an adequate supply of PQC hardware and software products, and encourage users to adopt them.</p><p>Research and development efforts also need to be ramped up, with more cooperation between government, industry, and academia, and the introduction of specific requirements within the framework of public procurement.</p><p>"Tackling the risks that the impending quantum computing era poses to current cryptographic systems, and ultimately organizations in which they are embedded, requires a coordinated global effort to transition to PQC," the report concluded. </p><p>"To strengthen collective resilience and safeguard confidential data, supply chains, and critical systems, public and private organizations must jointly act now. The transition to PQC is the key foundation to help build a secure and resilient digital future."</p><h2 id="still-a-long-way-to-go">Still a long way to go</h2><p>The advice from the working group might not resonate with enterprises, however. A <a href="https://www.itpro.com/security/post-quantum-encryption-enterprise-preparation-juniper-research"><u>study</u></a> by Juniper Research earlier this year found that only 27% of global businesses are set to be using PQC by 2030.</p><p>Those figures come despite recent predictions from Google that computers capable of breaking existing encryption could be here within just three years.</p><p>"The most important part of the G7’s message is the recognition that quantum can no longer be treated as a distant technology problem. Organizations are being told to start their PQC transition now, but transition and protection are not the same thing," said Simon Pamplin, CTO at Certes.</p><p>"The real challenge will be legacy infrastructure. Replacing cryptography embedded across decades of applications, supply chains and interconnected systems is not something organisations can achieve overnight. </p><p>"Security therefore needs to be abstracted away from individual applications and infrastructure and attached directly to the data, allowing the cryptography protecting it to change without repeatedly rebuilding the systems underneath."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the MSSP model is broken, and how to fix it ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Can small Managed Security Service Providers (MSSPs) outcompete the world’s biggest Systems Integrators (SIs)? It might sound like a fool’s errand. But SIs have a glaring weakness: a generic, heavily standardized approach that fails to move in step with the rapidly evolving threat landscape. There’s an opportunity for smaller, more agile MSSPs, if they’re bold enough to take it.</p><p>Unfortunately, many are failing to take advantage. In fact, they’re making it harder for CISOs to differentiate their offerings by citing inaccurate metrics. These do nothing but confuse prospective customers. But for those MSSPs willing to go against the status quo, the market is there for the taking.</p><h2 id="why-bigger-doesn-t-mean-better-in-cybersecurity">Why bigger doesn’t mean better in cybersecurity</h2><p>The threat landscape stands still for no one. Over the past couple of years, we’ve witnessed an unprecedented weaponization of new technologies by threat actors. AI is being used in victim reconnaissance, social engineering, malware generation, and vulnerability research and exploit development. </p><p>According to <a href="https://www.verizon.com/business/resources/T1f0/reports/2026-dbir-data-breach-investigations-report.pdf"><u>Verizon</u></a>, the median threat actor researched or used AI assistance in 15 different documented techniques last year, with some using as many as 50. <a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-collapsing-exploit-window-ai-mtte-20260411-cs/"><u>Researchers are warning</u></a> that the exploitation window is collapsing as a result. <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"><u>Google’s most recent M-Trends report</u></a> puts mean-time-to-exploitation at less than seven days. </p><p>This means that SecOps teams live in a world of constant flux. One in which continuous improvements need to be made to the SOC — to swap in and out services and evaluate and reevaluate vendors in order to maintain a good security posture. Now think of a typical SI. They may have deep domain knowledge and plenty of smart people on the books. But their business model is scale, not agility. In fact, they tend to charge punitive fees for any change requests outside the original scope of work.</p><p>Rigid contracts and multiple management layers are a recipe for inertia. That’s bad news for CISO customers at a time when IT infrastructure and threat actor innovation are moving at pace. If you can’t afford to mitigate new risks around agentic AI data leakage or prompt injection, what do you do? Delay investment in the technology? Or accept increased risk? There are no good options.  </p><h2 id="missing-an-open-goal">Missing an open goal</h2><p>This business opportunity should be an open goal for MSSPs. But the truth is that many also adopt a cookie-cutter approach in order to efficiently service as wide a bank of customers as possible. This ultimately erodes the value of a potentially powerful differentiator.</p><p>They make things worse by resorting to disingenuous tricks to outcompete their rivals. They might claim to respond to alerts within 30 minutes, for example. But in reality, that metric is only applied to critical-severity alerts. Those deemed less urgent may take many more hours to respond to. That’s not only insincere. It could be a major security risk at a time when attackers go to deliberate lengths to hide in low-level activity. It’s critically important to spot and stop living-off-the-land techniques like these before they escalate.</p><p>There’s more. It’s also become accepted industry practice today for MSSPs to include automatically assigned and closed alerts when working out Mean Time to Acknowledge (MTTA) and Mean Time to Close (MTTC) — artificially shrinking these values. MSSPs may exclude alerts that weren’t handled within SLA parameters, like those at the weekend. And they may even reset the clock when an alert is escalated between tiers, to make it appear as if SLA targets were met.</p><p>This isn’t just bad practice. It means CISOs can no longer trust the sales pitch. That’s bad news for those who operate differently.</p><h2 id="honesty-and-agility">Honesty and agility</h2><p>Yet if they can get their message out, there is an opportunity for more dynamic MSSPs. They must be honest about SLAs, clearly define the terminology they use, and resist the urge to manipulate metrics. But just as importantly, they should offer services that move in step with the needs of their customers and the changing nature of the threat landscape, to outcompete their larger SI rivals.</p><p>It can be done. Think: red teaming for rogue behavior. Continuous risk reporting that maps findings to best-practice compliance standards. And AI posture management that integrates with SOC playbooks and exposure management dashboards to mitigate risk across the AI attack surface.</p><p>There are some fantastic solution providers out there offering cutting-edge capabilities—from real-time runtime detection to observability and model provenance checks. But no single vendor offers the whole package a SOC needs. That’s where the MSSP can add value. It’s about continuously evaluating what’s out there on the market, and integrating it into a seamless, 24/7 managed service offering. </p><h2 id="protection-for-today-and-tomorrow">Protection for today and tomorrow</h2><p>The MSSP space has never been more important for customers. The accelerating pace of industry regulation, infrastructure, and threat innovation is a testament to that. </p><p>For IT security leaders, the question to ask is not just whether your service provider is good enough right now. It’s whether they have a convincing vision of where security is heading in the future. </p><p>For many organizations, that’s not going to be an SI where only 80% of what they do might be “good enough.” In cyber, 80% is no longer good enough. CISOs need a more dynamic partner to protect their business: for today and tomorrow.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/why-the-mssp-model-is-broken-and-how-to-fix-it</link>
                                                                            <description>
                            <![CDATA[ CISOs are struggling to differentiate between MSSPs due to confusing metrics and SLAs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WMGQNfGDo8Dv973X4k2ap7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 21:33:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Martin Jakobsen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/5WF2fD8fctFhUR7Zg5UeNm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Martin Jakobsen is the managing director of Cybanetix and brings over 20 years of experience delivering NOC and SOC services to a wide range of customers. &lt;/p&gt;&lt;p&gt;At Cybanetix, Martin has overseen the company’s growth into a trusted MDR specialist supporting clients across multiple sectors, including large-scale enterprises and public sector organizations. Martin remains focused on expanding Cybanetix’s capabilities and its use of advanced, AI-enabled security operations to deliver practical, intelligence-driven services. &lt;/p&gt;&lt;p&gt;Before Cybanetix, Martin served as managing director of Capita Cyber Security and holds board positions at KonsensIT A/S and CapMon A/S, contributing his expertise in governance and strategic growth.  &lt;/p&gt;&lt;p&gt;He has played a central role in the design and build of some of the UK’s largest government networks and has provided outsourced security operations to multinational enterprises. His combination of technical expertise and leadership has enabled organizations to strengthen their defences and run more resilient security operations. &lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:description>                                                            <media:text><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:text>
                                <media:title type="plain"><![CDATA[Password security concept image showing person logging into an account on a laptop while using password manager authenticator on smartphone.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/b3uNg73ogqmmGDNjaScXE3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Can small Managed Security Service Providers (MSSPs) outcompete the world’s biggest Systems Integrators (SIs)? It might sound like a fool’s errand. But SIs have a glaring weakness: a generic, heavily standardized approach that fails to move in step with the rapidly evolving threat landscape. There’s an opportunity for smaller, more agile MSSPs, if they’re bold enough to take it.</p><p>Unfortunately, many are failing to take advantage. In fact, they’re making it harder for CISOs to differentiate their offerings by citing inaccurate metrics. These do nothing but confuse prospective customers. But for those MSSPs willing to go against the status quo, the market is there for the taking.</p><h2 id="why-bigger-doesn-t-mean-better-in-cybersecurity">Why bigger doesn’t mean better in cybersecurity</h2><p>The threat landscape stands still for no one. Over the past couple of years, we’ve witnessed an unprecedented weaponization of new technologies by threat actors. AI is being used in victim reconnaissance, social engineering, malware generation, and vulnerability research and exploit development. </p><p>According to <a href="https://www.verizon.com/business/resources/T1f0/reports/2026-dbir-data-breach-investigations-report.pdf"><u>Verizon</u></a>, the median threat actor researched or used AI assistance in 15 different documented techniques last year, with some using as many as 50. <a href="https://labs.cloudsecurityalliance.org/research/csa-whitepaper-collapsing-exploit-window-ai-mtte-20260411-cs/"><u>Researchers are warning</u></a> that the exploitation window is collapsing as a result. <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026"><u>Google’s most recent M-Trends report</u></a> puts mean-time-to-exploitation at less than seven days. </p><p>This means that SecOps teams live in a world of constant flux. One in which continuous improvements need to be made to the SOC — to swap in and out services and evaluate and reevaluate vendors in order to maintain a good security posture. Now think of a typical SI. They may have deep domain knowledge and plenty of smart people on the books. But their business model is scale, not agility. In fact, they tend to charge punitive fees for any change requests outside the original scope of work.</p><p>Rigid contracts and multiple management layers are a recipe for inertia. That’s bad news for CISO customers at a time when IT infrastructure and threat actor innovation are moving at pace. If you can’t afford to mitigate new risks around agentic AI data leakage or prompt injection, what do you do? Delay investment in the technology? Or accept increased risk? There are no good options.  </p><h2 id="missing-an-open-goal">Missing an open goal</h2><p>This business opportunity should be an open goal for MSSPs. But the truth is that many also adopt a cookie-cutter approach in order to efficiently service as wide a bank of customers as possible. This ultimately erodes the value of a potentially powerful differentiator.</p><p>They make things worse by resorting to disingenuous tricks to outcompete their rivals. They might claim to respond to alerts within 30 minutes, for example. But in reality, that metric is only applied to critical-severity alerts. Those deemed less urgent may take many more hours to respond to. That’s not only insincere. It could be a major security risk at a time when attackers go to deliberate lengths to hide in low-level activity. It’s critically important to spot and stop living-off-the-land techniques like these before they escalate.</p><p>There’s more. It’s also become accepted industry practice today for MSSPs to include automatically assigned and closed alerts when working out Mean Time to Acknowledge (MTTA) and Mean Time to Close (MTTC) — artificially shrinking these values. MSSPs may exclude alerts that weren’t handled within SLA parameters, like those at the weekend. And they may even reset the clock when an alert is escalated between tiers, to make it appear as if SLA targets were met.</p><p>This isn’t just bad practice. It means CISOs can no longer trust the sales pitch. That’s bad news for those who operate differently.</p><h2 id="honesty-and-agility">Honesty and agility</h2><p>Yet if they can get their message out, there is an opportunity for more dynamic MSSPs. They must be honest about SLAs, clearly define the terminology they use, and resist the urge to manipulate metrics. But just as importantly, they should offer services that move in step with the needs of their customers and the changing nature of the threat landscape, to outcompete their larger SI rivals.</p><p>It can be done. Think: red teaming for rogue behavior. Continuous risk reporting that maps findings to best-practice compliance standards. And AI posture management that integrates with SOC playbooks and exposure management dashboards to mitigate risk across the AI attack surface.</p><p>There are some fantastic solution providers out there offering cutting-edge capabilities—from real-time runtime detection to observability and model provenance checks. But no single vendor offers the whole package a SOC needs. That’s where the MSSP can add value. It’s about continuously evaluating what’s out there on the market, and integrating it into a seamless, 24/7 managed service offering. </p><h2 id="protection-for-today-and-tomorrow">Protection for today and tomorrow</h2><p>The MSSP space has never been more important for customers. The accelerating pace of industry regulation, infrastructure, and threat innovation is a testament to that. </p><p>For IT security leaders, the question to ask is not just whether your service provider is good enough right now. It’s whether they have a convincing vision of where security is heading in the future. </p><p>For many organizations, that’s not going to be an SI where only 80% of what they do might be “good enough.” In cyber, 80% is no longer good enough. CISOs need a more dynamic partner to protect their business: for today and tomorrow.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Attackers are steering their botnets with greater precision and control’: DDoS attack numbers might be dwindling, but they’re intensifying ]]></title>
                                                                                                <dc:content><![CDATA[ <p>While the number of <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS) attacks</a> on European organizations is falling, attacks have become more targeted and intense. </p><p>Findings from Link11's <a href="https://www.link11.com/en/download/european-cyber-report-midyear-2026/" target="_blank"><u><em>European Cyber Report</em></u></a> for the first half of 2026 show that the number of attacks was down by 42%, but revealed new highs for attack intensity across bandwidth, packet rate, and cumulative data volume.</p><p>The highest measured bandwidth attack reached 2.3 Tbit/s – 85% higher than the previous peak of 1.2 Tbit/s in the first half of 2025.</p><p>The packet rate followed the same pattern, reaching a new peak of 322 million packets per second — up 56% from 207 million packets per second a year earlier. </p><p>Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period — a 61% increase.</p><p>“Attacks are shorter, but the total volume that we had to mitigate is higher than ever," said Karsten Desler, Link11 <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO</a>. "Attackers are steering their botnets with greater precision and control, generating more traffic in less time.”</p><h2 id="law-enforcement-takedowns-are-working">Law enforcement takedowns are working</h2><p>The drop in the number of attacks is down to sustained pressure from international law enforcement, including the takedown of pro-Russian group NoName057(16)'s infrastructure in July 2025. </p><p>Similarly, the takedown in March of the command-and-control servers of four major <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">IoT botnets</a> has played a key role. These controlled more than three million devices between them.</p><p>Despite positive gains by law enforcement, a rise in super-botnets such as Aisuru and its successor, Kimwolf, as well as a growing number of hijacked cloud servers, has increased the intensity of attacks. </p><p>Unlike a private IoT camera with just a few Mbit/s of upload bandwidth, a compromised server in a data center has a connection in the Gbit/s range - meaning that just a few thousand hacked cloud instances can easily eclipse the attack potential of an IoT botnet with millions of end devices.</p><p>“These numbers show that the threat isn't shrinking; it's shifting from breadth to peak intensity,” said Jens-Philipp Jung, CEO of Link11. “Organizations that size their defenses based on last year's attack count are underestimating how quickly a single incident can escalate today.”</p><h2 id="no-reprieve-for-victims">No reprieve for victims</h2><p>Notably, the report found that getting hit once makes it more likely that you'll get hit again: 56% fell victim to a second attack within 30 days of the first, compared with 46% a year earlier.</p><p>Link11 said the most dangerous attacks aren't always the most visible ones. In one case, attackers used a traffic spike against two domains as cover while quietly running SQL injection and cross-site scripting (XSS) probes behind it. </p><p>The attack was only spotted because the attackers used the same IP addresses for both.</p><p>"The most dangerous attacks we deal with are rarely the loudest ones anymore,” said Jag Bains, VP solution engineering, at Link11. “If you're only watching bandwidth and known signatures, you'll miss the attacks designed to do the most damage, because they're built to stay unnoticed.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/attackers-are-steering-their-botnets-with-greater-precision-and-control-ddos-attack-numbers-might-be-dwindling-but-theyre-intensifying</link>
                                                                            <description>
                            <![CDATA[ While law enforcement efforts have had their effect, the rise in super-botnets and hijacked cloud servers has increased the intensity of attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">uhcoePthCZXTsAMeLrja3S</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JNx6cDAorJmPFmr2saspoG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 10:36:45 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JNx6cDAorJmPFmr2saspoG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[DDoS attack concept image showing data terminals distributed in several different global locations, all interlinked with red glowing lights.]]></media:description>                                                            <media:text><![CDATA[DDoS attack concept image showing data terminals distributed in several different global locations, all interlinked with red glowing lights.]]></media:text>
                                <media:title type="plain"><![CDATA[DDoS attack concept image showing data terminals distributed in several different global locations, all interlinked with red glowing lights.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JNx6cDAorJmPFmr2saspoG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>While the number of <a href="https://www.itpro.com/security/28026/what-is-a-ddos-attack">distributed denial of service (DDoS) attacks</a> on European organizations is falling, attacks have become more targeted and intense. </p><p>Findings from Link11's <a href="https://www.link11.com/en/download/european-cyber-report-midyear-2026/" target="_blank"><u><em>European Cyber Report</em></u></a> for the first half of 2026 show that the number of attacks was down by 42%, but revealed new highs for attack intensity across bandwidth, packet rate, and cumulative data volume.</p><p>The highest measured bandwidth attack reached 2.3 Tbit/s – 85% higher than the previous peak of 1.2 Tbit/s in the first half of 2025.</p><p>The packet rate followed the same pattern, reaching a new peak of 322 million packets per second — up 56% from 207 million packets per second a year earlier. </p><p>Cumulative traffic also increased, rising from 438 to 705 terabytes over the six-month period — a 61% increase.</p><p>“Attacks are shorter, but the total volume that we had to mitigate is higher than ever," said Karsten Desler, Link11 <a href="https://www.itpro.com/strategy/28237/cto-job-description-what-does-a-cto-do">CTO</a>. "Attackers are steering their botnets with greater precision and control, generating more traffic in less time.”</p><h2 id="law-enforcement-takedowns-are-working">Law enforcement takedowns are working</h2><p>The drop in the number of attacks is down to sustained pressure from international law enforcement, including the takedown of pro-Russian group NoName057(16)'s infrastructure in July 2025. </p><p>Similarly, the takedown in March of the command-and-control servers of four major <a href="https://www.itpro.com/botnets/1644/what-is-a-botnet">IoT botnets</a> has played a key role. These controlled more than three million devices between them.</p><p>Despite positive gains by law enforcement, a rise in super-botnets such as Aisuru and its successor, Kimwolf, as well as a growing number of hijacked cloud servers, has increased the intensity of attacks. </p><p>Unlike a private IoT camera with just a few Mbit/s of upload bandwidth, a compromised server in a data center has a connection in the Gbit/s range - meaning that just a few thousand hacked cloud instances can easily eclipse the attack potential of an IoT botnet with millions of end devices.</p><p>“These numbers show that the threat isn't shrinking; it's shifting from breadth to peak intensity,” said Jens-Philipp Jung, CEO of Link11. “Organizations that size their defenses based on last year's attack count are underestimating how quickly a single incident can escalate today.”</p><h2 id="no-reprieve-for-victims">No reprieve for victims</h2><p>Notably, the report found that getting hit once makes it more likely that you'll get hit again: 56% fell victim to a second attack within 30 days of the first, compared with 46% a year earlier.</p><p>Link11 said the most dangerous attacks aren't always the most visible ones. In one case, attackers used a traffic spike against two domains as cover while quietly running SQL injection and cross-site scripting (XSS) probes behind it. </p><p>The attack was only spotted because the attackers used the same IP addresses for both.</p><p>"The most dangerous attacks we deal with are rarely the loudest ones anymore,” said Jag Bains, VP solution engineering, at Link11. “If you're only watching bandwidth and known signatures, you'll miss the attacks designed to do the most damage, because they're built to stay unnoticed.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Outages at OpenAI, Anthropic, and xAI should be a wake-up call for enterprises: ‘AI is increasingly becoming operational infrastructure rather than a productivity add-on’ ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A simultaneous outage affecting OpenAI, Anthropic and xAI should act as a wake-up call for enterprises, analysts have told <em>ITPro</em>. </p><p>All three providers reported service disruption starting at about 6.30am Pacific Time on 3 September. While the outages were resolved within two-to-three, Charlie Dai, VP principal analyst at Forrester, said the incident puts the growing reliance of enterprises on <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> in the spotlight. </p><p>“The near-simultaneous disruptions highlight that AI is increasingly becoming operational infrastructure rather than a productivity add-on,” he told <em>ITPro</em>. </p><p>“Enterprises should treat AI availability as a resilience issue, implementing multi-model strategies, fallback workflows, and business continuity plans instead of assuming frontier AI services will always be available.”</p><p><a href="https://www.itpro.com/security/downtime-hits-hard-as-organizations-battle-hidden-costs">Downtime </a>of any kind can be highly damaging for businesses, impacting finances, consumer trust, and operational efficiency. With OpenAI and Anthropic ranking among the most popular AI providers on the market, any outage raises the stakes. </p><p>“Downtime can quickly translate into lost revenue, reduced employee productivity, delayed decisions, operational disruptions, SLA breaches, and customer dissatisfaction,” Dai said. </p><p>“As AI becomes embedded in customer service, software development, knowledge management, and business processes, even short interruptions can create cascading impacts across multiple teams and customer touchpoints.</p><h2 id="openai-anthropic-and-xai-outage-timeline">OpenAI, Anthropic, and xAI outage timeline</h2><p>OpenAI, Anthropic, and xAI first reported issues between 6.23 am and 7.45 am Pacific time yesterday. </p><p>Anthropic <a href="https://status.claude.com/" target="_blank"><u>confirmed </u></a>“elevated errors on requests” for Mythos 5.1, Claude Fable 5.1, and Claude Opus 5 at 6.23 am PT. </p><p>OpenAI, meanwhile, <a href="https://status.openai.com/incidents/01M1KWEDH417T2CF44YYHZDFCR" target="_blank"><u>reported </u></a>“elevated errors” across <a href="https://www.itpro.com/technology/artificial-intelligence/openai-just-revealed-what-people-really-use-chatgpt-for-and-70-percent-of-queries-have-nothing-to-do-with-work">ChatGPT </a>and <a href="https://www.itpro.com/technology/artificial-intelligence/openais-codex-app-is-now-available-on-macos-and-its-free-for-some-chatgpt-users-for-a-limited-time">Codex</a>. xAI also confirmed Grok was “experiencing issues”. </p><p>Based on respective status updates, all three providers resolved the issues within two-to-three hours: OpenAI marked the case as resolved at 9.15 am, while Anthropic and xAI reported fixes at 9.16 am and 10.05 am respectively.</p><h2 id="the-mystery-source">The mystery source</h2><p>With all three providers all experiencing outages in tandem, speculation over a common source was rife. Initial suggestions that a cloud or networking provider was behind the outages fell flat, however. </p><p>Neither Amazon Web Services (AWS), Microsoft Azure, nor Google Cloud reported downtime yesterday. Cloudflare, meanwhile, told <em>ITPro </em>that services were operating as expected at the time. </p><p>“Cloudflare is not experiencing any significant service disruptions at this time,” the company said. “Our services are operating normally, and any reporting that deviates from this is incorrect.”</p><p>In a <a href="https://x.com/SpaceXAI/status/2095597264043717014?s=20" target="_blank"><u>statement via X</u></a>, however, SpaceX revealed an outage at the company’s Memphis data center yesterday morning impacted Grok services. </p><p>“We are sorry for the issues you may have experienced with Grok following an outage at our Memphis compute center this morning,” the company said. </p><p>“We’d also like to apologize to our impacted compute partners. All systems have now been restored and are functioning nominally.”</p><p>As <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal"><u><em>ITPro </em></u><u>reported in May</u></a>, Anthropic signed a multi-billion dollar deal with SpaceX to rent out “<a href="https://www.anthropic.com/news/higher-limits-spacex" target="_blank"><u>all of the compute capacity</u></a>” at the company’s Colossus 1 data center. The company also relies on infrastructure provided by Amazon, Google, Broadcom, Microsoft.</p><p>Some users on X have <a href="https://x.com/mark_k/status/2095782755577610614?s=20" target="_blank"><u>pointed to a potential domino effect situation</u></a> unfolding in the wake of the SpaceX outage. With Grok and Claude down, users may have flocked to OpenAI as a backup. </p><p>A spokesperson for OpenAI told <a href="https://www.wired.com/story/nobody-is-saying-why-openai-and-anthropic-had-outages-today/" target="_blank"><u><em>Wired </em></u></a>that a “routing error” started at around 7.43 am PT. <em>ITPro </em>approached OpenAI for comment, but did not receive a response by time of publication.</p><p>Dai said that the lack of clarity from each of the providers should raise concerns for enterprises and reinforces the need for greater vendor transparency. </p><p>When multiple major providers experience overlapping failures without a clearly established common cause, enterprises cannot accurately assess systemic risk, dependency concentration, or recurrence likelihood,” he told <em>ITPro</em>. </p><p>“This reinforces the importance of vendor transparency, dependency mapping, and risk assessments that extend beyond individual AI providers to the underlying infrastructure ecosystem.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/ai-is-increasingly-becoming-operational-infrastructure-rather-than-a-productivity-add-on-yesterdays-triple-ai-outage-should-be-a-wake-up-call-for-enterprises</link>
                                                                            <description>
                            <![CDATA[ Greater vendor transparency is needed in the wake of outages at OpenAI, Anthropic, and xAI ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VvAMFenFjr62ETLTm2pEc6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eyFHeH5jjDEbUmBZf8PrHJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 10:07:16 +0000</pubDate>                                                                                                                                <updated>Mon, 07 Sep 2026 07:17:02 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eyFHeH5jjDEbUmBZf8PrHJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Smartphone screen with selection of AI apps pictured in a dedicated folder titled &#039;Artificial Intelligence&#039;, including ChatGPT, Claude, Grok, Gemini and DeepSeek app symbols.]]></media:description>                                                            <media:text><![CDATA[Smartphone screen with selection of AI apps pictured in a dedicated folder titled &#039;Artificial Intelligence&#039;, including ChatGPT, Claude, Grok, Gemini and DeepSeek app symbols.]]></media:text>
                                <media:title type="plain"><![CDATA[Smartphone screen with selection of AI apps pictured in a dedicated folder titled &#039;Artificial Intelligence&#039;, including ChatGPT, Claude, Grok, Gemini and DeepSeek app symbols.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eyFHeH5jjDEbUmBZf8PrHJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A simultaneous outage affecting OpenAI, Anthropic and xAI should act as a wake-up call for enterprises, analysts have told <em>ITPro</em>. </p><p>All three providers reported service disruption starting at about 6.30am Pacific Time on 3 September. While the outages were resolved within two-to-three, Charlie Dai, VP principal analyst at Forrester, said the incident puts the growing reliance of enterprises on <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today">AI tools</a> in the spotlight. </p><p>“The near-simultaneous disruptions highlight that AI is increasingly becoming operational infrastructure rather than a productivity add-on,” he told <em>ITPro</em>. </p><p>“Enterprises should treat AI availability as a resilience issue, implementing multi-model strategies, fallback workflows, and business continuity plans instead of assuming frontier AI services will always be available.”</p><p><a href="https://www.itpro.com/security/downtime-hits-hard-as-organizations-battle-hidden-costs">Downtime </a>of any kind can be highly damaging for businesses, impacting finances, consumer trust, and operational efficiency. With OpenAI and Anthropic ranking among the most popular AI providers on the market, any outage raises the stakes. </p><p>“Downtime can quickly translate into lost revenue, reduced employee productivity, delayed decisions, operational disruptions, SLA breaches, and customer dissatisfaction,” Dai said. </p><p>“As AI becomes embedded in customer service, software development, knowledge management, and business processes, even short interruptions can create cascading impacts across multiple teams and customer touchpoints.</p><h2 id="openai-anthropic-and-xai-outage-timeline">OpenAI, Anthropic, and xAI outage timeline</h2><p>OpenAI, Anthropic, and xAI first reported issues between 6.23 am and 7.45 am Pacific time yesterday. </p><p>Anthropic <a href="https://status.claude.com/" target="_blank"><u>confirmed </u></a>“elevated errors on requests” for Mythos 5.1, Claude Fable 5.1, and Claude Opus 5 at 6.23 am PT. </p><p>OpenAI, meanwhile, <a href="https://status.openai.com/incidents/01M1KWEDH417T2CF44YYHZDFCR" target="_blank"><u>reported </u></a>“elevated errors” across <a href="https://www.itpro.com/technology/artificial-intelligence/openai-just-revealed-what-people-really-use-chatgpt-for-and-70-percent-of-queries-have-nothing-to-do-with-work">ChatGPT </a>and <a href="https://www.itpro.com/technology/artificial-intelligence/openais-codex-app-is-now-available-on-macos-and-its-free-for-some-chatgpt-users-for-a-limited-time">Codex</a>. xAI also confirmed Grok was “experiencing issues”. </p><p>Based on respective status updates, all three providers resolved the issues within two-to-three hours: OpenAI marked the case as resolved at 9.15 am, while Anthropic and xAI reported fixes at 9.16 am and 10.05 am respectively.</p><h2 id="the-mystery-source">The mystery source</h2><p>With all three providers all experiencing outages in tandem, speculation over a common source was rife. Initial suggestions that a cloud or networking provider was behind the outages fell flat, however. </p><p>Neither Amazon Web Services (AWS), Microsoft Azure, nor Google Cloud reported downtime yesterday. Cloudflare, meanwhile, told <em>ITPro </em>that services were operating as expected at the time. </p><p>“Cloudflare is not experiencing any significant service disruptions at this time,” the company said. “Our services are operating normally, and any reporting that deviates from this is incorrect.”</p><p>In a <a href="https://x.com/SpaceXAI/status/2095597264043717014?s=20" target="_blank"><u>statement via X</u></a>, however, SpaceX revealed an outage at the company’s Memphis data center yesterday morning impacted Grok services. </p><p>“We are sorry for the issues you may have experienced with Grok following an outage at our Memphis compute center this morning,” the company said. </p><p>“We’d also like to apologize to our impacted compute partners. All systems have now been restored and are functioning nominally.”</p><p>As <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal"><u><em>ITPro </em></u><u>reported in May</u></a>, Anthropic signed a multi-billion dollar deal with SpaceX to rent out “<a href="https://www.anthropic.com/news/higher-limits-spacex" target="_blank"><u>all of the compute capacity</u></a>” at the company’s Colossus 1 data center. The company also relies on infrastructure provided by Amazon, Google, Broadcom, Microsoft.</p><p>Some users on X have <a href="https://x.com/mark_k/status/2095782755577610614?s=20" target="_blank"><u>pointed to a potential domino effect situation</u></a> unfolding in the wake of the SpaceX outage. With Grok and Claude down, users may have flocked to OpenAI as a backup. </p><p>A spokesperson for OpenAI told <a href="https://www.wired.com/story/nobody-is-saying-why-openai-and-anthropic-had-outages-today/" target="_blank"><u><em>Wired </em></u></a>that a “routing error” started at around 7.43 am PT. <em>ITPro </em>approached OpenAI for comment, but did not receive a response by time of publication.</p><p>Dai said that the lack of clarity from each of the providers should raise concerns for enterprises and reinforces the need for greater vendor transparency. </p><p>When multiple major providers experience overlapping failures without a clearly established common cause, enterprises cannot accurately assess systemic risk, dependency concentration, or recurrence likelihood,” he told <em>ITPro</em>. </p><p>“This reinforces the importance of vendor transparency, dependency mapping, and risk assessments that extend beyond individual AI providers to the underlying infrastructure ecosystem.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Kaseya announces new compliance and Apple device management tools for Datto RMM ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Kaseya has launched two major enhancements to its Datto RMM platform, in a move designed to help MSPs and IT teams strengthen their compliance capabilities and simplify management of Apple devices.</p><p>Unveiled during the vendor’s <em>Kaseya Connect Edge</em> event, the updates will introduce FIPS 140-3 validated cryptography and native <a href="https://www.itpro.com/business-operations/business-management/361508/apple-unveils-business-essentials-for-smbs">Apple mobile device management</a> (MDM) capabilities to the firm’s cloud-based remote monitoring and management platform from October.</p><p>With the FIPS 140-3 update, the company is aiming to help organizations meet evolving compliance requirements in regulated sectors, while the native Apple MDM will enable users to manage iOS, iPadOS, and <a href="https://www.itpro.com/technology/artificial-intelligence/openais-codex-app-is-now-available-on-macos-and-its-free-for-some-chatgpt-users-for-a-limited-time">macOS </a>devices alongside other endpoints from within Datto RMM.</p><p>"As regulatory requirements continue to evolve, MSPs and IT teams shouldn't have to choose between compliance and operational efficiency," said Kaseya chief technology officer Pratik Wadher in an announcement.</p><p>"At Kaseya, we're making it easier for organizations to pursue opportunities in highly regulated industries while continuing to leverage the automation, visibility and security capabilities they rely on every day.”</p><h2 id="fips-140-3-compliance">FIPS 140-3 compliance</h2><p>Starting in October, Datto RMM will add FIPS 140-3 validated cryptography at no additional cost to customers.</p><p>The capability uses a NIST-validated cryptographic module to secure the platform’s core communication channels and can be enabled through a single account-wide setting. Kaseya said its inclusion will enable organizations to adopt the new standard on their own timeline, with the feature switched off by default.</p><p>Existing <a href="https://www.itpro.com/technology/datto-rmm-a-security-first-solution">Datto RMM</a> capabilities – including patch management, automation, monitoring, and remote control – will remain available when the setting is enabled, with audit-ready logging built in to reduce audit and legal exposure.</p><p>The company added that the move aims to help partners pursue opportunities in regulated industries such as government, healthcare, finance, and defense, as organizations transition toward the FIPS 140-3 standard.</p><h2 id="native-apple-mdm">Native Apple MDM</h2><p>Datto RMM is also gaining native Apple MDM capabilities from early October, which will give MSPs and IT teams a centralized way to manage Apple devices without relying on a separate mobile device management platform.</p><p>According to Kaseya, the update will help reduce the cost, complexity, and visibility gaps involved with managing mobile devices through separate MDM tools.</p><p>Users will be able to enroll iOS, iPadOS, and macOS devices individually or in bulk via Apple Business Manager, configure security and compliance policies, deploy applications, and take remote actions directly within Datto RMM.</p><p>Apple devices will also appear alongside other managed endpoints across the platform’s existing dashboards, filters, and compliance reports, which Kaseya said will provide technicians with a more unified view of their customers’ environments.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-protection/kaseya-announces-new-compliance-and-apple-device-management-tools-for-datto-rmm</link>
                                                                            <description>
                            <![CDATA[ The enhancements will introduce FIPS 140-3 validated cryptography and native Apple MDM to the remote monitoring and management platform ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Lin7pGXoVrmevnfHF6JCbm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QDVrTGUP6HsSVNuiHY5oe6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 04 Sep 2026 08:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QDVrTGUP6HsSVNuiHY5oe6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Kaseya company logo pictured on a smartphone screen with company branding blurred in background.]]></media:description>                                                            <media:text><![CDATA[Kaseya company logo pictured on a smartphone screen with company branding blurred in background.]]></media:text>
                                <media:title type="plain"><![CDATA[Kaseya company logo pictured on a smartphone screen with company branding blurred in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QDVrTGUP6HsSVNuiHY5oe6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Kaseya has launched two major enhancements to its Datto RMM platform, in a move designed to help MSPs and IT teams strengthen their compliance capabilities and simplify management of Apple devices.</p><p>Unveiled during the vendor’s <em>Kaseya Connect Edge</em> event, the updates will introduce FIPS 140-3 validated cryptography and native <a href="https://www.itpro.com/business-operations/business-management/361508/apple-unveils-business-essentials-for-smbs">Apple mobile device management</a> (MDM) capabilities to the firm’s cloud-based remote monitoring and management platform from October.</p><p>With the FIPS 140-3 update, the company is aiming to help organizations meet evolving compliance requirements in regulated sectors, while the native Apple MDM will enable users to manage iOS, iPadOS, and <a href="https://www.itpro.com/technology/artificial-intelligence/openais-codex-app-is-now-available-on-macos-and-its-free-for-some-chatgpt-users-for-a-limited-time">macOS </a>devices alongside other endpoints from within Datto RMM.</p><p>"As regulatory requirements continue to evolve, MSPs and IT teams shouldn't have to choose between compliance and operational efficiency," said Kaseya chief technology officer Pratik Wadher in an announcement.</p><p>"At Kaseya, we're making it easier for organizations to pursue opportunities in highly regulated industries while continuing to leverage the automation, visibility and security capabilities they rely on every day.”</p><h2 id="fips-140-3-compliance">FIPS 140-3 compliance</h2><p>Starting in October, Datto RMM will add FIPS 140-3 validated cryptography at no additional cost to customers.</p><p>The capability uses a NIST-validated cryptographic module to secure the platform’s core communication channels and can be enabled through a single account-wide setting. Kaseya said its inclusion will enable organizations to adopt the new standard on their own timeline, with the feature switched off by default.</p><p>Existing <a href="https://www.itpro.com/technology/datto-rmm-a-security-first-solution">Datto RMM</a> capabilities – including patch management, automation, monitoring, and remote control – will remain available when the setting is enabled, with audit-ready logging built in to reduce audit and legal exposure.</p><p>The company added that the move aims to help partners pursue opportunities in regulated industries such as government, healthcare, finance, and defense, as organizations transition toward the FIPS 140-3 standard.</p><h2 id="native-apple-mdm">Native Apple MDM</h2><p>Datto RMM is also gaining native Apple MDM capabilities from early October, which will give MSPs and IT teams a centralized way to manage Apple devices without relying on a separate mobile device management platform.</p><p>According to Kaseya, the update will help reduce the cost, complexity, and visibility gaps involved with managing mobile devices through separate MDM tools.</p><p>Users will be able to enroll iOS, iPadOS, and macOS devices individually or in bulk via Apple Business Manager, configure security and compliance policies, deploy applications, and take remote actions directly within Datto RMM.</p><p>Apple devices will also appear alongside other managed endpoints across the platform’s existing dashboards, filters, and compliance reports, which Kaseya said will provide technicians with a more unified view of their customers’ environments.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Open weight models are closing the capability gap with frontier models at a fraction of the cost’: Cheap Chinese AI models could spell trouble for US big tech ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The rising quality of <a href="https://www.itpro.com/technology/artificial-intelligence/should-businesses-consider-using-chinese-ai-models">cheaper Chinese AI models</a> could wreak havoc on the US tech industry, according to Juniper Research. </p><p><a href="https://www.juniperresearch.com/resources/free-research/beyond-the-headlines-what-the-ai-bubble-really-means/" target="_blank"><u>Analysis from the consultancy</u></a> suggests leading US tech giants could find themselves losing out to Chinese rivals offering alternatives in a bid to break the industry’s global dominance. </p><p>Juniper Research pointed to figures from OpenRouter, which show that just 30% of the work on that platform was through AI models offered by leading providers such as OpenAI, Google, or Anthropic. That marks a steep fall from 70% last year. </p><p>The report noted that Chinese models typically run 60% to 90% cheaper than rivals from Anthropic and OpenAI. The pricing challenge from China was first faced last year when <a href="https://www.itpro.com/technology/artificial-intelligence/chinese-ai-firm-deepseek-has-silicon-valley-flustered"><u>DeepSeek hit the market</u></a>, tanking tech stocks briefly by offering high-level performance at a much lower cost. </p><p>This year, Alibaba's <a href="https://www.itpro.com/technology/artificial-intelligence/three-open-source-large-language-models-you-can-use-today">Qwen models</a> had overtaken Meta's Llama as the most downloaded open model system, the report noted. </p><p>February marked the "real crossover into cheaper inference", Juniper added, with Chinese models processing 4.12 trillion tokens on OpenRouter vs 2.94 trillion for American models. </p><p>That's all down to lower prices for capable-enough open models, the consultancy noted.</p><p>“Open weight models are closing the capability gap with frontier models at a fraction of the cost," said Juniper Senior Analyst Jawad Jahan.</p><p>The trend is also being aided by more efficient designs, such as Mixture of Experts (MoE) models, which only use necessary parameters for a given query. </p><p>"This cuts compute-per-query without shrinking the model’s capability," the report noted. "DeepSeek is the cleanest example of this. Its V3 models carry 671 billion parameters in total, but only 37 billion of them fire for any given token. This led to a cut of V3.2’s price by more than half, as a result of lowering the cost of long-context inference."</p><h2 id="cutting-costs-with-chinese-ai-models">Cutting costs with Chinese AI models</h2><p>According to Juniper, DeepSeek's V4 Flash cost $0.14 per million input tokens against $5.00 for <a href="https://www.itpro.com/security/openai-expands-daybreak-cyber-program-new-tools-partnerships-and-a-cyber-focused-gpt-5-5-aim-to-help-patch-the-world">OpenAI’s GPT-5.5</a>, while Claude Opus 4.8 was at the time charging about $5 for input and $25 for output per million tokens. </p><p>"This pricing gap has existed ever since the release of the first Chinese open-sourced model that was able to rival frontier organizations in the West," the report noted. </p><p>Shifting demand has altered the picture, however, with programming rising from 11% to more than half of OpenRouter's token volume. Agentic workloads also account for the majority of output, Juniper said. </p><p>"Given the large call frequency for agentic workloads, per-token pricing starts to become a real budget consideration and constraint," the report noted.</p><h2 id="funding-the-ai-roll-out">Funding the AI roll-out</h2><p>That raises a problem, one that Juniper refers to as an "existential risk": can we afford all the borrowed billions being spent on data centers via "complex financing agreements" if customers stop paying for the very best models and instead choose cheaper Chinese options? </p><p>The firm argued that if the price of running AI falls too low, companies will lose the ability to make revenue from it to pay for all this investment. </p><p>That concern isn't new, either. Investors have been <a href="https://www.itpro.com/business/business-strategy/google-clouds-record-results-cant-quiet-concerns-on-ai-spending-and-model-release-timelines"><u>questioning the massive spending on data centers</u></a>, with Juniper noting that the four major hyperscalers are expected to spend $725 billion on capital expenditure this year, up by 77% compared to the year prior.</p><p>Beyond the raw figures, Juniper pointed to the convoluted ways American companies are gathering the funds to pay for such projects, largely spurred by the AI infrastructure spending outpacing available cashflow and revenue. </p><p>The firm noted that this year the top five hyperscalers will spend more than a trillion dollars on infrastructure for AI. </p><p>"This figure exceeds their combined earnings and free cashflow," the report said. </p><p>Juniper claimed this has driven a rise in "off balance sheet financing" — in which companies don't borrow directly but build standalone legal entities to carry debt, later leasing the infrastructure back to the hyperscaler.</p><p>Circular financing is also a concern, which Juniper defines as a supplier investing in a company with the understanding the recipient will spend those funds buying the supplier's products. </p><p>The consultancy pointed to OpenAI's deals with Oracle and Nvidia as prime examples.</p><h2 id="chinese-challenge-to-funding-structures">Chinese challenge to funding structures</h2><p>If revenue from AI starts to shift to China, these spending levels and funding structures could prove problematic, the analyst firm noted. </p><p>"If this trend continues, the inference revenue underwriting the Western datacentre build-out weakens, and, correspondingly, the financing structures resting on that revenue,” Jahan commented.</p><p>That's exacerbated by the fact Chinese companies don't face the same issues, with funding either so far provided by external financial businesses, particularly in the case of DeepSeek. </p><p>Similarly, they aren’t beholden to a business model that sees cloud providers like Alibaba and Baidu effectively give the model away, then sell the compute to make use of it. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/open-weight-models-are-closing-the-capability-gap-with-frontier-models-at-a-fraction-of-the-cost-cheap-chinese-ai-models-could-spell-trouble-for-us-big-tech</link>
                                                                            <description>
                            <![CDATA[ Powerful new open weight models from Chinese providers could undercut AI revenues and unbalance funding models for big tech's infrastructure rollout ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">94ag4G4VKN5objAr8n2hnk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/B2K9HhHgVDEXtjMsMYMowg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 15:20:15 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/B2K9HhHgVDEXtjMsMYMowg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The flag of the People&#039;s Republic of China (PRC) and United States pictured side-by-side.]]></media:description>                                                            <media:text><![CDATA[The flag of the People&#039;s Republic of China (PRC) and United States pictured side-by-side.]]></media:text>
                                <media:title type="plain"><![CDATA[The flag of the People&#039;s Republic of China (PRC) and United States pictured side-by-side.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/B2K9HhHgVDEXtjMsMYMowg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The rising quality of <a href="https://www.itpro.com/technology/artificial-intelligence/should-businesses-consider-using-chinese-ai-models">cheaper Chinese AI models</a> could wreak havoc on the US tech industry, according to Juniper Research. </p><p><a href="https://www.juniperresearch.com/resources/free-research/beyond-the-headlines-what-the-ai-bubble-really-means/" target="_blank"><u>Analysis from the consultancy</u></a> suggests leading US tech giants could find themselves losing out to Chinese rivals offering alternatives in a bid to break the industry’s global dominance. </p><p>Juniper Research pointed to figures from OpenRouter, which show that just 30% of the work on that platform was through AI models offered by leading providers such as OpenAI, Google, or Anthropic. That marks a steep fall from 70% last year. </p><p>The report noted that Chinese models typically run 60% to 90% cheaper than rivals from Anthropic and OpenAI. The pricing challenge from China was first faced last year when <a href="https://www.itpro.com/technology/artificial-intelligence/chinese-ai-firm-deepseek-has-silicon-valley-flustered"><u>DeepSeek hit the market</u></a>, tanking tech stocks briefly by offering high-level performance at a much lower cost. </p><p>This year, Alibaba's <a href="https://www.itpro.com/technology/artificial-intelligence/three-open-source-large-language-models-you-can-use-today">Qwen models</a> had overtaken Meta's Llama as the most downloaded open model system, the report noted. </p><p>February marked the "real crossover into cheaper inference", Juniper added, with Chinese models processing 4.12 trillion tokens on OpenRouter vs 2.94 trillion for American models. </p><p>That's all down to lower prices for capable-enough open models, the consultancy noted.</p><p>“Open weight models are closing the capability gap with frontier models at a fraction of the cost," said Juniper Senior Analyst Jawad Jahan.</p><p>The trend is also being aided by more efficient designs, such as Mixture of Experts (MoE) models, which only use necessary parameters for a given query. </p><p>"This cuts compute-per-query without shrinking the model’s capability," the report noted. "DeepSeek is the cleanest example of this. Its V3 models carry 671 billion parameters in total, but only 37 billion of them fire for any given token. This led to a cut of V3.2’s price by more than half, as a result of lowering the cost of long-context inference."</p><h2 id="cutting-costs-with-chinese-ai-models">Cutting costs with Chinese AI models</h2><p>According to Juniper, DeepSeek's V4 Flash cost $0.14 per million input tokens against $5.00 for <a href="https://www.itpro.com/security/openai-expands-daybreak-cyber-program-new-tools-partnerships-and-a-cyber-focused-gpt-5-5-aim-to-help-patch-the-world">OpenAI’s GPT-5.5</a>, while Claude Opus 4.8 was at the time charging about $5 for input and $25 for output per million tokens. </p><p>"This pricing gap has existed ever since the release of the first Chinese open-sourced model that was able to rival frontier organizations in the West," the report noted. </p><p>Shifting demand has altered the picture, however, with programming rising from 11% to more than half of OpenRouter's token volume. Agentic workloads also account for the majority of output, Juniper said. </p><p>"Given the large call frequency for agentic workloads, per-token pricing starts to become a real budget consideration and constraint," the report noted.</p><h2 id="funding-the-ai-roll-out">Funding the AI roll-out</h2><p>That raises a problem, one that Juniper refers to as an "existential risk": can we afford all the borrowed billions being spent on data centers via "complex financing agreements" if customers stop paying for the very best models and instead choose cheaper Chinese options? </p><p>The firm argued that if the price of running AI falls too low, companies will lose the ability to make revenue from it to pay for all this investment. </p><p>That concern isn't new, either. Investors have been <a href="https://www.itpro.com/business/business-strategy/google-clouds-record-results-cant-quiet-concerns-on-ai-spending-and-model-release-timelines"><u>questioning the massive spending on data centers</u></a>, with Juniper noting that the four major hyperscalers are expected to spend $725 billion on capital expenditure this year, up by 77% compared to the year prior.</p><p>Beyond the raw figures, Juniper pointed to the convoluted ways American companies are gathering the funds to pay for such projects, largely spurred by the AI infrastructure spending outpacing available cashflow and revenue. </p><p>The firm noted that this year the top five hyperscalers will spend more than a trillion dollars on infrastructure for AI. </p><p>"This figure exceeds their combined earnings and free cashflow," the report said. </p><p>Juniper claimed this has driven a rise in "off balance sheet financing" — in which companies don't borrow directly but build standalone legal entities to carry debt, later leasing the infrastructure back to the hyperscaler.</p><p>Circular financing is also a concern, which Juniper defines as a supplier investing in a company with the understanding the recipient will spend those funds buying the supplier's products. </p><p>The consultancy pointed to OpenAI's deals with Oracle and Nvidia as prime examples.</p><h2 id="chinese-challenge-to-funding-structures">Chinese challenge to funding structures</h2><p>If revenue from AI starts to shift to China, these spending levels and funding structures could prove problematic, the analyst firm noted. </p><p>"If this trend continues, the inference revenue underwriting the Western datacentre build-out weakens, and, correspondingly, the financing structures resting on that revenue,” Jahan commented.</p><p>That's exacerbated by the fact Chinese companies don't face the same issues, with funding either so far provided by external financial businesses, particularly in the case of DeepSeek. </p><p>Similarly, they aren’t beholden to a business model that sees cloud providers like Alibaba and Baidu effectively give the model away, then sell the compute to make use of it. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security experts warn cyber insurance ‘should not be treated as a get-out-of-jail-free card’ ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Just one in five UK business leaders believe their <a href="https://www.itpro.com/security/cyber-security/368458/what-is-cyber-insurance"><u>cyber insurance</u></a> will provide adequate protection in the event of a breach, according to new research from Cohesity. </p><p>In a survey conducted by the firm, only 22% of respondents believe cyber insurance policies will cover the costs and revenue losses associated with a cyber attack.</p><p>Cohesity said the survey highlights growing anxiety among business leaders given the heightened threats enterprises face. Concerns over losses in the wake of an attack are also growing, the survey noted. </p><p>CEOs estimate that a cyber attack could cut their organization’s revenue by 15.17% on average. </p><p>These figures are a ballpark estimate, however. One in five reveal that their business has “never undertaken business impact modelling to understand the potential cost of an attack”. </p><p>Without modelling, Cohesity warned that enterprises might never know the true scale of their potential insurance shortfalls, and this could come back to bite them. </p><p>Fraser Hutchison, VP UKI at Cohesity, said the study shows cyber insurance “should not be treated as a get-out-of-jail-free card”. </p><p>“As the threat landscape becomes increasingly complex, organizations cannot treat an insurance policy as a substitute for resilience,” he said. </p><p>“Organizations need to understand exactly what their policies will and will not cover, model the potential impact of different attack scenarios and prepare for losses that may fall outside their policies.”</p><h2 id="cyber-insurance-in-the-spotlight">Cyber insurance in the spotlight</h2><p><a href="https://www.itpro.com/security/why-your-business-needs-cyber-insurance"><u>Cyber insurance is now viewed as a critical fallback for enterprises </u></a>due to rising global security threats, yet research from the UK government’s <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025"><u>Cyber Security Breaches</u></a> survey found half of firms across the country have no policy at all. </p><p>Awareness is rising, however. <a href="https://www.itpro.com/security/cyber-attacks/cyber-insurance-payouts-are-skyrocketing"><u>Analysis from the Association of British Insurers (ABI)</u></a> in November last year showed 17% more policies were taken out across 2025 than in the year prior. </p><p>Speaking at the time, Jonathan Fong, head of general insurance policy at the ABI, said cyber insurance is “more than just a financial safety net” and now forms a key component of broader resilience strategies. </p><p>“The right policy not only supports businesses in the aftermath of an incident, but can also help prevent attacks through access to expert advice, threat monitoring, and incident response planning,” he said. </p><p>That study from ABI found cyber insurance payouts skyrocketed in 2025, with £197 million paid out across the year. </p><p>ABI pointed to Marks & Spencer (M&S), which <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack"><u>recovered £100 million from insurers</u></a> after a devastating attack disrupted operations in April 2025. </p><h2 id="knowing-your-policy">Knowing your policy</h2><p>Cohesity urged UK business leaders to improve their understanding of cyber insurance policies, including what they’re entitled to in the event of a cyber attack. </p><p>First and foremost, firms need to understand their full financial exposure, modeling the “direct and indirect consequences of different attack scenarios”. </p><p>This includes potential revenue losses, downtime, remediation costs, customer attrition, reputational damage, and lost productivity. All these metrics are crucial when measuring the broader impact of an attack. </p><p>Similarly, understanding what insurers <em>will and will not</em> cover is vital. According to Cohesity, business leaders “need clarity” on areas such as policy limits, exclusions, and conditions, as well as the losses the organization itself needs to absorb. </p><h2 id="focus-on-resilience">Focus on resilience</h2><p>According to Hutchison, the best approach for enterprises is to bolster cyber resilience capabilities to avoid any difficult conversations in the event of an attack. </p><p>“Cyber insurance can mitigate some of the financial risk, but the only way to truly bounce back from a cyber attack is by embedding genuine resilience into operations,” he said. </p><p>Hutchison added that enterprises need to identify systems and data that are critical to keeping the lights on in the event of a breach. </p><p>Elsewhere, assigning “clear responsibility” for recovery decisions is vital, as is regular testing to establish whether critical services can be restored in a timely fashion. </p><p>Improving cyber resilience also has a tangible impact on the cost of cyber insurance, research shows. </p><p>As <a href="https://www.itpro.com/security/want-cheaper-cyber-insurance-security-leaders-say-improving-resilience-has-helped-them-save-on-coverage"><em>ITPro </em>previously reported</a>, research from Sophos found enterprises that improved security capabilities were able to push down cyber insurance coverage rates. </p><p>A whopping 97% of respondents told the security firm that they had invested in cyber resilience with the explicit goal of improving insurance rates. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/security-experts-warn-cyber-insurance-should-not-be-treated-as-a-get-out-of-jail-free-card</link>
                                                                            <description>
                            <![CDATA[ Cyber insurance might alleviate financial losses after an attack, but building resilience is still the best defense ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZTZuVQnT4G3yN5vEF9hwhF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L2yET6pYuZAKmcRAwtxBWV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:18:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L2yET6pYuZAKmcRAwtxBWV-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cyber Insurance concept image showing stacked dollar bills placed upon a cliff edge.]]></media:description>                                                            <media:text><![CDATA[Cyber Insurance concept image showing stacked dollar bills placed upon a cliff edge.]]></media:text>
                                <media:title type="plain"><![CDATA[Cyber Insurance concept image showing stacked dollar bills placed upon a cliff edge.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L2yET6pYuZAKmcRAwtxBWV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Just one in five UK business leaders believe their <a href="https://www.itpro.com/security/cyber-security/368458/what-is-cyber-insurance"><u>cyber insurance</u></a> will provide adequate protection in the event of a breach, according to new research from Cohesity. </p><p>In a survey conducted by the firm, only 22% of respondents believe cyber insurance policies will cover the costs and revenue losses associated with a cyber attack.</p><p>Cohesity said the survey highlights growing anxiety among business leaders given the heightened threats enterprises face. Concerns over losses in the wake of an attack are also growing, the survey noted. </p><p>CEOs estimate that a cyber attack could cut their organization’s revenue by 15.17% on average. </p><p>These figures are a ballpark estimate, however. One in five reveal that their business has “never undertaken business impact modelling to understand the potential cost of an attack”. </p><p>Without modelling, Cohesity warned that enterprises might never know the true scale of their potential insurance shortfalls, and this could come back to bite them. </p><p>Fraser Hutchison, VP UKI at Cohesity, said the study shows cyber insurance “should not be treated as a get-out-of-jail-free card”. </p><p>“As the threat landscape becomes increasingly complex, organizations cannot treat an insurance policy as a substitute for resilience,” he said. </p><p>“Organizations need to understand exactly what their policies will and will not cover, model the potential impact of different attack scenarios and prepare for losses that may fall outside their policies.”</p><h2 id="cyber-insurance-in-the-spotlight">Cyber insurance in the spotlight</h2><p><a href="https://www.itpro.com/security/why-your-business-needs-cyber-insurance"><u>Cyber insurance is now viewed as a critical fallback for enterprises </u></a>due to rising global security threats, yet research from the UK government’s <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025"><u>Cyber Security Breaches</u></a> survey found half of firms across the country have no policy at all. </p><p>Awareness is rising, however. <a href="https://www.itpro.com/security/cyber-attacks/cyber-insurance-payouts-are-skyrocketing"><u>Analysis from the Association of British Insurers (ABI)</u></a> in November last year showed 17% more policies were taken out across 2025 than in the year prior. </p><p>Speaking at the time, Jonathan Fong, head of general insurance policy at the ABI, said cyber insurance is “more than just a financial safety net” and now forms a key component of broader resilience strategies. </p><p>“The right policy not only supports businesses in the aftermath of an incident, but can also help prevent attacks through access to expert advice, threat monitoring, and incident response planning,” he said. </p><p>That study from ABI found cyber insurance payouts skyrocketed in 2025, with £197 million paid out across the year. </p><p>ABI pointed to Marks & Spencer (M&S), which <a href="https://www.itpro.com/security/cyber-attacks/m-and-s-reveals-massive-financial-hit-from-cyber-attack"><u>recovered £100 million from insurers</u></a> after a devastating attack disrupted operations in April 2025. </p><h2 id="knowing-your-policy">Knowing your policy</h2><p>Cohesity urged UK business leaders to improve their understanding of cyber insurance policies, including what they’re entitled to in the event of a cyber attack. </p><p>First and foremost, firms need to understand their full financial exposure, modeling the “direct and indirect consequences of different attack scenarios”. </p><p>This includes potential revenue losses, downtime, remediation costs, customer attrition, reputational damage, and lost productivity. All these metrics are crucial when measuring the broader impact of an attack. </p><p>Similarly, understanding what insurers <em>will and will not</em> cover is vital. According to Cohesity, business leaders “need clarity” on areas such as policy limits, exclusions, and conditions, as well as the losses the organization itself needs to absorb. </p><h2 id="focus-on-resilience">Focus on resilience</h2><p>According to Hutchison, the best approach for enterprises is to bolster cyber resilience capabilities to avoid any difficult conversations in the event of an attack. </p><p>“Cyber insurance can mitigate some of the financial risk, but the only way to truly bounce back from a cyber attack is by embedding genuine resilience into operations,” he said. </p><p>Hutchison added that enterprises need to identify systems and data that are critical to keeping the lights on in the event of a breach. </p><p>Elsewhere, assigning “clear responsibility” for recovery decisions is vital, as is regular testing to establish whether critical services can be restored in a timely fashion. </p><p>Improving cyber resilience also has a tangible impact on the cost of cyber insurance, research shows. </p><p>As <a href="https://www.itpro.com/security/want-cheaper-cyber-insurance-security-leaders-say-improving-resilience-has-helped-them-save-on-coverage"><em>ITPro </em>previously reported</a>, research from Sophos found enterprises that improved security capabilities were able to push down cyber insurance coverage rates. </p><p>A whopping 97% of respondents told the security firm that they had invested in cyber resilience with the explicit goal of improving insurance rates. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Popular’ AI use cases aren’t those delivering results. Gartner says focus on the basics for success and easy wins ]]></title>
                                                                                                <dc:content><![CDATA[ <p>IT leaders need to get back to basics and prioritize AI integration in areas where it can deliver real impact, according to Gartner, and that requires a more considered approach to adoption. </p><p>Tina Nunno, distinguished vice president and Gartner fellow, told <em>ITPro </em>that many IT leaders are still falling into a trap of following hype when it comes to <a href="https://www.itpro.com/technology/artificial-intelligence">AI</a>, and it’s hampering success. </p><p>“We’re human beings, and we follow hype,” she said. “We're curious about what we last saw published, or in a keynote, or we're curious about what the vendors are talking about.”</p><p>“But we still have to have, I think, a reasonable balance and need to think about what’s the business case? Some of the basics still really matter here.”</p><p>Nunno’s comments come after a Gartner survey found the most <a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-real-world-stories-of-the-sectors-ai-is-changing">popular AI use cases</a> are rarely the ones that deliver real business impact and value. </p><p>The survey of C-suite executives warned that adoption projects are being influenced by “heavily hyped” applications of the technology over those that actually generate value.</p><p>“We calculated what the most common use cases were, and then we compared them to the ones where they were getting the most reliable rates of return, and they didn't match,” Nunno told <em>ITPro</em>. “There wasn't even a lot of overlap.”</p><h2 id="choosing-the-popular-ai-use-cases-doesn-t-always-work">Choosing the ‘popular’ AI use cases doesn’t always work</h2><p>Gartner’s survey found that the three most popular AI use cases included <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>threat detection and response, identified by 54% of respondents, alongside IT service desk automation (54%), and <a href="https://www.itpro.com/software/development/ai-generated-code-software-developer-security-risk">automated code generation</a> and refactoring (44%). </p><p>Yet only the latter of these use cases ranked among the use cases that delivered positive operational or financial returns. </p><p>Intelligent IT asset and cost optimization (40%), <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-synthetic-data">synthetic data generation</a> (28%) and automated code generation and refactoring (23%) all ranked as the most successful use cases. </p><p>While hype is a key factor behind this disparity, Nunno told <em>ITPro </em>that it shows some ‘high performers’ are taking a more surgical approach to integrating the technology. </p><p>These businesses are focusing on overhauling or streamlining specific processes in a highly strategic manner, rather than taking a slap-dash approach and seeing what works. </p><p>“When we look at what’s most common, sometimes they’re more foundational AI implementations,” she explained. They’re not specific to the business unit. They’re not specific to the specific function that they’re attempting to perform.”</p><p>Nunno added that approaching adoption with a degree of generality rarely delivers tangible returns. It’s why having a clear-cut goal from the get-go is critical. </p><p>“There was a bit more specific nature in those that actually were showing returns,” she said. “They appeared to be more targeted, and as a result, because they were more targeted, they seem much more likely to deliver”. </p><p>Gartner’s findings align closely with recent <a href="https://www.itpro.com/business/business-strategy/flexibility-is-a-huge-advantage-for-small-businesses-adopting-ai-but-clear-strategy-and-bold-leadership-is-critical">research from Dell Technologies</a>, which also highlighted the importance of clear goals when it comes to AI adoption. </p><p>More than half (52%) of AI ‘front runners’ – those Dell identified as having the most success with the technology - had “clearly defined specific AI use cases”.</p><h2 id="be-prepared">Be prepared</h2><p>A lack of clear objectives and strategies is having a direct impact on scaling of AI across the enterprise, Gartner found. Indeed, just 22% of respondents said they’ve successfully scaled the technology across multiple business units. </p><p>Nunno told <em>ITPro </em>that this reinforces the importance of laying solid foundations before even embarking on projects. <a href="https://www.itpro.com/business/business-strategy/a-striking-finding-this-year-is-the-gap-between-individual-gains-and-enterprise-impact-mckinsey-says-ai-is-finally-paying-off-for-enterprises-but-rising-costs-and-constrained-efficiency-boosts-are-still-a-major-hurdle">Building maturity is critical</a>. </p><p>“For some organizations, we've seen there's a very strong correlation between the maturity of the organization and their ability to take advantage of AI,” she said. </p><p>“They haven't yet grown the AI skill sets that they need to bring the AI to scale, and that can be anything from the current state of their data, for example.”</p><p>Nunno admitted that this is often easier said than done. Basic foundational tasks like getting data in good shape and order are “a lot of work”. </p><p>“There’s still a very real investment that many of our clients are telling us they’re putting in to build those foundations to actually scale AI in the way that they would like,” she said. </p><p>“There’s a lot of heavy lifting that sometimes has to happen.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/popular-ai-use-cases-arent-those-delivering-results-gartner-says-focus-on-the-basics-for-success-and-easy-wins</link>
                                                                            <description>
                            <![CDATA[ Focusing on hype-driven AI use cases rarely delivers, so it’s important to start with the basics and build  from there ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SPBUe3TQ7BBzC57xucVLA6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/wHyq8nVFtPiG8vKPhbvPqG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 10:09:20 +0000</pubDate>                                                                                                                                <updated>Thu, 03 Sep 2026 10:10:20 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/wHyq8nVFtPiG8vKPhbvPqG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital transformation concept image showing male technologist in casual work wear standing in an office with glowing walls of data on either side.]]></media:description>                                                            <media:text><![CDATA[Digital transformation concept image showing male technologist in casual work wear standing in an office with glowing walls of data on either side.]]></media:text>
                                <media:title type="plain"><![CDATA[Digital transformation concept image showing male technologist in casual work wear standing in an office with glowing walls of data on either side.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/wHyq8nVFtPiG8vKPhbvPqG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>IT leaders need to get back to basics and prioritize AI integration in areas where it can deliver real impact, according to Gartner, and that requires a more considered approach to adoption. </p><p>Tina Nunno, distinguished vice president and Gartner fellow, told <em>ITPro </em>that many IT leaders are still falling into a trap of following hype when it comes to <a href="https://www.itpro.com/technology/artificial-intelligence">AI</a>, and it’s hampering success. </p><p>“We’re human beings, and we follow hype,” she said. “We're curious about what we last saw published, or in a keynote, or we're curious about what the vendors are talking about.”</p><p>“But we still have to have, I think, a reasonable balance and need to think about what’s the business case? Some of the basics still really matter here.”</p><p>Nunno’s comments come after a Gartner survey found the most <a href="https://www.itpro.com/technology/artificial-intelligence/practical-ai-real-world-stories-of-the-sectors-ai-is-changing">popular AI use cases</a> are rarely the ones that deliver real business impact and value. </p><p>The survey of C-suite executives warned that adoption projects are being influenced by “heavily hyped” applications of the technology over those that actually generate value.</p><p>“We calculated what the most common use cases were, and then we compared them to the ones where they were getting the most reliable rates of return, and they didn't match,” Nunno told <em>ITPro</em>. “There wasn't even a lot of overlap.”</p><h2 id="choosing-the-popular-ai-use-cases-doesn-t-always-work">Choosing the ‘popular’ AI use cases doesn’t always work</h2><p>Gartner’s survey found that the three most popular AI use cases included <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>threat detection and response, identified by 54% of respondents, alongside IT service desk automation (54%), and <a href="https://www.itpro.com/software/development/ai-generated-code-software-developer-security-risk">automated code generation</a> and refactoring (44%). </p><p>Yet only the latter of these use cases ranked among the use cases that delivered positive operational or financial returns. </p><p>Intelligent IT asset and cost optimization (40%), <a href="https://www.itpro.com/technology/artificial-intelligence/what-is-synthetic-data">synthetic data generation</a> (28%) and automated code generation and refactoring (23%) all ranked as the most successful use cases. </p><p>While hype is a key factor behind this disparity, Nunno told <em>ITPro </em>that it shows some ‘high performers’ are taking a more surgical approach to integrating the technology. </p><p>These businesses are focusing on overhauling or streamlining specific processes in a highly strategic manner, rather than taking a slap-dash approach and seeing what works. </p><p>“When we look at what’s most common, sometimes they’re more foundational AI implementations,” she explained. They’re not specific to the business unit. They’re not specific to the specific function that they’re attempting to perform.”</p><p>Nunno added that approaching adoption with a degree of generality rarely delivers tangible returns. It’s why having a clear-cut goal from the get-go is critical. </p><p>“There was a bit more specific nature in those that actually were showing returns,” she said. “They appeared to be more targeted, and as a result, because they were more targeted, they seem much more likely to deliver”. </p><p>Gartner’s findings align closely with recent <a href="https://www.itpro.com/business/business-strategy/flexibility-is-a-huge-advantage-for-small-businesses-adopting-ai-but-clear-strategy-and-bold-leadership-is-critical">research from Dell Technologies</a>, which also highlighted the importance of clear goals when it comes to AI adoption. </p><p>More than half (52%) of AI ‘front runners’ – those Dell identified as having the most success with the technology - had “clearly defined specific AI use cases”.</p><h2 id="be-prepared">Be prepared</h2><p>A lack of clear objectives and strategies is having a direct impact on scaling of AI across the enterprise, Gartner found. Indeed, just 22% of respondents said they’ve successfully scaled the technology across multiple business units. </p><p>Nunno told <em>ITPro </em>that this reinforces the importance of laying solid foundations before even embarking on projects. <a href="https://www.itpro.com/business/business-strategy/a-striking-finding-this-year-is-the-gap-between-individual-gains-and-enterprise-impact-mckinsey-says-ai-is-finally-paying-off-for-enterprises-but-rising-costs-and-constrained-efficiency-boosts-are-still-a-major-hurdle">Building maturity is critical</a>. </p><p>“For some organizations, we've seen there's a very strong correlation between the maturity of the organization and their ability to take advantage of AI,” she said. </p><p>“They haven't yet grown the AI skill sets that they need to bring the AI to scale, and that can be anything from the current state of their data, for example.”</p><p>Nunno admitted that this is often easier said than done. Basic foundational tasks like getting data in good shape and order are “a lot of work”. </p><p>“There’s still a very real investment that many of our clients are telling us they’re putting in to build those foundations to actually scale AI in the way that they would like,” she said. </p><p>“There’s a lot of heavy lifting that sometimes has to happen.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Manchester Airports Group attack: Millions of holidaymakers urged to look out for scams as hackers publish stolen data online ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hackers have leaked the personal details of 8.7 million people following an attack on three British airports.</p><p>The incident was first disclosed in late August, impacting travellers at <a href="https://www.itpro.com/security/cyber-attacks/manchester-airports-group-attack-everything-we-know-so-far-as-8-7-million-customers-impacted-in-breach">three locations managed by Manchester Airports Group (MAG)</a>: Stansted, East Midlands, and Manchester airports.</p><p>The criminals behind the attack, believed to be FulcrumSec, published the data online, claiming to have half a terabyte of personally identifiable information. </p><p>However, the hackers <a href="https://www.computerweekly.com/news/366649824/UK-airport-hackers-leak-stolen-customer-data" target="_blank"><u>reportedly said</u></a> they wouldn't be selling "dangerous" data about future travel plans over concerns it would lead to stalking or burglary. </p><p>"This is an expected update, but it’s one none of the victims wanted to hear," said Timon Johnson, principal cyber essentials assessor at Closed Door Security.  </p><p>"It was always unlikely MAG would pay the ransom demand as it is akin to doing business with criminals, and it’s also highly unlikely the data would ever have been returned in full without further exploitation."</p><h2 id="free-release-as-punishment">Free release as punishment</h2><p>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, agreed that MAG made the right call by refusing to pay the ransom. </p><p>However, that decision puts nearly nine million people at risk for mistakes that weren't made by them. </p><p>"The 'free release' model is deliberately designed to maximize harm and reputational damage as a warning to the next target," he said. </p><p>"Publishing almost nine million records for free isn't just punishment for MAG — it's a marketing campaign aimed at every other organization watching. Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost."</p><p>At this point, the airlines group says it has contacted everyone whose data was compromised.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement sent to the <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank"><u><em>BBC</em></u></a>.</p><h2 id="what-happened">What happened?</h2><p>The attack is believed to have started over the weekend of 22 August, with the intrusion spotted the following Tuesday by MAG's security team, which promptly shut down further access. The attack was publicly disclosed on Thursday, 27 August. </p><p>FulcrumSec later claimed responsibility for the attack, saying it would publish the data owing to MAG not negotiating a ransom. Yesterday, they followed through with that threat. </p><p>MAG said in a <a href="https://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/" target="_blank"><u>statement</u></a> that the customer data relates to the car park, lounge, and Fast Track bookings at the airports, as well as Wi-Fi signups, stressing there had been no operational disruption and that aviation security had not been compromised.</p><p>The data taken includes email addresses, phone numbers, vehicle registrations, and postcodes, but does not include bank or payment card details. </p><h2 id="what-now">What now? </h2><p>As the data has been published on the open web, the focus now turns to scams against the 8.7 million victims. </p><p>"Now that the data is available for free on the <a href="https://www.itpro.com/security/the-dark-web-is-absolutely-awash-with-stolen-data-on-british-mps">dark web</a>, other criminals will be working to exploit it," says Johnson. "<a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>presents the greatest risk, and all individuals must be vigilant for scams. These could come in via email, phone calls or texts, so all these communication methods must be monitored closely."</p><p>As ever, this means constant vigilance online: be wary of clicking links or opening attachments and don't share any financial or other personal data unless the receiver has been verified, added Johnson. </p><p>The inclusion of travel data exacerbates the risk, according to security expert Kevin Beaumont. </p><p>"The data includes both historical locations and planned future travel, so individuals sensitive to their movements being known may need to take precautions," he told the <em>BBC</em>. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-breaches/manchester-airports-group-attack-millions-of-holidaymakers-urged-to-look-out-for-scams-as-hackers-publish-stolen-data-online</link>
                                                                            <description>
                            <![CDATA[ The Manchester Airports Group attack could lead to fraud and scams, experts warn ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PoLZxGbqtMjx83aVosQkf5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DVmkPfYJrV73rHN98npwDo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 09:53:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DVmkPfYJrV73rHN98npwDo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Terminal 2 departures building at Manchester Airport, run by Manchester Airports Group, with passengers queuing at check-in point.]]></media:description>                                                            <media:text><![CDATA[Terminal 2 departures building at Manchester Airport, run by Manchester Airports Group, with passengers queuing at check-in point.]]></media:text>
                                <media:title type="plain"><![CDATA[Terminal 2 departures building at Manchester Airport, run by Manchester Airports Group, with passengers queuing at check-in point.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DVmkPfYJrV73rHN98npwDo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have leaked the personal details of 8.7 million people following an attack on three British airports.</p><p>The incident was first disclosed in late August, impacting travellers at <a href="https://www.itpro.com/security/cyber-attacks/manchester-airports-group-attack-everything-we-know-so-far-as-8-7-million-customers-impacted-in-breach">three locations managed by Manchester Airports Group (MAG)</a>: Stansted, East Midlands, and Manchester airports.</p><p>The criminals behind the attack, believed to be FulcrumSec, published the data online, claiming to have half a terabyte of personally identifiable information. </p><p>However, the hackers <a href="https://www.computerweekly.com/news/366649824/UK-airport-hackers-leak-stolen-customer-data" target="_blank"><u>reportedly said</u></a> they wouldn't be selling "dangerous" data about future travel plans over concerns it would lead to stalking or burglary. </p><p>"This is an expected update, but it’s one none of the victims wanted to hear," said Timon Johnson, principal cyber essentials assessor at Closed Door Security.  </p><p>"It was always unlikely MAG would pay the ransom demand as it is akin to doing business with criminals, and it’s also highly unlikely the data would ever have been returned in full without further exploitation."</p><h2 id="free-release-as-punishment">Free release as punishment</h2><p>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, agreed that MAG made the right call by refusing to pay the ransom. </p><p>However, that decision puts nearly nine million people at risk for mistakes that weren't made by them. </p><p>"The 'free release' model is deliberately designed to maximize harm and reputational damage as a warning to the next target," he said. </p><p>"Publishing almost nine million records for free isn't just punishment for MAG — it's a marketing campaign aimed at every other organization watching. Pay up, or your customers' data gets handed to every fraudster and scammer on the internet at no cost."</p><p>At this point, the airlines group says it has contacted everyone whose data was compromised.</p><p>"MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support," the company said in a statement sent to the <a href="https://www.bbc.co.uk/news/articles/c74k39g3ee5o" target="_blank"><u><em>BBC</em></u></a>.</p><h2 id="what-happened">What happened?</h2><p>The attack is believed to have started over the weekend of 22 August, with the intrusion spotted the following Tuesday by MAG's security team, which promptly shut down further access. The attack was publicly disclosed on Thursday, 27 August. </p><p>FulcrumSec later claimed responsibility for the attack, saying it would publish the data owing to MAG not negotiating a ransom. Yesterday, they followed through with that threat. </p><p>MAG said in a <a href="https://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/" target="_blank"><u>statement</u></a> that the customer data relates to the car park, lounge, and Fast Track bookings at the airports, as well as Wi-Fi signups, stressing there had been no operational disruption and that aviation security had not been compromised.</p><p>The data taken includes email addresses, phone numbers, vehicle registrations, and postcodes, but does not include bank or payment card details. </p><h2 id="what-now">What now? </h2><p>As the data has been published on the open web, the focus now turns to scams against the 8.7 million victims. </p><p>"Now that the data is available for free on the <a href="https://www.itpro.com/security/the-dark-web-is-absolutely-awash-with-stolen-data-on-british-mps">dark web</a>, other criminals will be working to exploit it," says Johnson. "<a href="https://www.itpro.com/security/29093/what-is-phishing">Phishing </a>presents the greatest risk, and all individuals must be vigilant for scams. These could come in via email, phone calls or texts, so all these communication methods must be monitored closely."</p><p>As ever, this means constant vigilance online: be wary of clicking links or opening attachments and don't share any financial or other personal data unless the receiver has been verified, added Johnson. </p><p>The inclusion of travel data exacerbates the risk, according to security expert Kevin Beaumont. </p><p>"The data includes both historical locations and planned future travel, so individuals sensitive to their movements being known may need to take precautions," he told the <em>BBC</em>. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know about the Dropbox breach so far ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hackers have breached cloud storage provider <a href="https://www.itpro.com/cloud-storage/32814/dropbox-business-advanced-review-first-rate-filesharing">Dropbox </a>via a flaw in Lenovo’s email verification process.</p><p>Around 5,000 accounts are believed to have been compromised during the first three weeks of August, with files viewed or downloaded from around 1,500 of these. It's not known who carried out the attack.</p><p>The breach arose through the <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a> option using Lenovo IDs. Dropbox partners with Lenovo as an identity provider, allowing users to log in to their Dropbox accounts using verified Lenovo IDs.</p><p>However, the process lacked enforced <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA)</a>, meaning that an attacker could gain full access without needing a password. Even users without a pre-existing Lenovo ID were vulnerable.</p><p>The company has now <a href="https://x.com/yonilevy/status/2094521566826541248/photo/1" target="_blank"><u>alerted users</u></a>.</p><p>"While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address," the company said.</p><p>Justin Beals, CEO and founder of Strike Graph, said the incident appears to have derived from a trusted legacy integration between the two firms.</p><p>"This is the same failure mode we keep seeing across every major vendor breach this year. Organizations assess the vendors they contract with directly, then treat every integration that vendor maintains as inherited trust. Nobody re-verifies the third-party connections a trusted platform has already built," he said. </p><p>"Traditional third-party <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">risk management</a> approaches have true positive detection rates below 30%, and a legacy authentication bridge between two major platforms is exactly the kind of dependency that a point-in-time questionnaire was never built to catch."</p><h2 id="dropbox-breach-could-39-ve-been-avoided">Dropbox breach could've been avoided</h2><p>Dropbox has now closed the loophole by expiring all sessions authenticated through Lenovo IDs, cutting any link between Lenovo, and adding the requirement for users to enter their Dropbox account password when attempting to use Lenovo ID authentication.</p><p>A spokesperson for Dropbox told <em>ITPro </em>the company reacted swiftly to the incident and has informed affected users. </p><p>“We emailed users we know were impacted, offered them support, and reported this event to relevant data protection regulators," they said.</p><p>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, suggested that some users only have themselves to blame for not implementing <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a>. </p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap, and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," he said.</p><p>Organizations should periodically audit what third-party services have authentication access to their accounts, he said. </p><p>"OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends,” Patel added.</p><p>Dropbox has been <a href="https://www.itpro.com/security/27169/68-million-dropbox-credentials-leak-online"><u>hit before</u></a>, with a 2012 breach that affected around two-thirds of the company's user base. Four years later, more than 68 million customer usernames and passwords were leaked. </p><p>On that occasion, accounts were compromised through password reuse, Dropbox said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-breaches/everything-we-know-about-the-dropbox-breach-so-far</link>
                                                                            <description>
                            <![CDATA[ The company has confirmed that thousands of accounts connected through Lenovo ID and lacking Dropbox two-factor authentication have been affected ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MXpDKnoTrX5pqNJcEH83ue</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/whouCEvG367mE97QpHjVuF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 03 Sep 2026 09:42:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/whouCEvG367mE97QpHjVuF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dropbox logo and branding displayed on a smartphone screen with black background.]]></media:description>                                                            <media:text><![CDATA[Dropbox logo and branding displayed on a smartphone screen with black background.]]></media:text>
                                <media:title type="plain"><![CDATA[Dropbox logo and branding displayed on a smartphone screen with black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/whouCEvG367mE97QpHjVuF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers have breached cloud storage provider <a href="https://www.itpro.com/cloud-storage/32814/dropbox-business-advanced-review-first-rate-filesharing">Dropbox </a>via a flaw in Lenovo’s email verification process.</p><p>Around 5,000 accounts are believed to have been compromised during the first three weeks of August, with files viewed or downloaded from around 1,500 of these. It's not known who carried out the attack.</p><p>The breach arose through the <a href="https://www.itpro.com/security/single-sign-on-sso/361728/what-is-single-sign-on-sso">single sign-on (SSO)</a> option using Lenovo IDs. Dropbox partners with Lenovo as an identity provider, allowing users to log in to their Dropbox accounts using verified Lenovo IDs.</p><p>However, the process lacked enforced <a href="https://www.itpro.com/security/29982/what-is-two-factor-authentication">two-factor authentication (2FA)</a>, meaning that an attacker could gain full access without needing a password. Even users without a pre-existing Lenovo ID were vulnerable.</p><p>The company has now <a href="https://x.com/yonilevy/status/2094521566826541248/photo/1" target="_blank"><u>alerted users</u></a>.</p><p>"While you may not have an existing Lenovo ID, our investigation determined that an issue with Lenovo’s email verification process allowed an unauthorized party to register a Lenovo ID using your email address and then use that Lenovo ID to log into the Dropbox account associated with that email address," the company said.</p><p>Justin Beals, CEO and founder of Strike Graph, said the incident appears to have derived from a trusted legacy integration between the two firms.</p><p>"This is the same failure mode we keep seeing across every major vendor breach this year. Organizations assess the vendors they contract with directly, then treat every integration that vendor maintains as inherited trust. Nobody re-verifies the third-party connections a trusted platform has already built," he said. </p><p>"Traditional third-party <a href="https://www.itpro.com/security/do-risk-awareness-and-risk-management-strategies-actually-make-a-difference">risk management</a> approaches have true positive detection rates below 30%, and a legacy authentication bridge between two major platforms is exactly the kind of dependency that a point-in-time questionnaire was never built to catch."</p><h2 id="dropbox-breach-could-39-ve-been-avoided">Dropbox breach could've been avoided</h2><p>Dropbox has now closed the loophole by expiring all sessions authenticated through Lenovo IDs, cutting any link between Lenovo, and adding the requirement for users to enter their Dropbox account password when attempting to use Lenovo ID authentication.</p><p>A spokesperson for Dropbox told <em>ITPro </em>the company reacted swiftly to the incident and has informed affected users. </p><p>“We emailed users we know were impacted, offered them support, and reported this event to relevant data protection regulators," they said.</p><p>Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, suggested that some users only have themselves to blame for not implementing <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA)</a>. </p><p>“Every single one of the compromised accounts lacked multi-factor authentication. In 2026, for cloud storage accounts holding data, that’s an indefensible gap, and it’s one that users could have closed themselves regardless of what Lenovo or Dropbox did or didn’t do with their legacy integration," he said.</p><p>Organizations should periodically audit what third-party services have authentication access to their accounts, he said. </p><p>"OAuth grants, SSO connections, and third-party login integrations accumulate silently and rarely get removed when the relationship that created them ends,” Patel added.</p><p>Dropbox has been <a href="https://www.itpro.com/security/27169/68-million-dropbox-credentials-leak-online"><u>hit before</u></a>, with a 2012 breach that affected around two-thirds of the company's user base. Four years later, more than 68 million customer usernames and passwords were leaked. </p><p>On that occasion, accounts were compromised through password reuse, Dropbox said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How MSSPs can deliver continuous pentesting without hiring more security experts ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Managed Security Service Providers (MSSPs) need continuous security testing and faster risk identification. But the cybersecurity talent shortage makes it harder to expand service delivery through hiring alone.</p><p>The challenge is becoming more urgent as cyber threats continue to grow. More than <a href="https://zerothreat.ai/blog/cyberattack-statistics"><u>2,244 cyberattacks occur every day worldwide</u></a>, according to our research. This creates constant pressure for organizations to identify and address security gaps before attackers do.</p><p>More risk and more demand. Traditional approaches and tools simply can’t keep up.</p><p>That reality is forcing MSSPs to change how they scale security services. The good part is that continuous pentesting no longer requires a proportional increase in headcount. With AI-powered automated penetration testing, MSSPs can expand security coverage, increase testing frequency, and serve more clients without continuously adding security specialists.</p><h2 id="why-continuous-security-coverage-is-getting-harder">Why continuous security coverage is getting harder</h2><p>Managing security for clients used to be like checking a box once a year, but that has changed. Each organization needs continuous security coverage to keep up with the updates they are deploying and the growing number of cyber threats.</p><p>The complexity of today’s applications can’t be tackled by traditional methods because:</p><ul><li>Cloud-native apps and APIs change daily, making annual penetration tests obsolete within weeks.</li><li>Hiring more security experts to manually test every environment is not feasible.</li><li>Attackers now use AI to scan and exploit systems continuously, moving far faster than manual audit cycles.</li></ul><p>As a result, many providers are rethinking how they scale offensive security services without continually expanding their security teams.</p><h2 id="why-hiring-more-people-isn-39-t-a-scalable-security-strategy">Why hiring more people isn't a scalable security strategy</h2><p>Hiring more security experts seems like the obvious way to add to continuous pentesting services. But in reality, fluctuating demand, shortage of skills, and other operational costs can make it difficult to sustain.</p><ol start="1"><li><strong>Skilled security talent is hard to find: </strong>The cybersecurity talent gap remains a major challenge across the industry. Recent ISC2 research found that 95% of organizations report at least one cybersecurity skills gap, while 59% face significant or critical skills shortages. Finding experienced pentesters, application security specialists, and offensive security experts is becoming increasingly tough.</li><li><strong>Hiring costs keep increasing: </strong>Recruiting security professionals is expensive, and other than salary, MSSPs need to account for onboarding, training, certifications, and retention efforts. With high demand for application security and threat exposure management skills, the cost of building larger teams rises with it.</li><li><strong>Client growth often outpaces team growth: </strong>Security teams do not scale at the same rate as client demand. As MSSPs add more customers, each new environment introduces additional assets, attack surfaces, vulnerabilities, and testing requirements. Hiring one person at a time rarely keeps pace with the volume of continuous security assessments clients expect.</li><li><strong>Specialized expertise does not scale easily: </strong>Continuous pentesting demands expertise in web applications, APIs, cloud environments, business logic testing, and risk validation. Building teams with every required specialty can easily become impractical for growing MSSPs.</li><li><strong>More people can create operational bottlenecks: </strong>Adding more heads to the team does not mean improved service delivery. Larger teams require coordination, management, quality assurance, and workflow standardization. In many cases, operational complexity grows faster than productivity, reducing the efficiency gains MSSPs expected from hiring more analysts and testers.</li></ol><p>The key problem with hiring more isn’t just about finding more skilled experts; it’s finding a way to offer continuous security coverage while utilizing the resources efficiently.</p><h2 id="how-mssps-can-provide-continuous-pentesting-without-hiring">How MSSPs can provide continuous pentesting without hiring</h2><p>The most practical way to scale continuous pentesting today is to combine security expertise with AI-powered automated penetration testing that increases coverage, testing frequency, and operational efficiency.</p><p><strong>Automate repetitive security testing tasks:</strong> A large portion of pentesting involves reconnaissance, attack surface discovery, vulnerability validation, and retesting. AI-powered pentesting platforms can help you automate these repeatable tasks so that you can focus on higher-value investigations and risk analysis.</p><p><strong>Integrate security testing into existing pipelines: </strong>You should embed automated testing directly into the client delivery process. This ensures that every configuration change is tested immediately rather than waiting for an annual check. It turns security from periodic, labor-intensive work into an automated process.</p><p><strong>Implement multi-tenant management: </strong>Instead of configuring tests for each client individually, use multi-tenant dashboards. This allows your current engineering or SOC team to centrally schedule automated tests, distribute reports, and track remediation across hundreds of client environments simultaneously.</p><p><strong>Prioritize findings based on real risk:</strong> Use modern AI-powered pentesting platforms that help correlate findings, validate exploitability, and highlight the issues most likely to impact the client. This improves remediation efficiency and helps you deliver clearer security outcomes.</p><p><strong>Utilize white-label reseller tools:</strong> The best way to save time and effort on preparing reports is by using a tool that offers white-labeled reports. The reports are generated by AI-powered tools, and you can keep your Logos & URLs, making sure you deliver professional, client-ready documentation without manual formatting.</p><h2 id="what-mssps-should-look-for-in-a-scalable-continuous-pentesting-solution">What MSSPs should look for in a scalable continuous pentesting solution</h2><p>As client environments grow complex, MSSPs need solutions that can expand security coverage without operational burden. The ideal platform should help teams identify risks faster, validate findings more efficiently, and deliver consistent security outcomes across multiple customers.</p><p>When evaluating a solution, focus on capabilities that support long-term scalability:</p><ul><li>Continuous attack surface monitoring</li><li>AI-assisted vulnerability validation</li><li>Web application, API, cloud, and external asset coverage</li><li>Risk-based prioritization of findings</li><li>Automated retesting and remediation tracking</li><li>Multi-tenant management and reporting</li><li>Integration with existing security workflows and ticketing systems</li></ul><p>The right tool helps security teams spend less time on repetitive testing and more time delivering meaningful risk insights. For MSSPs, that balance is what makes continuous pentesting both operationally sustainable and commercially viable.</p><p>Continuous pentesting is the new basic expectation of clients, and that has turned out to be the new challenge for MSSPs. If they rely only on hiring to offer continuous testing services, it is rarely sustainable in a market already facing a cybersecurity skills shortage.</p><p>The most effective path forward is to combine security expertise with AI-powered automation.</p><p>By automating repetitive testing activities and enabling continuous security validation, MSSPs can support more clients, identify risks faster, and scale their services without compromising the quality of protection they deliver.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/how-mssps-can-deliver-continuous-pentesting-without-hiring-more-security-experts</link>
                                                                            <description>
                            <![CDATA[ MSSPs can scale and strengthen their security posture using AI instead of expanding security teams... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7sUn7zuCnbDyeX8LYaxNpK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 22:05:25 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 22:06:31 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Dharmesh Acharya ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/UakkT3isdrj83uFs6V7FiW.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity concept image symbolizing third-party data breaches with give padlock symbols and one pictured in red, signifying a security breach.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Gmv6VGAN4vkgH2urwaX2Yf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Managed Security Service Providers (MSSPs) need continuous security testing and faster risk identification. But the cybersecurity talent shortage makes it harder to expand service delivery through hiring alone.</p><p>The challenge is becoming more urgent as cyber threats continue to grow. More than <a href="https://zerothreat.ai/blog/cyberattack-statistics"><u>2,244 cyberattacks occur every day worldwide</u></a>, according to our research. This creates constant pressure for organizations to identify and address security gaps before attackers do.</p><p>More risk and more demand. Traditional approaches and tools simply can’t keep up.</p><p>That reality is forcing MSSPs to change how they scale security services. The good part is that continuous pentesting no longer requires a proportional increase in headcount. With AI-powered automated penetration testing, MSSPs can expand security coverage, increase testing frequency, and serve more clients without continuously adding security specialists.</p><h2 id="why-continuous-security-coverage-is-getting-harder">Why continuous security coverage is getting harder</h2><p>Managing security for clients used to be like checking a box once a year, but that has changed. Each organization needs continuous security coverage to keep up with the updates they are deploying and the growing number of cyber threats.</p><p>The complexity of today’s applications can’t be tackled by traditional methods because:</p><ul><li>Cloud-native apps and APIs change daily, making annual penetration tests obsolete within weeks.</li><li>Hiring more security experts to manually test every environment is not feasible.</li><li>Attackers now use AI to scan and exploit systems continuously, moving far faster than manual audit cycles.</li></ul><p>As a result, many providers are rethinking how they scale offensive security services without continually expanding their security teams.</p><h2 id="why-hiring-more-people-isn-39-t-a-scalable-security-strategy">Why hiring more people isn't a scalable security strategy</h2><p>Hiring more security experts seems like the obvious way to add to continuous pentesting services. But in reality, fluctuating demand, shortage of skills, and other operational costs can make it difficult to sustain.</p><ol start="1"><li><strong>Skilled security talent is hard to find: </strong>The cybersecurity talent gap remains a major challenge across the industry. Recent ISC2 research found that 95% of organizations report at least one cybersecurity skills gap, while 59% face significant or critical skills shortages. Finding experienced pentesters, application security specialists, and offensive security experts is becoming increasingly tough.</li><li><strong>Hiring costs keep increasing: </strong>Recruiting security professionals is expensive, and other than salary, MSSPs need to account for onboarding, training, certifications, and retention efforts. With high demand for application security and threat exposure management skills, the cost of building larger teams rises with it.</li><li><strong>Client growth often outpaces team growth: </strong>Security teams do not scale at the same rate as client demand. As MSSPs add more customers, each new environment introduces additional assets, attack surfaces, vulnerabilities, and testing requirements. Hiring one person at a time rarely keeps pace with the volume of continuous security assessments clients expect.</li><li><strong>Specialized expertise does not scale easily: </strong>Continuous pentesting demands expertise in web applications, APIs, cloud environments, business logic testing, and risk validation. Building teams with every required specialty can easily become impractical for growing MSSPs.</li><li><strong>More people can create operational bottlenecks: </strong>Adding more heads to the team does not mean improved service delivery. Larger teams require coordination, management, quality assurance, and workflow standardization. In many cases, operational complexity grows faster than productivity, reducing the efficiency gains MSSPs expected from hiring more analysts and testers.</li></ol><p>The key problem with hiring more isn’t just about finding more skilled experts; it’s finding a way to offer continuous security coverage while utilizing the resources efficiently.</p><h2 id="how-mssps-can-provide-continuous-pentesting-without-hiring">How MSSPs can provide continuous pentesting without hiring</h2><p>The most practical way to scale continuous pentesting today is to combine security expertise with AI-powered automated penetration testing that increases coverage, testing frequency, and operational efficiency.</p><p><strong>Automate repetitive security testing tasks:</strong> A large portion of pentesting involves reconnaissance, attack surface discovery, vulnerability validation, and retesting. AI-powered pentesting platforms can help you automate these repeatable tasks so that you can focus on higher-value investigations and risk analysis.</p><p><strong>Integrate security testing into existing pipelines: </strong>You should embed automated testing directly into the client delivery process. This ensures that every configuration change is tested immediately rather than waiting for an annual check. It turns security from periodic, labor-intensive work into an automated process.</p><p><strong>Implement multi-tenant management: </strong>Instead of configuring tests for each client individually, use multi-tenant dashboards. This allows your current engineering or SOC team to centrally schedule automated tests, distribute reports, and track remediation across hundreds of client environments simultaneously.</p><p><strong>Prioritize findings based on real risk:</strong> Use modern AI-powered pentesting platforms that help correlate findings, validate exploitability, and highlight the issues most likely to impact the client. This improves remediation efficiency and helps you deliver clearer security outcomes.</p><p><strong>Utilize white-label reseller tools:</strong> The best way to save time and effort on preparing reports is by using a tool that offers white-labeled reports. The reports are generated by AI-powered tools, and you can keep your Logos & URLs, making sure you deliver professional, client-ready documentation without manual formatting.</p><h2 id="what-mssps-should-look-for-in-a-scalable-continuous-pentesting-solution">What MSSPs should look for in a scalable continuous pentesting solution</h2><p>As client environments grow complex, MSSPs need solutions that can expand security coverage without operational burden. The ideal platform should help teams identify risks faster, validate findings more efficiently, and deliver consistent security outcomes across multiple customers.</p><p>When evaluating a solution, focus on capabilities that support long-term scalability:</p><ul><li>Continuous attack surface monitoring</li><li>AI-assisted vulnerability validation</li><li>Web application, API, cloud, and external asset coverage</li><li>Risk-based prioritization of findings</li><li>Automated retesting and remediation tracking</li><li>Multi-tenant management and reporting</li><li>Integration with existing security workflows and ticketing systems</li></ul><p>The right tool helps security teams spend less time on repetitive testing and more time delivering meaningful risk insights. For MSSPs, that balance is what makes continuous pentesting both operationally sustainable and commercially viable.</p><p>Continuous pentesting is the new basic expectation of clients, and that has turned out to be the new challenge for MSSPs. If they rely only on hiring to offer continuous testing services, it is rarely sustainable in a market already facing a cybersecurity skills shortage.</p><p>The most effective path forward is to combine security expertise with AI-powered automation.</p><p>By automating repetitive testing activities and enabling continuous security validation, MSSPs can support more clients, identify risks faster, and scale their services without compromising the quality of protection they deliver.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers ran up a $600,000 AI bill after swiping API keys, says METR – and nobody realized for weeks ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI research non-profit METR has disclosed two security incidents – and while no sensitive information is believed to have been accessed, one of the attacks led to what might have been a massive bill.</p><p><a href="https://metr.org/blog/2026-08-31-security-update/#our-approach-to-security" target="_blank"><u>According to METR</u></a>, attackers stole an API key for inference on public AI models in March, consuming $600,000 worth of credits. Luckily, the model developer had granted them to METR for free. </p><p>A researcher left an <a href="https://www.itpro.com/cloud/370070/what-is-aws-ec2">EC2 </a>instance publicly accessible behind Google authentication, the company said, which contained an API key for METR’s general-access (public models) account. </p><p>METR noted that the <a href="https://www.itpro.com/technology/artificial-intelligence/vibe-coding-security-risks-how-to-mitigate">vibe-coded app</a> included a fail-open vulnerability that silently disabled authentication, exposing the system to the public internet for several days.</p><p>METR reckons the attacker found the instance by looking through recently registered websites to find vibe-coded sites with high-signal keywords relating to LLMs or agents.</p><p>The attacker prompted an agent directly to reveal its model provider API key, added an SSH key for persistent access, and over the course of three weeks used the stolen credentials to consume the API credits.</p><h2 id="why-didn-39-t-metr-notice">Why didn't METR notice?</h2><p>METR noted that because the organisation is “accustomed to running evaluations and experiments that use large volumes of tokens”, the incident flew under the radar. </p><p>The non-profit regularly runs large-scale evaluations with pre-deployment AI models, meaning it typically deals with “lots of weird rate limits and API errors”. </p><p>"At the time of the incident, our internal usage dashboard didn’t show data on rate-limited requests to all users, even if they were occurring,” METR said.</p><p>Notably, because it wasn't actually paying for the tokens there was no natural token spend ceiling, and no way at the time to put a spending limit on keys.</p><h2 id="metr-lifts-lid-on-separate-attack">METR lifts lid on separate attack</h2><p>In another attack in May, METR spotted attackers systematically probing its publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint. </p><p>"We were tipped off that we were being targeted by hackers who appeared to be financially motivated and may have been looking to obtain frontier model access," it said. </p><p>"We observed the attackers systematically probing our publicly accessible infrastructure, with heavy use of agents to automate vulnerability discovery, including by credential stuffing authentication providers, attempting OAuth token grants, scanning newly deployed services, and attempting to phish staff."</p><p>METR said it's now maintaining an isolated public production environment for public-facing applications that's architecturally separated from its internal infrastructure. </p><p>This means a misconfiguration in a public service can't expose internal data. It's also hired a security lead and is expanding security staff further. </p><p>Elsewhere, METR revealed it has shut down legacy infrastructure that was unnecessarily expanding the attack surface and has set up monitoring for unusual API key usage and other abnormal behavior.</p><p>"Although these incidents had limited consequences, we considered them near-misses, and increased our security investment in response," it said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/hackers-ran-up-a-usd600-000-ai-bill-after-swiping-api-keys-says-metr-and-nobody-realized-for-weeks</link>
                                                                            <description>
                            <![CDATA[ Luckily the organization wasn't paying for the tokens; others might not have been so lucky ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iJ8YUwrrj8ciQwd26ZdEZ9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/K77LEmNgKcHxRxhEtmnX3W-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 10:19:47 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 14:46:47 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/K77LEmNgKcHxRxhEtmnX3W-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Concept image showing a US dollar bill burning at the edges with smoke pluming outwards.]]></media:description>                                                            <media:text><![CDATA[Concept image showing a US dollar bill burning at the edges with smoke pluming outwards.]]></media:text>
                                <media:title type="plain"><![CDATA[Concept image showing a US dollar bill burning at the edges with smoke pluming outwards.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/K77LEmNgKcHxRxhEtmnX3W-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI research non-profit METR has disclosed two security incidents – and while no sensitive information is believed to have been accessed, one of the attacks led to what might have been a massive bill.</p><p><a href="https://metr.org/blog/2026-08-31-security-update/#our-approach-to-security" target="_blank"><u>According to METR</u></a>, attackers stole an API key for inference on public AI models in March, consuming $600,000 worth of credits. Luckily, the model developer had granted them to METR for free. </p><p>A researcher left an <a href="https://www.itpro.com/cloud/370070/what-is-aws-ec2">EC2 </a>instance publicly accessible behind Google authentication, the company said, which contained an API key for METR’s general-access (public models) account. </p><p>METR noted that the <a href="https://www.itpro.com/technology/artificial-intelligence/vibe-coding-security-risks-how-to-mitigate">vibe-coded app</a> included a fail-open vulnerability that silently disabled authentication, exposing the system to the public internet for several days.</p><p>METR reckons the attacker found the instance by looking through recently registered websites to find vibe-coded sites with high-signal keywords relating to LLMs or agents.</p><p>The attacker prompted an agent directly to reveal its model provider API key, added an SSH key for persistent access, and over the course of three weeks used the stolen credentials to consume the API credits.</p><h2 id="why-didn-39-t-metr-notice">Why didn't METR notice?</h2><p>METR noted that because the organisation is “accustomed to running evaluations and experiments that use large volumes of tokens”, the incident flew under the radar. </p><p>The non-profit regularly runs large-scale evaluations with pre-deployment AI models, meaning it typically deals with “lots of weird rate limits and API errors”. </p><p>"At the time of the incident, our internal usage dashboard didn’t show data on rate-limited requests to all users, even if they were occurring,” METR said.</p><p>Notably, because it wasn't actually paying for the tokens there was no natural token spend ceiling, and no way at the time to put a spending limit on keys.</p><h2 id="metr-lifts-lid-on-separate-attack">METR lifts lid on separate attack</h2><p>In another attack in May, METR spotted attackers systematically probing its publicly accessible infrastructure, including an unsuccessful attempt to access internal data via an inadvertently exposed endpoint. </p><p>"We were tipped off that we were being targeted by hackers who appeared to be financially motivated and may have been looking to obtain frontier model access," it said. </p><p>"We observed the attackers systematically probing our publicly accessible infrastructure, with heavy use of agents to automate vulnerability discovery, including by credential stuffing authentication providers, attempting OAuth token grants, scanning newly deployed services, and attempting to phish staff."</p><p>METR said it's now maintaining an isolated public production environment for public-facing applications that's architecturally separated from its internal infrastructure. </p><p>This means a misconfiguration in a public service can't expose internal data. It's also hired a security lead and is expanding security staff further. </p><p>Elsewhere, METR revealed it has shut down legacy infrastructure that was unnecessarily expanding the attack surface and has set up monitoring for unusual API key usage and other abnormal behavior.</p><p>"Although these incidents had limited consequences, we considered them near-misses, and increased our security investment in response," it said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cato Networks launches SMB FlexPool to help MSPs scale managed SASE services ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cato Networks has cut the ribbon on SMB FlexPool, a new program designed to help MSPs deliver managed <a href="https://www.itpro.com/cloud/cloud-security/what-is-secure-access-service-edge-sase">SASE </a>services to small and midsize businesses at scale.</p><p>Available to both new and existing MSPs and service providers, the initiative offers access to a pool of Cato licenses that can be gradually allocated across eligible SMB customers as demand evolves.</p><p>The model allows partners to create customer accounts, allocate capacity, and activate services through a self-service workflow, while retaining control over customer relationships, service packaging, and support.</p><p>In an announcement, Cato said SMB FlexPool aims to remove the operational overhead associated with separate licensing transactions for every customer deployment, allowing partners to onboard customers faster and reallocate capacity as required.</p><p>"MSPs shouldn't have to slow down customer deployments because of licensing and operational overhead,” said Cato Networks’ global channel chief Karl Soderlund.</p><p>“SMB FlexPool aims to remove that friction with instant provisioning and flexible pooled licensing, enabling partners to activate new customers while maintaining full control of the customer experience."</p><p>Cato Networks provides a converged network and security cloud that brings networking, security and access capabilities together across enterprise environments. The platform offers visibility and control across users, applications, data, and AI interactions.</p><p>The company’s new SMB FlexPool initiative is built on the firm’s managed SASE (MSASE) Partner Platform, which provides <a href="https://www.itpro.com/business/business-strategy/msps-are-burned-out-and-overworked-as-tool-sprawl-and-it-complexity-grows-but-theres-light-on-the-horizon">MSPs </a>with tools, training, and automation across the partner lifecycle.</p><h2 id="pooled-licensing-for-msps">Pooled licensing for MSPs</h2><p>SMB FlexPool’s built-in partner-level capacity and license portability allow MSPs to allocate capacity across eligible SMB customers, as well as reallocate unused capacity as requirements change.</p><p>Cato said this approach aims to give MSPs greater flexibility as their customer base and pipeline develop, allowing them to ramp utilization of their purchased capacity in line with staged customer deployments and go-to-market progress.</p><p>Partners also retain control over key elements of their customer-facing packages, including their commercial offering, support model, and managed services.</p><p>By eliminating the friction associated with individual transactions, Cato said its new partner initiative will help partners move from opportunity to customer-ready service “in seconds.”</p><p>SMB FlexPool can be managed through Cato’s new MSASE dashboard in the MSASE Business Center, giving partners a unified view of customer accounts, orders, license usage, invoices, and customer lifecycle activity across both SMB and enterprise customers.</p><p>Art Nichols, chief technology officer at Uniti Solutions, said Cato’s new partner model will give the MSP a more efficient and scalable way to deliver managed SASE.</p><p>“Instead of managing separate licensing transactions for every new customer, we can provision services in seconds, bring customers online faster, and keep our operations simple as our business expands,” he explained. </p><p>“This means our customers benefit from faster deployment, a smoother onboarding experience, and the confidence that their secure network services can scale seamlessly alongside their business.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cato-networks-launches-smb-flexpool-to-help-msps-scale-managed-sase-services</link>
                                                                            <description>
                            <![CDATA[ The program is designed to remove licensing friction and speed up customer onboarding for partners serving the SMB market ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eGS6xFibmFhFVoQJWJ7uLo</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 07:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ itpro@futurenet.com (Daniel Todd) ]]></author>                    <dc:creator><![CDATA[ Daniel Todd ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/SRyC34qeLpNDj3dJtsVDhT.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:description>                                                            <media:text><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:text>
                                <media:title type="plain"><![CDATA[AI concept image showing digitized human eye monitoring digital interfaces and software.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eA94AYk6DLNFxKRQtGuKoT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cato Networks has cut the ribbon on SMB FlexPool, a new program designed to help MSPs deliver managed <a href="https://www.itpro.com/cloud/cloud-security/what-is-secure-access-service-edge-sase">SASE </a>services to small and midsize businesses at scale.</p><p>Available to both new and existing MSPs and service providers, the initiative offers access to a pool of Cato licenses that can be gradually allocated across eligible SMB customers as demand evolves.</p><p>The model allows partners to create customer accounts, allocate capacity, and activate services through a self-service workflow, while retaining control over customer relationships, service packaging, and support.</p><p>In an announcement, Cato said SMB FlexPool aims to remove the operational overhead associated with separate licensing transactions for every customer deployment, allowing partners to onboard customers faster and reallocate capacity as required.</p><p>"MSPs shouldn't have to slow down customer deployments because of licensing and operational overhead,” said Cato Networks’ global channel chief Karl Soderlund.</p><p>“SMB FlexPool aims to remove that friction with instant provisioning and flexible pooled licensing, enabling partners to activate new customers while maintaining full control of the customer experience."</p><p>Cato Networks provides a converged network and security cloud that brings networking, security and access capabilities together across enterprise environments. The platform offers visibility and control across users, applications, data, and AI interactions.</p><p>The company’s new SMB FlexPool initiative is built on the firm’s managed SASE (MSASE) Partner Platform, which provides <a href="https://www.itpro.com/business/business-strategy/msps-are-burned-out-and-overworked-as-tool-sprawl-and-it-complexity-grows-but-theres-light-on-the-horizon">MSPs </a>with tools, training, and automation across the partner lifecycle.</p><h2 id="pooled-licensing-for-msps">Pooled licensing for MSPs</h2><p>SMB FlexPool’s built-in partner-level capacity and license portability allow MSPs to allocate capacity across eligible SMB customers, as well as reallocate unused capacity as requirements change.</p><p>Cato said this approach aims to give MSPs greater flexibility as their customer base and pipeline develop, allowing them to ramp utilization of their purchased capacity in line with staged customer deployments and go-to-market progress.</p><p>Partners also retain control over key elements of their customer-facing packages, including their commercial offering, support model, and managed services.</p><p>By eliminating the friction associated with individual transactions, Cato said its new partner initiative will help partners move from opportunity to customer-ready service “in seconds.”</p><p>SMB FlexPool can be managed through Cato’s new MSASE dashboard in the MSASE Business Center, giving partners a unified view of customer accounts, orders, license usage, invoices, and customer lifecycle activity across both SMB and enterprise customers.</p><p>Art Nichols, chief technology officer at Uniti Solutions, said Cato’s new partner model will give the MSP a more efficient and scalable way to deliver managed SASE.</p><p>“Instead of managing separate licensing transactions for every new customer, we can provision services in seconds, bring customers online faster, and keep our operations simple as our business expands,” he explained. </p><p>“This means our customers benefit from faster deployment, a smoother onboarding experience, and the confidence that their secure network services can scale seamlessly alongside their business.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How seriously is your business taking the 'Q-Day' threat, and can you really be ready by 2029? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>If you can cast your mind back to 1999, the computing world was in a frenzy over the Y2K bug, or Millennium Bug, a coding flaw where systems abbreviated four-digit years to two digits – so, 99 instead of 1999. </p><p>First identified in 1958, the fear was that computers would read '00' as 1900 instead of 2000, potentially crashing global infrastructure. As such, $300 billion (now worth a staggering $600 billion in today's money) was spent to upgrade computers and application programs so they were Y2K-compliant. Because of this monumental effort over many years, the crisis was largely averted.</p><p>In 2026, a similar panic is simmering at a glacial pace. The fear is Q-Day: a hypothetical moment at which quantum computers become so powerful that they can crack encryption algorithms within seconds. Leading industry figures, quantum computing companies, cybersecurity advisors, and even <a href="https://www.govinfo.gov/content/pkg/DCPD-202200355/html/DCPD-202200355.htm"><u>national government agencies</u></a> have been warning about this moment for years — as far back as 1994, when mathematician Peter Shor first published his paper warning about this exact possibility. </p><p>Since then, the threat has felt far away and abstract – with under-pressure businesses spending their precious IT budgets on more immediate threats. </p><p>But in March 2026, Google Quantum AI published research revealing that quantum computers can crack the encryption underpinning Bitcoin using under 500,000 physical qubits. As such, <a href="https://www.itpro.com/security/google-just-revised-its-q-day-timeline-quantum-computers-could-break-existing-encryption-techniques-within-three-years-and-enterprises-are-nowhere-near-ready"><u>Google accelerated its migration timeline</u></a> from the 2030s to 2029. This is simply one example of the industry ramping up the pace of its migration, with another <a href="https://arxiv.org/html/2603.28627v1"><u>March study</u></a> showing quantum computers may need as few as 10,000 qubits to one day break the most secure encryption algorithms. </p><p>But that doesn't seem to have moved the needle very much, with countless businesses still completely unprotected or in the very earliest stages of exploring moves to implement post-quantum cryptography (PQC) or related countermeasures. With the timelines accelerating, why is the business world still so slow to react to these looming threats that lie over the horizon?    </p><h2 id="how-prepared-are-we-for-a-post-quantum-world">How prepared are we for a post-quantum world?</h2><p>Existing research into business preparedness is incredibly bleak. The vast majority (90%) of companies don't have systems in place to defend against quantum security threats, according to <a href="https://www.itpro.com/security/90-percent-of-companies-are-woefully-unprepared-for-quantum-security-threats-analysts-say-they-need-to-get-a-move-on"><u>Bain & Company analysis</u></a>. It's a similar, albeit less extreme, story with <a href="https://www.itpro.com/security/nearly-half-of-enterprises-arent-prepared-for-quantum-cybersecurity-threats"><u>Keyfactor research</u></a> that shows nearly half (48%) aren't ready. </p><p>Juniper Research found that just 27% of global companies will deploy PQC – but only by 2035. Right now, that figure stands at roughly 0.0009%, or just 35,000. Compound these findings with <a href="https://cdn.prod.website-files.com/643b94c382e84463a9e52264/698a5056aa19e254d8105a24_Part_1_2026_Quantum_Readiness_Survey_Report.pdf"><u>QuEra research</u></a> that showed the level of confidence in quantum preparedness actually fell from 65% to 55% between 2025 and 2026, meaning that as the threats become less abstract, businesses are increasingly aware that the measures they've taken may not be sufficient. </p><p>There's a readiness gap – no matter how you interpret the many and various findings. But what does this actually mean in practice and why is there such a large gap? Knowledge is the primary deficit, says Arjun Kudinoor, a doctoral student and NSF Graduate Research Fellow at MIT, as well as quantum security advisor at Protegrity. Many organizations lack the required expertise to understand the risks, prepare existing systems, and identify valuable applications, according to Kudinoor.</p><p>"Businesses must begin developing quantum literacy across technical and executive teams, assessing their exposure to quantum-enabled cybersecurity threats, and identifying problems for which quantum computing could provide a meaningful advantage," he adds. </p><p>But according to Orange Business' quantum-safe network lead and program director of edge computing, Frank de Jong, awareness has increased significantly in the last few years. </p><p>He tells <em>ITPro</em>: "It is impossible to be quantum-ready today, and in my opinion, it is also questionable if you could be completely quantum-safe before 2029. That's why we advise customers to start planning now and prioritize protecting their most valuable assets first. The key is to begin the journey, not to wait for perfect conditions."</p><p>As things stand, some sectors are more prepared than others. The earliest movers were telecoms providers and infrastructure-heavy organizations, with financial services, healthcare and software providers following suit. But it's also true to say that preparedness varies more based on resources and expertise, adds Kudinoor. He explains that firms with strong technical teams, quantum-related budgets, and executives concerned about planning for the threat are moving the fastest.</p><h2 id="avoiding-a-slow-motion-quantum-disaster">Avoiding a slow-motion quantum disaster</h2><p>Quantum computing is difficult to wrap your head around, and it's long been a technology that's some years away from maturation. For that reason, it might be tempting for many to have kicked the issue deep into the long grass. Suja Viswesan, IBM VP of security software, acknowledges this impact. "It can feel overwhelming at the sheer magnitude of possible impact. But the best place to start is by gaining visibility. You can’t fix what you can’t see." </p><p>Businesses, she says, should start small by mapping cryptographic assets – including certificates, secrets and API keys – across their environments. Then, they should prioritize risk and introduce controls such as proxy layers to, as she puts it, "buy time" before full PQC upgrades are available. </p><p>Kohinoor rejects the notion that quantum computing's threats are abstract, telling <em>ITPro</em>: "Much work has been done to estimate the number of qubits, error rates, and error correction methods required to implement such quantum factoring algorithms on quantum hardware." </p><p>The most powerful quantum computers commercially available are only one or two orders of magnitude away from breaking encryption schemes like RSA-2048. Thankfully, he adds, it's "not yet a disaster" because we are still several difficult breakthroughs away from achieving a fault-tolerant cryptographically relevant quantum computer. </p><p>So what's to explain the general malaise in preparing for this eventuality? The answer may lie on the balance sheet – and the IT and security budgets that so many organizations are under pressure to spend on far more immediate threats.</p><p>Although <a href="https://www.itpro.com/infrastructure/gartner-just-revised-its-global-it-spending-projection-for-2026-heres-why"><u>IT spending is expected to hit $6.37 trillion this year</u></a>, 14.2% higher than last year's spend, much of this has been allocated toward either trendier areas or toward more concrete threats. As de Jong puts it, IT budgets are spent "on where the center of attention is".</p><p>"In recent years, this was predominantly AI, and still today, this is where the majority of the “additional” money gets spent," he explains. </p><p>"Transitioning to quantum-safe infrastructure isn't a simple project. It will require substantial, sustained investment over many years. The most urgent call to action for CXOs today is to start planning and allocating substantial budgets for the coming years. This isn't fear-mongering — it's pragmatism. We cannot afford to wait and see."   </p><h2 id="is-it-too-late-to-prepare-for-the-post-quantum-world">Is it too late to prepare for the post-quantum world? </h2><p>The urgency is certainly there, and many experts fear it's far too late to avoid the damage – especially given the rise of <a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them"><u>"harvest now, decrypt later" (HNDL) attacks</u></a> – in which cybercriminals steal encrypted data with the intent of cracking it in the years to come using quantum computers. </p><p>But even if that were the case, there's still far more damage that can be done if businesses are sluggish about getting their defenses sorted. In that vein, the experts we interviewed say it's never too late to prepare.</p><p>"As the saying goes, ‘The best time to plant a tree was 20 years ago. The second-best time is now.’ The challenge with cybersecurity threats is that they may or may not affect you, but the fact that they could is sufficient reason to pay attention," de Jong says, but concedes that many will never be fully prepared. </p><p>"Most organizations face 15 years of work to become quantum-safe, but they may have only three years to do it. This means that they need to prioritize and accept the fact that not every asset can be defended at the same level from the start."</p><p>In the last few years, the mood has certainly shifted away from maximum preparedness to damage limitation as the reality has hit the industry that businesses haven't been moving quickly enough. MIT's Kudinoor advises businesses to upgrade all systems to PQC, beginning with the highest priority and most publicly available systems. </p><p>But the reality is that the threats themselves won't all hit at once – despite the 'Q-Day' label implying there's a single moment in the future beyond which there's no return. As IBM's Viswesan explains: "We’ll see it materialize over time, spanning multiple years as different cryptographic systems become vulnerable at different times." </p><h2 id="quantum-readiness-is-all-about-making-haste-slowly">Quantum readiness is all about making haste slowly</h2><p>Given the gradual and unfolding nature of 'Q-Day',  businesses should avoid rushing their decision-making and adopt a balanced and thoughtful approach, whether that's in assessing their estate or engaging with vendors. </p><p>The name for this dilemma – in which you need to act fast but not so fast that you end up making poor decisions – is "festina lente", a Latin term that roughly translates to "hurry slowly". But that's easier said than done.</p><p>"Organizations shouldn't wait to begin the transformation journey, but they also shouldn't rush into decisions. That’s where crypto-agility comes into play," Viswesan continues. </p><p>"Crypto‑agility is the ability to migrate to post-quantum cryptography (PQC), while maintaining the flexibility to make changes without business disruption. Crypto‑agility allows organizations to scale cryptography‑based data protection with confidence, reduce the operational costs associated with managing cryptography, and meaningfully lower long‑term security risk."</p><p>What about quantum companies themselves? After all, aren't they causing the problem in the first place? As de Jong says, the supply chain is already seeing a lot of countermeasures embedded into products by design, for example, quantum-safe features in the systems that cloud companies provide. </p><p>Pro bono support may also be available to smaller companies without the budgets or expertise to fight this battle. But, he says, the problem is likely to impact the larger companies the most. </p><p>To adequately prepare, the experts also recommend that building quantum literacy among technical teams and executives is essential. These teams should then devise roadmaps, with budgets over the coming years incorporating more quantum line items. </p><p>This transition is new to almost everyone, meaning that it's a journey of discovery and the best practice is still being formulated. There are, however, companies that are further along the journey than others – and organizations should liaise with one another so that everyone can benefit together.</p><p>"The transition to quantum-safe is new for almost everyone," de Jong adds, "so I would advise enterprise CXOs not to try and reinvent the wheel themselves, but rather work with companies that have been working on it for several years, so everyone can benefit from the collective knowledge."</p><p>The timelines are shrinking with each quantum computing breakthrough, and there's a general acceptance among experts that it won't be possible for businesses to be fully quantum-ready by 2029 – especially if you factor in the HNDL attacks that have already happened. </p><p>That said, it's never too late to act to avoid the very worst of it, and businesses should do what they can to get as far ahead of this threat as possible before it's too late – no matter how tempting it is to route budgets into more appealing areas like AI. </p><p>Should more businesses begin to act faster, when 'Q-Day' begins to take hold, there's still every chance, much like the Y2K bug, that this will become yet another amusing anecdote from the annals of tech history about a massive computing threat that was avoided.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/how-seriously-is-your-business-taking-the-q-day-threat-and-can-you-really-be-ready-by-2029</link>
                                                                            <description>
                            <![CDATA[ The pace of progress on quantum computing isn't slowing down, but so many businesses still haven't prepared for the looming threat – with experts now shifting their rhetoric toward damage limitation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GHXSXxUcuJ73QVF6HDKVGA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 02 Sep 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Wed, 02 Sep 2026 11:06:23 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ keumars.afifi-sabet@futurenet.com (Keumars Afifi-Sabet) ]]></author>                    <dc:creator><![CDATA[ Keumars Afifi-Sabet ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/EAvwpZggMZ2K5h8s2pTAEm.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:description>                                                            <media:text><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing concept image showing three purple-colored, glowing blocks placed on top of circuit boards with connected data flows.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/L5y7q8MWwZA5LGPEXPTRJM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>If you can cast your mind back to 1999, the computing world was in a frenzy over the Y2K bug, or Millennium Bug, a coding flaw where systems abbreviated four-digit years to two digits – so, 99 instead of 1999. </p><p>First identified in 1958, the fear was that computers would read '00' as 1900 instead of 2000, potentially crashing global infrastructure. As such, $300 billion (now worth a staggering $600 billion in today's money) was spent to upgrade computers and application programs so they were Y2K-compliant. Because of this monumental effort over many years, the crisis was largely averted.</p><p>In 2026, a similar panic is simmering at a glacial pace. The fear is Q-Day: a hypothetical moment at which quantum computers become so powerful that they can crack encryption algorithms within seconds. Leading industry figures, quantum computing companies, cybersecurity advisors, and even <a href="https://www.govinfo.gov/content/pkg/DCPD-202200355/html/DCPD-202200355.htm"><u>national government agencies</u></a> have been warning about this moment for years — as far back as 1994, when mathematician Peter Shor first published his paper warning about this exact possibility. </p><p>Since then, the threat has felt far away and abstract – with under-pressure businesses spending their precious IT budgets on more immediate threats. </p><p>But in March 2026, Google Quantum AI published research revealing that quantum computers can crack the encryption underpinning Bitcoin using under 500,000 physical qubits. As such, <a href="https://www.itpro.com/security/google-just-revised-its-q-day-timeline-quantum-computers-could-break-existing-encryption-techniques-within-three-years-and-enterprises-are-nowhere-near-ready"><u>Google accelerated its migration timeline</u></a> from the 2030s to 2029. This is simply one example of the industry ramping up the pace of its migration, with another <a href="https://arxiv.org/html/2603.28627v1"><u>March study</u></a> showing quantum computers may need as few as 10,000 qubits to one day break the most secure encryption algorithms. </p><p>But that doesn't seem to have moved the needle very much, with countless businesses still completely unprotected or in the very earliest stages of exploring moves to implement post-quantum cryptography (PQC) or related countermeasures. With the timelines accelerating, why is the business world still so slow to react to these looming threats that lie over the horizon?    </p><h2 id="how-prepared-are-we-for-a-post-quantum-world">How prepared are we for a post-quantum world?</h2><p>Existing research into business preparedness is incredibly bleak. The vast majority (90%) of companies don't have systems in place to defend against quantum security threats, according to <a href="https://www.itpro.com/security/90-percent-of-companies-are-woefully-unprepared-for-quantum-security-threats-analysts-say-they-need-to-get-a-move-on"><u>Bain & Company analysis</u></a>. It's a similar, albeit less extreme, story with <a href="https://www.itpro.com/security/nearly-half-of-enterprises-arent-prepared-for-quantum-cybersecurity-threats"><u>Keyfactor research</u></a> that shows nearly half (48%) aren't ready. </p><p>Juniper Research found that just 27% of global companies will deploy PQC – but only by 2035. Right now, that figure stands at roughly 0.0009%, or just 35,000. Compound these findings with <a href="https://cdn.prod.website-files.com/643b94c382e84463a9e52264/698a5056aa19e254d8105a24_Part_1_2026_Quantum_Readiness_Survey_Report.pdf"><u>QuEra research</u></a> that showed the level of confidence in quantum preparedness actually fell from 65% to 55% between 2025 and 2026, meaning that as the threats become less abstract, businesses are increasingly aware that the measures they've taken may not be sufficient. </p><p>There's a readiness gap – no matter how you interpret the many and various findings. But what does this actually mean in practice and why is there such a large gap? Knowledge is the primary deficit, says Arjun Kudinoor, a doctoral student and NSF Graduate Research Fellow at MIT, as well as quantum security advisor at Protegrity. Many organizations lack the required expertise to understand the risks, prepare existing systems, and identify valuable applications, according to Kudinoor.</p><p>"Businesses must begin developing quantum literacy across technical and executive teams, assessing their exposure to quantum-enabled cybersecurity threats, and identifying problems for which quantum computing could provide a meaningful advantage," he adds. </p><p>But according to Orange Business' quantum-safe network lead and program director of edge computing, Frank de Jong, awareness has increased significantly in the last few years. </p><p>He tells <em>ITPro</em>: "It is impossible to be quantum-ready today, and in my opinion, it is also questionable if you could be completely quantum-safe before 2029. That's why we advise customers to start planning now and prioritize protecting their most valuable assets first. The key is to begin the journey, not to wait for perfect conditions."</p><p>As things stand, some sectors are more prepared than others. The earliest movers were telecoms providers and infrastructure-heavy organizations, with financial services, healthcare and software providers following suit. But it's also true to say that preparedness varies more based on resources and expertise, adds Kudinoor. He explains that firms with strong technical teams, quantum-related budgets, and executives concerned about planning for the threat are moving the fastest.</p><h2 id="avoiding-a-slow-motion-quantum-disaster">Avoiding a slow-motion quantum disaster</h2><p>Quantum computing is difficult to wrap your head around, and it's long been a technology that's some years away from maturation. For that reason, it might be tempting for many to have kicked the issue deep into the long grass. Suja Viswesan, IBM VP of security software, acknowledges this impact. "It can feel overwhelming at the sheer magnitude of possible impact. But the best place to start is by gaining visibility. You can’t fix what you can’t see." </p><p>Businesses, she says, should start small by mapping cryptographic assets – including certificates, secrets and API keys – across their environments. Then, they should prioritize risk and introduce controls such as proxy layers to, as she puts it, "buy time" before full PQC upgrades are available. </p><p>Kohinoor rejects the notion that quantum computing's threats are abstract, telling <em>ITPro</em>: "Much work has been done to estimate the number of qubits, error rates, and error correction methods required to implement such quantum factoring algorithms on quantum hardware." </p><p>The most powerful quantum computers commercially available are only one or two orders of magnitude away from breaking encryption schemes like RSA-2048. Thankfully, he adds, it's "not yet a disaster" because we are still several difficult breakthroughs away from achieving a fault-tolerant cryptographically relevant quantum computer. </p><p>So what's to explain the general malaise in preparing for this eventuality? The answer may lie on the balance sheet – and the IT and security budgets that so many organizations are under pressure to spend on far more immediate threats.</p><p>Although <a href="https://www.itpro.com/infrastructure/gartner-just-revised-its-global-it-spending-projection-for-2026-heres-why"><u>IT spending is expected to hit $6.37 trillion this year</u></a>, 14.2% higher than last year's spend, much of this has been allocated toward either trendier areas or toward more concrete threats. As de Jong puts it, IT budgets are spent "on where the center of attention is".</p><p>"In recent years, this was predominantly AI, and still today, this is where the majority of the “additional” money gets spent," he explains. </p><p>"Transitioning to quantum-safe infrastructure isn't a simple project. It will require substantial, sustained investment over many years. The most urgent call to action for CXOs today is to start planning and allocating substantial budgets for the coming years. This isn't fear-mongering — it's pragmatism. We cannot afford to wait and see."   </p><h2 id="is-it-too-late-to-prepare-for-the-post-quantum-world">Is it too late to prepare for the post-quantum world? </h2><p>The urgency is certainly there, and many experts fear it's far too late to avoid the damage – especially given the rise of <a href="https://www.itpro.com/security/enterprises-arent-moving-fast-enough-on-post-quantum-cryptography-preparations-harvest-now-decrypt-later-attacks-mean-it-could-cost-them"><u>"harvest now, decrypt later" (HNDL) attacks</u></a> – in which cybercriminals steal encrypted data with the intent of cracking it in the years to come using quantum computers. </p><p>But even if that were the case, there's still far more damage that can be done if businesses are sluggish about getting their defenses sorted. In that vein, the experts we interviewed say it's never too late to prepare.</p><p>"As the saying goes, ‘The best time to plant a tree was 20 years ago. The second-best time is now.’ The challenge with cybersecurity threats is that they may or may not affect you, but the fact that they could is sufficient reason to pay attention," de Jong says, but concedes that many will never be fully prepared. </p><p>"Most organizations face 15 years of work to become quantum-safe, but they may have only three years to do it. This means that they need to prioritize and accept the fact that not every asset can be defended at the same level from the start."</p><p>In the last few years, the mood has certainly shifted away from maximum preparedness to damage limitation as the reality has hit the industry that businesses haven't been moving quickly enough. MIT's Kudinoor advises businesses to upgrade all systems to PQC, beginning with the highest priority and most publicly available systems. </p><p>But the reality is that the threats themselves won't all hit at once – despite the 'Q-Day' label implying there's a single moment in the future beyond which there's no return. As IBM's Viswesan explains: "We’ll see it materialize over time, spanning multiple years as different cryptographic systems become vulnerable at different times." </p><h2 id="quantum-readiness-is-all-about-making-haste-slowly">Quantum readiness is all about making haste slowly</h2><p>Given the gradual and unfolding nature of 'Q-Day',  businesses should avoid rushing their decision-making and adopt a balanced and thoughtful approach, whether that's in assessing their estate or engaging with vendors. </p><p>The name for this dilemma – in which you need to act fast but not so fast that you end up making poor decisions – is "festina lente", a Latin term that roughly translates to "hurry slowly". But that's easier said than done.</p><p>"Organizations shouldn't wait to begin the transformation journey, but they also shouldn't rush into decisions. That’s where crypto-agility comes into play," Viswesan continues. </p><p>"Crypto‑agility is the ability to migrate to post-quantum cryptography (PQC), while maintaining the flexibility to make changes without business disruption. Crypto‑agility allows organizations to scale cryptography‑based data protection with confidence, reduce the operational costs associated with managing cryptography, and meaningfully lower long‑term security risk."</p><p>What about quantum companies themselves? After all, aren't they causing the problem in the first place? As de Jong says, the supply chain is already seeing a lot of countermeasures embedded into products by design, for example, quantum-safe features in the systems that cloud companies provide. </p><p>Pro bono support may also be available to smaller companies without the budgets or expertise to fight this battle. But, he says, the problem is likely to impact the larger companies the most. </p><p>To adequately prepare, the experts also recommend that building quantum literacy among technical teams and executives is essential. These teams should then devise roadmaps, with budgets over the coming years incorporating more quantum line items. </p><p>This transition is new to almost everyone, meaning that it's a journey of discovery and the best practice is still being formulated. There are, however, companies that are further along the journey than others – and organizations should liaise with one another so that everyone can benefit together.</p><p>"The transition to quantum-safe is new for almost everyone," de Jong adds, "so I would advise enterprise CXOs not to try and reinvent the wheel themselves, but rather work with companies that have been working on it for several years, so everyone can benefit from the collective knowledge."</p><p>The timelines are shrinking with each quantum computing breakthrough, and there's a general acceptance among experts that it won't be possible for businesses to be fully quantum-ready by 2029 – especially if you factor in the HNDL attacks that have already happened. </p><p>That said, it's never too late to act to avoid the very worst of it, and businesses should do what they can to get as far ahead of this threat as possible before it's too late – no matter how tempting it is to route budgets into more appealing areas like AI. </p><p>Should more businesses begin to act faster, when 'Q-Day' begins to take hold, there's still every chance, much like the Y2K bug, that this will become yet another amusing anecdote from the annals of tech history about a massive computing threat that was avoided.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anthropic resumes model testing after recent cyber incidents – but it’s introduced new rules to improve security ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Anthropic is back to testing security models after systems went rogue – and claims the incident wasn’t entirely down to security faults but AI misalignment. </p><p>Back in July, Anthropic revealed its Claude models had slipped out of their apparent bounds to hack third-party systems. Days later, its <a href="https://www.itpro.com/security/cyber-attacks/anthropics-mythos-ai-tried-to-dupe-devs-in-social-engineering-attack-collaborated-with-other-agents"><u>Mythos system was spotted</u></a> with similar alarming behavior by the UK AI Security Institute. </p><p>The incidents followed <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime"><u>OpenAI revealing similar behavior</u></a> from its own security models. </p><p>Last week, <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident"><u>OpenAI reported on its own incident</u></a>, detailing plans to improve security around such models, and Anthropic has followed with its own efforts, including confirmation that it will begin testing again. </p><p>Anthropic noted it was currently conducting a review of what happened and said it is "planning" to work with METR on an independent review; OpenAI has already published an independent METR review into its own incident. </p><p>But Anthropic isn't waiting to make changes. In a <a href="https://www.anthropic.com/news/improving-alignment-security-efforts" target="_blank"><u>blog post</u></a> on 31 August, the firm said it plans to make tweaks to containment and monitoring, introduce new rules for third-party testers, as well as changes to the models. </p><p>Notably, the AI developer revealed it is seconding 150 product engineers to focus primarily on security. </p><p>"We believe the incidents reflect a failure of operational security, as well as two alignment issues: motivated reasoning, and willingness to take harmful actions in pursuit of a narrow task," the company said. </p><h2 id="anthropic-is-back-testing">Anthropic is back testing</h2><p>While the full investigation isn't yet complete, Anthropic said it was removing a "pause" on external <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>evaluations of pre-release models as well as internal tests. </p><p>To avoid similar issues happening again, Anthropic is adding additional layers of security and "hardening" the sandbox where these models are set loose, noting that move was prompted by its own evidence as well as that shared by OpenAI. </p><p>The changes include a system to spot when a model attempts to escape a testing environment or obtains internet access, immediately blocking the activity and alerting people overseeing the task, as well as fixing potential flaws and misconfigurations in the sandbox. </p><p>"We migrated high-risk internal cyber sandboxes to more robust isolation," the post added. "We are also further red-teaming our virtualization stack – that is, tasking pre-release models to try and escape it – to find and patch weaknesses."</p><p>Similar protections have been applied to reinforcement learning environments, with Anthropic adding it plans to expand its monitoring across most other internal frontier agentic usage. </p><p>Beyond testing environments, Anthropic is hardening security across the company, including blocking outbound traffic by default on computing clusters, boosting identity verification on internal services, retiring legacy services, and reducing the number of human and automated accounts that can access model weights or customer data. </p><h2 id="tougher-testing-rules">Tougher testing rules</h2><p>With regard to third-party testing, Anthropic said it will require testers to commit to a fresh set of best practices, noting that the reported incidents all took place in external evaluation environments. </p><p>As <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents"><u><em>ITPro </em></u><u>reported last month</u></a>, Israeli startup Irregular was identified as the external model testing firm involved in all three ‘rogue AI’ incidents involving Anthropic, OpenAI, and Meta. </p><p>The changes include running tests inside hardened sandboxes with no internet access, tasking the model being tested to look for flaws before tests under close human supervision, run monitoring continuously, and confirm whether test tasks are impossible or not. </p><p>"When an evaluation target is offline or a task can’t be completed, agents will often look for other ways to complete a challenge, increasing the chance that they take actions outside the intended scope of the evaluation," the company said. </p><h2 id="unpicking-why">Unpicking why</h2><p>Those operational changes should help prevent models from escaping their sandboxes, but Anthropic said it wants to better understand why its systems took such "dangerous actions" in the first place. </p><p>While the full investigation continues, Anthropic highlighted two challenges with alignment, which refers to ensuring that AI behaves how humans want and expect. </p><p>"One is motivated reasoning: the models were initially told their environments were simulated, but when they later encountered evidence that they were connected to the real internet, they may have interpreted that evidence in a way that allowed them to maintain that belief," the blog post explained. </p><p>"The second is recklessness: the model was willing to take harmful actions on the real internet in pursuit of the narrow goal of solving a cybersecurity evaluation."</p><p>The company noted that poorly designed training environments – including ones that are easy to cheat in or impossible to solve without cheating – can lead to misalignment behavior. </p><p>Anthropic is trying to avoid such issues in the future. The company said work on thie front goes back several months and involves training poorly and training well to try to spot differences – but admitted that the July incidents show "our process isn't perfect and our models aren't perfectly aligned". </p><p>Further details on security improvements are expected in the full report, according to Anthropic. </p><p>Beyond that, the firm also loosely backed calls to develop a framework for safe development of security-focused AI, acknowledging that its own executives had recently signed an open letter demanding better coordination globally. </p><p>Anthropic said it would "say more in the coming weeks" but intended to contribute to such efforts. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/anthropic-resumes-model-testing-after-recent-cyber-incidents-but-its-introduced-new-rules-to-improve-security</link>
                                                                            <description>
                            <![CDATA[ Anthropic has boosted its security and tweaked its training to avoid rogue AI ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">prrkks6bEQDGqqZoVB8jKR</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jLZncMSkFV4MARFdHwLLV5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 14:37:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jLZncMSkFV4MARFdHwLLV5-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo of AI startup Anthropic, developer of the Claude Opus 4 and Sonnet 4 AI models, pictured on a smartphone held in a human hand.]]></media:description>                                                            <media:text><![CDATA[Logo of AI startup Anthropic, developer of the Claude Opus 4 and Sonnet 4 AI models, pictured on a smartphone held in a human hand.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo of AI startup Anthropic, developer of the Claude Opus 4 and Sonnet 4 AI models, pictured on a smartphone held in a human hand.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jLZncMSkFV4MARFdHwLLV5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Anthropic is back to testing security models after systems went rogue – and claims the incident wasn’t entirely down to security faults but AI misalignment. </p><p>Back in July, Anthropic revealed its Claude models had slipped out of their apparent bounds to hack third-party systems. Days later, its <a href="https://www.itpro.com/security/cyber-attacks/anthropics-mythos-ai-tried-to-dupe-devs-in-social-engineering-attack-collaborated-with-other-agents"><u>Mythos system was spotted</u></a> with similar alarming behavior by the UK AI Security Institute. </p><p>The incidents followed <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime"><u>OpenAI revealing similar behavior</u></a> from its own security models. </p><p>Last week, <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident"><u>OpenAI reported on its own incident</u></a>, detailing plans to improve security around such models, and Anthropic has followed with its own efforts, including confirmation that it will begin testing again. </p><p>Anthropic noted it was currently conducting a review of what happened and said it is "planning" to work with METR on an independent review; OpenAI has already published an independent METR review into its own incident. </p><p>But Anthropic isn't waiting to make changes. In a <a href="https://www.anthropic.com/news/improving-alignment-security-efforts" target="_blank"><u>blog post</u></a> on 31 August, the firm said it plans to make tweaks to containment and monitoring, introduce new rules for third-party testers, as well as changes to the models. </p><p>Notably, the AI developer revealed it is seconding 150 product engineers to focus primarily on security. </p><p>"We believe the incidents reflect a failure of operational security, as well as two alignment issues: motivated reasoning, and willingness to take harmful actions in pursuit of a narrow task," the company said. </p><h2 id="anthropic-is-back-testing">Anthropic is back testing</h2><p>While the full investigation isn't yet complete, Anthropic said it was removing a "pause" on external <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>evaluations of pre-release models as well as internal tests. </p><p>To avoid similar issues happening again, Anthropic is adding additional layers of security and "hardening" the sandbox where these models are set loose, noting that move was prompted by its own evidence as well as that shared by OpenAI. </p><p>The changes include a system to spot when a model attempts to escape a testing environment or obtains internet access, immediately blocking the activity and alerting people overseeing the task, as well as fixing potential flaws and misconfigurations in the sandbox. </p><p>"We migrated high-risk internal cyber sandboxes to more robust isolation," the post added. "We are also further red-teaming our virtualization stack – that is, tasking pre-release models to try and escape it – to find and patch weaknesses."</p><p>Similar protections have been applied to reinforcement learning environments, with Anthropic adding it plans to expand its monitoring across most other internal frontier agentic usage. </p><p>Beyond testing environments, Anthropic is hardening security across the company, including blocking outbound traffic by default on computing clusters, boosting identity verification on internal services, retiring legacy services, and reducing the number of human and automated accounts that can access model weights or customer data. </p><h2 id="tougher-testing-rules">Tougher testing rules</h2><p>With regard to third-party testing, Anthropic said it will require testers to commit to a fresh set of best practices, noting that the reported incidents all took place in external evaluation environments. </p><p>As <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents"><u><em>ITPro </em></u><u>reported last month</u></a>, Israeli startup Irregular was identified as the external model testing firm involved in all three ‘rogue AI’ incidents involving Anthropic, OpenAI, and Meta. </p><p>The changes include running tests inside hardened sandboxes with no internet access, tasking the model being tested to look for flaws before tests under close human supervision, run monitoring continuously, and confirm whether test tasks are impossible or not. </p><p>"When an evaluation target is offline or a task can’t be completed, agents will often look for other ways to complete a challenge, increasing the chance that they take actions outside the intended scope of the evaluation," the company said. </p><h2 id="unpicking-why">Unpicking why</h2><p>Those operational changes should help prevent models from escaping their sandboxes, but Anthropic said it wants to better understand why its systems took such "dangerous actions" in the first place. </p><p>While the full investigation continues, Anthropic highlighted two challenges with alignment, which refers to ensuring that AI behaves how humans want and expect. </p><p>"One is motivated reasoning: the models were initially told their environments were simulated, but when they later encountered evidence that they were connected to the real internet, they may have interpreted that evidence in a way that allowed them to maintain that belief," the blog post explained. </p><p>"The second is recklessness: the model was willing to take harmful actions on the real internet in pursuit of the narrow goal of solving a cybersecurity evaluation."</p><p>The company noted that poorly designed training environments – including ones that are easy to cheat in or impossible to solve without cheating – can lead to misalignment behavior. </p><p>Anthropic is trying to avoid such issues in the future. The company said work on thie front goes back several months and involves training poorly and training well to try to spot differences – but admitted that the July incidents show "our process isn't perfect and our models aren't perfectly aligned". </p><p>Further details on security improvements are expected in the full report, according to Anthropic. </p><p>Beyond that, the firm also loosely backed calls to develop a framework for safe development of security-focused AI, acknowledging that its own executives had recently signed an open letter demanding better coordination globally. </p><p>Anthropic said it would "say more in the coming weeks" but intended to contribute to such efforts. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Security researchers warn of AI-powered PLC attacks in wake of Siemens advisories ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Security researchers have successfully used AI to port a remote code execution (RCE) exploit between two <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn">programmable logic controllers (PLCs)</a>. </p><p>While the experiment still required significant human expertise to negotiate dead ends and false leads, it showed how AI could make it easier to carry out attacks against embedded and industrial systems.</p><p>The team at Forescout’s Vedere Labs used AI to port an RCE exploit between two WAGO PLC models in an exploit that took eight hours and 32 minutes and consumed just $535.74 in API tokens.</p><p>Once code execution was achieved, AI produced multiple working network payloads within minutes, suggesting that post-exploitation could become increasingly automated as models improve.</p><p>The exploit targeted CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus FTP server that allowed arbitrary ARM shellcode to execute on the live PLC without credentials.</p><p>Researchers had already shown that RCE exploits on PLCs can enable Deep Lateral Movement and granular control over safety logic – and reckoned that as AI-assisted exploit development improves, these techniques could become more accessible.</p><h2 id="how-ai-was-used-to-crack-plcs">How AI was used to crack PLCs</h2><p>The AI-assisted exploit development process involved two steps, according to Forescout. First and foremost, this included confirming the vulnerability and writing the payload. </p><p>Each step consisted of interactive sessions between a researcher and <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal">Claude Code</a>, which had access to a terminal, the reference files, analysis tools including Ghidra, and the live target PLC.</p><p>Claude could use those tools directly, generate and test code, and ask the researcher for additional input when needed.</p><p>Researchers noted that Claude decided to confirm the presence of the vulnerability by both probing the live target and carrying out static code analysis. </p><p>It didn't work the first time, however, with one session failing to trace the vulnerable function correctly and producing an invalid exploit. </p><p>According to researchers, the analysis provided useful context for the next session, which used binary searches to map the relevant functions correctly – albeit with researcher input to steer the analysis away from dead ends and provide additional disassembly context where necessary.</p><p>Writing a working RCE exploit took much longer, with initial attempts failing. Claude also wasted a lot of time testing incorrect hypotheses, decompiling unrelated code, and pursuing false leads.</p><p>The researchers had to change to <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-reveals-claude-opus-4-6-enterprise-focused-model-1-million-token-context-window">Claude Opus 4.6</a> with 1M context, and add the prompt: “Ask for my help with disassembly if you are not certain about a firmware detail”, and instruct the AI to the sink of the vulnerability – the point where the attacker-supplied username is copied into memory.</p><p>Claude could then reason about the function call chain leading to the sink and understand that it needed more context about how FTP packets are treated throughout this call chain.</p><h2 id="operational-technology-in-the-crosshairs">Operational technology in the crosshairs</h2><p>Organizations shouldn't dismiss <a href="https://www.itpro.com/security/369739/high-severity-vulnerabilities-uncovered-in-three-quarters-of-operational-technology">operational technology (OT) vulnerabilities</a> because they seem hard to exploit, researchers warned.</p><p>"AI has already lowered the barrier to vulnerability research and exploit development in higher-level software. This experiment suggests that the same progression is beginning to reach low-level embedded systems, although substantial barriers remain," the report noted..</p><p>"As models become more capable and independent, the cost and expertise required to adapt exploits across related embedded targets could fall substantially."</p><p>The advice on mitigation is pretty standard: reduce unnecessary OT device exposure, monitor <a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot">OT environments</a> for early signs of exploitation, exercise incident response against AI-assisted OT attack paths and use AI defensively, but validate its outputs.</p><p>Programmable logic controllers are rapidly emerging as a major risk to critical infrastructure. The US National Security Agency (NSA) issued a <a href="https://www.itpro.com/security/an-evolution-in-threat-actor-capabilities-cisa-warns-hackers-are-targeting-siemens-industrial-controllers-and-theyre-using-ai-generated-code"><u>warning</u></a> last month over an active threat against Siemens PLCs.</p><p>Similarly, in recent months, a series of <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>attacks on US water supply infrastructure</u></a> targeted internet-exposed PLCs, with the attackers remotely changing IP addresses and turning on and setting passwords. </p><p>Several water firms were left unable to view connected equipment, and in some cases it was shut down. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories</link>
                                                                            <description>
                            <![CDATA[ While the exploit required significant human help, Forescout says it could become a significant threat in future ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">c7eafuMpjRRyW8X23c4KYM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qXYXXdT4d7pCmVTE7ztgCc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 01 Sep 2026 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qXYXXdT4d7pCmVTE7ztgCc-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Programmable logic controllers (PLCs) pictured inside an industrial cabinet unit with LEDs, power supply, relays, and organized wire ducts.]]></media:description>                                                            <media:text><![CDATA[Programmable logic controllers (PLCs) pictured inside an industrial cabinet unit with LEDs, power supply, relays, and organized wire ducts.]]></media:text>
                                <media:title type="plain"><![CDATA[Programmable logic controllers (PLCs) pictured inside an industrial cabinet unit with LEDs, power supply, relays, and organized wire ducts.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qXYXXdT4d7pCmVTE7ztgCc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Security researchers have successfully used AI to port a remote code execution (RCE) exploit between two <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn">programmable logic controllers (PLCs)</a>. </p><p>While the experiment still required significant human expertise to negotiate dead ends and false leads, it showed how AI could make it easier to carry out attacks against embedded and industrial systems.</p><p>The team at Forescout’s Vedere Labs used AI to port an RCE exploit between two WAGO PLC models in an exploit that took eight hours and 32 minutes and consumed just $535.74 in API tokens.</p><p>Once code execution was achieved, AI produced multiple working network payloads within minutes, suggesting that post-exploitation could become increasingly automated as models improve.</p><p>The exploit targeted CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus FTP server that allowed arbitrary ARM shellcode to execute on the live PLC without credentials.</p><p>Researchers had already shown that RCE exploits on PLCs can enable Deep Lateral Movement and granular control over safety logic – and reckoned that as AI-assisted exploit development improves, these techniques could become more accessible.</p><h2 id="how-ai-was-used-to-crack-plcs">How AI was used to crack PLCs</h2><p>The AI-assisted exploit development process involved two steps, according to Forescout. First and foremost, this included confirming the vulnerability and writing the payload. </p><p>Each step consisted of interactive sessions between a researcher and <a href="https://www.itpro.com/software/development/anthropic-claude-code-usage-limits-increase-spacex-compute-deal">Claude Code</a>, which had access to a terminal, the reference files, analysis tools including Ghidra, and the live target PLC.</p><p>Claude could use those tools directly, generate and test code, and ask the researcher for additional input when needed.</p><p>Researchers noted that Claude decided to confirm the presence of the vulnerability by both probing the live target and carrying out static code analysis. </p><p>It didn't work the first time, however, with one session failing to trace the vulnerable function correctly and producing an invalid exploit. </p><p>According to researchers, the analysis provided useful context for the next session, which used binary searches to map the relevant functions correctly – albeit with researcher input to steer the analysis away from dead ends and provide additional disassembly context where necessary.</p><p>Writing a working RCE exploit took much longer, with initial attempts failing. Claude also wasted a lot of time testing incorrect hypotheses, decompiling unrelated code, and pursuing false leads.</p><p>The researchers had to change to <a href="https://www.itpro.com/technology/artificial-intelligence/anthropic-reveals-claude-opus-4-6-enterprise-focused-model-1-million-token-context-window">Claude Opus 4.6</a> with 1M context, and add the prompt: “Ask for my help with disassembly if you are not certain about a firmware detail”, and instruct the AI to the sink of the vulnerability – the point where the attacker-supplied username is copied into memory.</p><p>Claude could then reason about the function call chain leading to the sink and understand that it needed more context about how FTP packets are treated throughout this call chain.</p><h2 id="operational-technology-in-the-crosshairs">Operational technology in the crosshairs</h2><p>Organizations shouldn't dismiss <a href="https://www.itpro.com/security/369739/high-severity-vulnerabilities-uncovered-in-three-quarters-of-operational-technology">operational technology (OT) vulnerabilities</a> because they seem hard to exploit, researchers warned.</p><p>"AI has already lowered the barrier to vulnerability research and exploit development in higher-level software. This experiment suggests that the same progression is beginning to reach low-level embedded systems, although substantial barriers remain," the report noted..</p><p>"As models become more capable and independent, the cost and expertise required to adapt exploits across related embedded targets could fall substantially."</p><p>The advice on mitigation is pretty standard: reduce unnecessary OT device exposure, monitor <a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot">OT environments</a> for early signs of exploitation, exercise incident response against AI-assisted OT attack paths and use AI defensively, but validate its outputs.</p><p>Programmable logic controllers are rapidly emerging as a major risk to critical infrastructure. The US National Security Agency (NSA) issued a <a href="https://www.itpro.com/security/an-evolution-in-threat-actor-capabilities-cisa-warns-hackers-are-targeting-siemens-industrial-controllers-and-theyre-using-ai-generated-code"><u>warning</u></a> last month over an active threat against Siemens PLCs.</p><p>Similarly, in recent months, a series of <a href="https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running"><u>attacks on US water supply infrastructure</u></a> targeted internet-exposed PLCs, with the attackers remotely changing IP addresses and turning on and setting passwords. </p><p>Several water firms were left unable to view connected equipment, and in some cases it was shut down. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top security teams use AI agents, says Hack The Box ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Most of the top security teams are using AI agents, employing them to support human activity rather than replace it, according to Hack The Box.</p><p>The latest <a href="https://www.hackthebox.com/hubfs/The_AI-Accelerated_Cyber_Team.pdf"><u>three-year benchmark data</u></a> from the cyber readiness platform finds disproportionate use of agents among many of the strongest-performing teams. </p><p>More than two-thirds (68%) of the top 25 teams having an AI agent, although AI agents represented just 2.7% of registered accounts.</p><p>Those agents accounted for 4.2% of submitted flags and 4.6% of points awarded. </p><p>Across all active teams in the research, AI-augmented teams recorded a 3.2 times solve-rate advantage; an advantage that narrowed to 1.69 times among the top 5%, while the speed advantage grew. </p><p>While AI-augmented teams completed challenges three to four times faster, with the speed advantage increasing among the strongest operators, the strongest human team completed all 36 challenges compared with 32 for the strongest AI team.</p><p>"AI therefore creates the greatest value when it is directed by people who already understand the problem. It can compress research, coding, troubleshooting, and first- pass analysis. The operator still has to choose the path, challenge weak output, and decide whether the result is valid," the researchers said.</p><h2 id="ai-is-now-a-critical-component-in-security-operations">AI is now a critical component in security operations</h2><p>Together, the findings suggest that AI is no longer just a question of experimentation, but is becoming part of the working methods of experienced cybersecurity practitioners. </p><p>Researchers emphasized the importance of human expertise in directing, evaluating, and validating AI-generated work, however.</p><p>"The findings do not establish that AI caused teams to perform better. They do, however, show that AI is already becoming part of the toolkit used by many of the competition’s strongest teams," Hack The Box said.</p><p>Performance across the competition has shifted substantially over the past three years, with the median recorded time-to-solve dropping from 26.1 hours in 2024 to just 13.8 hours this year. </p><p>At the same time, and even with the challenge board expanding, the number of teams completing the entire challenge board rose from two in 2024 and three in 2025 to 15 in 2026.</p><p>The improvement, said Hack The Box, could be down to better preparation, reusable tooling, platform familiarity, and deeper specialist knowledge.</p><p>“The question for security leaders is no longer whether AI will become part of cybersecurity operations. That is already happening on both sides of the equation,” said <a href="https://www.itpro.com/security/hack-the-box-haris-pylarinos-growth">Haris Pylarinos</a>, Founder and CEO of Hack The Box. </p><p>“What matters now is whether teams have the expertise to use it safely and effectively. Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them. As agents become more capable, human judgment, validation and hands-on technical skill become more important, not less.” </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/top-security-teams-use-ai-agents-says-hack-the-box</link>
                                                                            <description>
                            <![CDATA[ Median solve times are dropping, and more teams are completing the entire challenge board ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2k4HEGEAAkLuyzm279c38n</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PbaraXgyBf5cecgbD4TJLU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 31 Aug 2026 05:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PbaraXgyBf5cecgbD4TJLU-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An illustration showing an AI agent side profile, depicted as a blue robot, with seven human faces in varying earthy metallic tones shown to the right.]]></media:description>                                                            <media:text><![CDATA[An illustration showing an AI agent side profile, depicted as a blue robot, with seven human faces in varying earthy metallic tones shown to the right.]]></media:text>
                                <media:title type="plain"><![CDATA[An illustration showing an AI agent side profile, depicted as a blue robot, with seven human faces in varying earthy metallic tones shown to the right.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PbaraXgyBf5cecgbD4TJLU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Most of the top security teams are using AI agents, employing them to support human activity rather than replace it, according to Hack The Box.</p><p>The latest <a href="https://www.hackthebox.com/hubfs/The_AI-Accelerated_Cyber_Team.pdf"><u>three-year benchmark data</u></a> from the cyber readiness platform finds disproportionate use of agents among many of the strongest-performing teams. </p><p>More than two-thirds (68%) of the top 25 teams having an AI agent, although AI agents represented just 2.7% of registered accounts.</p><p>Those agents accounted for 4.2% of submitted flags and 4.6% of points awarded. </p><p>Across all active teams in the research, AI-augmented teams recorded a 3.2 times solve-rate advantage; an advantage that narrowed to 1.69 times among the top 5%, while the speed advantage grew. </p><p>While AI-augmented teams completed challenges three to four times faster, with the speed advantage increasing among the strongest operators, the strongest human team completed all 36 challenges compared with 32 for the strongest AI team.</p><p>"AI therefore creates the greatest value when it is directed by people who already understand the problem. It can compress research, coding, troubleshooting, and first- pass analysis. The operator still has to choose the path, challenge weak output, and decide whether the result is valid," the researchers said.</p><h2 id="ai-is-now-a-critical-component-in-security-operations">AI is now a critical component in security operations</h2><p>Together, the findings suggest that AI is no longer just a question of experimentation, but is becoming part of the working methods of experienced cybersecurity practitioners. </p><p>Researchers emphasized the importance of human expertise in directing, evaluating, and validating AI-generated work, however.</p><p>"The findings do not establish that AI caused teams to perform better. They do, however, show that AI is already becoming part of the toolkit used by many of the competition’s strongest teams," Hack The Box said.</p><p>Performance across the competition has shifted substantially over the past three years, with the median recorded time-to-solve dropping from 26.1 hours in 2024 to just 13.8 hours this year. </p><p>At the same time, and even with the challenge board expanding, the number of teams completing the entire challenge board rose from two in 2024 and three in 2025 to 15 in 2026.</p><p>The improvement, said Hack The Box, could be down to better preparation, reusable tooling, platform familiarity, and deeper specialist knowledge.</p><p>“The question for security leaders is no longer whether AI will become part of cybersecurity operations. That is already happening on both sides of the equation,” said <a href="https://www.itpro.com/security/hack-the-box-haris-pylarinos-growth">Haris Pylarinos</a>, Founder and CEO of Hack The Box. </p><p>“What matters now is whether teams have the expertise to use it safely and effectively. Our data shows that AI is appearing most often alongside some of the strongest practitioners, not instead of them. As agents become more capable, human judgment, validation and hands-on technical skill become more important, not less.” </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake North Korean IT workers are rampant: Here’s how to spot the telltale signs a new hire is a hacker ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Huntress has uncovered at least five North Korean operatives who have managed to get themselves hired so far this year, using techniques that the firm described as 'genuinely wild'. </p><p>Workers linked to the Famous Chollima group applied for jobs at IT, sales, and healthcare companies through normal channels, went through the usual onboarding process, and in some cases even went on to carry out the work as normal, sending their pay back to the North Korean regime.</p><p>The <a href="https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation" target="_blank"><u>findings by Huntress</u></a> come amidst growing concerns over hackers infiltrating enterprises across the United States and Europe. </p><p>Earlier this month, Recorded Future <a href="https://www.itpro.com/security/cyber-attacks/the-scale-of-purpledeltas-operation-is-easy-to-miss-fake-north-korean-it-workers-are-submitting-so-many-job-applications-that-companies-cant-keep-up"><u>revealed</u></a> that groups of <a href="https://www.itpro.com/security/fake-north-korean-it-workers-are-rampant-on-linkedin-security-experts-warn-operatives-are-stealing-profiles-to-apply-for-jobs-and-infiltrate-firms">North Korean IT workers</a> dubbed PurpleDelta had created at least 22 fabricated personas, applying for jobs across a range of recruitment websites and platforms such as LinkedIn and Upwork.</p><p>Between them, they were applying for as many as 60 jobs per day. Researchers found they were able to collect high-value intelligence and exfiltrate proprietary data, source code, and internal communications in support of North Korean state objectives.</p><p>According to Huntress, there are certain telltale signs that new hires could be covert cyber criminals. </p><p>Red flags include the use of <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses">VPNs</a>, PiKVM, and Guermok devices, particularly when they are both being used, along with web services and browser extensions associated with screen, audio, and video redirection or recording. </p><h2 id="caught-in-the-act">Caught in the act</h2><p>Researchers observed several red flags, including two ‘different’ new hires whose ID documents were issued by the same police station, one day apart. </p><p>Notably, the documents were photographed eight minutes apart on the same iPhone. </p><p>Meanwhile, a worker was discovered secretly using a Raspberry Pi-based remote KVM device to control a company laptop from thousands of miles away, before the security software was even installed.</p><p>In one example in February, Huntress was contacted by an Australian firm that suspected that three employees were North Korean workers impersonating Chinese individuals. </p><p>Huntress found that documents in two of the workers' OneDrive accounts shared a common naming convention, while their passports were supposedly issued in the same place and at the same time. </p><p>There were also strong similarities between the energy bills and resident identity cards supplied – and the two workers apparently lived on the same street.</p><p>An examination of the infrastructure they were using, including IP addresses, ASNs, geographic access patterns and more, found that the accounts were authenticating with several IP addresses identified to be Astrill VPN nodes. </p><p>They were also using IPRoyal Proxy, a legitimate commercial proxy service provider that sells access to IP addresses through which customers can route their internet traffic, as well as WorkTitans B.V. </p><p>This is a bulletproof-hosting operation that appears to have been raided by the Fiscal Information and Investigation Service of the Netherlands (FIOD).</p><h2 id="robust-identity-verification">Robust identity verification </h2><p>According to Huntress, the rise of fake IT workers means enterprises need to implement more robust identity verification processes. </p><p>"Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding," Huntress advised. </p><p>"When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/fake-north-korean-it-workers-are-rampant-heres-how-to-spot-the-telltale-signs-a-new-hire-is-a-hacker</link>
                                                                            <description>
                            <![CDATA[ New analysis from Huntress reveals the red flags to look out for when taking on new hires ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WtdUYZroCJQSyWZcKSVLG5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 10:41:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:description>                                                            <media:text><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Huntress has uncovered at least five North Korean operatives who have managed to get themselves hired so far this year, using techniques that the firm described as 'genuinely wild'. </p><p>Workers linked to the Famous Chollima group applied for jobs at IT, sales, and healthcare companies through normal channels, went through the usual onboarding process, and in some cases even went on to carry out the work as normal, sending their pay back to the North Korean regime.</p><p>The <a href="https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation" target="_blank"><u>findings by Huntress</u></a> come amidst growing concerns over hackers infiltrating enterprises across the United States and Europe. </p><p>Earlier this month, Recorded Future <a href="https://www.itpro.com/security/cyber-attacks/the-scale-of-purpledeltas-operation-is-easy-to-miss-fake-north-korean-it-workers-are-submitting-so-many-job-applications-that-companies-cant-keep-up"><u>revealed</u></a> that groups of <a href="https://www.itpro.com/security/fake-north-korean-it-workers-are-rampant-on-linkedin-security-experts-warn-operatives-are-stealing-profiles-to-apply-for-jobs-and-infiltrate-firms">North Korean IT workers</a> dubbed PurpleDelta had created at least 22 fabricated personas, applying for jobs across a range of recruitment websites and platforms such as LinkedIn and Upwork.</p><p>Between them, they were applying for as many as 60 jobs per day. Researchers found they were able to collect high-value intelligence and exfiltrate proprietary data, source code, and internal communications in support of North Korean state objectives.</p><p>According to Huntress, there are certain telltale signs that new hires could be covert cyber criminals. </p><p>Red flags include the use of <a href="https://www.itpro.com/network-internet/virtual-private-network-vpn/367994/vpn-or-virtual-private-networks-what-businesses">VPNs</a>, PiKVM, and Guermok devices, particularly when they are both being used, along with web services and browser extensions associated with screen, audio, and video redirection or recording. </p><h2 id="caught-in-the-act">Caught in the act</h2><p>Researchers observed several red flags, including two ‘different’ new hires whose ID documents were issued by the same police station, one day apart. </p><p>Notably, the documents were photographed eight minutes apart on the same iPhone. </p><p>Meanwhile, a worker was discovered secretly using a Raspberry Pi-based remote KVM device to control a company laptop from thousands of miles away, before the security software was even installed.</p><p>In one example in February, Huntress was contacted by an Australian firm that suspected that three employees were North Korean workers impersonating Chinese individuals. </p><p>Huntress found that documents in two of the workers' OneDrive accounts shared a common naming convention, while their passports were supposedly issued in the same place and at the same time. </p><p>There were also strong similarities between the energy bills and resident identity cards supplied – and the two workers apparently lived on the same street.</p><p>An examination of the infrastructure they were using, including IP addresses, ASNs, geographic access patterns and more, found that the accounts were authenticating with several IP addresses identified to be Astrill VPN nodes. </p><p>They were also using IPRoyal Proxy, a legitimate commercial proxy service provider that sells access to IP addresses through which customers can route their internet traffic, as well as WorkTitans B.V. </p><p>This is a bulletproof-hosting operation that appears to have been raided by the Fiscal Information and Investigation Service of the Netherlands (FIOD).</p><h2 id="robust-identity-verification">Robust identity verification </h2><p>According to Huntress, the rise of fake IT workers means enterprises need to implement more robust identity verification processes. </p><p>"Mitigating the risk of fraudulent workers begins at the interview stage and continues with performing rigorous background checks of new hires prior to onboarding," Huntress advised. </p><p>"When in doubt, performing standard background checks, searching the individuals online, and verifying any employment history will help to weed out DPRK workers early in the interview process."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'The threat landscape is moving so quickly': CrowdStrike CEO George Kurtz warns AI is raising the stakes in cybersecurity – and the firm is poised to capitalize on ‘the largest market opportunity in our history’ ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.itpro.com/security/crowdstrike-ceo-embrace-ai-or-be-crushed-by-cyber-crooks">CrowdStrike CEO George Kurtz</a> has issued a warning over skyrocketing cybersecurity risks and rising threats created by recent AI advances. </p><p>Speaking on <em>CNBC’s </em>‘<a href="https://www.cnbc.com/mad-money/" target="_blank"><u><em>Mad Money</em></u></a>’ show, the CrowdStrike chief claimed current <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>solutions aren’t equipped to contend with increasingly sophisticated threat groups and AI-related risks. </p><p>“A lot of companies are recognizing that legacy technology, and technology that they get for free, is not good enough,” he told host Jim Cramer. Notably, this warning applies to enterprises of all sizes regardless of their level of expertise, budgets, and security capabilities. </p><p>“Most companies have some level of gaps,” he commented, per <a href="https://www.cnbc.com/2026/08/27/crowdstrike-ceo-ai-exposes-dangerous-cyber-gaps.html" target="_blank"><u><em>CNBC </em></u></a>reports. “The challenge that you have - even if companies are sophisticated and spending a lot - is the threat landscape is moving so quickly.”</p><p>The warning from Kurtz comes amidst growing cybersecurity concerns globally, with enterprises facing an increasingly perilous threat landscape. Highly aggressive ransomware groups and sophisticated state-sponsored threat actors continue to pose a huge threat to organisations and critical infrastructure. </p><p>Earlier this week, The US <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA) </a>revealed that over 100 <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn">water systems were targeted by threat groups</a> in July. </p><p>That advisory came less than 24 hours after the FBI revealed a host of federal agencies including the <a href="https://www.itpro.com/security/cyber-attacks/us-claims-chinese-hackers-breached-justice-department-federal-reserve-nasa-in-lengthy-threat-campaign">Justice Department and Federal Reserve were breached</a> by a Chinese-backed hacker group. </p><p>Kurtz noted that threat groups are evolving rapidly and adapting techniques, which is creating huge challenges for cyber defenders. </p><p>“You really have to have the technologies with the right level of expertise to be able to combat these adversaries,” he said. “They’re moving so quickly, their techniques change so dramatically.”</p><h2 id="ai-security-in-the-spotlight">AI security in the spotlight</h2><p>AI security risks are also adding a new level of complexity to the global threat landscape, Kurtz told <em>CNBC</em>. </p><p>A series of powerful new cyber-focused AI models have been announced by leading developers in recent months, including Anthropic’s Claude Mythos. </p><p>When Anthropic unveiled the model earlier this year, it <a href="https://www.itpro.com/technology/artificial-intelligence/project-glasswing-anthropic-announces-big-tech-consortium-to-test-claude-mythos-ai-model-that-could-reshape-cybersecurity">rolled out as part of a gated release program</a> due to concerns that it could be used for nefarious purposes. </p><p>Since then, a series of high profile incidents involving Meta, OpenAI, and Anthropic AI tools have thrust AI safety into the spotlight. </p><p>OpenAI revealed in mid-July that AI agents escaped a sandbox test environment and <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime">breached a Hugging Face production database</a>. OpenAI’s admission was followed in quick succession by <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents">Anthropic and Meta</a>, who both confirmed similar incidents. </p><p>Kurtz told Cramer that the ability for AI agents to “swarm and find vulnerabilities and exploit those” raises the stakes for enterprises and security teams. The advent of AI agents is also creating risks elsewhere and creating blind spots for enterprises, as <a href="https://www.itpro.com/technology/artificial-intelligence/compromised-ai-agents-could-make-living-off-the-land-attacks-much-more-dangerous-says-crowdstrike-field-cto"><u><em>ITPro </em></u><u>reported in July</u></a>. </p><p>CrowdStrike’s field CTO for Europe, Zeki Turedi, told <em>ITPro </em>that the deep access these agents have to enterprise IT estates could further exacerbate ‘living off the land’ techniques used by hackers to infiltrate networks. </p><h2 id="capitalizing-on-the-ai-boom">Capitalizing on the AI boom</h2><p>CrowdStrike is one of a number of leading cybersecurity vendors capitalizing on the AI security boom in 2026. On 26 August, the company published its <a href="https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-reports-second-quarter-fiscal-year-2027-financial" target="_blank"><u>Q2 financial results</u></a>, which Kurtz described as “the best quarter in CrowdStrike’s history”. </p><p>Indeed, the company reported total revenue of $1.47 billion for the quarter, marking a 26% increase compared to Q1. Annual recurring revenue (ARR) also reached $333 million, with growth surging 51% year-over-year. </p><p>In a statement, Kurtz specifically highlighted adoption rates of Falcon Flex as a key contributor to recent growth. Falcon Flex is a subscription-based licensing scheme for its Falcon cybersecurity platform. </p><p>"Delivering record Falcon Flex results, record net new ARR, and accelerating growth—the Falcon is soaring,” he said.</p><p>“The Mythos moment translated into mass-market acceptance that AI adoption needs security, and that's CrowdStrike. Every enterprise will run on AI, and securing it is the largest market opportunity in our history."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/the-threat-landscape-is-moving-so-quickly-crowdstrike-ceo-george-kurtz-warns-ai-is-raising-the-stakes-in-cybersecurity-and-the-firm-is-poised-to-capitalize-on-the-largest-market-opportunity-in-our-history</link>
                                                                            <description>
                            <![CDATA[ With concerns over AI security rising, Kurtz believes CrowdStrike can position itself as the go-to provider for enterprises ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bDUuZLhyZUJqDbuXQFuDdf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3fBVScpFqs8x6qZDWSjPz9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 10:28:34 +0000</pubDate>                                                                                                                                <updated>Fri, 28 Aug 2026 10:28:41 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3fBVScpFqs8x6qZDWSjPz9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[CrowdStrike CEO George Kurtz speaking on stage at the Wall Street Journal D.Live global technology conference in Laguna Beach, California.]]></media:description>                                                            <media:text><![CDATA[CrowdStrike CEO George Kurtz speaking on stage at the Wall Street Journal D.Live global technology conference in Laguna Beach, California.]]></media:text>
                                <media:title type="plain"><![CDATA[CrowdStrike CEO George Kurtz speaking on stage at the Wall Street Journal D.Live global technology conference in Laguna Beach, California.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3fBVScpFqs8x6qZDWSjPz9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/crowdstrike-ceo-embrace-ai-or-be-crushed-by-cyber-crooks">CrowdStrike CEO George Kurtz</a> has issued a warning over skyrocketing cybersecurity risks and rising threats created by recent AI advances. </p><p>Speaking on <em>CNBC’s </em>‘<a href="https://www.cnbc.com/mad-money/" target="_blank"><u><em>Mad Money</em></u></a>’ show, the CrowdStrike chief claimed current <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>solutions aren’t equipped to contend with increasingly sophisticated threat groups and AI-related risks. </p><p>“A lot of companies are recognizing that legacy technology, and technology that they get for free, is not good enough,” he told host Jim Cramer. Notably, this warning applies to enterprises of all sizes regardless of their level of expertise, budgets, and security capabilities. </p><p>“Most companies have some level of gaps,” he commented, per <a href="https://www.cnbc.com/2026/08/27/crowdstrike-ceo-ai-exposes-dangerous-cyber-gaps.html" target="_blank"><u><em>CNBC </em></u></a>reports. “The challenge that you have - even if companies are sophisticated and spending a lot - is the threat landscape is moving so quickly.”</p><p>The warning from Kurtz comes amidst growing cybersecurity concerns globally, with enterprises facing an increasingly perilous threat landscape. Highly aggressive ransomware groups and sophisticated state-sponsored threat actors continue to pose a huge threat to organisations and critical infrastructure. </p><p>Earlier this week, The US <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA) </a>revealed that over 100 <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn">water systems were targeted by threat groups</a> in July. </p><p>That advisory came less than 24 hours after the FBI revealed a host of federal agencies including the <a href="https://www.itpro.com/security/cyber-attacks/us-claims-chinese-hackers-breached-justice-department-federal-reserve-nasa-in-lengthy-threat-campaign">Justice Department and Federal Reserve were breached</a> by a Chinese-backed hacker group. </p><p>Kurtz noted that threat groups are evolving rapidly and adapting techniques, which is creating huge challenges for cyber defenders. </p><p>“You really have to have the technologies with the right level of expertise to be able to combat these adversaries,” he said. “They’re moving so quickly, their techniques change so dramatically.”</p><h2 id="ai-security-in-the-spotlight">AI security in the spotlight</h2><p>AI security risks are also adding a new level of complexity to the global threat landscape, Kurtz told <em>CNBC</em>. </p><p>A series of powerful new cyber-focused AI models have been announced by leading developers in recent months, including Anthropic’s Claude Mythos. </p><p>When Anthropic unveiled the model earlier this year, it <a href="https://www.itpro.com/technology/artificial-intelligence/project-glasswing-anthropic-announces-big-tech-consortium-to-test-claude-mythos-ai-model-that-could-reshape-cybersecurity">rolled out as part of a gated release program</a> due to concerns that it could be used for nefarious purposes. </p><p>Since then, a series of high profile incidents involving Meta, OpenAI, and Anthropic AI tools have thrust AI safety into the spotlight. </p><p>OpenAI revealed in mid-July that AI agents escaped a sandbox test environment and <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime">breached a Hugging Face production database</a>. OpenAI’s admission was followed in quick succession by <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents">Anthropic and Meta</a>, who both confirmed similar incidents. </p><p>Kurtz told Cramer that the ability for AI agents to “swarm and find vulnerabilities and exploit those” raises the stakes for enterprises and security teams. The advent of AI agents is also creating risks elsewhere and creating blind spots for enterprises, as <a href="https://www.itpro.com/technology/artificial-intelligence/compromised-ai-agents-could-make-living-off-the-land-attacks-much-more-dangerous-says-crowdstrike-field-cto"><u><em>ITPro </em></u><u>reported in July</u></a>. </p><p>CrowdStrike’s field CTO for Europe, Zeki Turedi, told <em>ITPro </em>that the deep access these agents have to enterprise IT estates could further exacerbate ‘living off the land’ techniques used by hackers to infiltrate networks. </p><h2 id="capitalizing-on-the-ai-boom">Capitalizing on the AI boom</h2><p>CrowdStrike is one of a number of leading cybersecurity vendors capitalizing on the AI security boom in 2026. On 26 August, the company published its <a href="https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-reports-second-quarter-fiscal-year-2027-financial" target="_blank"><u>Q2 financial results</u></a>, which Kurtz described as “the best quarter in CrowdStrike’s history”. </p><p>Indeed, the company reported total revenue of $1.47 billion for the quarter, marking a 26% increase compared to Q1. Annual recurring revenue (ARR) also reached $333 million, with growth surging 51% year-over-year. </p><p>In a statement, Kurtz specifically highlighted adoption rates of Falcon Flex as a key contributor to recent growth. Falcon Flex is a subscription-based licensing scheme for its Falcon cybersecurity platform. </p><p>"Delivering record Falcon Flex results, record net new ARR, and accelerating growth—the Falcon is soaring,” he said.</p><p>“The Mythos moment translated into mass-market acceptance that AI adoption needs security, and that's CrowdStrike. Every enterprise will run on AI, and securing it is the largest market opportunity in our history."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Manchester Airports Group attack: Everything we know so far as 8.7 million customers impacted in breach ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Data belonging to millions of customers has been accessed in a cyber attack on Manchester Airports Group (MAG), the company has revealed. </p><p>MAG, which runs Manchester, London Stansted, and East Midlands airports, <a href="https://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/" target="_blank"><u>confirmed a cybersecurity incident</u></a> on 27 August. </p><p>Data exposed in the breach relates to car park, lounge and Fast Track bookings, and on-site Wi-Fi at all three airports, the company revealed in a statement. This includes:</p><ul><li>Customer email addresses</li><li>Phone numbers</li><li>Vehicle registrations</li><li>Postcodes</li></ul><p>MAG noted that banking and payment details were not exposed in the breach, which at this point is believed to have impacted around 8.7 million customers. </p><p>The company added that the breach hasn’t resulted in any operational disruption, with airport operations remaining unaffected. Customer parking services are still operating as expected. </p><p>"All upcoming bookings remain valid and are unaffected by this incident," it said. "Passengers should continue to travel to the airport as normal."</p><p>MAG said it has restricted access to the affected systems, called in specialist cyber security experts, and notified the relevant authorities.</p><h2 id="who-is-responsible-for-the-breach">Who is responsible for the breach?</h2><p>At present, there’s no indication on who is responsible for the breach, or how it occurred. However, like many recent attacks on organizations, the incident appears to have been a supply chain-related attack. </p><p>Nathan Davies-Webb, principal consultant at Acumen Cyber, said modern airports “sit at the center of a complex web of booking, parking, loyalty, payment, and internet connectivity services”. </p><p>“Many of the services in that ecosystem run on platforms operated by subsidiaries or third-party suppliers rather than the airport itself," he commented. </p><p>"That's a sensible commercial model but it creates an uncomfortable reality for security. A breach like this one in a shared upstream system can expose customer data from multiple services at multiple airports simultaneously."</p><p>Last year, a <a href="https://www.thalesgroup.com/en/worldwide/aerospace/press_release/aviation-sector-sees-600-year-year-increase-cyberattacks" target="_blank"><u>report</u></a> from Thales highlighted a 600% increase in ransomware attacks in the aviation sector over the previous year, with 27 major attacks by 22 ransomware groups between January 2024 and April 2025.</p><p>A string of attacks on Hawaiian Airlines, Canada's WestJet and <a href="https://www.itpro.com/security/cyber-attacks/qantas-cyber-attack-six-million-customers-exposed">Qantas </a>over the last year have all been <a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks">attributed to the Scattered Spider group</a>.</p><p>Muhammad Yahya Patel, vCISO and <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>advisor for EMEA at Huntress, said the nature of the data exposed poses a significant threat to customers. Cyber criminals frequently rely on exposed information such as email addresses to conduct follow-up <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns. </p><p>“Email addresses, phone numbers, and vehicle registrations combined is a precise targeting profile for anyone planning a follow-on fraud or phishing campaign. Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story," he said. </p><p>"When that data ends up in an unauthorized third party’s hands alongside parking and lounge booking details, it fills in a surprisingly detailed picture of someone’s travel habits."</p><h2 id="mag-urges-customers-to-remain-vigilant">MAG urges customers to remain vigilant</h2><p>MAG warned customers to remain vigilant for suspicious emails, text messages, or phone calls, and avoid clicking on links or opening attachments from unexpected communications. </p><p>The company stressed that it will never request payment card details, banking information, or passwords from customers. </p><p>Davies-Webb commended MAG for its swift response to the incident, although data protection regulations require enterprises to disclose breaches within a strict time frame. </p><p>"Public disclosure roughly forty-eight hours after they became aware is fast by UK standards and can point in one of two directions," said Davies-Webb. </p><p>"Either MAG undertook containment decisively enough that they felt safe releasing details of the breach on their own terms, or the volume and nature of the personal data compromised meant the seventy-two hour notification clock under UK GDPR was already running and disclosure was going to have to happen.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/manchester-airports-group-attack-everything-we-know-so-far-as-8-7-million-customers-impacted-in-breach</link>
                                                                            <description>
                            <![CDATA[ Manchester Airports Group says airports are running as normal, but warns customers to look out for phishing attacks ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3HHFYhd2MmVinx36cQh9ZW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DVmkPfYJrV73rHN98npwDo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 28 Aug 2026 09:51:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DVmkPfYJrV73rHN98npwDo-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Terminal 2 departures building at Manchester Airport, run by Manchester Airports Group, with passengers queuing at check-in point.]]></media:description>                                                            <media:text><![CDATA[Terminal 2 departures building at Manchester Airport, run by Manchester Airports Group, with passengers queuing at check-in point.]]></media:text>
                                <media:title type="plain"><![CDATA[Terminal 2 departures building at Manchester Airport, run by Manchester Airports Group, with passengers queuing at check-in point.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DVmkPfYJrV73rHN98npwDo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data belonging to millions of customers has been accessed in a cyber attack on Manchester Airports Group (MAG), the company has revealed. </p><p>MAG, which runs Manchester, London Stansted, and East Midlands airports, <a href="https://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/" target="_blank"><u>confirmed a cybersecurity incident</u></a> on 27 August. </p><p>Data exposed in the breach relates to car park, lounge and Fast Track bookings, and on-site Wi-Fi at all three airports, the company revealed in a statement. This includes:</p><ul><li>Customer email addresses</li><li>Phone numbers</li><li>Vehicle registrations</li><li>Postcodes</li></ul><p>MAG noted that banking and payment details were not exposed in the breach, which at this point is believed to have impacted around 8.7 million customers. </p><p>The company added that the breach hasn’t resulted in any operational disruption, with airport operations remaining unaffected. Customer parking services are still operating as expected. </p><p>"All upcoming bookings remain valid and are unaffected by this incident," it said. "Passengers should continue to travel to the airport as normal."</p><p>MAG said it has restricted access to the affected systems, called in specialist cyber security experts, and notified the relevant authorities.</p><h2 id="who-is-responsible-for-the-breach">Who is responsible for the breach?</h2><p>At present, there’s no indication on who is responsible for the breach, or how it occurred. However, like many recent attacks on organizations, the incident appears to have been a supply chain-related attack. </p><p>Nathan Davies-Webb, principal consultant at Acumen Cyber, said modern airports “sit at the center of a complex web of booking, parking, loyalty, payment, and internet connectivity services”. </p><p>“Many of the services in that ecosystem run on platforms operated by subsidiaries or third-party suppliers rather than the airport itself," he commented. </p><p>"That's a sensible commercial model but it creates an uncomfortable reality for security. A breach like this one in a shared upstream system can expose customer data from multiple services at multiple airports simultaneously."</p><p>Last year, a <a href="https://www.thalesgroup.com/en/worldwide/aerospace/press_release/aviation-sector-sees-600-year-year-increase-cyberattacks" target="_blank"><u>report</u></a> from Thales highlighted a 600% increase in ransomware attacks in the aviation sector over the previous year, with 27 major attacks by 22 ransomware groups between January 2024 and April 2025.</p><p>A string of attacks on Hawaiian Airlines, Canada's WestJet and <a href="https://www.itpro.com/security/cyber-attacks/qantas-cyber-attack-six-million-customers-exposed">Qantas </a>over the last year have all been <a href="https://www.itpro.com/security/cyber-attacks/scattered-spider-airline-industry-attacks">attributed to the Scattered Spider group</a>.</p><p>Muhammad Yahya Patel, vCISO and <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>advisor for EMEA at Huntress, said the nature of the data exposed poses a significant threat to customers. Cyber criminals frequently rely on exposed information such as email addresses to conduct follow-up <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns. </p><p>“Email addresses, phone numbers, and vehicle registrations combined is a precise targeting profile for anyone planning a follow-on fraud or phishing campaign. Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story," he said. </p><p>"When that data ends up in an unauthorized third party’s hands alongside parking and lounge booking details, it fills in a surprisingly detailed picture of someone’s travel habits."</p><h2 id="mag-urges-customers-to-remain-vigilant">MAG urges customers to remain vigilant</h2><p>MAG warned customers to remain vigilant for suspicious emails, text messages, or phone calls, and avoid clicking on links or opening attachments from unexpected communications. </p><p>The company stressed that it will never request payment card details, banking information, or passwords from customers. </p><p>Davies-Webb commended MAG for its swift response to the incident, although data protection regulations require enterprises to disclose breaches within a strict time frame. </p><p>"Public disclosure roughly forty-eight hours after they became aware is fast by UK standards and can point in one of two directions," said Davies-Webb. </p><p>"Either MAG undertook containment decisively enough that they felt safe releasing details of the breach on their own terms, or the volume and nature of the personal data compromised meant the seventy-two hour notification clock under UK GDPR was already running and disclosure was going to have to happen.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Everything we know about the Boston Scientific cyber attack so far ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Medical technology firm Boston Scientific has been hit with a cyber attack that has severely disrupted global operations.</p><p>In a <a href="https://www.sec.gov/ix?doc=/Archives/edgar/data/885725/000088572526000056/bsx-20260826.htm" target="_blank"><u>filing </u></a>with the US <a href="https://www.itpro.com/security/sec-cyber-security-filings-on-the-rise-as-new-reporting-rules-bite">Securities and Exchange Commission (SEC)</a>, the MedTech company said the incident was first detected on 25 August. </p><p>The attack resulted in a network outage, meaning the company only has limited access to certain systems and applications. </p><p>Boston Scientific supplies a range of devices used in cardiac care, endoscopy, and urology and reported $5.4 billion in net sales during the second quarter of 2026. </p><p>According to the firm, as soon as it detected the breach it activated its incident response protocols and began an investigation to assess and contain the threat with the help of third-party <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>experts.</p><p>The company is in the process of restoring affected functions and reinstating access to systems, but that there's as yet no timeline for a full restoration.</p><p>“The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders,” the filing reads. </p><h2 id="who-s-behind-the-boston-scientific-cyber-attack">Who’s behind the Boston Scientific cyber attack?</h2><p>As of yet, there’s no information on the initial access method used by the hackers, nor the type of attack, who may have carried it out, or what data may have been accessed.</p><p>Ross Filipek, <a href="https://www.itpro.com/business/business-strategy/why-the-ciso-role-is-so-demanding-and-how-leaders-can-help">CISO </a>at Corsica Technologies, said at this stage the company will be prioritizing containment and establishing how the threat actor(s) gained access. </p><p>"<a href="https://www.itpro.com/business/business-strategy/lack-of-visibility-creates-cascade-of-security-risk-says-kiteworks">Security teams need constant visibility</a> into what was affected and which systems are safe to bring back online," Filipek commented.</p><p>"In healthcare, downtime carries operational consequences quickly. Strong incident response has to protect the environment while helping the business restore critical services as safely and efficiently as possible.”</p><h2 id="healthcare-in-the-crosshairs">Healthcare in the crosshairs</h2><p>The Boston Scientific breach marks the latest in a string of attacks on major medical device manufacturers, with Stryker, Medtronic, and Abbott all having disclosed cyber incidents in recent months. </p><p>In March, Stryker was <a href="https://www.itpro.com/technology/artificial-intelligence/its-destructive-not-ransomware-security-experts-weigh-in-on-motivation-behind-stryker-cyber-attack"><u>hit in an attack</u></a> claimed by Iranian-linked threat group <a href="https://www.itpro.com/security/cyber-attacks/stryker-hackers-struck-by-fbi-in-domain-seizure-campaign">Handala</a>, which claimed to have wiped thousands of systems across the company’s global operations and stolen around 50 terabytes of data.</p><p>A month later, the notorious <a href="https://www.itpro.com/security/data-breaches/european-commission-confirms-data-breach-as-shinyhunters-group-claims-responsibility">ShinyHunters </a>group claimed responsibility for an attack on the world’s largest medical device maker Medtronic. Just last month, cancer diagnostics device supplier Abbott said it had detected unauthorized access to some internal systems.</p><p>Dray Agha, senior manager of security operations at Huntress, said the data used by healthcare and medical technology providers makes them prime targets for cyber criminals. </p><p>“This is an unfortunate ripple effect on the healthcare supply chain. The attack on Boston Scientific demonstrates that cyber incidents in the MedTech sector extend far beyond IT and actively threaten the global healthcare supply chain," Agha said. </p><p>"When a major manufacturer is paralysed and unable to process or ship medical orders, the disruption creates immediate ripple effects that can ultimately delay critical treatments and impact patient care down the line."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/everything-we-know-about-the-boston-scientific-cyber-attack-so-far</link>
                                                                            <description>
                            <![CDATA[ Details remain limited, but Boston Scientific says it's lost access to some systems and is having problems processing orders ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nM5HT5Mo7Y8QpzYjMS3VQf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/XTkDYhRoKcWRc2uU4g3Kid-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 27 Aug 2026 09:51:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/XTkDYhRoKcWRc2uU4g3Kid-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Boston Scientific sign with the slogan &quot;Innovate for Life&quot; pictured at the 8th China International Import Expo.]]></media:description>                                                            <media:text><![CDATA[Boston Scientific sign with the slogan &quot;Innovate for Life&quot; pictured at the 8th China International Import Expo.]]></media:text>
                                <media:title type="plain"><![CDATA[Boston Scientific sign with the slogan &quot;Innovate for Life&quot; pictured at the 8th China International Import Expo.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/XTkDYhRoKcWRc2uU4g3Kid-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Medical technology firm Boston Scientific has been hit with a cyber attack that has severely disrupted global operations.</p><p>In a <a href="https://www.sec.gov/ix?doc=/Archives/edgar/data/885725/000088572526000056/bsx-20260826.htm" target="_blank"><u>filing </u></a>with the US <a href="https://www.itpro.com/security/sec-cyber-security-filings-on-the-rise-as-new-reporting-rules-bite">Securities and Exchange Commission (SEC)</a>, the MedTech company said the incident was first detected on 25 August. </p><p>The attack resulted in a network outage, meaning the company only has limited access to certain systems and applications. </p><p>Boston Scientific supplies a range of devices used in cardiac care, endoscopy, and urology and reported $5.4 billion in net sales during the second quarter of 2026. </p><p>According to the firm, as soon as it detected the breach it activated its incident response protocols and began an investigation to assess and contain the threat with the help of third-party <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>experts.</p><p>The company is in the process of restoring affected functions and reinstating access to systems, but that there's as yet no timeline for a full restoration.</p><p>“The incident has caused, and is expected to continue to cause, disruptions and limitations of access to certain of the Company’s information systems and business applications that support aspects of the Company’s operations, including the ability to process and ship customer orders,” the filing reads. </p><h2 id="who-s-behind-the-boston-scientific-cyber-attack">Who’s behind the Boston Scientific cyber attack?</h2><p>As of yet, there’s no information on the initial access method used by the hackers, nor the type of attack, who may have carried it out, or what data may have been accessed.</p><p>Ross Filipek, <a href="https://www.itpro.com/business/business-strategy/why-the-ciso-role-is-so-demanding-and-how-leaders-can-help">CISO </a>at Corsica Technologies, said at this stage the company will be prioritizing containment and establishing how the threat actor(s) gained access. </p><p>"<a href="https://www.itpro.com/business/business-strategy/lack-of-visibility-creates-cascade-of-security-risk-says-kiteworks">Security teams need constant visibility</a> into what was affected and which systems are safe to bring back online," Filipek commented.</p><p>"In healthcare, downtime carries operational consequences quickly. Strong incident response has to protect the environment while helping the business restore critical services as safely and efficiently as possible.”</p><h2 id="healthcare-in-the-crosshairs">Healthcare in the crosshairs</h2><p>The Boston Scientific breach marks the latest in a string of attacks on major medical device manufacturers, with Stryker, Medtronic, and Abbott all having disclosed cyber incidents in recent months. </p><p>In March, Stryker was <a href="https://www.itpro.com/technology/artificial-intelligence/its-destructive-not-ransomware-security-experts-weigh-in-on-motivation-behind-stryker-cyber-attack"><u>hit in an attack</u></a> claimed by Iranian-linked threat group <a href="https://www.itpro.com/security/cyber-attacks/stryker-hackers-struck-by-fbi-in-domain-seizure-campaign">Handala</a>, which claimed to have wiped thousands of systems across the company’s global operations and stolen around 50 terabytes of data.</p><p>A month later, the notorious <a href="https://www.itpro.com/security/data-breaches/european-commission-confirms-data-breach-as-shinyhunters-group-claims-responsibility">ShinyHunters </a>group claimed responsibility for an attack on the world’s largest medical device maker Medtronic. Just last month, cancer diagnostics device supplier Abbott said it had detected unauthorized access to some internal systems.</p><p>Dray Agha, senior manager of security operations at Huntress, said the data used by healthcare and medical technology providers makes them prime targets for cyber criminals. </p><p>“This is an unfortunate ripple effect on the healthcare supply chain. The attack on Boston Scientific demonstrates that cyber incidents in the MedTech sector extend far beyond IT and actively threaten the global healthcare supply chain," Agha said. </p><p>"When a major manufacturer is paralysed and unable to process or ship medical orders, the disruption creates immediate ripple effects that can ultimately delay critical treatments and impact patient care down the line."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US claims Chinese hackers breached Justice Department, Federal Reserve, NASA in lengthy threat campaign ]]></title>
                                                                                                <dc:content><![CDATA[ <p>US government officials have revealed that Chinese state-sponsored hackers breached a host of federal institutions as part of a recent espionage campaign. </p><p>In a <a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers" target="_blank"><u>statement</u></a>, the US Justice Department and FBI confirmed it has successfully seized domains used to support two hacking platforms known as ‘QScan’ and ‘QTRouter’. </p><p>These platforms were used by a state-sponsored group known as ‘QTFY’ to target critical infrastructure and “other sensitive networks”. </p><p>According to the FBI, the group successfully breached NASA, the Federal Reserve, Department of Energy, the US Senate, Department of Justice, and other agencies.</p><p>The scope and nature of the breaches has not been revealed. </p><p>“Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China,” said Attorney General Todd Blanche.</p><p>“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise.” </p><h2 id="state-backed-operators">State-backed operators</h2><p>The QTFY group provides hacker-for-hire services to paying customers, as well as the People’s Republic of China’s (PRC) Ministry of State Security and the People’s Liberation Army (PLA), according to court documents. </p><p>QScan and QTRouter are frequently-used platforms in QTFY operations, according to the Justice Department. The first of these is used to scan for and automatically infect vulnerable <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot">IoT </a>devices, which are then added to the broader QTRouter network of controlled devices. </p><p>“QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers,” the Justice Department noted. </p><p>QTRouter serves as an "obfuscation network" for the group, meaning that it enables QTFY and other "malicious cyber actors" to conceal their location and activities. </p><p>Officials noted that the seized domains were hard-coded into both QScan and QTRouter <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, which were then used in follow-up attacks against US government agencies. </p><h2 id="disrupting-cyber-threats">Disrupting cyber threats</h2><p>The takedown announced by the Justice Department marks the latest in a string of operations aimed at mitigating Chinese state-backed threats. </p><p>In 2025, for example, the FBI helped remove the PlugX surveillance malware from more than 4,000 computers across the US following a campaign conducted by the Mustang Panda group. </p><p>That operation came just months after a similar sting that crippled a botnet hosted by the Flax Typhoon hacker group. </p><p>“These tools were used by PRC cyber actors to hide the origin of their attacks,” said FBI Director Kash Patel. </p><p>“Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/us-claims-chinese-hackers-breached-justice-department-federal-reserve-nasa-in-lengthy-threat-campaign</link>
                                                                            <description>
                            <![CDATA[ The state-backed QTFY group has been identified as the culprit behind the campaign ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WTgb5mcEuGGKhaE8joQzch</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/B2K9HhHgVDEXtjMsMYMowg-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 15:30:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/B2K9HhHgVDEXtjMsMYMowg-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The flag of the People&#039;s Republic of China (PRC) and United States pictured side-by-side.]]></media:description>                                                            <media:text><![CDATA[The flag of the People&#039;s Republic of China (PRC) and United States pictured side-by-side.]]></media:text>
                                <media:title type="plain"><![CDATA[The flag of the People&#039;s Republic of China (PRC) and United States pictured side-by-side.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/B2K9HhHgVDEXtjMsMYMowg-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US government officials have revealed that Chinese state-sponsored hackers breached a host of federal institutions as part of a recent espionage campaign. </p><p>In a <a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers" target="_blank"><u>statement</u></a>, the US Justice Department and FBI confirmed it has successfully seized domains used to support two hacking platforms known as ‘QScan’ and ‘QTRouter’. </p><p>These platforms were used by a state-sponsored group known as ‘QTFY’ to target critical infrastructure and “other sensitive networks”. </p><p>According to the FBI, the group successfully breached NASA, the Federal Reserve, Department of Energy, the US Senate, Department of Justice, and other agencies.</p><p>The scope and nature of the breaches has not been revealed. </p><p>“Federal law enforcement investigated and disabled the PRC’s malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China,” said Attorney General Todd Blanche.</p><p>“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise.” </p><h2 id="state-backed-operators">State-backed operators</h2><p>The QTFY group provides hacker-for-hire services to paying customers, as well as the People’s Republic of China’s (PRC) Ministry of State Security and the People’s Liberation Army (PLA), according to court documents. </p><p>QScan and QTRouter are frequently-used platforms in QTFY operations, according to the Justice Department. The first of these is used to scan for and automatically infect vulnerable <a href="https://www.itpro.com/cloud-computing/28037/what-is-iot">IoT </a>devices, which are then added to the broader QTRouter network of controlled devices. </p><p>“QTRouter consists of these compromised IoT devices, as well as commercial proxy service devices and leased virtual private servers,” the Justice Department noted. </p><p>QTRouter serves as an "obfuscation network" for the group, meaning that it enables QTFY and other "malicious cyber actors" to conceal their location and activities. </p><p>Officials noted that the seized domains were hard-coded into both QScan and QTRouter <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, which were then used in follow-up attacks against US government agencies. </p><h2 id="disrupting-cyber-threats">Disrupting cyber threats</h2><p>The takedown announced by the Justice Department marks the latest in a string of operations aimed at mitigating Chinese state-backed threats. </p><p>In 2025, for example, the FBI helped remove the PlugX surveillance malware from more than 4,000 computers across the US following a campaign conducted by the Mustang Panda group. </p><p>That operation came just months after a similar sting that crippled a botnet hosted by the Flax Typhoon hacker group. </p><p>“These tools were used by PRC cyber actors to hide the origin of their attacks,” said FBI Director Kash Patel. </p><p>“Thanks to the work of FBI San Diego, FBI Cyber Division, and DOJ partners, we seized adversary infrastructure and shut these platforms down.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers have breached hundreds of Zimbra servers, despite a patch having been available for weeks ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hundreds of internet-facing Zimbra instances have been compromised through a vulnerability that was patched last month, researchers have warned. </p><p>The Zimbra Collaboration Suite (ZCS) hosts email, calendars, contacts, and administrative services. It has hundreds of millions of users, including thousands of businesses and hundreds of government agencies worldwide.</p><p>The security flaw, tracked as CVE-2026-73570 and rated high severity with a CVSS score of 8.9, allows unauthenticated attackers to execute malicious code remotely.</p><p>It works by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, and affects Zimbra Collaboration's Simple Network Management Protocol (SNMP). </p><p>This is a monitoring functionality in deployments where the optional zimbra-snmp package is installed and SNMP notifications are enabled.</p><p>"This vulnerability could allow an unauthenticated attacker to send specially crafted SMTP requests, potentially resulting in the execution of arbitrary operating system commands as the Zimbra user when the optional zimbra-snmp package is installed and SNMP notifications are enabled," <a href="https://www.hkcert.org/security-bulletin/zimbra-multiple-vulnerabilities_20260824" target="_blank"><u>warned </u></a>the Hong Hong Computer Emergency Response Team (HKCert) this week. </p><p>Hackers can then establish persistence, access email accounts, harvest credentials, and move laterally to other systems. Synacor, the company behind the collaboration suite, was first made aware of the issue in June, issued a temporary mitigation, and fixed it with the release of ZCS version 10.1.20 on July 20.</p><h2 id="agencies-issue-zimbra-flaw-warnings">Agencies issue Zimbra flaw warnings</h2><p>The US <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a> last week <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><u>added</u></a> the flaw to its Known Exploited Vulnerabilities (KEV) list and ordered US federal civilian agencies to address it within three days.  </p><p>However, it appears that the vulnerability is still being actively exploited.</p><p>Non-profit security organization Shadowserver said it has <a href="https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=possible-cve-2026-73570%2B&data_set=count&scale=log&auto_update=on" target="_blank"><u>spotted</u></a> at least 274 internet-exposed Zimbra instances that have been breached. </p><p>Meanwhile, at least 8,200 organizations worldwide are still using vulnerable versions, although this doesn't mean they're exploitable as the vulnerability may be in a non-default configuration.</p><p>Dray Agha, senior manager of Huntress’ EMEA security operations center, said the exploitation of the flaw highlights the importance of <a href="https://www.itpro.com/software/ios/apples-ios-update-cycle-overhaul-how-security-teams-should-react">rapid patching</a>. </p><p>"This widespread compromise of Zimbra servers is a textbook example of the enterprise patching gap. The patch for CVE-2026-73570 was released in July, yet weeks later, attackers are still easily finding hundreds of vulnerable instances to exploit," he said. </p><p>"When dealing with an unauthenticated, remote code execution flaw on an internet-facing email server, the window for remediation isn't measured in weeks or days, it’s honestly measured in hours. Organizations need to treat collaboration suites as highly critical perimeter infrastructure and patch them with zero delay."</p><p>It's not clear who is behind the attacks, but exploitation of Zimbra vulnerabilities has in the past been linked to Russian state-sponsored hackers, including APT28, APT29, and Winter Vivern. </p><p>These groups have targeted military and diplomatic intelligence, alongside opportunistic cybercriminals seeking financial gain. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/hackers-have-breached-hundreds-of-zimbra-servers-despite-a-patch-having-been-available-for-weeks</link>
                                                                            <description>
                            <![CDATA[ The flaw allows attackers to trigger cross-site scripting, sensitive information disclosure, security restriction bypass, and remote code execution ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sRkCh47T7zx7J2wdFNm3eH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/R9xjBCdRw6ruDKaYUtp4c4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 26 Aug 2026 10:53:53 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/R9xjBCdRw6ruDKaYUtp4c4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity alert concept image showing a red glowing warning symbol placed on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Cybersecurity alert concept image showing a red glowing warning symbol placed on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity alert concept image showing a red glowing warning symbol placed on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/R9xjBCdRw6ruDKaYUtp4c4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hundreds of internet-facing Zimbra instances have been compromised through a vulnerability that was patched last month, researchers have warned. </p><p>The Zimbra Collaboration Suite (ZCS) hosts email, calendars, contacts, and administrative services. It has hundreds of millions of users, including thousands of businesses and hundreds of government agencies worldwide.</p><p>The security flaw, tracked as CVE-2026-73570 and rated high severity with a CVSS score of 8.9, allows unauthenticated attackers to execute malicious code remotely.</p><p>It works by exploiting a command injection weakness in the SNMP monitoring component when SNMP notifications are enabled, and affects Zimbra Collaboration's Simple Network Management Protocol (SNMP). </p><p>This is a monitoring functionality in deployments where the optional zimbra-snmp package is installed and SNMP notifications are enabled.</p><p>"This vulnerability could allow an unauthenticated attacker to send specially crafted SMTP requests, potentially resulting in the execution of arbitrary operating system commands as the Zimbra user when the optional zimbra-snmp package is installed and SNMP notifications are enabled," <a href="https://www.hkcert.org/security-bulletin/zimbra-multiple-vulnerabilities_20260824" target="_blank"><u>warned </u></a>the Hong Hong Computer Emergency Response Team (HKCert) this week. </p><p>Hackers can then establish persistence, access email accounts, harvest credentials, and move laterally to other systems. Synacor, the company behind the collaboration suite, was first made aware of the issue in June, issued a temporary mitigation, and fixed it with the release of ZCS version 10.1.20 on July 20.</p><h2 id="agencies-issue-zimbra-flaw-warnings">Agencies issue Zimbra flaw warnings</h2><p>The US <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a> last week <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><u>added</u></a> the flaw to its Known Exploited Vulnerabilities (KEV) list and ordered US federal civilian agencies to address it within three days.  </p><p>However, it appears that the vulnerability is still being actively exploited.</p><p>Non-profit security organization Shadowserver said it has <a href="https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=possible-cve-2026-73570%2B&data_set=count&scale=log&auto_update=on" target="_blank"><u>spotted</u></a> at least 274 internet-exposed Zimbra instances that have been breached. </p><p>Meanwhile, at least 8,200 organizations worldwide are still using vulnerable versions, although this doesn't mean they're exploitable as the vulnerability may be in a non-default configuration.</p><p>Dray Agha, senior manager of Huntress’ EMEA security operations center, said the exploitation of the flaw highlights the importance of <a href="https://www.itpro.com/software/ios/apples-ios-update-cycle-overhaul-how-security-teams-should-react">rapid patching</a>. </p><p>"This widespread compromise of Zimbra servers is a textbook example of the enterprise patching gap. The patch for CVE-2026-73570 was released in July, yet weeks later, attackers are still easily finding hundreds of vulnerable instances to exploit," he said. </p><p>"When dealing with an unauthenticated, remote code execution flaw on an internet-facing email server, the window for remediation isn't measured in weeks or days, it’s honestly measured in hours. Organizations need to treat collaboration suites as highly critical perimeter infrastructure and patch them with zero delay."</p><p>It's not clear who is behind the attacks, but exploitation of Zimbra vulnerabilities has in the past been linked to Russian state-sponsored hackers, including APT28, APT29, and Winter Vivern. </p><p>These groups have targeted military and diplomatic intelligence, alongside opportunistic cybercriminals seeking financial gain. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zero-click email attacks: What businesses need to know ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Zero-click attacks bring to mind the advanced spyware typically targeted at a specific subset of users. Infamous examples, such as the <a href="https://www.amnesty.org/en/latest/news/2021/07/the-pegasus-project-2/"><u>Pegasus spyware</u></a> that targeted the family of murdered Saudi dissident <a href="https://www.bbc.co.uk/news/world-europe-45812399" target="_blank"><u>Jamal Khashoggi</u></a>, saw a user compromised simply by receiving a WhatsApp or iMessage. </p><p>But now, email is being used in a zero-click phishing campaign waged by <a href="https://www.itpro.com/security/cyber-attacks/russian-ddos-whats-the-threat-to-businesses"><u>Russian state-backed hackers,</u></a> according to the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>, which has issued an <a href="https://www.itpro.com/security/phishing/ncsc-issues-alert-over-zero-click-phishing-campaign-hitting-enterprises"><u>alert</u></a>.</p><p>Targeting a vulnerability in the Zimbra Collaboration Suite (ZCS) software, the so-called <a href="https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign"><u>‘beehive’ attacks</u></a> by Russian group Laundry Bear aim to steal email correspondence from organizations operating in critical sectors, according to the <a href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/0/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF"><u>joint advisory</u></a>. </p><p>Similar to the zero-click campaigns involving text messages, users only have to view a malicious email to be compromised.</p><h2 id="zero-click-attack-evolution">Zero-click attack evolution</h2><p>Zero-click used to mean “expensive, highly-targeted <a href="https://www.itpro.com/software/ios/apples-ios-update-cycle-overhaul-how-security-teams-should-react"><u>mobile exploits</u></a>” used by nation-states for “silently dropping spyware” via WhatsApp or iMessage, says Matt Cooke, cybersecurity strategist at Proofpoint. </p><p>In the latest attacks, Laundry Bear – also known as <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a"><u>TA488</u></a> and Void Blizzard – “has taken that mechanic out of the intelligence-gathering niche” and “turned it into a mass espionage tool aimed at the corporate inbox”, says Cooke. </p><p>His company has published a <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits"><u>detailed breakdown</u></a> of the new campaign. </p><p>Zero-click attacks such as these are concerning because they remove “the one thing firms have spent years training people not to do: Click the link”, says Rich Greene, certified instructor at SANS.</p><p>This type of activity is an evolution of attacks carried out via platforms such as WhatsApp and iMessage in highly targeted spyware campaigns, according to Greene. </p><p>“Moving those same ideas into email makes complete sense from an attacker’s perspective,” he said. Email is everywhere, businesses depend on it, and messages are constantly being processed in the background before the user ever decides whether to interact with them.”</p><h2 id="how-the-email-attacks-work">How the email attacks work </h2><p>In the Laundry Bear campaign, which likely used <a href="https://www.itpro.com/technology/neural-network/after-openai-hugging-face-how-do-it-leaders-need-to-change-the-way-they-think-about-ai"><u>AI</u></a>, viewing a crafted message in a vulnerable version of Zimbra webmail was enough to trigger the exploit. This would provide adversaries access while leaving the victim “with little reason to suspect anything had actually happened”, explains Alexander Leslie, a senior advisor at Recorded Future. </p><p>Analysis of the latest campaign found the techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations.</p><p>The attackers initially exploited a flaw tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376"><u>CVE-2025-66376</u></a> in Zimbra Collaboration Suite, but they later took advantage of a second vulnerability in <a href="https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit"><u>Outlook Web Access</u></a>, according to Cooke. “The group has shown it will scale a working technique, rather than retire it after one campaign,” he says.</p><p>The flaw is architectural, explains Cooke. “Email clients render HTML as browsers do. TA488 doesn't need a phishing hook; it hides malicious script fragments inside standard mail formatting.”</p><p>However, while mobile zero-click attacks often don’t require any interaction at all, the campaign does require users to open an email. Therefore, this would properly be described as a “half-click” exploit by researchers, says Cooke.  </p><h2 id="who-is-a-target">Who is a target?</h2><p>The Zimbra campaign ran for at least five months against Ukrainian government entities and US defence, nuclear and research targets. During this time, adversaries exfiltrated information including 90 days of email, session tokens and saved credentials.</p><p>It’s notable how quickly TA488 moved on, says Cooke. “The day after an advisory on that campaign went public, researchers caught the same group already running the second exploit chain against Outlook Web Access, hitting government, telecoms, finance, hospitality and aerospace targets.”</p><p>The Outlook payload is “a step up in sophistication”, according to Cooke. </p><p>“It steals OAuth tokens through compromised mailbox add-ins and grants itself server-side folder permissions via a low-privilege default account. That access survives password resets and even a full device re-image, because it doesn't live on the endpoint at all.”</p><p>Going forward, the sectors most at risk are those that could be targeted by Russian intelligence. This includes defence, government, energy, law enforcement and media, says Leslie. Any organization holding politically, militarily, or commercially sensitive correspondence could be of interest, he adds. </p><h2 id="tackling-zero-click-email-attacks">Tackling zero-click email attacks</h2><p>As zero-click attacks move from messaging to email, telling users not to click on links is no longer a valid response. Yet there’s no need to panic. The latest attacks are still very targeted and require unpatched flaws to compromise firms. </p><p>If you are in an at-risk sector, or if you use ZCS, there are a few steps you can take to reduce the risk. Greene believes organizations need to focus on the basics and “execute them well”.</p><p>The NCSC has advised ZCS users to patch immediately, as well as follow mitigation advice, <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business"><u>use a third-party authentication service that supports passkeys</u></a> where possible, and boost network monitoring capabilities. </p><p>“Patch quickly, keep email clients and operating systems up to date, reduce unnecessary message preview or content-processing features, monitor endpoints and accounts for unusual behaviour, and use layered email, identity and endpoint security controls,” adds Greene. </p><p>Defence in depth is becoming increasingly important, with many organizations using Microsoft Defender Suite for endpoint, email, application and identity protection, says Peter Jones, cyber security specialist at Conscia UK.</p><p>However, he believes it’s worth complementing these controls with behavior detection across the network and within the data center, using tools such as Cisco’s Secure Network Analytics or Secure Workload capabilities.</p><p> “When implemented correctly, Microsoft and Cisco Security tools can work well to provide the visibility to respond effectively in the event of a breach.”</p><p>As zero-click attacks continue to evolve, Cooke thinks the response must be “architectural”. He advises firms to patch webmail and Exchange promptly, but to also “assume patching will always trail behind zero-days”. </p><p>With this in mind, treat sessions and tokens as “short-lived by design”, he advises. “Shorten token lifetimes, and build identity monitoring that flags anomalous token behavior.”</p><p>Overall, he believes firms should plan for containment speed over prevention. “As TA488's Outlook campaign shows, once persistence is server-side, revoking a password isn't enough. Isolating and revoking the session, and auditing folder permissions and add-in access, is what actually closes the door.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/phishing/zero-click-email-attacks-what-businesses-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Russian state-backed attackers are using email to carry out zero-click phishing campaigns. Here’s the need-to-know information ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BmMHY9RbzeSYvomJphTmH6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 14:34:39 +0000</pubDate>                                                                                                                                <updated>Tue, 25 Aug 2026 19:25:58 +0000</updated>
                                                                                                                                            <category><![CDATA[Phishing]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:description>                                                            <media:text><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing attack concept image showing an email symbol with red alert symbol on top of a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/FEpm7PoPiWegwbyvEVshN7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Zero-click attacks bring to mind the advanced spyware typically targeted at a specific subset of users. Infamous examples, such as the <a href="https://www.amnesty.org/en/latest/news/2021/07/the-pegasus-project-2/"><u>Pegasus spyware</u></a> that targeted the family of murdered Saudi dissident <a href="https://www.bbc.co.uk/news/world-europe-45812399" target="_blank"><u>Jamal Khashoggi</u></a>, saw a user compromised simply by receiving a WhatsApp or iMessage. </p><p>But now, email is being used in a zero-click phishing campaign waged by <a href="https://www.itpro.com/security/cyber-attacks/russian-ddos-whats-the-threat-to-businesses"><u>Russian state-backed hackers,</u></a> according to the UK’s <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>, which has issued an <a href="https://www.itpro.com/security/phishing/ncsc-issues-alert-over-zero-click-phishing-campaign-hitting-enterprises"><u>alert</u></a>.</p><p>Targeting a vulnerability in the Zimbra Collaboration Suite (ZCS) software, the so-called <a href="https://www.ncsc.gov.uk/news/uk-and-partners-expose-russian-state-supported-actors-for-new-zero-click-phishing-campaign"><u>‘beehive’ attacks</u></a> by Russian group Laundry Bear aim to steal email correspondence from organizations operating in critical sectors, according to the <a href="https://media.defense.gov/2026/Jul/22/2003965244/-1/-1/0/CSA_RUSSIA_PHISHING_TARGET_ZIMBRA.PDF"><u>joint advisory</u></a>. </p><p>Similar to the zero-click campaigns involving text messages, users only have to view a malicious email to be compromised.</p><h2 id="zero-click-attack-evolution">Zero-click attack evolution</h2><p>Zero-click used to mean “expensive, highly-targeted <a href="https://www.itpro.com/software/ios/apples-ios-update-cycle-overhaul-how-security-teams-should-react"><u>mobile exploits</u></a>” used by nation-states for “silently dropping spyware” via WhatsApp or iMessage, says Matt Cooke, cybersecurity strategist at Proofpoint. </p><p>In the latest attacks, Laundry Bear – also known as <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-204a"><u>TA488</u></a> and Void Blizzard – “has taken that mechanic out of the intelligence-gathering niche” and “turned it into a mass espionage tool aimed at the corporate inbox”, says Cooke. </p><p>His company has published a <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits"><u>detailed breakdown</u></a> of the new campaign. </p><p>Zero-click attacks such as these are concerning because they remove “the one thing firms have spent years training people not to do: Click the link”, says Rich Greene, certified instructor at SANS.</p><p>This type of activity is an evolution of attacks carried out via platforms such as WhatsApp and iMessage in highly targeted spyware campaigns, according to Greene. </p><p>“Moving those same ideas into email makes complete sense from an attacker’s perspective,” he said. Email is everywhere, businesses depend on it, and messages are constantly being processed in the background before the user ever decides whether to interact with them.”</p><h2 id="how-the-email-attacks-work">How the email attacks work </h2><p>In the Laundry Bear campaign, which likely used <a href="https://www.itpro.com/technology/neural-network/after-openai-hugging-face-how-do-it-leaders-need-to-change-the-way-they-think-about-ai"><u>AI</u></a>, viewing a crafted message in a vulnerable version of Zimbra webmail was enough to trigger the exploit. This would provide adversaries access while leaving the victim “with little reason to suspect anything had actually happened”, explains Alexander Leslie, a senior advisor at Recorded Future. </p><p>Analysis of the latest campaign found the techniques could be adapted to exploit vulnerabilities in other email software applications used by Western organizations.</p><p>The attackers initially exploited a flaw tracked as <a href="https://www.cve.org/CVERecord?id=CVE-2025-66376"><u>CVE-2025-66376</u></a> in Zimbra Collaboration Suite, but they later took advantage of a second vulnerability in <a href="https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit"><u>Outlook Web Access</u></a>, according to Cooke. “The group has shown it will scale a working technique, rather than retire it after one campaign,” he says.</p><p>The flaw is architectural, explains Cooke. “Email clients render HTML as browsers do. TA488 doesn't need a phishing hook; it hides malicious script fragments inside standard mail formatting.”</p><p>However, while mobile zero-click attacks often don’t require any interaction at all, the campaign does require users to open an email. Therefore, this would properly be described as a “half-click” exploit by researchers, says Cooke.  </p><h2 id="who-is-a-target">Who is a target?</h2><p>The Zimbra campaign ran for at least five months against Ukrainian government entities and US defence, nuclear and research targets. During this time, adversaries exfiltrated information including 90 days of email, session tokens and saved credentials.</p><p>It’s notable how quickly TA488 moved on, says Cooke. “The day after an advisory on that campaign went public, researchers caught the same group already running the second exploit chain against Outlook Web Access, hitting government, telecoms, finance, hospitality and aerospace targets.”</p><p>The Outlook payload is “a step up in sophistication”, according to Cooke. </p><p>“It steals OAuth tokens through compromised mailbox add-ins and grants itself server-side folder permissions via a low-privilege default account. That access survives password resets and even a full device re-image, because it doesn't live on the endpoint at all.”</p><p>Going forward, the sectors most at risk are those that could be targeted by Russian intelligence. This includes defence, government, energy, law enforcement and media, says Leslie. Any organization holding politically, militarily, or commercially sensitive correspondence could be of interest, he adds. </p><h2 id="tackling-zero-click-email-attacks">Tackling zero-click email attacks</h2><p>As zero-click attacks move from messaging to email, telling users not to click on links is no longer a valid response. Yet there’s no need to panic. The latest attacks are still very targeted and require unpatched flaws to compromise firms. </p><p>If you are in an at-risk sector, or if you use ZCS, there are a few steps you can take to reduce the risk. Greene believes organizations need to focus on the basics and “execute them well”.</p><p>The NCSC has advised ZCS users to patch immediately, as well as follow mitigation advice, <a href="https://www.itpro.com/security/what-do-passkeys-mean-for-your-business"><u>use a third-party authentication service that supports passkeys</u></a> where possible, and boost network monitoring capabilities. </p><p>“Patch quickly, keep email clients and operating systems up to date, reduce unnecessary message preview or content-processing features, monitor endpoints and accounts for unusual behaviour, and use layered email, identity and endpoint security controls,” adds Greene. </p><p>Defence in depth is becoming increasingly important, with many organizations using Microsoft Defender Suite for endpoint, email, application and identity protection, says Peter Jones, cyber security specialist at Conscia UK.</p><p>However, he believes it’s worth complementing these controls with behavior detection across the network and within the data center, using tools such as Cisco’s Secure Network Analytics or Secure Workload capabilities.</p><p> “When implemented correctly, Microsoft and Cisco Security tools can work well to provide the visibility to respond effectively in the event of a breach.”</p><p>As zero-click attacks continue to evolve, Cooke thinks the response must be “architectural”. He advises firms to patch webmail and Exchange promptly, but to also “assume patching will always trail behind zero-days”. </p><p>With this in mind, treat sessions and tokens as “short-lived by design”, he advises. “Shorten token lifetimes, and build identity monitoring that flags anomalous token behavior.”</p><p>Overall, he believes firms should plan for containment speed over prevention. “As TA488's Outlook campaign shows, once persistence is server-side, revoking a password isn't enough. Isolating and revoking the session, and auditing folder permissions and add-in access, is what actually closes the door.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US lawmakers say CISA cuts raise ‘serious concerns about the agency's ability to fulfil its mission’ ]]></title>
                                                                                                <dc:content><![CDATA[ <p>US lawmakers are pushing back against the Trump administration's decision to reduce headcount at the <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a>.</p><p>Five Democrats have <a href="https://walkinshaw.house.gov/uploadedfiles/2026.08.20_final_letter_to_gao_re_cisa_cuts.pdf" target="_blank"><u>written</u></a> to the Government Accountability Office (GAO), calling on it to look into the effects of the cuts on the agency's ability to protect critical infrastructure and respond to evolving cyber threats.</p><p>The group has requested an investigation into how CISA’s workforce has changed over the past five years, including its size, composition, geographic distribution and number of contractors. </p><p>They also want the GAO to identify which programs have been affected by the cuts, what the effects have been, what data CISA collects and analyzes for workforce planning and whether it uses that data to align resources with agency priorities.</p><p>"At precisely the moment when our adversaries are accelerating <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat">attacks against critical infrastructure</a>, the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA), the nation's lead civilian cyber defense agency, has lost nearly one-third of its workforce, raising serious concerns about the agency's ability to fulfil its mission," they wrote.</p><p>"Little is known about the impact of these workforce reductions on CISA’s programs and services or what processes and plans the agency has in place to ensure the agency is hiring the right people to address lost skill sets and meet mission demands."</p><h2 id="cisa-cuts-run-deep">CISA cuts run deep</h2><p>The latest changes were announced in June as part of the 2027 budget proposal. CISA is set for a cut in funding of around $700 million - with the White House claiming that it's been functioning “as a hub in the Censorship Industrial Complex, conspiring against the First Amendment rights”.</p><p>The cuts would refocus CISA on its core mission – Federal network defense and coordinating with critical infrastructure partners – while eliminating waste by consolidating redundant security advisors and programs. Around 900 jobs are expected to go.</p><p>CISA lost nearly 1,000 employees, or about a third of its workforce, in the first half of 2025 - although the agency has since made moves to try and boost staffing again. </p><p>It's also seen cutbacks to its work on election security. And all this has come as its work has expanded more than ever, thanks to an accelerating threat environment.</p><p>Gene Moody, field CTO at Action1, said the cuts show a lack of awareness over the critical work conducted by the agency. </p><p>"In many respects, vulnerability analysis is further behind the curve than it has ever been. And it is being attacked by its own governing bodies out of ignorance and misunderstanding. This is an existential threat to cybersecurity," Moody commented. </p><p>"When analysts and programs are overloaded, the ecosystem gets noisier: important vulnerabilities compete with an enormous amount of lower-value information, prioritization becomes harder, and defenders have less confidence about what actually deserves immediate attention."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/us-lawmakers-say-cisa-cuts-raise-serious-concerns-about-the-agencys-ability-to-fulfil-its-mission</link>
                                                                            <description>
                            <![CDATA[ With hundreds more jobs set to go, concerns are rising about whether the agency can continue its critical work defending organizations ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NjytsAjXnN7uybfGo5Umz9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dFiSMke7iCE59e29NuVMg8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 25 Aug 2026 09:49:02 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dFiSMke7iCE59e29NuVMg8-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Insignia of the Cybersecurity and Infrastructure Security Agency (CISA) pictured on a smartphone screen.]]></media:description>                                                            <media:text><![CDATA[Insignia of the Cybersecurity and Infrastructure Security Agency (CISA) pictured on a smartphone screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Insignia of the Cybersecurity and Infrastructure Security Agency (CISA) pictured on a smartphone screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dFiSMke7iCE59e29NuVMg8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>US lawmakers are pushing back against the Trump administration's decision to reduce headcount at the <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a>.</p><p>Five Democrats have <a href="https://walkinshaw.house.gov/uploadedfiles/2026.08.20_final_letter_to_gao_re_cisa_cuts.pdf" target="_blank"><u>written</u></a> to the Government Accountability Office (GAO), calling on it to look into the effects of the cuts on the agency's ability to protect critical infrastructure and respond to evolving cyber threats.</p><p>The group has requested an investigation into how CISA’s workforce has changed over the past five years, including its size, composition, geographic distribution and number of contractors. </p><p>They also want the GAO to identify which programs have been affected by the cuts, what the effects have been, what data CISA collects and analyzes for workforce planning and whether it uses that data to align resources with agency priorities.</p><p>"At precisely the moment when our adversaries are accelerating <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat">attacks against critical infrastructure</a>, the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA), the nation's lead civilian cyber defense agency, has lost nearly one-third of its workforce, raising serious concerns about the agency's ability to fulfil its mission," they wrote.</p><p>"Little is known about the impact of these workforce reductions on CISA’s programs and services or what processes and plans the agency has in place to ensure the agency is hiring the right people to address lost skill sets and meet mission demands."</p><h2 id="cisa-cuts-run-deep">CISA cuts run deep</h2><p>The latest changes were announced in June as part of the 2027 budget proposal. CISA is set for a cut in funding of around $700 million - with the White House claiming that it's been functioning “as a hub in the Censorship Industrial Complex, conspiring against the First Amendment rights”.</p><p>The cuts would refocus CISA on its core mission – Federal network defense and coordinating with critical infrastructure partners – while eliminating waste by consolidating redundant security advisors and programs. Around 900 jobs are expected to go.</p><p>CISA lost nearly 1,000 employees, or about a third of its workforce, in the first half of 2025 - although the agency has since made moves to try and boost staffing again. </p><p>It's also seen cutbacks to its work on election security. And all this has come as its work has expanded more than ever, thanks to an accelerating threat environment.</p><p>Gene Moody, field CTO at Action1, said the cuts show a lack of awareness over the critical work conducted by the agency. </p><p>"In many respects, vulnerability analysis is further behind the curve than it has ever been. And it is being attacked by its own governing bodies out of ignorance and misunderstanding. This is an existential threat to cybersecurity," Moody commented. </p><p>"When analysts and programs are overloaded, the ecosystem gets noisier: important vulnerabilities compete with an enormous amount of lower-value information, prioritization becomes harder, and defenders have less confidence about what actually deserves immediate attention."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Researchers warn thousands of active AWS access keys are publicly exposed ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Tens of thousands of previously-exposed AWS access keys are still active and valid, researchers have warned, with hundreds holding full admin rights.</p><p>Truffle Security <a href="https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights" target="_blank"><u>said</u></a> its scanners verified 64,024 unique AWS key pairs across 431,875 public findings that surfaced publicly between August 2022 and August this year.</p><p>This includes git history, <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime">Hugging Face</a> datasets, Docker images, package registries, and CI logs, the company said. </p><p>It then re-verified the 10,616 leaked keys with complete credentials and found that 88% still authenticate, including 526 root keys and 242 <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">identity and access management (IAM)</a> users holding AdministratorAccess - which have full admin rights.</p><p>"The largest single source is Hugging Face. AWS credentials are the second most common secret type we verify there, with 8,482 unique live keys across 3,394 public datasets," said the firm. </p><p>"Hugging Face keys also skew privileged: 17.9% are root, the highest share of any source we track. Most of those datasets are snapshots of public code repackaged for training."</p><p>Of the live keys with creation dates, the median age was 1,831 days. Half are over five years old. The oldest was 17.4 years, nearly as old as IAM itself.</p><p>"Only 25 keys (0.9%) were created in the last 30 days. Almost none of this population leaked recently. The count has been building for years," Truffle Security said.</p><p>"Rotation is the rarer event. Of the keys where we could enumerate the user's access keys, only 13.7% (398 of 2,903) have any newer key alongside the leaked one. The other 86% were never rotated, superseded, or cleaned up."</p><p>Of the 7,590 active IAM users, 929 carry AWS's own AWSCompromisedKeyQuarantine policy, and were detected by AWS as exposed and restricted. Of these, 112 carry the original version, which AWS stopped applying in 2023. </p><p>Researchers noted that they were flagged at least three years ago and their owners notified by AWS. However, no action was apparently taken and the keys still authenticate.</p><h2 id="tighter-access-controls">Tighter access controls</h2><p>Truffle Security said organizations delete root access keys. One-in-six leaked keys is root, for example, and as such there is no longer any legitimate reason for a root access key to exist in 2026.</p><p>They should also sort their IAM keys by age and set a budget alarm, even a small one, to catch cryptomining early - 90.5% of leaked-key accounts have none. </p><p>Elsewhere, researchers said security teams should assume that committed means leaked. Nearly half (43%) of keys were sighted more than once across repos, datasets, and images. Deleting the file does not help once it is in a training corpus.</p><p>"Any time AWS is aware of exposed keys, we notify the affected customers. We also thoroughly investigate all reports of exposed keys and quickly take any necessary actions, such as applying quarantine policies to minimize risks for customers without disrupting their IT environment," an AWS spokesperson told <em>ITPro</em>. </p><p>"As always, customers can contact AWS Support with any questions or concerns about the security of their account."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/researchers-warn-thousands-of-active-aws-access-keys-are-publicly-exposed</link>
                                                                            <description>
                            <![CDATA[ In hundreds of cases, the keys could give attackers complete administrative control ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4kPptzQTbXTwcCpoauExJE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/i2VUb2oLPjFFkMn6CA4Huj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 11:16:36 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/i2VUb2oLPjFFkMn6CA4Huj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Amazon Web Services (AWS) logo and branding pictured at the Hannover Messe industrial trade fair for mechanical and electrical engineering and digital industries.]]></media:description>                                                            <media:text><![CDATA[Amazon Web Services (AWS) logo and branding pictured at the Hannover Messe industrial trade fair for mechanical and electrical engineering and digital industries.]]></media:text>
                                <media:title type="plain"><![CDATA[Amazon Web Services (AWS) logo and branding pictured at the Hannover Messe industrial trade fair for mechanical and electrical engineering and digital industries.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/i2VUb2oLPjFFkMn6CA4Huj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Tens of thousands of previously-exposed AWS access keys are still active and valid, researchers have warned, with hundreds holding full admin rights.</p><p>Truffle Security <a href="https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights" target="_blank"><u>said</u></a> its scanners verified 64,024 unique AWS key pairs across 431,875 public findings that surfaced publicly between August 2022 and August this year.</p><p>This includes git history, <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime">Hugging Face</a> datasets, Docker images, package registries, and CI logs, the company said. </p><p>It then re-verified the 10,616 leaked keys with complete credentials and found that 88% still authenticate, including 526 root keys and 242 <a href="https://www.itpro.com/security/how-to-implement-identity-and-access-management-iam-effectively-in-your-business">identity and access management (IAM)</a> users holding AdministratorAccess - which have full admin rights.</p><p>"The largest single source is Hugging Face. AWS credentials are the second most common secret type we verify there, with 8,482 unique live keys across 3,394 public datasets," said the firm. </p><p>"Hugging Face keys also skew privileged: 17.9% are root, the highest share of any source we track. Most of those datasets are snapshots of public code repackaged for training."</p><p>Of the live keys with creation dates, the median age was 1,831 days. Half are over five years old. The oldest was 17.4 years, nearly as old as IAM itself.</p><p>"Only 25 keys (0.9%) were created in the last 30 days. Almost none of this population leaked recently. The count has been building for years," Truffle Security said.</p><p>"Rotation is the rarer event. Of the keys where we could enumerate the user's access keys, only 13.7% (398 of 2,903) have any newer key alongside the leaked one. The other 86% were never rotated, superseded, or cleaned up."</p><p>Of the 7,590 active IAM users, 929 carry AWS's own AWSCompromisedKeyQuarantine policy, and were detected by AWS as exposed and restricted. Of these, 112 carry the original version, which AWS stopped applying in 2023. </p><p>Researchers noted that they were flagged at least three years ago and their owners notified by AWS. However, no action was apparently taken and the keys still authenticate.</p><h2 id="tighter-access-controls">Tighter access controls</h2><p>Truffle Security said organizations delete root access keys. One-in-six leaked keys is root, for example, and as such there is no longer any legitimate reason for a root access key to exist in 2026.</p><p>They should also sort their IAM keys by age and set a budget alarm, even a small one, to catch cryptomining early - 90.5% of leaked-key accounts have none. </p><p>Elsewhere, researchers said security teams should assume that committed means leaked. Nearly half (43%) of keys were sighted more than once across repos, datasets, and images. Deleting the file does not help once it is in a training corpus.</p><p>"Any time AWS is aware of exposed keys, we notify the affected customers. We also thoroughly investigate all reports of exposed keys and quickly take any necessary actions, such as applying quarantine policies to minimize risks for customers without disrupting their IT environment," an AWS spokesperson told <em>ITPro</em>. </p><p>"As always, customers can contact AWS Support with any questions or concerns about the security of their account."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iranian cyber attack on UK power plant ‘should concern every organization responsible for keeping this country running’ ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A small UK power plant was reportedly shut down for four days last month following a cyber attack attributed to Iranian hackers.</p><p>The incident appears to have affected a small-scale gas generator, rather than a large power station, and did not affect the wider grid. </p><p>According to the <a href="https://www.telegraph.co.uk/news/2026/08/22/iranian-hackers-shut-down-uk-power-plant/" target="_blank"><u><em>Daily Telegraph</em></u></a><em>,</em> the government has contacted the chief executives of power companies following the incident and has written to businesses with advice on the steps they should take to protect themselves.</p><p>The attack has been attributed to hackers affiliated to the Iranian government, and is believed to be the first of its kind in the UK.</p><p>Graeme Stewart, head of public sector at Check Point, said the incident highlights the potential risks posed by threats to critical infrastructure. </p><p>“This marks a grave escalation in the <a href="https://www.itpro.com/technology/artificial-intelligence/its-destructive-not-ransomware-security-experts-weigh-in-on-motivation-behind-stryker-cyber-attack">Iran conflict</a> because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days,” he said. </p><p>“That should concern every organization responsible for keeping this country running. For most Brits, the Iran conflict is happening thousands of miles away and cyber warfare probably still conjures up images of stolen passwords, leaked data and companies being held to ransom,” Stewart added. </p><p>“The prospect of a hostile state being able to reach into the infrastructure beneath our everyday lives changes that dramatically."</p><h2 id="rising-state-sponsored-threats">Rising state-sponsored threats</h2><p>Notably, the incident coincided with a <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn"><u>series of attacks on US water supply infrastructure</u></a> in recent weeks. More than a dozen states were affected in the campaign, which is believed to be linked to Iranian-backed threat groups. </p><p>The attacks <a href="https://www.itpro.com/security/an-evolution-in-threat-actor-capabilities-cisa-warns-hackers-are-targeting-siemens-industrial-controllers-and-theyre-using-ai-generated-code"><u>targeted internet-exposed programmable logic controllers (PLCs),</u></a> with the attackers remotely changing IP addresses and turning on and setting passwords. </p><p>Several water firms were left unable to view connected equipment, and in some cases it was shut down. </p><p>The FBI has <a href="https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions" target="_blank"><u>recommended</u></a> disconnecting PLCs from the public-facing internet, strictly controlling access to them, tightening up passwords, and reviewing project files running on PLCs for unauthorized changes.</p><h2 id="uk-infrastructure-in-the-crosshairs">UK infrastructure in the crosshairs</h2><p>According to the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>, the UK is experiencing increased threats from Iranian-backed cyber groups. </p><p>Earlier this year, the agency <a href="https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-middle-east"><u>issued a warning</u></a> over heightened risk of indirect threats for organizations with a presence, or supply chains, in the Middle East. </p><p>Stewart suggested that the impact of an attack on larger power supply operators or other critical infrastructure firms could be disastrous. </p><p>"We have to ask what happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on. Britain’s critical national infrastructure underpins almost every part of modern life, including electricity, water, transport and communications, and those systems are increasingly digital, interconnected and dependent on one another," he said. </p><p>"The question now has to be whether Britain is genuinely ready if something more serious follows.”</p><p>A spokesperson for the UK government told ITPro that it's working on an Energy Resilience Strategy. Set for publication later this year, this will outline plans for ensuring the energy system remains stable and secure. </p><p>"The UK has a highly resilience energy system. We work closely with the energy sector to protect infrastructure and ensure the highest standards of security," the spokesperson added.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/iranian-cyber-attack-on-uk-power-plant-should-concern-every-organization-responsible-for-keeping-this-country-running</link>
                                                                            <description>
                            <![CDATA[ The attack is believed to be the first of its kind in the UK ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a3KtrhTkLYTLzbspGv6TUX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9Aj26fi5g7AJFcmpsnt24C-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 09:58:17 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Aug 2026 10:00:36 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9Aj26fi5g7AJFcmpsnt24C-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Map of the United Kingdom and Northern Ireland on a digital interface.]]></media:description>                                                            <media:text><![CDATA[Map of the United Kingdom and Northern Ireland on a digital interface.]]></media:text>
                                <media:title type="plain"><![CDATA[Map of the United Kingdom and Northern Ireland on a digital interface.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9Aj26fi5g7AJFcmpsnt24C-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A small UK power plant was reportedly shut down for four days last month following a cyber attack attributed to Iranian hackers.</p><p>The incident appears to have affected a small-scale gas generator, rather than a large power station, and did not affect the wider grid. </p><p>According to the <a href="https://www.telegraph.co.uk/news/2026/08/22/iranian-hackers-shut-down-uk-power-plant/" target="_blank"><u><em>Daily Telegraph</em></u></a><em>,</em> the government has contacted the chief executives of power companies following the incident and has written to businesses with advice on the steps they should take to protect themselves.</p><p>The attack has been attributed to hackers affiliated to the Iranian government, and is believed to be the first of its kind in the UK.</p><p>Graeme Stewart, head of public sector at Check Point, said the incident highlights the potential risks posed by threats to critical infrastructure. </p><p>“This marks a grave escalation in the <a href="https://www.itpro.com/technology/artificial-intelligence/its-destructive-not-ransomware-security-experts-weigh-in-on-motivation-behind-stryker-cyber-attack">Iran conflict</a> because a hostile state-linked cyber threat has reportedly reached into UK energy infrastructure and caused a physical shutdown lasting four days,” he said. </p><p>“That should concern every organization responsible for keeping this country running. For most Brits, the Iran conflict is happening thousands of miles away and cyber warfare probably still conjures up images of stolen passwords, leaked data and companies being held to ransom,” Stewart added. </p><p>“The prospect of a hostile state being able to reach into the infrastructure beneath our everyday lives changes that dramatically."</p><h2 id="rising-state-sponsored-threats">Rising state-sponsored threats</h2><p>Notably, the incident coincided with a <a href="https://www.itpro.com/security/cyber-attacks/attacks-on-us-water-systems-could-be-the-tip-of-the-iceberg-cyber-experts-warn"><u>series of attacks on US water supply infrastructure</u></a> in recent weeks. More than a dozen states were affected in the campaign, which is believed to be linked to Iranian-backed threat groups. </p><p>The attacks <a href="https://www.itpro.com/security/an-evolution-in-threat-actor-capabilities-cisa-warns-hackers-are-targeting-siemens-industrial-controllers-and-theyre-using-ai-generated-code"><u>targeted internet-exposed programmable logic controllers (PLCs),</u></a> with the attackers remotely changing IP addresses and turning on and setting passwords. </p><p>Several water firms were left unable to view connected equipment, and in some cases it was shut down. </p><p>The FBI has <a href="https://www.fbi.gov/investigate/cyber/alerts/2026/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions" target="_blank"><u>recommended</u></a> disconnecting PLCs from the public-facing internet, strictly controlling access to them, tightening up passwords, and reviewing project files running on PLCs for unauthorized changes.</p><h2 id="uk-infrastructure-in-the-crosshairs">UK infrastructure in the crosshairs</h2><p>According to the <a href="https://www.itpro.com/security/what-is-the-national-cyber-security-centre-ncsc-and-what-does-it-do"><u>National Cyber Security Centre (NCSC)</u></a>, the UK is experiencing increased threats from Iranian-backed cyber groups. </p><p>Earlier this year, the agency <a href="https://www.ncsc.gov.uk/news/ncsc-advises-uk-organisations-take-action-following-conflict-in-middle-east"><u>issued a warning</u></a> over heightened risk of indirect threats for organizations with a presence, or supply chains, in the Middle East. </p><p>Stewart suggested that the impact of an attack on larger power supply operators or other critical infrastructure firms could be disastrous. </p><p>"We have to ask what happens if the next target is bigger, more critical or more deeply connected to the services millions of people rely on. Britain’s critical national infrastructure underpins almost every part of modern life, including electricity, water, transport and communications, and those systems are increasingly digital, interconnected and dependent on one another," he said. </p><p>"The question now has to be whether Britain is genuinely ready if something more serious follows.”</p><p>A spokesperson for the UK government told ITPro that it's working on an Energy Resilience Strategy. Set for publication later this year, this will outline plans for ensuring the energy system remains stable and secure. </p><p>"The UK has a highly resilience energy system. We work closely with the energy sector to protect infrastructure and ensure the highest standards of security," the spokesperson added.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘We are about to see the greatest boom in people starting smaller businesses that we’ve ever seen’: OpenAI CEO Sam Altman thinks AI will spark a new wave of entrepreneurship ]]></title>
                                                                                                <dc:content><![CDATA[ <p>OpenAI CEO Sam Altman believes AI could spark a new wave of small businesses, but the tech industry has a lot of work to do convincing entrepreneurs how the technology can help. </p><p>Speaking on the <a href="https://www.youtube.com/watch?v=kG8AoExkX40" target="_blank"><u>David Senra podcast</u></a>, Altman suggested AI could help break down traditional barriers for entrepreneurs, particularly in terms of financing and technical capabilities. </p><p>“Even if most people don’t want to start really big companies, a lot of people want to start smaller companies, and that has been hard,” he said. </p><p>“That has been something that has required a fair amount of privilege, and luck, and resources to be able to do. We are about to see the greatest boom in people starting smaller businesses that we have ever seen,” Altman added. “I think AI is empowering that.”</p><p>Altman’s optimistic outlook on this front is reflected in recent research conducted by OpenAI. As <a href="https://www.itpro.com/technology/artificial-intelligence/openai-says-ai-tools-are-paying-dividends-for-small-businesses-but-uptake-is-sluggish-in-several-uk-regions"><u><em>ITPro </em></u><u>reported in March</u></a>, a survey by the firm highlighted a strong appetite for <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today"><u>AI tools</u></a> among small businesses across the UK. </p><p>Eight-in-ten small businesses across the country now use the technology in daily operations, OpenAI found, although the study warned that uptake varies wildly on a region-by-region basis. </p><p>Notably, Altman told Senra that OpenAI and the broader tech industry hasn’t quite emphasized the potential benefits of AI to entrepreneurs and small businesses in recent years. </p><p>The focus has largely been on larger organizations and how the technology is impacting operations in these domains. </p><p>“For some reason the field, including us, has not talked about that enough, even though we see all the signs of it,” he said. “We have not built enough products to accelerate that, but I think we’re going to see a lot more of that."</p><h2 id="some-smbs-are-pulling-ahead">Some SMBs are pulling ahead</h2><p>Altman’s comments come in the wake of recent <a href="https://www.itpro.com/business/business-strategy/flexibility-is-a-huge-advantage-for-small-businesses-adopting-ai-but-clear-strategy-and-bold-leadership-is-critical"><u>research from Dell Technologies</u></a> which found small and medium-sized businesses (SMBs) are increasingly optimistic about the impact of AI. </p><p>The study found two-thirds (66%) of UK small businesses view AI as a “route to growth” while more than half (56%) believe the technology will give them a competitive advantage. </p><p>Brian Horsburgh, UK small business country manager at Dell Technologies, told <em>ITPro </em>that small businesses have a huge advantage over larger companies in terms of adoption. </p><p>Smaller firms are far more agile and typically more flexible in how they integrate the technology in daily operations. This, the study found, is highlighted in the rate of successful adoption projects. </p><p>Indeed, larger companies tend to cite a broader range of barriers when it comes to adoption, including lengthy approval processes, fear of failure, or resistance to change across the workforce. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/we-are-about-to-see-the-greatest-boom-in-people-starting-smaller-businesses-that-weve-ever-seen-openai-ceo-sam-altman-thinks-ai-will-spark-a-new-wave-of-entrepreneurship</link>
                                                                            <description>
                            <![CDATA[ The OpenAI chief executive thinks the tech industry needs to get better at selling the benefits of AI to small businesses and entrepreneurs ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZU76ERZMpmJb6gx9Cq2tCE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Qt2sKwuHXnFVHSX5uqCX8W-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 24 Aug 2026 09:39:22 +0000</pubDate>                                                                                                                                <updated>Mon, 24 Aug 2026 11:16:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Qt2sKwuHXnFVHSX5uqCX8W-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI CEO Sam Altman pictured during a presentation at the 2026 BlackRock Infrastructure Summit in Washington DC.]]></media:description>                                                            <media:text><![CDATA[OpenAI CEO Sam Altman pictured during a presentation at the 2026 BlackRock Infrastructure Summit in Washington DC.]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI CEO Sam Altman pictured during a presentation at the 2026 BlackRock Infrastructure Summit in Washington DC.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Qt2sKwuHXnFVHSX5uqCX8W-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>OpenAI CEO Sam Altman believes AI could spark a new wave of small businesses, but the tech industry has a lot of work to do convincing entrepreneurs how the technology can help. </p><p>Speaking on the <a href="https://www.youtube.com/watch?v=kG8AoExkX40" target="_blank"><u>David Senra podcast</u></a>, Altman suggested AI could help break down traditional barriers for entrepreneurs, particularly in terms of financing and technical capabilities. </p><p>“Even if most people don’t want to start really big companies, a lot of people want to start smaller companies, and that has been hard,” he said. </p><p>“That has been something that has required a fair amount of privilege, and luck, and resources to be able to do. We are about to see the greatest boom in people starting smaller businesses that we have ever seen,” Altman added. “I think AI is empowering that.”</p><p>Altman’s optimistic outlook on this front is reflected in recent research conducted by OpenAI. As <a href="https://www.itpro.com/technology/artificial-intelligence/openai-says-ai-tools-are-paying-dividends-for-small-businesses-but-uptake-is-sluggish-in-several-uk-regions"><u><em>ITPro </em></u><u>reported in March</u></a>, a survey by the firm highlighted a strong appetite for <a href="https://www.itpro.com/technology/artificial-intelligence/amazing-ai-tools-to-try-today"><u>AI tools</u></a> among small businesses across the UK. </p><p>Eight-in-ten small businesses across the country now use the technology in daily operations, OpenAI found, although the study warned that uptake varies wildly on a region-by-region basis. </p><p>Notably, Altman told Senra that OpenAI and the broader tech industry hasn’t quite emphasized the potential benefits of AI to entrepreneurs and small businesses in recent years. </p><p>The focus has largely been on larger organizations and how the technology is impacting operations in these domains. </p><p>“For some reason the field, including us, has not talked about that enough, even though we see all the signs of it,” he said. “We have not built enough products to accelerate that, but I think we’re going to see a lot more of that."</p><h2 id="some-smbs-are-pulling-ahead">Some SMBs are pulling ahead</h2><p>Altman’s comments come in the wake of recent <a href="https://www.itpro.com/business/business-strategy/flexibility-is-a-huge-advantage-for-small-businesses-adopting-ai-but-clear-strategy-and-bold-leadership-is-critical"><u>research from Dell Technologies</u></a> which found small and medium-sized businesses (SMBs) are increasingly optimistic about the impact of AI. </p><p>The study found two-thirds (66%) of UK small businesses view AI as a “route to growth” while more than half (56%) believe the technology will give them a competitive advantage. </p><p>Brian Horsburgh, UK small business country manager at Dell Technologies, told <em>ITPro </em>that small businesses have a huge advantage over larger companies in terms of adoption. </p><p>Smaller firms are far more agile and typically more flexible in how they integrate the technology in daily operations. This, the study found, is highlighted in the rate of successful adoption projects. </p><p>Indeed, larger companies tend to cite a broader range of barriers when it comes to adoption, including lengthy approval processes, fear of failure, or resistance to change across the workforce. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Be careful who you talk to at conferences: Security researchers claim they were targeted by cyber criminals after DEF CON event ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Visitors to Black Hat/DEF CON earlier this month were targeted after the event by cyber criminals posing as a well-known crypto media executive.</p><p>The X account @HartmansDoeke sent a direct message to one Huntress security researcher claiming to be CoinDesk's VP and head of marketing, asking for help with an upcoming conference. </p><p>While the researcher cottoned on to the scam immediately, they carried on engaging with the scammer to check out the tactics they were using. This involved a Google Doc featuring a custom Google Apps Script sidebar designed to guide them through the execution of <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>. </p><p>The document asked the potential victim to enter an 'encryption key' – supplied by the actor in direct messages – which appeared to fail when entered. The sidebar provided two follow-on options: <a href="https://www.itpro.com/security/malware/opera-browser-thinks-it-has-the-solution-to-stopping-clickfix-malware-attacks">ClickFix</a>-style instructions and a download option, both intended to download and execute malicious code. </p><p>Mac users were served an infostealer targeting browser passwords, crypto wallets and even private Notes app data. Meanwhile, Windows users were served a remote access trojan, a fake crypto wallet implant, and a network-intercepting proxy delivered via an installer signed with what appears to be a stolen certificate.</p><p>When the researcher didn't fall for the malicious Google Doc, the threat actor followed up the next day with a second malicious document. </p><p>This masqueraded as a Dropbox DocSend share and led to a counterfeit DocSend installer that delivered AMOS stealer to macOS users and NetSupport RAT, a Ledger wallet implant, and a traffic-intercepting proxy to those on Windows.</p><p>"Taken together, the two lures show how the threat actor used familiar platforms to build credibility and keep the target engaged," Huntress said. "By combining social media DMs with trusted document and file-sharing services, the actor created a legitimate-looking workflow designed to trick targets into running the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>."</p><h2 id="conference-attendees-urged-to-remain-vigilant">Conference attendees urged to remain vigilant</h2><p>According to Huntress, the researcher was just one of many to be targeted.</p><p>"Large industry events like Black Hat and DEF CON create a target-rich environment for bad actors, with attendees exchanging new contacts, documents, invitations, and follow-up plans," Huntress said. </p><p>"Attackers are using this activity to make malicious outreach look like just another routine post-conference interaction."</p><p>Anybody who's interacted with a lure like this is advised to isolate the system from the network, collect any relevant forensic evidence, and consider reimaging the system. </p><p>They should assume that credentials on the system have been compromised and revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system – and also review any cryptocurrency wallets. </p><p>While visitors to a security conference might not seem like the most obvious victims, this wasn't the only attempt to scam this year's DEF CON attendees.</p><p>One passenger on a Delta flight out of Las Vegas <a href="https://www.itpro.com/security/cyber-attacks/delta-airlines-flight-wi-fi-tampered-with-after-def-con-conference"><u>attempted to jam in-flight Wi-Fi</u></a> and broadcast a rogue network designed to look like the airline’s service, in an apparent phishing attempt. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/be-careful-who-you-talk-to-at-conferences-security-researchers-claim-they-were-targeted-by-cyber-criminals-after-def-con-event</link>
                                                                            <description>
                            <![CDATA[ Scammers contacted conference attendees with a booby-trapped Google Doc designed to look like a routine post-event contact ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sRMYXq8ixyDvmQ8HtFvSNA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 08:56:22 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing silhouette of a hooded individual using a laptop computer with binary code imposed against a red backdrop. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pjqoPws66yCB4ujEfq3dte-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Visitors to Black Hat/DEF CON earlier this month were targeted after the event by cyber criminals posing as a well-known crypto media executive.</p><p>The X account @HartmansDoeke sent a direct message to one Huntress security researcher claiming to be CoinDesk's VP and head of marketing, asking for help with an upcoming conference. </p><p>While the researcher cottoned on to the scam immediately, they carried on engaging with the scammer to check out the tactics they were using. This involved a Google Doc featuring a custom Google Apps Script sidebar designed to guide them through the execution of <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>. </p><p>The document asked the potential victim to enter an 'encryption key' – supplied by the actor in direct messages – which appeared to fail when entered. The sidebar provided two follow-on options: <a href="https://www.itpro.com/security/malware/opera-browser-thinks-it-has-the-solution-to-stopping-clickfix-malware-attacks">ClickFix</a>-style instructions and a download option, both intended to download and execute malicious code. </p><p>Mac users were served an infostealer targeting browser passwords, crypto wallets and even private Notes app data. Meanwhile, Windows users were served a remote access trojan, a fake crypto wallet implant, and a network-intercepting proxy delivered via an installer signed with what appears to be a stolen certificate.</p><p>When the researcher didn't fall for the malicious Google Doc, the threat actor followed up the next day with a second malicious document. </p><p>This masqueraded as a Dropbox DocSend share and led to a counterfeit DocSend installer that delivered AMOS stealer to macOS users and NetSupport RAT, a Ledger wallet implant, and a traffic-intercepting proxy to those on Windows.</p><p>"Taken together, the two lures show how the threat actor used familiar platforms to build credibility and keep the target engaged," Huntress said. "By combining social media DMs with trusted document and file-sharing services, the actor created a legitimate-looking workflow designed to trick targets into running the <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>."</p><h2 id="conference-attendees-urged-to-remain-vigilant">Conference attendees urged to remain vigilant</h2><p>According to Huntress, the researcher was just one of many to be targeted.</p><p>"Large industry events like Black Hat and DEF CON create a target-rich environment for bad actors, with attendees exchanging new contacts, documents, invitations, and follow-up plans," Huntress said. </p><p>"Attackers are using this activity to make malicious outreach look like just another routine post-conference interaction."</p><p>Anybody who's interacted with a lure like this is advised to isolate the system from the network, collect any relevant forensic evidence, and consider reimaging the system. </p><p>They should assume that credentials on the system have been compromised and revoke active sessions, reset passwords, and rotate API keys or any other secrets that may reside on the system – and also review any cryptocurrency wallets. </p><p>While visitors to a security conference might not seem like the most obvious victims, this wasn't the only attempt to scam this year's DEF CON attendees.</p><p>One passenger on a Delta flight out of Las Vegas <a href="https://www.itpro.com/security/cyber-attacks/delta-airlines-flight-wi-fi-tampered-with-after-def-con-conference"><u>attempted to jam in-flight Wi-Fi</u></a> and broadcast a rogue network designed to look like the airline’s service, in an apparent phishing attempt. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Modern players are essentially the architects of the future technical labor pool’: IT leaders want gamers on their teams, and they’re more likely to hire job candidates who list experience on resumes ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Many IT leaders are “avid gamers”, according to new research from <a href="https://www.itpro.com/hardware/Logitech-Spot-office-environmental-sensor">Logitech</a>, and this increasingly shapes how they make business and hiring decisions. </p><p>While gaming has traditionally been viewed as a hobby, the study noted that there are a range of transferable workplace skills. 98.8% of IT decision makers said that gaming directly affects their job performance and competency, for example. </p><p>IT leaders said gaming benefits them in areas such as strategic thinking (65.7%), problem solving (65.5%), and performing under pressure (63.5%), according to Logitech. </p><p>"Savvy enterprise tech buyers don't just shop for features – they stress-test systems and demand friction-free workflows,” said Henry Levak, general manager for Logitech’s team workspace solutions division. </p><p>“Managing complex IT infrastructure requires quick thinking, constant adaptation, and staying calm under pressure—the same skills gamers use every day.”</p><h2 id="gamers-get-the-jobs">Gamers get the jobs</h2><p>Notably, Logitech found 82% of IT leaders are more likely to consider job candidates who list gaming experience on their resumes.</p><p>A key factor here, the study noted, is that it points to skills such as “multiplayer coordination and strategic execution” - both of which are viewed as valuable real-world attributes. </p><p>This trend shows no signs of slowing down either, according to Logitech. </p><p>Looking ahead, more than 90% of IT leaders said they expect technology leadership to become “increasingly influenced by gaming standards” – particularly with regard to team performance. </p><p>"The data validates a shift many tech executives already recognize: modern players are essentially the architects of the future technical labor pool," noted Robin Piispanen, general manager at Logitech Gaming. </p><p>"The cognitive flexibility, rapid response times, and analytical capabilities honed in gaming environments are proving to be significant professional assets in the contemporary office."</p><h2 id="transferable-skills">Transferable skills</h2><p>Logitech’s study isn’t the first to highlight the benefits of gaming. Previous research suggests that gaming has a direct benefit in terms of building ‘soft skills’ such as communication, teamwork, and time management. </p><p>In a <a href="https://journals.sagepub.com/doi/10.1177/10468781221137361" target="_blank"><u>study</u></a> conducted by the University of Surrey, researchers found that online gaming also helped improve job prospects. </p><p>“Our study found that online gaming behaviour varied between different job categories, allowing the participants to gain different soft skills,” the study noted. </p><p>“The soft skills gained could assist gamers with training that leads to a particular career path.”</p><p>Some industries have begun looking to areas such as esports as a means to attract digital-savvy talent, including the UK Armed Forces. </p><p>As <a href="https://www.itpro.com/business/business-strategy/game-on-esports-as-an-enterprise-tool"><u><em>ITPro </em></u><u>previously reported</u></a>, the Ministry of Defence (MoD) recognized esports as an official sport. Some British Army and Royal Air Force (RAF) sites even have dedicated esports facilities for personnel. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/modern-players-are-essentially-the-architects-of-the-future-technical-labor-pool-it-leaders-want-gamers-on-their-teams-and-theyre-more-likely-to-hire-job-candidates-who-list-experience-on-resumes</link>
                                                                            <description>
                            <![CDATA[ New research suggests IT leaders are increasingly looking to gamers to bolster workforce skills capabilities ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VpHYaoVm3v78onUgidjo26</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YXRMz37UFjFhpmTxy5yfGX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 14:45:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YXRMz37UFjFhpmTxy5yfGX-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Young man playing video games on a desktop computer in a dimly lit room, with glowing headphones.]]></media:description>                                                            <media:text><![CDATA[Young man playing video games on a desktop computer in a dimly lit room, with glowing headphones.]]></media:text>
                                <media:title type="plain"><![CDATA[Young man playing video games on a desktop computer in a dimly lit room, with glowing headphones.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YXRMz37UFjFhpmTxy5yfGX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Many IT leaders are “avid gamers”, according to new research from <a href="https://www.itpro.com/hardware/Logitech-Spot-office-environmental-sensor">Logitech</a>, and this increasingly shapes how they make business and hiring decisions. </p><p>While gaming has traditionally been viewed as a hobby, the study noted that there are a range of transferable workplace skills. 98.8% of IT decision makers said that gaming directly affects their job performance and competency, for example. </p><p>IT leaders said gaming benefits them in areas such as strategic thinking (65.7%), problem solving (65.5%), and performing under pressure (63.5%), according to Logitech. </p><p>"Savvy enterprise tech buyers don't just shop for features – they stress-test systems and demand friction-free workflows,” said Henry Levak, general manager for Logitech’s team workspace solutions division. </p><p>“Managing complex IT infrastructure requires quick thinking, constant adaptation, and staying calm under pressure—the same skills gamers use every day.”</p><h2 id="gamers-get-the-jobs">Gamers get the jobs</h2><p>Notably, Logitech found 82% of IT leaders are more likely to consider job candidates who list gaming experience on their resumes.</p><p>A key factor here, the study noted, is that it points to skills such as “multiplayer coordination and strategic execution” - both of which are viewed as valuable real-world attributes. </p><p>This trend shows no signs of slowing down either, according to Logitech. </p><p>Looking ahead, more than 90% of IT leaders said they expect technology leadership to become “increasingly influenced by gaming standards” – particularly with regard to team performance. </p><p>"The data validates a shift many tech executives already recognize: modern players are essentially the architects of the future technical labor pool," noted Robin Piispanen, general manager at Logitech Gaming. </p><p>"The cognitive flexibility, rapid response times, and analytical capabilities honed in gaming environments are proving to be significant professional assets in the contemporary office."</p><h2 id="transferable-skills">Transferable skills</h2><p>Logitech’s study isn’t the first to highlight the benefits of gaming. Previous research suggests that gaming has a direct benefit in terms of building ‘soft skills’ such as communication, teamwork, and time management. </p><p>In a <a href="https://journals.sagepub.com/doi/10.1177/10468781221137361" target="_blank"><u>study</u></a> conducted by the University of Surrey, researchers found that online gaming also helped improve job prospects. </p><p>“Our study found that online gaming behaviour varied between different job categories, allowing the participants to gain different soft skills,” the study noted. </p><p>“The soft skills gained could assist gamers with training that leads to a particular career path.”</p><p>Some industries have begun looking to areas such as esports as a means to attract digital-savvy talent, including the UK Armed Forces. </p><p>As <a href="https://www.itpro.com/business/business-strategy/game-on-esports-as-an-enterprise-tool"><u><em>ITPro </em></u><u>previously reported</u></a>, the Ministry of Defence (MoD) recognized esports as an official sport. Some British Army and Royal Air Force (RAF) sites even have dedicated esports facilities for personnel. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'An evolution in threat actor capabilities': CISA warns hackers are targeting Siemens industrial controllers – and they're using AI generated code ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Hackers are using AI-generated exploitation scripts disguised as legitimate monitoring tools to hack Siemens programmable logic controllers.</p><p>An <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a" target="_blank"><u>advisory</u></a> from the US National Security Agency (NSA), the FBI, and other agencies warns of an active threat against the Siemens controllers, which are widely used in critical infrastructure sectors such as manufacturing, energy, and agriculture. </p><p>The threat actors use internet scanning services to find internet-exposed PLCs running outdated software, or that are otherwise poorly protected.</p><p>"This is not a theoretical risk — it is an active threat," the <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a> warned. </p><p>"Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems."</p><p><a href="https://www.itpro.com/software/development/ai-generated-code-is-now-the-cause-of-one-in-five-breaches-but-developers-and-security-leaders-alike-are-convinced-the-technology-will-come-good-eventually">Using AI to generate exploit scripts</a> is a new tactic, CISA noted. This helps dramatically reduce the time, effort, and technical expertise required to develop working industrial control system exploitation scripts and malicious tools. </p><p>The tactic also allows hackers to exploit additional attack vectors at speed and adapt to defensive measures by collecting public information about vulnerabilities and weaknesses, finding exposed and exploitable PLCs and using AI-generated scripts to act on that information. </p><p>"If PLCs are exposed to the internet, they are at high risk for exploitation," CISA said. </p><h2 id="siemens-s7-series-users-urged-to-act-now">Siemens S7 Series users urged to act now</h2><p>Security agencies have urged all owners and operators of <a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot">operational technology (OT) </a>systems using Siemens S7 Series and other PLC devices to make sure their systems are properly protected. </p><p>This includes implementing applicable security patches and updates, ensuring isolation from the internet wherever possible, and having strong access controls and security tooling to monitor environments for malicious activity.</p><p>Andrew Costis, engineering manager of the Adversary Research Team at AttackIQ, said the warning should be taken seriously by critical infrastructure operators given traditional targeting methods by threat groups. </p><p>Recent <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat">attacks on critical infrastructure</a> have often centered on “gaining persistent access, stealing sensitive information or positioning inside networks for future operations,” he noted. </p><p>"This latest exposure poses a bit of a different threat. The danger is more immediate because PLCs sit much closer to the physical processes that keep critical infrastructure running. Where a compromised business system can expose data, a compromised PLC can interfere with manufacturing, energy, water, or other physical processes. The downstream effects can reach far beyond the initial target."</p><p>The NSA stresses that the risks extend beyond the Siemens PLCs highlighted in the advisory, saying they represent just one subset of the wider threat landscape. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/an-evolution-in-threat-actor-capabilities-cisa-warns-hackers-are-targeting-siemens-industrial-controllers-and-theyre-using-ai-generated-code</link>
                                                                            <description>
                            <![CDATA[ Security agencies are warning that attackers are exploiting Siemens S7 Series programmable logic controllers to target critical infrastructure ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HHCmk5fdMJTgBwKx6CTEa5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jy9kHQDBFhxUBovKBUkYaG-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 10:39:21 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jy9kHQDBFhxUBovKBUkYaG-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Logo and branding of Siemens pictured on the side of a company building in Berlin, Germany.]]></media:description>                                                            <media:text><![CDATA[Logo and branding of Siemens pictured on the side of a company building in Berlin, Germany.]]></media:text>
                                <media:title type="plain"><![CDATA[Logo and branding of Siemens pictured on the side of a company building in Berlin, Germany.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jy9kHQDBFhxUBovKBUkYaG-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Hackers are using AI-generated exploitation scripts disguised as legitimate monitoring tools to hack Siemens programmable logic controllers.</p><p>An <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a" target="_blank"><u>advisory</u></a> from the US National Security Agency (NSA), the FBI, and other agencies warns of an active threat against the Siemens controllers, which are widely used in critical infrastructure sectors such as manufacturing, energy, and agriculture. </p><p>The threat actors use internet scanning services to find internet-exposed PLCs running outdated software, or that are otherwise poorly protected.</p><p>"This is not a theoretical risk — it is an active threat," the <a href="https://www.itpro.com/security/what-is-cisa">Cybersecurity and Infrastructure Security Agency (CISA)</a> warned. </p><p>"Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems."</p><p><a href="https://www.itpro.com/software/development/ai-generated-code-is-now-the-cause-of-one-in-five-breaches-but-developers-and-security-leaders-alike-are-convinced-the-technology-will-come-good-eventually">Using AI to generate exploit scripts</a> is a new tactic, CISA noted. This helps dramatically reduce the time, effort, and technical expertise required to develop working industrial control system exploitation scripts and malicious tools. </p><p>The tactic also allows hackers to exploit additional attack vectors at speed and adapt to defensive measures by collecting public information about vulnerabilities and weaknesses, finding exposed and exploitable PLCs and using AI-generated scripts to act on that information. </p><p>"If PLCs are exposed to the internet, they are at high risk for exploitation," CISA said. </p><h2 id="siemens-s7-series-users-urged-to-act-now">Siemens S7 Series users urged to act now</h2><p>Security agencies have urged all owners and operators of <a href="https://www.itpro.com/infrastructure/what-is-operational-technology-ot">operational technology (OT) </a>systems using Siemens S7 Series and other PLC devices to make sure their systems are properly protected. </p><p>This includes implementing applicable security patches and updates, ensuring isolation from the internet wherever possible, and having strong access controls and security tooling to monitor environments for malicious activity.</p><p>Andrew Costis, engineering manager of the Adversary Research Team at AttackIQ, said the warning should be taken seriously by critical infrastructure operators given traditional targeting methods by threat groups. </p><p>Recent <a href="https://www.itpro.com/security/cyber-attacks/why-attacks-against-critical-national-infrastructure-cni-are-such-a-threat">attacks on critical infrastructure</a> have often centered on “gaining persistent access, stealing sensitive information or positioning inside networks for future operations,” he noted. </p><p>"This latest exposure poses a bit of a different threat. The danger is more immediate because PLCs sit much closer to the physical processes that keep critical infrastructure running. Where a compromised business system can expose data, a compromised PLC can interfere with manufacturing, energy, water, or other physical processes. The downstream effects can reach far beyond the initial target."</p><p>The NSA stresses that the risks extend beyond the Siemens PLCs highlighted in the advisory, saying they represent just one subset of the wider threat landscape. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This company wants you to break out of its security sandbox – and there’s $1 million up for grabs ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cloud development company Vercel has dared cyber researchers to break out of its security sandbox environment as part of a $1 million challenge. </p><p>The two-week program will be run through <a href="https://www.itpro.com/business/careers-and-training/hackerone-names-nidhi-aggarwal-as-its-new-chief-product-officer">HackerOne </a>and challenges participants to break out of an isolated sandbox hosted by the company. </p><p>This is a two-pronged challenge, according to Vercel, requiring hackers to escape compute boundaries to reach an <a href="https://www.itpro.com/cloud/370070/what-is-aws-ec2">EC2 </a>host, reach another tenant’s sandbox, or crash another tenant’s sandbox. </p><p>Network boundaries are also in the crosshairs, the company noted. Participants are challenged to “defeat the sandbox firewall” and reach unauthorized destinations, infiltrate data, or scoop up credentials. </p><p>Vercel said bounties will be paid per report, with a maximum pay-out of $50,000 for identifying a vulnerability that allows a threat actor to “read or modify another Vercel tenant’s data”. </p><h2 id="under-the-hood-of-the-vercel-sandbox">Under the hood of the Vercel Sandbox</h2><p>In a <a href="https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox" target="_blank"><u>blog post</u></a> detailing the challenge, Vercel said its sandbox environment runs on bare-metal EC2 hosts, with each sandbox given its own Firecracker microVM with a “dedicated guest kernel”. </p><p>“Inside that microVM a Linux container runs the operator’s code,” the company noted. “The microVM, not the container, is the security boundary, so operator-supplied code runs two layers removed from the host.”</p><p>Meanwhile, the network boundary is enforced on the host outside of the microVM. </p><p>“The sandbox firewall intercepts outbound TCP and DNS, checks each connection against the operator's domain and CIDR policies, and can inject credentials at the boundary so they never enter the microVM.”</p><h2 id="sandbox-security-in-the-spotlight">Sandbox security in the spotlight</h2><p>In a <a href="https://x.com/rauchg/status/2089747453004468339?s=20" target="_blank">statement on X</a>, CEO Guillermo Rauch said the challenge comes in direct response to high-profile incidents involving AI agents. </p><p>Agents at OpenAI, Anthropic, and Meta all breached containment during recent testing schemes, thereafter waging <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime">attacks against other companies such as Hugging Face</a>. </p><p>As <em>ITPro </em>reported in early August, the sandbox testing environments used by all three companies <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents">were hosted by a third-party provider, Irregular</a>. </p><p>“We are putting $1m towards verifying the security of Vercel Sandbox, in the open,” he said. I'm looking forward to bringing transparency to what frontier models can and cannot do in terms of real-world guardrail exploitability.”</p><p>In the event that participants do escape the Vercel Sandbox, Rauch said the company will be “ready to patch, iterate, and share our findings with the broader community”. </p><p>Vercel pointed to a recent test which saw the company’s CTO use an open-weight model to try and break sandbox containment. While the firm <a href="https://vercel.com/blog/everything-hackable-will-get-hacked">noted </a>it did not escape, it “mapped the guest kernel, built a VM to reproduce its ideas, and wrote a fuzzer”.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/this-company-wants-you-to-break-out-of-its-security-sandbox-and-theres-usd1-million-up-for-grabs</link>
                                                                            <description>
                            <![CDATA[ A new HackerOne bounty scheme challenges participants to breach a Vercel sandbox ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zPHH3WLXNU2qKypzrUJc6T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6MnnsrffitCG2bQAJKNJPS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 10:19:34 +0000</pubDate>                                                                                                                                <updated>Thu, 20 Aug 2026 10:19:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6MnnsrffitCG2bQAJKNJPS-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security sandbox concept image showing silhouette of a man standing behind bars, with two bars in center warped to create a gap.]]></media:description>                                                            <media:text><![CDATA[Security sandbox concept image showing silhouette of a man standing behind bars, with two bars in center warped to create a gap.]]></media:text>
                                <media:title type="plain"><![CDATA[Security sandbox concept image showing silhouette of a man standing behind bars, with two bars in center warped to create a gap.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6MnnsrffitCG2bQAJKNJPS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cloud development company Vercel has dared cyber researchers to break out of its security sandbox environment as part of a $1 million challenge. </p><p>The two-week program will be run through <a href="https://www.itpro.com/business/careers-and-training/hackerone-names-nidhi-aggarwal-as-its-new-chief-product-officer">HackerOne </a>and challenges participants to break out of an isolated sandbox hosted by the company. </p><p>This is a two-pronged challenge, according to Vercel, requiring hackers to escape compute boundaries to reach an <a href="https://www.itpro.com/cloud/370070/what-is-aws-ec2">EC2 </a>host, reach another tenant’s sandbox, or crash another tenant’s sandbox. </p><p>Network boundaries are also in the crosshairs, the company noted. Participants are challenged to “defeat the sandbox firewall” and reach unauthorized destinations, infiltrate data, or scoop up credentials. </p><p>Vercel said bounties will be paid per report, with a maximum pay-out of $50,000 for identifying a vulnerability that allows a threat actor to “read or modify another Vercel tenant’s data”. </p><h2 id="under-the-hood-of-the-vercel-sandbox">Under the hood of the Vercel Sandbox</h2><p>In a <a href="https://vercel.com/blog/one-million-dollar-hacker-challenge-for-vercel-sandbox" target="_blank"><u>blog post</u></a> detailing the challenge, Vercel said its sandbox environment runs on bare-metal EC2 hosts, with each sandbox given its own Firecracker microVM with a “dedicated guest kernel”. </p><p>“Inside that microVM a Linux container runs the operator’s code,” the company noted. “The microVM, not the container, is the security boundary, so operator-supplied code runs two layers removed from the host.”</p><p>Meanwhile, the network boundary is enforced on the host outside of the microVM. </p><p>“The sandbox firewall intercepts outbound TCP and DNS, checks each connection against the operator's domain and CIDR policies, and can inject credentials at the boundary so they never enter the microVM.”</p><h2 id="sandbox-security-in-the-spotlight">Sandbox security in the spotlight</h2><p>In a <a href="https://x.com/rauchg/status/2089747453004468339?s=20" target="_blank">statement on X</a>, CEO Guillermo Rauch said the challenge comes in direct response to high-profile incidents involving AI agents. </p><p>Agents at OpenAI, Anthropic, and Meta all breached containment during recent testing schemes, thereafter waging <a href="https://www.itpro.com/security/an-unprecedented-cyber-incident-how-openai-models-breached-hugging-face-and-why-it-could-herald-a-new-phase-of-ai-powered-cyber-crime">attacks against other companies such as Hugging Face</a>. </p><p>As <em>ITPro </em>reported in early August, the sandbox testing environments used by all three companies <a href="https://www.itpro.com/technology/artificial-intelligence/independent-testing-firm-irregular-the-source-of-misconfigurations-that-led-to-meta-openai-and-anthropic-ai-incidents">were hosted by a third-party provider, Irregular</a>. </p><p>“We are putting $1m towards verifying the security of Vercel Sandbox, in the open,” he said. I'm looking forward to bringing transparency to what frontier models can and cannot do in terms of real-world guardrail exploitability.”</p><p>In the event that participants do escape the Vercel Sandbox, Rauch said the company will be “ready to patch, iterate, and share our findings with the broader community”. </p><p>Vercel pointed to a recent test which saw the company’s CTO use an open-weight model to try and break sandbox containment. While the firm <a href="https://vercel.com/blog/everything-hackable-will-get-hacked">noted </a>it did not escape, it “mapped the guest kernel, built a VM to reproduce its ideas, and wrote a fuzzer”.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data belonging to 3.75 million patients was exposed in the CareCloud breach – not the 350,000 originally reported ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The number of victims affected in the CareCloud breach has been revised from 350,000 to roughly 3.75 million, the company has revealed.</p><p>The American medical record storage first confirmed it had been breached back in March, with hackers gaining access to medical data held in its cloud over six whole days. </p><p>According to <a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-627090" target="_blank"><u>regulatory filings</u></a> from CareCloud at the time, the intrusion was spotted on 16 March. An investigation into the incident found an unauthorized party had gained access to an AWS environment for several days. </p><p>The initial filing said the attack caused a network outage of eight hours, disrupting access to the impacted database. </p><p>CareCloud noted the hackers "claimed to have exfiltrated data from databases within that environment", though the nature of the attack and whether CareCloud was directly communicating with the attackers remains unclear. </p><p><a href="https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/" target="_blank">Reports</a> suggest no hacking group has as yet claimed responsibility for the attack.</p><p>After CareCloud spotted the incident, access was shut down and no further unauthorized activity was spotted. </p><h2 id="carecloud-breach-notices-cited-far-lower-victim-numbers">CareCloud breach notices cited far lower victim numbers</h2><p>In July, disclosure letters were distributed to around 350,000 people in the US who were believed to be affected — but that has <a href="https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf" target="_blank">since risen to 3.75 million potential victims</a>. </p><p>Leaked data includes names and addresses, as well as more sensitive details such as bank accounts, payment card numbers, medical data, and government identification including driver's licenses, passports, and Social Security numbers. </p><p>Ross Filipek, <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>at Corsica Technologies, said the revision to the victim list highlights the disastrous impact of cyber attacks on healthcare organizations – which rank among the <a href="https://www.itpro.com/security/hospital-cyber-attacks-are-increasingly-hitting-patient-care">top targets for cyber criminals</a>. </p><p>"This isn't just a massive breach of data, it's a warning," Filipek commented. "Nearly four million patients having their information exposed shows just how much sensitive data can be concentrated behind a single healthcare technology provider."</p><p>"It also creates significant legal and regulatory exposure for a provider handling this much protected health information, which could make the fallout expensive for CareCloud."</p><h2 id="what-s-next">What's next?</h2><p>CareCloud hasn't revealed much detail about the attack – including whether it was <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>or a <a href="https://www.itpro.com/security/ransomware/instructure-chose-to-a-pay-ransom-following-the-canvas-cyber-attack-research-shows-more-than-half-of-security-leaders-would-follow-suit">ransom was paid</a> – but the company says its continuing to investigate and lockdown systems. </p><p>"Upon discovering the incident, CareCloud quickly launched an investigation and took steps to contain and remediate the issue," a spokesperson said, per reports from <a href="https://www.teiss.co.uk/news/carecloud-says-data-security-incident-affected-over-37-million-18010" target="_blank"><u><em>Teiss</em></u></a>. </p><p>"CareCloud engaged external cybersecurity experts and, with their assistance, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained. CareCloud is continuing to strengthen the security of its systems and environments."</p><p><em>ITPro </em>approached CareCloud for comment, but did not receive a response by time of publication. </p><p>Disclosure letters distributed to affected patients note the company has seen no attempts at identity fraud to date, but warns recipients to be mindful of misuse of the stolen information.  </p><p>Data exposed in the breach gives cyber criminals “plenty to work with long after the initial incident is over,” Filipek said. </p><p>Hackers often use exposed information such as email addresses and phone numbers in follow-up scams in the wake of a cyber attack or breach. </p><p>"For patients, the risk doesn’t stop at identity theft," noted Filipek. "Stolen health information can fuel highly convincing <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, medical fraud, and other scams built around deeply personal details."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-breaches/data-belonging-to-3-75-million-patients-was-exposed-in-the-carecloud-breach-not-the-350-000-originally-reported</link>
                                                                            <description>
                            <![CDATA[ The number of victims in the CareCloud breach has surged to over three and a half million ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xNzHhGDkf8VTwZySnBZEDQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3J7Au6MQQeAP7axuLLnkPe-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 10:10:31 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3J7Au6MQQeAP7axuLLnkPe-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data breach concept image showing lines of locked padlocks, with one in center unlocked.]]></media:description>                                                            <media:text><![CDATA[Data breach concept image showing lines of locked padlocks, with one in center unlocked.]]></media:text>
                                <media:title type="plain"><![CDATA[Data breach concept image showing lines of locked padlocks, with one in center unlocked.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3J7Au6MQQeAP7axuLLnkPe-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The number of victims affected in the CareCloud breach has been revised from 350,000 to roughly 3.75 million, the company has revealed.</p><p>The American medical record storage first confirmed it had been breached back in March, with hackers gaining access to medical data held in its cloud over six whole days. </p><p>According to <a href="https://oag.ca.gov/ecrime/databreach/reports/sb24-627090" target="_blank"><u>regulatory filings</u></a> from CareCloud at the time, the intrusion was spotted on 16 March. An investigation into the incident found an unauthorized party had gained access to an AWS environment for several days. </p><p>The initial filing said the attack caused a network outage of eight hours, disrupting access to the impacted database. </p><p>CareCloud noted the hackers "claimed to have exfiltrated data from databases within that environment", though the nature of the attack and whether CareCloud was directly communicating with the attackers remains unclear. </p><p><a href="https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/" target="_blank">Reports</a> suggest no hacking group has as yet claimed responsibility for the attack.</p><p>After CareCloud spotted the incident, access was shut down and no further unauthorized activity was spotted. </p><h2 id="carecloud-breach-notices-cited-far-lower-victim-numbers">CareCloud breach notices cited far lower victim numbers</h2><p>In July, disclosure letters were distributed to around 350,000 people in the US who were believed to be affected — but that has <a href="https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf" target="_blank">since risen to 3.75 million potential victims</a>. </p><p>Leaked data includes names and addresses, as well as more sensitive details such as bank accounts, payment card numbers, medical data, and government identification including driver's licenses, passports, and Social Security numbers. </p><p>Ross Filipek, <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>at Corsica Technologies, said the revision to the victim list highlights the disastrous impact of cyber attacks on healthcare organizations – which rank among the <a href="https://www.itpro.com/security/hospital-cyber-attacks-are-increasingly-hitting-patient-care">top targets for cyber criminals</a>. </p><p>"This isn't just a massive breach of data, it's a warning," Filipek commented. "Nearly four million patients having their information exposed shows just how much sensitive data can be concentrated behind a single healthcare technology provider."</p><p>"It also creates significant legal and regulatory exposure for a provider handling this much protected health information, which could make the fallout expensive for CareCloud."</p><h2 id="what-s-next">What's next?</h2><p>CareCloud hasn't revealed much detail about the attack – including whether it was <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>or a <a href="https://www.itpro.com/security/ransomware/instructure-chose-to-a-pay-ransom-following-the-canvas-cyber-attack-research-shows-more-than-half-of-security-leaders-would-follow-suit">ransom was paid</a> – but the company says its continuing to investigate and lockdown systems. </p><p>"Upon discovering the incident, CareCloud quickly launched an investigation and took steps to contain and remediate the issue," a spokesperson said, per reports from <a href="https://www.teiss.co.uk/news/carecloud-says-data-security-incident-affected-over-37-million-18010" target="_blank"><u><em>Teiss</em></u></a>. </p><p>"CareCloud engaged external cybersecurity experts and, with their assistance, secured the affected environment, eliminated the threat, and confirmed that no persistent unauthorized access remained. CareCloud is continuing to strengthen the security of its systems and environments."</p><p><em>ITPro </em>approached CareCloud for comment, but did not receive a response by time of publication. </p><p>Disclosure letters distributed to affected patients note the company has seen no attempts at identity fraud to date, but warns recipients to be mindful of misuse of the stolen information.  </p><p>Data exposed in the breach gives cyber criminals “plenty to work with long after the initial incident is over,” Filipek said. </p><p>Hackers often use exposed information such as email addresses and phone numbers in follow-up scams in the wake of a cyber attack or breach. </p><p>"For patients, the risk doesn’t stop at identity theft," noted Filipek. "Stolen health information can fuel highly convincing <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing</a>, medical fraud, and other scams built around deeply personal details."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘The economics of vulnerability discovery have changed’: NIST wants to modernize the National Vulnerability Database amid AI advances – cyber experts say it needs to be redesigned with machine-speed in mind ]]></title>
                                                                                                <dc:content><![CDATA[ <p>NIST has issued a call for advice on how it can modernize the <a href="https://www.itpro.com/security/the-cve-system-isnt-working-what-next">National Vulnerability Database (NVD) </a>in light of recent AI advances – cyber experts have told <em>ITPro </em>that it’s desperately needed. </p><p>In a recent <a href="https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of" target="_blank">request for information</a> (RFI), the institute said it is seeking stakeholder input on how to overhaul the vulnerability reporting service. The NVD plays a key role in helping organizations keep their finger on the pulse of the threat landscape. </p><p>The database acts as a catalog for software and hardware-related security flaws, drawing on the Common Vulnerabilities and Exposures (CVE) system to provide details and guidance on vulnerabilities. </p><p>Yet recent AI advances, particularly in the cybersecurity field, have raised the stakes when it comes to vulnerability identification and remediation. </p><p>Rob O’Connor, EMEA CISO at Insight, told <em>ITPro </em>that “the economics of vulnerability discovery have changed” due to AI. Humans simply can’t match the speed of agents, and that creates blind spots for security teams. </p><p>“Automated agents can analyse and triage code at a scale humans can no longer match,” he said. “This means the bottleneck now isn’t finding the vulnerabilities. Instead, it’s in contextualising and remediating them.”</p><p>Researchers at Forescout <a href="https://www.itpro.com/security/brace-yourselves-for-a-vulnerability-explosion-forescout-warns">told <em>ITPro earlier </em>this year that businesses should prepare for an explosion of vulnerabilities</a>, with AI now being used to identify software flaws at record pace.</p><p>Some big tech companies have already taken action on this front, including Apple. In late June, the company <a href="https://www.itpro.com/software/apple-is-speeding-up-software-updates-due-to-ai-security-concerns-heres-what-you-need-to-know">revealed plans to speed up software patching </a>in direct response to AI.</p><p>At the core of NIST’s request, the institute said the goal is to “improve the NVD’s scalability, automation, interoperability, transparency, and utility”. </p><p>Put simply, AI is speeding things up, and the NVD needs to match the pace of vulnerability disclosures, which the institute itself <a href="https://www.itpro.com/security/nist-national-vulnerability-database-overhaul-increased-cve-submissions">recently admitted has become untenable</a>. </p><p>In April, NIST revealed it would scrap efforts to analyze every submitted CVE, instead focusing on only the most severe vulnerabilities. The shake-up means that only CVEs that meet certain criteria will be ‘enriched’ with additional details and guidance. </p><h2 id="the-nvd-was-built-around-human-speed">The NVD was built around human speed</h2><p>A key issue with the NVD in its current state is that it was designed around “human speed”, according to Crystal Morin, senior <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>strategist at Sysdig. </p><p>The database launched in 2005, having evolved from an earlier setup known as the Internet-Categorization of Attacks Toolkit (ICAT). The scale – and indeed, speed – of threats at that time pales in comparison to what organizations face in 2026. </p><p>That’s not to suggest that reporting standards are obsolete, though - they just need a rethink to remain fit-for-purpose in an AI-powered era. </p><p>“They were designed for human speed. We now operate in a machine-speed world. A CVE with a static severity score tells you a flaw exists and, roughly, how bad it could be in theory. It doesn’t tell you whether it is exploitable in your environment, or if it’s already being weaponized,” she told <em>ITPro</em>. </p><p>With AI in the mix, Morin said this creates two distinct gaps: namely speed and the detail required to act on potential vulnerabilities. </p><p>“The reporting and enrichment pipeline still moves in weeks while exploitation moves in hours,” she said. “Second, the same detailed advisory that helps defenders is also raw material for AI-generated exploit code.”</p><p>“Ultimately, severity scoring on its own drives the ‘patch everything’ behavior that simply does not scale.”</p><p>Morin noted that Sysdig’s threat intelligence unit saw this dynamic play out in real-time when a Langflow vulnerability with a 9.9 CVSS score “essentially sat untouched while a lower-scored 9.3 vulnerability in the same product was mass exploited”.</p><p>“Standards must evolve toward data that is real-time, machine-readable, and grounded in real-world exploitability rather than theoretical severity.”</p><h2 id="designing-for-machine-consumption">Designing for machine consumption</h2><p>Efforts to modernize the NVD should focus primarily on designing it for “machine consumption”, according to Rob O’Connor, EMEA <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>at Insight. </p><p>With AI playing an increasing role in vulnerability management, curating easily consumed information could help speed up reaction times for security practitioners. </p><p>“I’d recommend designing it primarily for machine consumption, with human users as a secondary consideration,” he told <em>ITPro</em>. “As vulnerability management becomes more automated, data needs to be structured so machines can interpret and act on it easily, while remaining clear and useful for human analysts.”</p><p>Douglas McKee, director of vulnerability intelligence at Rapid7, noted that the ecosystem has already begun moving toward “structured enrichment” through <a href="https://www.cve.org/ProgramOrganization/ADPs" target="_blank">authorized data publishers (ADPs)</a>.</p><p>These are organizations that are authorized to “enrich the content” of CVE records, a practice that NIST noted earlier this year that it will roll back. </p><p>Elsewhere, standards such as the <a href="https://www.csaf.io/">Common Security Advisory Framework (CSAF)</a> and the <a href="https://cyclonedx.org/capabilities/vex/">Vulnerability Exploitability eXchange (VEX)</a> also provide machine-readable information on what specific products are affected by flaws.</p><p>“Those are exactly the kind of building blocks an automated vulnerability management system needs,” McKee told <em>ITPro</em>. </p><p>“I would move the NVD toward a federated enrichment model rather than trying to make NIST the place where every piece of vulnerability analysis has to happen. Let CNAs, vendors, researchers, and qualified data publishers contribute structured enrichment while the NVD acts as the trusted aggregation and normalization layer.”</p><p>Morin echoed McKee and O’Connor’s comments regarding machine-speed upgrades to the database. </p><p>“My core recommendation would be to evolve the NVD from telling defenders a vulnerability exists to telling them the extent to which it matters in production environments, in real time and in a form machine-speed security can act on,” she said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/nist-national-vulnerability-database-modernization-machine-speed-consumption</link>
                                                                            <description>
                            <![CDATA[ The National Vulnerability Database was designed for human-speed. Advances in AI mean it needs a much-needed overhaul ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HDjrAfXsf83JW2JHGdo6nB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y7KM9xXWdcmTpuScLoy7jW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 07:35:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ ross.kelly@futurenet.com (Ross Kelly) ]]></author>                    <dc:creator><![CDATA[ Ross Kelly ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Y5vrV2V98Np6jHAGmAtCd3.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Ross Kelly is ITPro&#039;s News &amp;amp; Analysis Editor, with a keen interest in cyber security, business leadership and emerging technologies.&lt;/p&gt;
&lt;p&gt;He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In his spare time, Ross enjoys cycling, walking and is an avid reader of history and non-fiction.&lt;/p&gt;
&lt;p&gt;You can contact Ross at ross.kelly@futurenet.com or on &lt;a href=&quot;https://twitter.com/rosswritesetc&quot;&gt;Twitter&lt;/a&gt; and &lt;a href=&quot;https://www.linkedin.com/in/ross-kelly-18a54411a/&quot;&gt;LinkedIn&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y7KM9xXWdcmTpuScLoy7jW-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Software vulnerability concept image depicting a digitized padlock with pixels fragmenting and drifting away.]]></media:description>                                                            <media:text><![CDATA[Software vulnerability concept image depicting a digitized padlock with pixels fragmenting and drifting away.]]></media:text>
                                <media:title type="plain"><![CDATA[Software vulnerability concept image depicting a digitized padlock with pixels fragmenting and drifting away.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y7KM9xXWdcmTpuScLoy7jW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>NIST has issued a call for advice on how it can modernize the <a href="https://www.itpro.com/security/the-cve-system-isnt-working-what-next">National Vulnerability Database (NVD) </a>in light of recent AI advances – cyber experts have told <em>ITPro </em>that it’s desperately needed. </p><p>In a recent <a href="https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of" target="_blank">request for information</a> (RFI), the institute said it is seeking stakeholder input on how to overhaul the vulnerability reporting service. The NVD plays a key role in helping organizations keep their finger on the pulse of the threat landscape. </p><p>The database acts as a catalog for software and hardware-related security flaws, drawing on the Common Vulnerabilities and Exposures (CVE) system to provide details and guidance on vulnerabilities. </p><p>Yet recent AI advances, particularly in the cybersecurity field, have raised the stakes when it comes to vulnerability identification and remediation. </p><p>Rob O’Connor, EMEA CISO at Insight, told <em>ITPro </em>that “the economics of vulnerability discovery have changed” due to AI. Humans simply can’t match the speed of agents, and that creates blind spots for security teams. </p><p>“Automated agents can analyse and triage code at a scale humans can no longer match,” he said. “This means the bottleneck now isn’t finding the vulnerabilities. Instead, it’s in contextualising and remediating them.”</p><p>Researchers at Forescout <a href="https://www.itpro.com/security/brace-yourselves-for-a-vulnerability-explosion-forescout-warns">told <em>ITPro earlier </em>this year that businesses should prepare for an explosion of vulnerabilities</a>, with AI now being used to identify software flaws at record pace.</p><p>Some big tech companies have already taken action on this front, including Apple. In late June, the company <a href="https://www.itpro.com/software/apple-is-speeding-up-software-updates-due-to-ai-security-concerns-heres-what-you-need-to-know">revealed plans to speed up software patching </a>in direct response to AI.</p><p>At the core of NIST’s request, the institute said the goal is to “improve the NVD’s scalability, automation, interoperability, transparency, and utility”. </p><p>Put simply, AI is speeding things up, and the NVD needs to match the pace of vulnerability disclosures, which the institute itself <a href="https://www.itpro.com/security/nist-national-vulnerability-database-overhaul-increased-cve-submissions">recently admitted has become untenable</a>. </p><p>In April, NIST revealed it would scrap efforts to analyze every submitted CVE, instead focusing on only the most severe vulnerabilities. The shake-up means that only CVEs that meet certain criteria will be ‘enriched’ with additional details and guidance. </p><h2 id="the-nvd-was-built-around-human-speed">The NVD was built around human speed</h2><p>A key issue with the NVD in its current state is that it was designed around “human speed”, according to Crystal Morin, senior <a href="https://www.itpro.com/security/28133/what-is-cyber-security">cybersecurity </a>strategist at Sysdig. </p><p>The database launched in 2005, having evolved from an earlier setup known as the Internet-Categorization of Attacks Toolkit (ICAT). The scale – and indeed, speed – of threats at that time pales in comparison to what organizations face in 2026. </p><p>That’s not to suggest that reporting standards are obsolete, though - they just need a rethink to remain fit-for-purpose in an AI-powered era. </p><p>“They were designed for human speed. We now operate in a machine-speed world. A CVE with a static severity score tells you a flaw exists and, roughly, how bad it could be in theory. It doesn’t tell you whether it is exploitable in your environment, or if it’s already being weaponized,” she told <em>ITPro</em>. </p><p>With AI in the mix, Morin said this creates two distinct gaps: namely speed and the detail required to act on potential vulnerabilities. </p><p>“The reporting and enrichment pipeline still moves in weeks while exploitation moves in hours,” she said. “Second, the same detailed advisory that helps defenders is also raw material for AI-generated exploit code.”</p><p>“Ultimately, severity scoring on its own drives the ‘patch everything’ behavior that simply does not scale.”</p><p>Morin noted that Sysdig’s threat intelligence unit saw this dynamic play out in real-time when a Langflow vulnerability with a 9.9 CVSS score “essentially sat untouched while a lower-scored 9.3 vulnerability in the same product was mass exploited”.</p><p>“Standards must evolve toward data that is real-time, machine-readable, and grounded in real-world exploitability rather than theoretical severity.”</p><h2 id="designing-for-machine-consumption">Designing for machine consumption</h2><p>Efforts to modernize the NVD should focus primarily on designing it for “machine consumption”, according to Rob O’Connor, EMEA <a href="https://www.itpro.com/careers/28228/ciso-job-description-what-does-a-ciso-do">CISO </a>at Insight. </p><p>With AI playing an increasing role in vulnerability management, curating easily consumed information could help speed up reaction times for security practitioners. </p><p>“I’d recommend designing it primarily for machine consumption, with human users as a secondary consideration,” he told <em>ITPro</em>. “As vulnerability management becomes more automated, data needs to be structured so machines can interpret and act on it easily, while remaining clear and useful for human analysts.”</p><p>Douglas McKee, director of vulnerability intelligence at Rapid7, noted that the ecosystem has already begun moving toward “structured enrichment” through <a href="https://www.cve.org/ProgramOrganization/ADPs" target="_blank">authorized data publishers (ADPs)</a>.</p><p>These are organizations that are authorized to “enrich the content” of CVE records, a practice that NIST noted earlier this year that it will roll back. </p><p>Elsewhere, standards such as the <a href="https://www.csaf.io/">Common Security Advisory Framework (CSAF)</a> and the <a href="https://cyclonedx.org/capabilities/vex/">Vulnerability Exploitability eXchange (VEX)</a> also provide machine-readable information on what specific products are affected by flaws.</p><p>“Those are exactly the kind of building blocks an automated vulnerability management system needs,” McKee told <em>ITPro</em>. </p><p>“I would move the NVD toward a federated enrichment model rather than trying to make NIST the place where every piece of vulnerability analysis has to happen. Let CNAs, vendors, researchers, and qualified data publishers contribute structured enrichment while the NVD acts as the trusted aggregation and normalization layer.”</p><p>Morin echoed McKee and O’Connor’s comments regarding machine-speed upgrades to the database. </p><p>“My core recommendation would be to evolve the NVD from telling defenders a vulnerability exists to telling them the extent to which it matters in production environments, in real time and in a form machine-speed security can act on,” she said.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘The scale of PurpleDelta’s operation is easy to miss’: Fake North Korean IT workers are submitting so many job applications that companies can’t keep up ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat">Fake North Korean IT workers</a> are taking their job-hunt seriously, submitting as many as 60 job applications per day according to new research. </p><p>Groups of North Korean IT workers, <a href="https://www.recordedfuture.com/research/purpledelta-fraudulent-employment-operations" target="_blank">dubbed PurpleDelta</a> by Recorded Future, created at least 22 fabricated personas, with job applications being made across a range of recruitment websites and <a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat">platforms such as LinkedIn and Upwork</a>. </p><p>Notably, the group is using identity-brokering services, account-renting via <a href="https://www.itpro.com/mobile/remote-access/368059/anydesk-review">AnyDesk</a>, and multi-accounting tools. </p><p>Researchers found these fraudulent workers are often coordinating via Telegram and Slack, with support from facilitators who procure and maintain company-issued hardware on the operators' behalf.</p><p>“A successful job placement provides the PurpleDelta operation with a steady income and places a false employee within a company’s normal systems," said Alexander Leslie, senior advisor at Recorded Future. </p><p>"Wages are often funnelled toward sanctioned North Korean military and nuclear programs, and access may also expose information that was never meant to leave a company.”</p><h2 id="fake-north-korean-it-workers-are-turning-to-ai">Fake North Korean IT workers are turning to AI</h2><p>The fake workers' applications typically include AI-generated profile photos, custom-configured <a href="https://www.itpro.com/technology/artificial-intelligence/openai-just-revealed-what-people-really-use-chatgpt-for-and-70-percent-of-queries-have-nothing-to-do-with-work">ChatGPT </a>assistants, and identity documents sourced from an illicit ID-generation service. </p><p>In terms of targets, researchers noted they’ve been applying for jobs at software and technology companies, as well as healthcare and biotechnology firms. Some appear to have been successful, according to Recorded Future, infiltrating at least 10 organizations. </p><p>Once inside, the fraudulent workers recorded internal meetings, used screen recording software during work sessions, and drafted pre-written Google Translate excuses to justify the use of personal devices and personal bank accounts. </p><p>“The scale of PurpleDelta’s operation is easy to miss when a company sees only one application," said Leslie. </p><p>"During interviews, PurpleDelta operators copied transcribed questions into ChatGPT and read the answers back, sometimes word for word, and occasionally repeated incorrect answers. A candidate can sound prepared without fully understanding what they are saying, which makes ordinary interview cues less reliable."</p><h2 id="manipulating-company-hardware">Manipulating company hardware</h2><p>In some cases, Recorded Future said fraudulent workers received a company laptop and kept it and connected it in the country where they claim to live - usually the US, Germany or Brazil. </p><p>In one instance, researchers spotted one operative managing at least four identities simultaneously. </p><p>“PurpleDelta can recover quickly when one identity is exposed and a persona can be replaced," said Leslie. </p><p>"The same application machinery can keep running under a new name, and organizations should expect these operatives to adjust their methods as hiring teams become more familiar with them. Continued verification gives companies a better chance of catching changes."</p><p>Researchers warned that these fraudulent workers have been highly successful so far, collecting high-value intelligence and exfiltrating proprietary data, source code, and internal communications in support of North Korean state objectives. </p><p>"Companies should verify an employee’s identity after hiring, checking this during onboarding, so they can confirm where a worker and the hardware actually are," Leslie said. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/the-scale-of-purpledeltas-operation-is-easy-to-miss-fake-north-korean-it-workers-are-submitting-so-many-job-applications-that-companies-cant-keep-up</link>
                                                                            <description>
                            <![CDATA[ The PurpleDelta group is applying for thousands of jobs to steal proprietary data, source code, and internal communications ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">osiLPVSnYqZZJKwzNyTEGM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 11:16:46 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:description>                                                            <media:text><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean hacker concept image showing a man in military uniform working on a laptop computer with flag of North Korea pictured on screen in background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rBaWcKkPGkJSvaRS3NHzSB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat">Fake North Korean IT workers</a> are taking their job-hunt seriously, submitting as many as 60 job applications per day according to new research. </p><p>Groups of North Korean IT workers, <a href="https://www.recordedfuture.com/research/purpledelta-fraudulent-employment-operations" target="_blank">dubbed PurpleDelta</a> by Recorded Future, created at least 22 fabricated personas, with job applications being made across a range of recruitment websites and <a href="https://www.itpro.com/security/cyber-attacks/north-korean-it-workers-the-growing-threat">platforms such as LinkedIn and Upwork</a>. </p><p>Notably, the group is using identity-brokering services, account-renting via <a href="https://www.itpro.com/mobile/remote-access/368059/anydesk-review">AnyDesk</a>, and multi-accounting tools. </p><p>Researchers found these fraudulent workers are often coordinating via Telegram and Slack, with support from facilitators who procure and maintain company-issued hardware on the operators' behalf.</p><p>“A successful job placement provides the PurpleDelta operation with a steady income and places a false employee within a company’s normal systems," said Alexander Leslie, senior advisor at Recorded Future. </p><p>"Wages are often funnelled toward sanctioned North Korean military and nuclear programs, and access may also expose information that was never meant to leave a company.”</p><h2 id="fake-north-korean-it-workers-are-turning-to-ai">Fake North Korean IT workers are turning to AI</h2><p>The fake workers' applications typically include AI-generated profile photos, custom-configured <a href="https://www.itpro.com/technology/artificial-intelligence/openai-just-revealed-what-people-really-use-chatgpt-for-and-70-percent-of-queries-have-nothing-to-do-with-work">ChatGPT </a>assistants, and identity documents sourced from an illicit ID-generation service. </p><p>In terms of targets, researchers noted they’ve been applying for jobs at software and technology companies, as well as healthcare and biotechnology firms. Some appear to have been successful, according to Recorded Future, infiltrating at least 10 organizations. </p><p>Once inside, the fraudulent workers recorded internal meetings, used screen recording software during work sessions, and drafted pre-written Google Translate excuses to justify the use of personal devices and personal bank accounts. </p><p>“The scale of PurpleDelta’s operation is easy to miss when a company sees only one application," said Leslie. </p><p>"During interviews, PurpleDelta operators copied transcribed questions into ChatGPT and read the answers back, sometimes word for word, and occasionally repeated incorrect answers. A candidate can sound prepared without fully understanding what they are saying, which makes ordinary interview cues less reliable."</p><h2 id="manipulating-company-hardware">Manipulating company hardware</h2><p>In some cases, Recorded Future said fraudulent workers received a company laptop and kept it and connected it in the country where they claim to live - usually the US, Germany or Brazil. </p><p>In one instance, researchers spotted one operative managing at least four identities simultaneously. </p><p>“PurpleDelta can recover quickly when one identity is exposed and a persona can be replaced," said Leslie. </p><p>"The same application machinery can keep running under a new name, and organizations should expect these operatives to adjust their methods as hiring teams become more familiar with them. Continued verification gives companies a better chance of catching changes."</p><p>Researchers warned that these fraudulent workers have been highly successful so far, collecting high-value intelligence and exfiltrating proprietary data, source code, and internal communications in support of North Korean state objectives. </p><p>"Companies should verify an employee’s identity after hiring, checking this during onboarding, so they can confirm where a worker and the hardware actually are," Leslie said. </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Wiz CTO speaks out amid confusion over Snowflake-GitHub Copilot flaw ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.itpro.com/business/business-strategy/google-confirms-wiz-acquisition-in-record-breaking-usd32-billion-deal">Wiz</a> claims its AI found a flaw written and reviewed by GitHub Copilot, but the developer platform has pinned the blame on boring old human error. </p><p>In a <a href="https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug" target="_blank"><u>blog post</u></a> this week Wiz Research said that its Red Agent, an AI-powered bug hunting tool, had spotted a vulnerability in one of Snowflake's public repositories. </p><p>That is very much what Red Agent is designed to do, but the Google-owned security company claimed that the flaw had actually been introduced by AI itself, pinning the fault on <a href="https://www.itpro.com/software/development/github-copilot-pricing-changes-usage-based-billing-explained">GitHub Copilot</a>. </p><p>"This incident highlights a new reality in software development: Critical vulnerabilities can still be introduced and approved within workflows involving AI coding agents and can still pass established automated security checks," wrote Gal Nagli, head of offensive security at Wiz.. </p><p>Except that's not exactly what happened here. Wiz researchers noted that the flaw listed “Copilot Autofix powered by AI” as a co-author. After sifting through the commits, <a href="https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html"><u><em>The Hacker News</em></u></a> noted that the section with the flaw was actually attributable to a Snowflake engineer, while Copilot changed certain aspects. </p><p>Wiz has since updated its blog post to clarify this. In a statement given to <em>ITPro</em>, Wiz co-founder and CTO Ami Luttwak offered additional details on the incident. </p><p>“The relevant PR was co-authored by multiple contributors including Copilot. Initially the blog implied the vulnerable code flow was generated by AI,” Luttwak explained. </p><p>“Soon after the blog was published, we issued an update following community feedback to clarify that the specific lines of code that caused the vulnerability, were not created by copilot (although it is mentioned as a co-author). Note that copilot did participate in the PR and contributed code and also scanned these specific lines via GitHub advanced security (AI code scanner) that missed the vulnerable flow.”</p><p>Luttwak noted that the case shows that clear attribution between humans and AI is “becoming a bit harder to establish”. </p><p>“Just looking at co-authors of the PR is not enough,” he added. </p><h2 id="wiz-did-find-a-snowflake-flaw">Wiz did find a Snowflake flaw</h2><p>Regardless of the co-author confusion, a flaw in Snowflake was indeed found. </p><p>Wiz Red Agent spotted a script injection vulnerability that would have allowed an unauthenticated user to execute arbitrary commands “within a GitHub Actions runner by opening a <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>issue with a specially crafted title," the company noted. </p><p>Even if Copilot didn't write the flaw, Wiz said the issue still wasn’t spotted when it was reviewed. </p><p>"GitHub Advanced Security scan analyzed the final PR revision, including the vulnerable workflow, but did not flag the critical injection," Nagli added. </p><p>The flaw was responsibly disclosed at the end of June to Snowflake, which quickly fixed the issue and confirmed that no-one but Wiz had made use of the vulnerability. </p><p>"Snowflake appreciates Wiz's responsible reporting of and collaboration around these findings through our vulnerability disclosure and bug bounty program, <a href="https://www.itpro.com/business/leadership/hackerone-eyes-enterprise-growth-with-double-c-suite-appointment">HackerOne</a>," Snowflake said via a statement on Wiz's blog post. </p><p>"The disclosure was received on June 23, 2026, and it was immediately investigated and remediated, and our investigation found no evidence of unauthorized access."</p><p>Indeed, the flaw had only been live five days before Wiz Red Agent spotted it — and perhaps that's the real story, from published to uncovered to fixed in just five days, it's clear AI is speeding up the pace of security. </p><p>"The vulnerability was live for only five days before an automated agent discovered and validated it," Nagli said in the blog post. "Security operations must adapt to a landscape where automated discovery occurs in hours, requiring rapid patch cycles and short-lived credentials."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/wiz-cto-speaks-out-amid-snowflake-github-flaw-confusion</link>
                                                                            <description>
                            <![CDATA[ Did Wiz spot an AI-written bug? Maybe not, but it did catch a five-day-old flaw ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XG5UbyEvRP8HSH432ZTJMD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 09:36:06 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Aug 2026 09:37:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nicole Kobie ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/8Y8JDDTQ7XDEk49FoAFP2S.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nicole Kobie first started writing for ITPro in 2007. As a freelance journalist covering technology and business, Nicole&#039;s work includes  bylines in New Scientist, Wired, PC Pro and many more. &lt;/p&gt;&lt;p&gt;Nicole the author of a book about the history of technology, The Long History of the Future.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:description>                                                            <media:text><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:text>
                                <media:title type="plain"><![CDATA[An abstract image showing a skull over a pixelated background to symbolise a cyber security vulnerability]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rcgqGm2k9qbr9K4kHhEmvU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.itpro.com/business/business-strategy/google-confirms-wiz-acquisition-in-record-breaking-usd32-billion-deal">Wiz</a> claims its AI found a flaw written and reviewed by GitHub Copilot, but the developer platform has pinned the blame on boring old human error. </p><p>In a <a href="https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug" target="_blank"><u>blog post</u></a> this week Wiz Research said that its Red Agent, an AI-powered bug hunting tool, had spotted a vulnerability in one of Snowflake's public repositories. </p><p>That is very much what Red Agent is designed to do, but the Google-owned security company claimed that the flaw had actually been introduced by AI itself, pinning the fault on <a href="https://www.itpro.com/software/development/github-copilot-pricing-changes-usage-based-billing-explained">GitHub Copilot</a>. </p><p>"This incident highlights a new reality in software development: Critical vulnerabilities can still be introduced and approved within workflows involving AI coding agents and can still pass established automated security checks," wrote Gal Nagli, head of offensive security at Wiz.. </p><p>Except that's not exactly what happened here. Wiz researchers noted that the flaw listed “Copilot Autofix powered by AI” as a co-author. After sifting through the commits, <a href="https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html"><u><em>The Hacker News</em></u></a> noted that the section with the flaw was actually attributable to a Snowflake engineer, while Copilot changed certain aspects. </p><p>Wiz has since updated its blog post to clarify this. In a statement given to <em>ITPro</em>, Wiz co-founder and CTO Ami Luttwak offered additional details on the incident. </p><p>“The relevant PR was co-authored by multiple contributors including Copilot. Initially the blog implied the vulnerable code flow was generated by AI,” Luttwak explained. </p><p>“Soon after the blog was published, we issued an update following community feedback to clarify that the specific lines of code that caused the vulnerability, were not created by copilot (although it is mentioned as a co-author). Note that copilot did participate in the PR and contributed code and also scanned these specific lines via GitHub advanced security (AI code scanner) that missed the vulnerable flow.”</p><p>Luttwak noted that the case shows that clear attribution between humans and AI is “becoming a bit harder to establish”. </p><p>“Just looking at co-authors of the PR is not enough,” he added. </p><h2 id="wiz-did-find-a-snowflake-flaw">Wiz did find a Snowflake flaw</h2><p>Regardless of the co-author confusion, a flaw in Snowflake was indeed found. </p><p>Wiz Red Agent spotted a script injection vulnerability that would have allowed an unauthenticated user to execute arbitrary commands “within a GitHub Actions runner by opening a <a href="https://www.itpro.com/open-source/31833/what-is-github">GitHub </a>issue with a specially crafted title," the company noted. </p><p>Even if Copilot didn't write the flaw, Wiz said the issue still wasn’t spotted when it was reviewed. </p><p>"GitHub Advanced Security scan analyzed the final PR revision, including the vulnerable workflow, but did not flag the critical injection," Nagli added. </p><p>The flaw was responsibly disclosed at the end of June to Snowflake, which quickly fixed the issue and confirmed that no-one but Wiz had made use of the vulnerability. </p><p>"Snowflake appreciates Wiz's responsible reporting of and collaboration around these findings through our vulnerability disclosure and bug bounty program, <a href="https://www.itpro.com/business/leadership/hackerone-eyes-enterprise-growth-with-double-c-suite-appointment">HackerOne</a>," Snowflake said via a statement on Wiz's blog post. </p><p>"The disclosure was received on June 23, 2026, and it was immediately investigated and remediated, and our investigation found no evidence of unauthorized access."</p><p>Indeed, the flaw had only been live five days before Wiz Red Agent spotted it — and perhaps that's the real story, from published to uncovered to fixed in just five days, it's clear AI is speeding up the pace of security. </p><p>"The vulnerability was live for only five days before an automated agent discovered and validated it," Nagli said in the blog post. "Security operations must adapt to a landscape where automated discovery occurs in hours, requiring rapid patch cycles and short-lived credentials."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The CISO now owns physical security. Here’s what that means for the channel ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For years, selling physical security meant knowing one buyer. The director of physical security, or facilities, signed off on cameras, locks, and badge readers, and the conversation rarely left that room. That buyer is being moved aside.</p><p>Physical security budgets are rising sharply. EY research found that <a href="https://www.facilitiesdive.com/news/more-money-is-going-to-physical-security-but-its-often-cisos-that-overse/820077/"><u>nearly 80% of organizations</u></a> increased spending in the last budget cycle, and more than a quarter have now shifted oversight to the CISO, a role built for network defense, not card readers and lockdown logic. The money is growing, and the person controlling it has changed. For Value-Added-Resellers (VARs), Managed Service Providers (MSPs) and integrators, that is the most important shift in this market, and the partners who haven’t adjusted their go-to-market are still pitching buyers who no longer control the budget.</p><p>Here is what that looks like on the ground. A reseller who used to walk in with a door schedule now sits across from a CISO who wants to see NIST CSF mappings. An integrator arrives for a campus deployment and finds the cybersecurity team holds policy authority over systems they have never seen up close. Deals that should close stall, because no one in the room feels accountable for a physical incident. The handoff is happening faster than buying committees are used to.</p><p>Four things will determine which partners own this shift - and which get left behind.</p><h2 id="who-actually-owns-the-budget-now">Who actually owns the budget now?</h2><p>Map the buying committee before you pitch anything. In most organizations going through this shift, the CISO owns the budget and the risk, but the physical security or facilities lead still owns day-to-day operations. Both are in the room. </p><p>If you assume the old buyer is still in charge, you will lose to a competitor who figured out the money moved. Your first job on any new opportunity is to establish who signs, who operates, and who is accountable when something goes wrong. In a convergence deal, those are often three different stakeholders.</p><h2 id="how-do-you-earn-credibility-with-a-ciso-who-has-never-run-a-physical-system">How do you earn credibility with a CISO who has never run a physical system?</h2><p>Learn their language. A CISO does not think in door schedules and panel counts; they think in frameworks, risk, and auditability. When you can map a physical access control deployment to NIST CSF, explain how it changes their attack surface, and show how you would prove it works under audit, you stop being a hardware vendor and become someone they can defend a budget line to.</p><p>The mistake we see most often is the reverse: walking a CISO through the technical detail of the physical install. That buyer does not want the schematic. They want to know what risk you remove, what you can attest to, and what happens when something is compromised. Translate physical implementation into security outcomes, and you will be in conversations your competitors never reach.</p><h2 id="where-can-partners-attach-services">Where can partners attach services?</h2><p>The opportunity sits in the gap nobody owns: the space between IT policy and physical implementation.</p><p>In the deployments we work on at Acre, that gap is almost always wider than the organization expects. The CISO sets policy, the facilities team runs the hardware, but almost no one owns the interface between them- the integration that decides what the physical system does when the identity provider is compromised, or what happens to a badge when a credential is exposed. </p><p>That is billable work, and it recurs: assessments that map physical controls to the security framework, integration between access control and identity systems, and managed services that keep the two estates talking and produce the evidence an auditor will ask for. This is where partners move from one-time installers to retained advisors, which is the more durable revenue anyway.</p><h2 id="how-do-you-structure-the-sale-when-the-buying-committee-has-changed">How do you structure the sale when the buying committee has changed?</h2><p>Sell to the committee, not the individual. The deals that stall are the ones pitched to one stakeholder while another quietly holds a veto. Get the CISO, the physical security lead, and, often, IT into the same conversation early, and make accountability explicit. </p><p>Who owns a physical breach? Who owns a credential compromise that has physical consequences? When you name those owners in the room, you remove the ambiguity that kills deals, and you position yourself as the partner who understands the new org chart rather than the one still selling to the old one.</p><p>None of this requires the channel to become a cybersecurity practice overnight. It requires recognizing that the buyer has changed, learning enough of the CISO’s language to be credible, and building services around the integration gap the convergence created. </p><p>The partners who make that shift will own the relationship as physical and digital security keep merging. The ones who don’t will keep pitching to a room that’s already moved on.</p><p>The budgets are there. The question is: Are your conversations reaching the people who control that money?</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/the-ciso-now-owns-physical-security-heres-what-that-means-for-the-channel</link>
                                                                            <description>
                            <![CDATA[ Physical security budgets have moved to CISOs, and partners must adapt to this important shift ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BnxYQKT4SpVNPTVCqCmzYG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/tgkJFyUdDXpZ6K4JudVfCE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kumar Sokka ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/rogaiTcHwVmqEPQqMSJ5m6.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/tgkJFyUdDXpZ6K4JudVfCE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A CGI image of a padlock on a blue background, with glowing data points on top of it to represent cybersecurity.]]></media:description>                                                            <media:text><![CDATA[A CGI image of a padlock on a blue background, with glowing data points on top of it to represent cybersecurity.]]></media:text>
                                <media:title type="plain"><![CDATA[A CGI image of a padlock on a blue background, with glowing data points on top of it to represent cybersecurity.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/tgkJFyUdDXpZ6K4JudVfCE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For years, selling physical security meant knowing one buyer. The director of physical security, or facilities, signed off on cameras, locks, and badge readers, and the conversation rarely left that room. That buyer is being moved aside.</p><p>Physical security budgets are rising sharply. EY research found that <a href="https://www.facilitiesdive.com/news/more-money-is-going-to-physical-security-but-its-often-cisos-that-overse/820077/"><u>nearly 80% of organizations</u></a> increased spending in the last budget cycle, and more than a quarter have now shifted oversight to the CISO, a role built for network defense, not card readers and lockdown logic. The money is growing, and the person controlling it has changed. For Value-Added-Resellers (VARs), Managed Service Providers (MSPs) and integrators, that is the most important shift in this market, and the partners who haven’t adjusted their go-to-market are still pitching buyers who no longer control the budget.</p><p>Here is what that looks like on the ground. A reseller who used to walk in with a door schedule now sits across from a CISO who wants to see NIST CSF mappings. An integrator arrives for a campus deployment and finds the cybersecurity team holds policy authority over systems they have never seen up close. Deals that should close stall, because no one in the room feels accountable for a physical incident. The handoff is happening faster than buying committees are used to.</p><p>Four things will determine which partners own this shift - and which get left behind.</p><h2 id="who-actually-owns-the-budget-now">Who actually owns the budget now?</h2><p>Map the buying committee before you pitch anything. In most organizations going through this shift, the CISO owns the budget and the risk, but the physical security or facilities lead still owns day-to-day operations. Both are in the room. </p><p>If you assume the old buyer is still in charge, you will lose to a competitor who figured out the money moved. Your first job on any new opportunity is to establish who signs, who operates, and who is accountable when something goes wrong. In a convergence deal, those are often three different stakeholders.</p><h2 id="how-do-you-earn-credibility-with-a-ciso-who-has-never-run-a-physical-system">How do you earn credibility with a CISO who has never run a physical system?</h2><p>Learn their language. A CISO does not think in door schedules and panel counts; they think in frameworks, risk, and auditability. When you can map a physical access control deployment to NIST CSF, explain how it changes their attack surface, and show how you would prove it works under audit, you stop being a hardware vendor and become someone they can defend a budget line to.</p><p>The mistake we see most often is the reverse: walking a CISO through the technical detail of the physical install. That buyer does not want the schematic. They want to know what risk you remove, what you can attest to, and what happens when something is compromised. Translate physical implementation into security outcomes, and you will be in conversations your competitors never reach.</p><h2 id="where-can-partners-attach-services">Where can partners attach services?</h2><p>The opportunity sits in the gap nobody owns: the space between IT policy and physical implementation.</p><p>In the deployments we work on at Acre, that gap is almost always wider than the organization expects. The CISO sets policy, the facilities team runs the hardware, but almost no one owns the interface between them- the integration that decides what the physical system does when the identity provider is compromised, or what happens to a badge when a credential is exposed. </p><p>That is billable work, and it recurs: assessments that map physical controls to the security framework, integration between access control and identity systems, and managed services that keep the two estates talking and produce the evidence an auditor will ask for. This is where partners move from one-time installers to retained advisors, which is the more durable revenue anyway.</p><h2 id="how-do-you-structure-the-sale-when-the-buying-committee-has-changed">How do you structure the sale when the buying committee has changed?</h2><p>Sell to the committee, not the individual. The deals that stall are the ones pitched to one stakeholder while another quietly holds a veto. Get the CISO, the physical security lead, and, often, IT into the same conversation early, and make accountability explicit. </p><p>Who owns a physical breach? Who owns a credential compromise that has physical consequences? When you name those owners in the room, you remove the ambiguity that kills deals, and you position yourself as the partner who understands the new org chart rather than the one still selling to the old one.</p><p>None of this requires the channel to become a cybersecurity practice overnight. It requires recognizing that the buyer has changed, learning enough of the CISO’s language to be credible, and building services around the integration gap the convergence created. </p><p>The partners who make that shift will own the relationship as physical and digital security keep merging. The ones who don’t will keep pitching to a room that’s already moved on.</p><p>The budgets are there. The question is: Are your conversations reaching the people who control that money?</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why software supply chain security is the next accountability challenge for channel partners ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Modern applications rely heavily on open-source packages and third-party dependencies, meaning almost every application organizations run is built on layers of code written by people outside the organization. </p><p>Channel partners are often responsible for recommending, integrating and managing these environments. As a result, when a dependency is compromised, accountability increasingly lands with the partner managing the stack.</p><h2 id="why-vulnerable-and-malicious-packages-remain-in-production">Why vulnerable and malicious packages remain in production</h2><p>Unfortunately, public disclosure does not equal remediation. Organizations continue running outdated or vulnerable dependencies months after Common Vulnerabilities and Exposures (CVEs) become public, and this is increasingly becoming the norm. <a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth"><u>CVE volume has grown</u></a> by 263% since 2020, with 2026 already seeing a further 33% increase. At this pace, security teams are struggling to digest the volume of vulnerabilities, let alone prioritise and implement effective remediation plans. </p><p>Many Managed Service Providers (MSPs) and consultancies also inherit environments they didn't originally architect. Combined with security frameworks that were designed around infrastructure and endpoints rather than continuously evolving software dependencies, the challenge becomes even greater. Moreover, the growing use of AI-assisted development is adding another layer of complexity, accelerating software creation while increasing the volume of third-party code and dependencies entering production. </p><p>Modern applications can contain hundreds of transitive dependencies, making it difficult to maintain an accurate inventory of what's actually running in production. Limited adoption of Software Bills of Materials (SBOMs), alongside the challenge of auditing applications thoroughly, only compounds the problem. Meanwhile, CVE severity scores don't always reflect real-world exploitability, making triage more difficult and further delaying remediation.</p><h2 id="how-supply-chain-attacks-are-changing-the-threat-model">How supply chain attacks are changing the threat model</h2><p>A single compromised dependency can now create risk across multiple customer environments simultaneously and at speed. Attackers are increasingly targeting shared development tooling and open-source repositories, exploiting assumptions around shared responsibility and the belief that someone else is managing the risk.</p><p>Traditional perimeter-based security was never designed for trusted software components becoming the attack vector. Increasingly, nation-state actors and organized cybercriminal groups are targeting open-source maintainers directly, recognising that compromising a widely used dependency offers far greater scale than attacking individual endpoints.</p><p>Because these attacks are delivered through trusted, signed software components, they can bypass many traditional detection controls. In many cases, organizations receive few, if any, alerts, leaving security teams unaware until the compromise has already spread.</p><h2 id="new-expectations">New expectations</h2><p>Clients increasingly expect partners to explain software supply chain risk in business terms, marking a shift from reactive remediation to demonstrable governance. Visibility, software inventories, and continuous monitoring are quickly becoming baseline expectations rather than value-added services.</p><p>Cyber insurance underwriters are also asking for evidence of SBOM practices and software inventory controls. Partners who cannot demonstrate these capabilities risk creating challenges for clients during policy renewals, which can ultimately affect the services they are trusted to deliver. At the same time, legal and procurement teams are beginning to include software supply chain requirements in vendor contracts, meaning partners need to be prepared for increasingly detailed conversations.</p><p>For partners, this represents more than another security challenge. Clients increasingly need help understanding software supply chain risk, interpreting SBOMs, assessing third-party dependencies, and embedding these practices into procurement and governance. Those who can provide this expertise move from being technology providers to trusted advisors. </p><h2 id="the-responsibility-and-accountability-expansion">The responsibility and accountability expansion</h2><p>Software supply chain security is becoming a defining issue for partners operating across cloud and DevSecOps environments. As responsibility for managing modern development environments expands, so too does accountability when something goes wrong. To retain client trust, partners must move beyond fragmented tooling and demonstrate a clear, structured approach to managing software supply chain risk at scale.</p><p>Partners that get ahead of this have an opportunity to differentiate themselves. Rather than viewing software supply chain security as another compliance exercise, they can provide credible answers to the questions clients and their boards are already asking.</p><p>The conversation is also changing commercially. It has shifted from the value proposition of fixing vulnerabilities after the event to providing continuous assurance. For partners, that's an opportunity to deepen customer relationships while developing new security services that generate recurring revenue. </p><p>Within boardrooms, conversations are increasingly focused on who owns software supply chain risk, what impact it could have on the business, and what the financial implications might be. </p><p>Partners that cannot answer those questions risk losing credibility and, ultimately, customer relationships. Partners that can answer those questions with a proven strategy are much more likely to have stronger client adoption, expanded revenue opportunity, and longer-lasting relationships.  </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/why-software-supply-chain-security-is-the-next-accountability-challenge-for-channel-partners</link>
                                                                            <description>
                            <![CDATA[ Partners need to be able to confidently answer key client questions relating to supply chain security going forward... ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CExBMbRkEmJqrFm3PzvZhb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Hr8Z3QGRRnSdJ7oqmTW3V6-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 16:56:40 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Amir Akhtar ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Ztwq8hts48LYRZxB6r87cW.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Hr8Z3QGRRnSdJ7oqmTW3V6-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital chain link hologram on future tech background.]]></media:description>                                                            <media:text><![CDATA[Digital chain link hologram on future tech background.]]></media:text>
                                <media:title type="plain"><![CDATA[Digital chain link hologram on future tech background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Hr8Z3QGRRnSdJ7oqmTW3V6-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Modern applications rely heavily on open-source packages and third-party dependencies, meaning almost every application organizations run is built on layers of code written by people outside the organization. </p><p>Channel partners are often responsible for recommending, integrating and managing these environments. As a result, when a dependency is compromised, accountability increasingly lands with the partner managing the stack.</p><h2 id="why-vulnerable-and-malicious-packages-remain-in-production">Why vulnerable and malicious packages remain in production</h2><p>Unfortunately, public disclosure does not equal remediation. Organizations continue running outdated or vulnerable dependencies months after Common Vulnerabilities and Exposures (CVEs) become public, and this is increasingly becoming the norm. <a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth"><u>CVE volume has grown</u></a> by 263% since 2020, with 2026 already seeing a further 33% increase. At this pace, security teams are struggling to digest the volume of vulnerabilities, let alone prioritise and implement effective remediation plans. </p><p>Many Managed Service Providers (MSPs) and consultancies also inherit environments they didn't originally architect. Combined with security frameworks that were designed around infrastructure and endpoints rather than continuously evolving software dependencies, the challenge becomes even greater. Moreover, the growing use of AI-assisted development is adding another layer of complexity, accelerating software creation while increasing the volume of third-party code and dependencies entering production. </p><p>Modern applications can contain hundreds of transitive dependencies, making it difficult to maintain an accurate inventory of what's actually running in production. Limited adoption of Software Bills of Materials (SBOMs), alongside the challenge of auditing applications thoroughly, only compounds the problem. Meanwhile, CVE severity scores don't always reflect real-world exploitability, making triage more difficult and further delaying remediation.</p><h2 id="how-supply-chain-attacks-are-changing-the-threat-model">How supply chain attacks are changing the threat model</h2><p>A single compromised dependency can now create risk across multiple customer environments simultaneously and at speed. Attackers are increasingly targeting shared development tooling and open-source repositories, exploiting assumptions around shared responsibility and the belief that someone else is managing the risk.</p><p>Traditional perimeter-based security was never designed for trusted software components becoming the attack vector. Increasingly, nation-state actors and organized cybercriminal groups are targeting open-source maintainers directly, recognising that compromising a widely used dependency offers far greater scale than attacking individual endpoints.</p><p>Because these attacks are delivered through trusted, signed software components, they can bypass many traditional detection controls. In many cases, organizations receive few, if any, alerts, leaving security teams unaware until the compromise has already spread.</p><h2 id="new-expectations">New expectations</h2><p>Clients increasingly expect partners to explain software supply chain risk in business terms, marking a shift from reactive remediation to demonstrable governance. Visibility, software inventories, and continuous monitoring are quickly becoming baseline expectations rather than value-added services.</p><p>Cyber insurance underwriters are also asking for evidence of SBOM practices and software inventory controls. Partners who cannot demonstrate these capabilities risk creating challenges for clients during policy renewals, which can ultimately affect the services they are trusted to deliver. At the same time, legal and procurement teams are beginning to include software supply chain requirements in vendor contracts, meaning partners need to be prepared for increasingly detailed conversations.</p><p>For partners, this represents more than another security challenge. Clients increasingly need help understanding software supply chain risk, interpreting SBOMs, assessing third-party dependencies, and embedding these practices into procurement and governance. Those who can provide this expertise move from being technology providers to trusted advisors. </p><h2 id="the-responsibility-and-accountability-expansion">The responsibility and accountability expansion</h2><p>Software supply chain security is becoming a defining issue for partners operating across cloud and DevSecOps environments. As responsibility for managing modern development environments expands, so too does accountability when something goes wrong. To retain client trust, partners must move beyond fragmented tooling and demonstrate a clear, structured approach to managing software supply chain risk at scale.</p><p>Partners that get ahead of this have an opportunity to differentiate themselves. Rather than viewing software supply chain security as another compliance exercise, they can provide credible answers to the questions clients and their boards are already asking.</p><p>The conversation is also changing commercially. It has shifted from the value proposition of fixing vulnerabilities after the event to providing continuous assurance. For partners, that's an opportunity to deepen customer relationships while developing new security services that generate recurring revenue. </p><p>Within boardrooms, conversations are increasingly focused on who owns software supply chain risk, what impact it could have on the business, and what the financial implications might be. </p><p>Partners that cannot answer those questions risk losing credibility and, ultimately, customer relationships. Partners that can answer those questions with a proven strategy are much more likely to have stronger client adoption, expanded revenue opportunity, and longer-lasting relationships.  </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hacker claims to have stolen millions of Azure customer records from McDonald’s, Vodafone, Kyndryl, and others – here's what we know so far ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A hacker is advertising data allegedly stolen from an array of companies including McDonald's, Vodafone, Kyndryl, and more. </p><p>Researchers at HudsonRock <a href="https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/" target="_blank">said</a> that the criminal, known as TheHatman, downloaded the databases directly from the organizations’ Azure or Entra portals, claiming to have done so through the use of compromised credentials.</p><p>Other victims include HCL Technologies, IHG Hotels & Resorts, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts.</p><p>"The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics," researchers said. </p><p>"Our researchers went over the data and it seems highly legitimate based on the corporate email addresses found, combined with field names perfectly matching standard Azure directory exports."</p><p>The data – which includes roughly 3.6 million records in total – appears to include full names, corporate email addresses, including active domains and tenant-specific .onmicrosoft.com structures, phone numbers, and physical addresses.</p><p>It also covers employee IDs, job titles, departments, notes, manager details, and direct reports, along with user group memberships, service accounts, and highly privileged account records such as Global Administrator listings.</p><p>"The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations," HudsonRock said.</p><h2 id="thehatman-s-methods-still-unclear">TheHatman's methods still unclear</h2><p>Exact details on how the threat actor gained access to this trove of data remains unclear, according to researchers. </p><p>Possibilities include infostealer <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>infections which compromised employee session tokens, <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns, or a lack of strict <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA) </a>on specific tenant portals. </p><p>Researchers also suggested it could be down to abuse of a third-party API that had excessive read privileges across multiple environments. </p><p>According to HudsonRock, the most likely explanation is a targeted exploitation of infostealer infections rather than a systemic zero-day vulnerability in Azure, as this would have hit a far broader range of victims. </p><h2 id="alleged-victims-react">Alleged victims react</h2><p>Companies said to have been caught up in the breach have begun taking action. </p><p>TCS, for example, has <a href="https://www.bseindia.com/xml-data/corpfiling/AttachLive/ac9edbea-ea43-4c0a-beb8-5239bcd03ec9.pdf" target="_blank">filed a statement</a> with India’s stock exchange, revealing that it hasn’t yet found any credible evidence of a breach of systems or customer environments. </p><p>"The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted," the statement reads. </p><p><em>ITPro </em>approached the other aforementioned victims, but did not receive a response by time of publication. </p><h2 id="valuable-credentials">Valuable credentials</h2><p>Darren Williams, CEO and founder of BlackFog, said that if the claims are legitimate then this once again highlights the value of exposed credentials for cyber criminals. </p><p>These can often represent the keys to the castle for hackers, giving them sweeping access to enterprise environments. </p><p>“The reported use of leaked credentials to access Azure and Entra environments shows how valuable compromised identities have become to cyber criminals," he said.</p><p>"MFA, strong identity controls and employee awareness remain essential, but organizations must assume credentials can be compromised. These measures must be backed by technology that prevents sensitive data from being exfiltrated, even when attackers successfully gain access to the network.”</p><p><strong>UPDATE</strong></p><p>A spokesperson for Vodafone told <em>ITPro</em>: “We have been investigating a claim that has been made in relation to Vodafone data. Our current assessment is that data is old Vodafone employee information that would be available on a business card. The information available could be accessed from an address list. </p><p>"No Vodafone customer data or impact has been identified. We would like to assure our customers that we take security very seriously. Our security tools are constantly updated and we proactively track new threats and vulnerabilities. We have an international team of cyber security professionals who constantly protect, defend and monitor our systems.”</p><p>A spokesperson for Gap told <em>ITPro</em>: “Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised.” </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-breaches/hacker-claims-to-have-stolen-millions-of-azure-customer-records-from-mcdonalds-vodafone-kyndryl-and-others-heres-what-we-know-so-far</link>
                                                                            <description>
                            <![CDATA[ TheHatman claims the data has been stolen from the victims' Azure and Entra tenants using compromised credentials ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TVa6rANrRRcHEUqifJqS47</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RSjE8LWxBzgjnadXPUW8mB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 10:54:20 +0000</pubDate>                                                                                                                                <updated>Wed, 19 Aug 2026 13:34:00 +0000</updated>
                                                                                                                                            <category><![CDATA[Data Breaches]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RSjE8LWxBzgjnadXPUW8mB-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacker concept image showing a silhouetted person in a black hat with binary code in background. ]]></media:description>                                                            <media:text><![CDATA[Hacker concept image showing a silhouetted person in a black hat with binary code in background. ]]></media:text>
                                <media:title type="plain"><![CDATA[Hacker concept image showing a silhouetted person in a black hat with binary code in background. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RSjE8LWxBzgjnadXPUW8mB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A hacker is advertising data allegedly stolen from an array of companies including McDonald's, Vodafone, Kyndryl, and more. </p><p>Researchers at HudsonRock <a href="https://www.infostealers.com/article/massive-azure-exfiltration-campaign-exposes-millions-of-enterprise-records-via-compromised-credentials-mcdonalds-vodafone-kyndryl-others/" target="_blank">said</a> that the criminal, known as TheHatman, downloaded the databases directly from the organizations’ Azure or Entra portals, claiming to have done so through the use of compromised credentials.</p><p>Other victims include HCL Technologies, IHG Hotels & Resorts, Gap, Hexaware Technologies, and Wyndham Hotels & Resorts.</p><p>"The campaign impacts multiple global enterprises across IT services, hospitality, telecommunications, retail, and logistics," researchers said. </p><p>"Our researchers went over the data and it seems highly legitimate based on the corporate email addresses found, combined with field names perfectly matching standard Azure directory exports."</p><p>The data – which includes roughly 3.6 million records in total – appears to include full names, corporate email addresses, including active domains and tenant-specific .onmicrosoft.com structures, phone numbers, and physical addresses.</p><p>It also covers employee IDs, job titles, departments, notes, manager details, and direct reports, along with user group memberships, service accounts, and highly privileged account records such as Global Administrator listings.</p><p>"The exposure of service accounts and global admin names is particularly concerning, as this provides a direct roadmap for subsequent social engineering, spear-phishing, or targeted privilege escalation attacks against these organizations," HudsonRock said.</p><h2 id="thehatman-s-methods-still-unclear">TheHatman's methods still unclear</h2><p>Exact details on how the threat actor gained access to this trove of data remains unclear, according to researchers. </p><p>Possibilities include infostealer <a href="https://www.itpro.com/malware/28076/what-is-malware">malware </a>infections which compromised employee session tokens, <a href="https://www.itpro.com/security/29093/what-is-phishing">phishing </a>campaigns, or a lack of strict <a href="https://www.itpro.com/security/cyber-security/369745/what-is-mfa-fatigue">multi-factor authentication (MFA) </a>on specific tenant portals. </p><p>Researchers also suggested it could be down to abuse of a third-party API that had excessive read privileges across multiple environments. </p><p>According to HudsonRock, the most likely explanation is a targeted exploitation of infostealer infections rather than a systemic zero-day vulnerability in Azure, as this would have hit a far broader range of victims. </p><h2 id="alleged-victims-react">Alleged victims react</h2><p>Companies said to have been caught up in the breach have begun taking action. </p><p>TCS, for example, has <a href="https://www.bseindia.com/xml-data/corpfiling/AttachLive/ac9edbea-ea43-4c0a-beb8-5239bcd03ec9.pdf" target="_blank">filed a statement</a> with India’s stock exchange, revealing that it hasn’t yet found any credible evidence of a breach of systems or customer environments. </p><p>"The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted," the statement reads. </p><p><em>ITPro </em>approached the other aforementioned victims, but did not receive a response by time of publication. </p><h2 id="valuable-credentials">Valuable credentials</h2><p>Darren Williams, CEO and founder of BlackFog, said that if the claims are legitimate then this once again highlights the value of exposed credentials for cyber criminals. </p><p>These can often represent the keys to the castle for hackers, giving them sweeping access to enterprise environments. </p><p>“The reported use of leaked credentials to access Azure and Entra environments shows how valuable compromised identities have become to cyber criminals," he said.</p><p>"MFA, strong identity controls and employee awareness remain essential, but organizations must assume credentials can be compromised. These measures must be backed by technology that prevents sensitive data from being exfiltrated, even when attackers successfully gain access to the network.”</p><p><strong>UPDATE</strong></p><p>A spokesperson for Vodafone told <em>ITPro</em>: “We have been investigating a claim that has been made in relation to Vodafone data. Our current assessment is that data is old Vodafone employee information that would be available on a business card. The information available could be accessed from an address list. </p><p>"No Vodafone customer data or impact has been identified. We would like to assure our customers that we take security very seriously. Our security tools are constantly updated and we proactively track new threats and vulnerabilities. We have an international team of cyber security professionals who constantly protect, defend and monitor our systems.”</p><p>A spokesperson for Gap told <em>ITPro</em>: “Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised.” </p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Sovereignty is the channel’s next trust test ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The <a href="https://www.gov.uk/government/news/a-decisive-shift-to-power-british-ai-new-11-billion-plan-to-back-chip-firms-boost-computing-power-and-skills-for-the-ai-revolution"><u>UK government’s £1.1bn AI sovereignty plan</u></a> has put infrastructure control firmly on the boardroom agenda. With £750m earmarked for a national AI supercomputer and further funding for domestic chip capability, the message is clear: sovereignty has moved way past an abstract policy debate. It is now a practical test of how much control the UK has over the compute, data, networks, and suppliers that increasingly underpin its economy.</p><p>That question is affecting the channel, too, particularly as <a href="https://www.cityam.com/ms-profit-slumps-in-fallout-from-cyber-attack/"><u>major cyber incidents</u></a> have sharpened focus on the resilience of the networks underpinning operations. While buyers continue to care about performance and price, they are placing greater emphasis on the level of control their technology partners have over business-critical infrastructure.</p><h2 id="security-is-now-a-commercial-decision">Security is now a commercial decision</h2><p>The majority (88%) of IT decision makers (ITDMs) say that UK data sovereignty is vital when choosing technology partners, according to our <a href="https://btgroup.foleon.com/future-unlocked/your-key-to-a-future-unlocked/cyber-security"><u>research</u></a>. Some 70% identify cyber risk as one of their top organizational threats. Among resellers, 77% believe customers would switch providers for better protection.</p><p>Cyber resilience, therefore, needs to appear early in the sales conversation, framed around operational risk, customer confidence and the confidence that businesses will be able to keep trading when threats escalate. It also needs to be communicated over time, rather than treated as a one-off assurance during procurement, with 89% of ITDMs saying they want providers to deliver proactive updates on how their networks are being protected.</p><p>In short, as trust has become an even more integral part of the buying decision, partners need to move beyond headline credentials and make the delivery model behind the service much clearer. </p><h2 id="partners-must-deliver-across-data-operations-and-technical-control">Partners must deliver across data, operations and technical control</h2><p>Sales conversations can set the expectation, but the delivery model is what proves it. In practice, partners now need to deliver across three forms of control: data, operational, and technical. That starts with where the data sits, then extends to which suppliers and platforms are involved to support the service and how continuity is maintained if something goes wrong.</p><p>The first question is where information sits and whose legal framework applies to it. Put simply, customers need answers on where data is stored and handled and whether it falls under UK law. For many organizations, this matters because data is tied to regulatory obligations and internal governance, so vague assurances about cloud security do not give them enough to fully understand exposure. </p><p>Customers also need to understand who is involved in running the service. A contract may sit with a UK provider while parts of the support depend on third parties or overseas teams. The priority is knowing who delivers the service and which legal and operational frameworks govern the people and processes behind it. Partners need to be clear about these dependencies, so customers can judge how resilient the service really is beyond the primary contract.</p><p>The final question is what happens when circumstances change. Services have to be adaptable enough to withstand disruption or a shift in business strategy without leaving organizations locked into fragile arrangements. This becomes especially important in environments where downtime has an immediate operational impact. A manufacturer using connected production systems, for example, needs to be sure that the service chain behind that connectivity is recoverable and able to keep pace with changing requirements.</p><p>Working with vendors that can 100% confirm sovereignty of infrastructure – spanning connectivity, cloud, voice and AI – gives partners a strong foundation to address all these concerns with confidence.</p><h2 id="the-network-is-where-sovereignty-meets-delivery">The network is where sovereignty meets delivery</h2><p>Every dependency described above runs across the network.</p><p>It is the layer that connects policy concerns to business outcomes, turning questions about control into decisions about architecture, routing, access, monitoring and recovery. As AI, 5G and hybrid work reshape how organizations operate, customers will look for partners that can help them make sense of the underlying infrastructure. </p><p>For the channel, the prize is stronger commercial traction. Those that can explain how connectivity choices affect productivity, compliance, customer experience, and resilience will build stronger relationships and, ultimately, win more business. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/data-protection/sovereignty-is-the-channels-next-trust-test</link>
                                                                            <description>
                            <![CDATA[ Data sovereignty has become a key channel priority ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6MN27mLroiEwh9rdXAmVHm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 17:21:33 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Data Protection]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Gavin Jones ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/JeMgqbizkXh95JHUuJf5oZ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:description>                                                            <media:text><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:text>
                                <media:title type="plain"><![CDATA[IoT security concept image showing network symbols on a blue background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/2LvDwLLQ8jfBDzQBX5WER9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The <a href="https://www.gov.uk/government/news/a-decisive-shift-to-power-british-ai-new-11-billion-plan-to-back-chip-firms-boost-computing-power-and-skills-for-the-ai-revolution"><u>UK government’s £1.1bn AI sovereignty plan</u></a> has put infrastructure control firmly on the boardroom agenda. With £750m earmarked for a national AI supercomputer and further funding for domestic chip capability, the message is clear: sovereignty has moved way past an abstract policy debate. It is now a practical test of how much control the UK has over the compute, data, networks, and suppliers that increasingly underpin its economy.</p><p>That question is affecting the channel, too, particularly as <a href="https://www.cityam.com/ms-profit-slumps-in-fallout-from-cyber-attack/"><u>major cyber incidents</u></a> have sharpened focus on the resilience of the networks underpinning operations. While buyers continue to care about performance and price, they are placing greater emphasis on the level of control their technology partners have over business-critical infrastructure.</p><h2 id="security-is-now-a-commercial-decision">Security is now a commercial decision</h2><p>The majority (88%) of IT decision makers (ITDMs) say that UK data sovereignty is vital when choosing technology partners, according to our <a href="https://btgroup.foleon.com/future-unlocked/your-key-to-a-future-unlocked/cyber-security"><u>research</u></a>. Some 70% identify cyber risk as one of their top organizational threats. Among resellers, 77% believe customers would switch providers for better protection.</p><p>Cyber resilience, therefore, needs to appear early in the sales conversation, framed around operational risk, customer confidence and the confidence that businesses will be able to keep trading when threats escalate. It also needs to be communicated over time, rather than treated as a one-off assurance during procurement, with 89% of ITDMs saying they want providers to deliver proactive updates on how their networks are being protected.</p><p>In short, as trust has become an even more integral part of the buying decision, partners need to move beyond headline credentials and make the delivery model behind the service much clearer. </p><h2 id="partners-must-deliver-across-data-operations-and-technical-control">Partners must deliver across data, operations and technical control</h2><p>Sales conversations can set the expectation, but the delivery model is what proves it. In practice, partners now need to deliver across three forms of control: data, operational, and technical. That starts with where the data sits, then extends to which suppliers and platforms are involved to support the service and how continuity is maintained if something goes wrong.</p><p>The first question is where information sits and whose legal framework applies to it. Put simply, customers need answers on where data is stored and handled and whether it falls under UK law. For many organizations, this matters because data is tied to regulatory obligations and internal governance, so vague assurances about cloud security do not give them enough to fully understand exposure. </p><p>Customers also need to understand who is involved in running the service. A contract may sit with a UK provider while parts of the support depend on third parties or overseas teams. The priority is knowing who delivers the service and which legal and operational frameworks govern the people and processes behind it. Partners need to be clear about these dependencies, so customers can judge how resilient the service really is beyond the primary contract.</p><p>The final question is what happens when circumstances change. Services have to be adaptable enough to withstand disruption or a shift in business strategy without leaving organizations locked into fragile arrangements. This becomes especially important in environments where downtime has an immediate operational impact. A manufacturer using connected production systems, for example, needs to be sure that the service chain behind that connectivity is recoverable and able to keep pace with changing requirements.</p><p>Working with vendors that can 100% confirm sovereignty of infrastructure – spanning connectivity, cloud, voice and AI – gives partners a strong foundation to address all these concerns with confidence.</p><h2 id="the-network-is-where-sovereignty-meets-delivery">The network is where sovereignty meets delivery</h2><p>Every dependency described above runs across the network.</p><p>It is the layer that connects policy concerns to business outcomes, turning questions about control into decisions about architecture, routing, access, monitoring and recovery. As AI, 5G and hybrid work reshape how organizations operate, customers will look for partners that can help them make sense of the underlying infrastructure. </p><p>For the channel, the prize is stronger commercial traction. Those that can explain how connectivity choices affect productivity, compliance, customer experience, and resilience will build stronger relationships and, ultimately, win more business. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Expired domains are a goldmine for hackers – and some cyber crime groups are investing millions in 'dropcatch' scams to deliver malware ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Cyber criminals are spending millions buying up expired domains to repurpose them for <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, scams, illegal streaming, and online gambling, according to new research. </p><p>Taking advantage of the domains' trust, backlinks, and web traffic, they're not only being used by the original threat actors, but are also being sold on.</p><p>Domains originally registered years ago, dropped, and then acquired by someone else can still carry signals associated with their history. Researchers, security products, and reputation-based algorithms may view them more favorably than a genuinely brand-new registration.</p><p>This makes these re-registered 'dropcatch' domains a hot property for threat actors. <a href="https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/" target="_blank">Analysis </a>conducted by Infoblox Threat Intel observed around 65,000 being registered per day during the first half of this year, representing nearly one-in-five of all newly observed domains. </p><p>"The sheer volume of dropcatch domains is astounding. We’ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn’t well understood.” said Renée Burton, VP of Infoblox Threat Intel. </p><p>"Expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly-registered domain.”</p><h2 id="huge-investment">Huge investment</h2><p>One investigation uncovered a threat actor dubbed Sable Squirrel, estimated to have invested more than $7 million in acquiring over 10,000 expired domains now used for illegal streaming, online gambling, and malware distribution.</p><p>Most support a large Asian sports piracy operation whose sites look like consumer streaming products. These offer live football, match schedules, chat rooms, mirrors, and mobile promotion. </p><p>However, Infoblox said it's not the streaming that's the real business: it's the betting platforms that the group appears to control.  </p><p>"A subset of these same domains also operate as malware C2. We identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>signatures," said the researchers. </p><p>"In such cases, a human visitor sees a live football streaming site while an infected device uses the same domain as a control channel."</p><p>Meanwhile, other threat actors are taking over well-known malicious domains that are inserted into compromised websites. Researchers uncovered one actor delivering potential victims to SocGholish, the <a href="https://www.itpro.com/security/malware/this-operation-marked-a-shift-in-strategy-three-notorious-malware-networks-have-been-taken-down-using-rico-legislation">notorious 'fake update' infrastructure</a> which was the target of <a href="https://www.itpro.com/security/ransomware/its-been-a-bad-week-for-ransomware-operators">Operation Endgame</a> in June 2026. </p><p>Tracked as Shady Squirrel by Infoblox Threat Intel, the group delivered malware through scareware and call centers before partnering up with SocGholish’s operator TA569 in July.</p><p>"We see around 65,000 new dropcatch domains every day. Some of them are legitimate registrations picking up domains people are going to use for commercial or personal use. But an awful lot are grabbed for grey to black purposes," the researchers said. </p><p>"Any way you slice it, the risk posed by dropcatch domains is significant, arguably greater than that of newly registered domains."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-crime/expired-domains-are-a-goldmine-for-hackers-and-some-cyber-crime-groups-are-investing-millions-in-dropcatch-scams-to-deliver-malware</link>
                                                                            <description>
                            <![CDATA[ Tens of thousands of so-called 'dropcatch' domains are being registered every day ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fYa5evNWABEXTq23J5Vvo5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rvaWWDDqxKsTbUB3bzVu5Q-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 10:54:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rvaWWDDqxKsTbUB3bzVu5Q-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pile of multi-colored cubes with regional domain options such as .co.uk and .org.]]></media:description>                                                            <media:text><![CDATA[A pile of multi-colored cubes with regional domain options such as .co.uk and .org.]]></media:text>
                                <media:title type="plain"><![CDATA[A pile of multi-colored cubes with regional domain options such as .co.uk and .org.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rvaWWDDqxKsTbUB3bzVu5Q-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Cyber criminals are spending millions buying up expired domains to repurpose them for <a href="https://www.itpro.com/malware/28076/what-is-malware">malware</a>, scams, illegal streaming, and online gambling, according to new research. </p><p>Taking advantage of the domains' trust, backlinks, and web traffic, they're not only being used by the original threat actors, but are also being sold on.</p><p>Domains originally registered years ago, dropped, and then acquired by someone else can still carry signals associated with their history. Researchers, security products, and reputation-based algorithms may view them more favorably than a genuinely brand-new registration.</p><p>This makes these re-registered 'dropcatch' domains a hot property for threat actors. <a href="https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/" target="_blank">Analysis </a>conducted by Infoblox Threat Intel observed around 65,000 being registered per day during the first half of this year, representing nearly one-in-five of all newly observed domains. </p><p>"The sheer volume of dropcatch domains is astounding. We’ve known that bad guys buy expired domains to repurpose them, but the way in which they were used, and the amount of money actors are willing to spend wasn’t well understood.” said Renée Burton, VP of Infoblox Threat Intel. </p><p>"Expired domains can be a shortcut to both trust and traffic, making dropcatch domains a higher risk than the average newly-registered domain.”</p><h2 id="huge-investment">Huge investment</h2><p>One investigation uncovered a threat actor dubbed Sable Squirrel, estimated to have invested more than $7 million in acquiring over 10,000 expired domains now used for illegal streaming, online gambling, and malware distribution.</p><p>Most support a large Asian sports piracy operation whose sites look like consumer streaming products. These offer live football, match schedules, chat rooms, mirrors, and mobile promotion. </p><p>However, Infoblox said it's not the streaming that's the real business: it's the betting platforms that the group appears to control.  </p><p>"A subset of these same domains also operate as malware C2. We identified over 31,000 malware samples connecting to Sable Squirrel domains, including Quasar RAT, AsyncRAT, DCRat, NanoCore, Remcos, njRAT, and samples carrying HiddenTear <a href="https://www.itpro.com/security/28084/what-is-ransomware">ransomware </a>signatures," said the researchers. </p><p>"In such cases, a human visitor sees a live football streaming site while an infected device uses the same domain as a control channel."</p><p>Meanwhile, other threat actors are taking over well-known malicious domains that are inserted into compromised websites. Researchers uncovered one actor delivering potential victims to SocGholish, the <a href="https://www.itpro.com/security/malware/this-operation-marked-a-shift-in-strategy-three-notorious-malware-networks-have-been-taken-down-using-rico-legislation">notorious 'fake update' infrastructure</a> which was the target of <a href="https://www.itpro.com/security/ransomware/its-been-a-bad-week-for-ransomware-operators">Operation Endgame</a> in June 2026. </p><p>Tracked as Shady Squirrel by Infoblox Threat Intel, the group delivered malware through scareware and call centers before partnering up with SocGholish’s operator TA569 in July.</p><p>"We see around 65,000 new dropcatch domains every day. Some of them are legitimate registrations picking up domains people are going to use for commercial or personal use. But an awful lot are grabbed for grey to black purposes," the researchers said. </p><p>"Any way you slice it, the risk posed by dropcatch domains is significant, arguably greater than that of newly registered domains."</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Stopping supply chain attacks ]]></title>
                                                                                                <dc:content><![CDATA[ <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/c2d9c770-6596-467a-91b4-09b2da63f1c2/"></iframe><p>Supply chain attacks are increasingly common and increasingly disruptive, but organizations still struggle to defend against them properly.</p><p>In this episode of the ITPro Podcast, Jane and Ross are joined by Haydn Brooks, CEO of supply chain security firm Risk Ledger, to talk about what threats businesses are facing, what mitigation strategies could work well, and why cyber teams need to work together throughout the supply chain.</p><h2 id="highlights">Highlights</h2><p>"Most of the attacks that you find in in kind of the supply chain main are untargeted. So it's where you've had a threat actor launch a lot of attacks against a lot of different targets, they've breached a company without really knowing who that company is or was, and then they've basically passed that access on to somebody else, or they've gone on and leaked data or taken that company offline. And it's not really like a targeted attack against someone else, it's just that other companies who use that supply ... experience that as a supply chain attack, and very few of them are targeted. Where they are targeted, they are very hard to defend against because essentially, as the end target, I'm having to worry about an attack against somebody else, which I have no control over, being able to detect that and then being able to somehow respond to it as well."</p><p>"I think actually the regulation has kind of followed the the movement that we've seen within the industry rather than the other way around ... we're seeing a lot of these regulations also requiring companies to be either taking threat intelligence from others or sharing threat intelligence with others, as well as reporting incidents. So all of the regulation and the way security teams operate is moving in that direction of being more open, sharing more to benefit for the wider industry."</p><h2 id="related-content">Related content</h2><ul><li><a href="https://www.itpro.com/security/cyber-resilience-uk-learning-to-take-the-punches">Cyber resilience in the UK: learning to take the punches</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board">DORA and why resilience (once again) matters to the board</a></li><li><a href="https://www.itpro.com/security/securing-the-supply-chain-why-zero-trust-and-recovery-readiness-are-non-negotiable">Securing the supply chain: Why zero trust and recovery readiness are non-negotiable</a></li><li><a href="https://www.itpro.com/security/data-breaches/logistics-firm-supply-chain-breach-hits-valve-and-other-customers">Logistics firm supply chain breach hits Valve and other customers</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre">Former NCSC head says the Jaguar Land Rover attack was the 'single most financially damaging cyber event ever to hit the UK' as impact laid bare</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/the-litellm-supply-chain-attack-this-year-could-be-the-biggest-ever">The LiteLLM supply chain attack this year could be the biggest ever</a></li><li><a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight">Why supply chain resilience is under the spotlight</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-did-the-right-thing-shutting-down-systems-to-thwart-cyber-attack">Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack</a></li></ul> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/stopping-supply-chain-attacks</link>
                                                                            <description>
                            <![CDATA[ Why cyber teams need to work together to improve everyone's security ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ukzUwtBBi7EdYSg2R7pAFX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/w8NJiNPVH9eTRKENgPJoiT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 10:12:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                <author><![CDATA[ jane.mccallion@futurenet.com (Jane McCallion) ]]></author>                    <dc:creator><![CDATA[ Jane McCallion ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/Wq9nnLr7TNkY8gyBRb7YsA.jpeg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Jane is managing editor at ITPro and ChannelPro. She started out with the brands as a staff writer specializing in cloud computing before going on to become senior writer and reports editor, managing the content and creation of ITPro’s quarterly whitepapers. During this time, she broadened her expertise to include cybersecurity, data centers and enterprise IT infrastructure. In 2016, she became features editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, data centers, and business strategy.&lt;/p&gt;&lt;p&gt;In October 2021, she became the sites’ deputy editor, before moving to the role of managing editor in June 2024. Although she now has a more strategic role,  she is still a specialist in enterprise IT infrastructure, business strategy, and cybersecurity.&lt;/p&gt;&lt;p&gt;Jane holds an MA in journalism from Goldsmiths, University of London, and a BA in Applied Languages from the University of Portsmouth. She is fluent in French and Spanish, and has written features in both languages.&lt;/p&gt;&lt;p&gt;Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/w8NJiNPVH9eTRKENgPJoiT-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[&quot;Stopping supply chain attacks&quot; in yellow and white text overlaid on top of an image of purple and pink neon chain links with one link shattering.]]></media:description>                                                            <media:text><![CDATA[&quot;Stopping supply chain attacks&quot; in yellow and white text overlaid on top of an image of purple and pink neon chain links with one link shattering.]]></media:text>
                                <media:title type="plain"><![CDATA[&quot;Stopping supply chain attacks&quot; in yellow and white text overlaid on top of an image of purple and pink neon chain links with one link shattering.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/w8NJiNPVH9eTRKENgPJoiT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <iframe allow="clipboard-write" height="200px" width="100%" id="" style="width: 100%; height: 200px;" class="position-center" data-lazy-priority="high" data-lazy-src="https://player.captivate.fm/episode/c2d9c770-6596-467a-91b4-09b2da63f1c2/"></iframe><p>Supply chain attacks are increasingly common and increasingly disruptive, but organizations still struggle to defend against them properly.</p><p>In this episode of the ITPro Podcast, Jane and Ross are joined by Haydn Brooks, CEO of supply chain security firm Risk Ledger, to talk about what threats businesses are facing, what mitigation strategies could work well, and why cyber teams need to work together throughout the supply chain.</p><h2 id="highlights">Highlights</h2><p>"Most of the attacks that you find in in kind of the supply chain main are untargeted. So it's where you've had a threat actor launch a lot of attacks against a lot of different targets, they've breached a company without really knowing who that company is or was, and then they've basically passed that access on to somebody else, or they've gone on and leaked data or taken that company offline. And it's not really like a targeted attack against someone else, it's just that other companies who use that supply ... experience that as a supply chain attack, and very few of them are targeted. Where they are targeted, they are very hard to defend against because essentially, as the end target, I'm having to worry about an attack against somebody else, which I have no control over, being able to detect that and then being able to somehow respond to it as well."</p><p>"I think actually the regulation has kind of followed the the movement that we've seen within the industry rather than the other way around ... we're seeing a lot of these regulations also requiring companies to be either taking threat intelligence from others or sharing threat intelligence with others, as well as reporting incidents. So all of the regulation and the way security teams operate is moving in that direction of being more open, sharing more to benefit for the wider industry."</p><h2 id="related-content">Related content</h2><ul><li><a href="https://www.itpro.com/security/cyber-resilience-uk-learning-to-take-the-punches">Cyber resilience in the UK: learning to take the punches</a></li><li><a href="https://www.itpro.com/business/policy-and-legislation/dora-and-why-resilience-once-again-matters-to-the-board">DORA and why resilience (once again) matters to the board</a></li><li><a href="https://www.itpro.com/security/securing-the-supply-chain-why-zero-trust-and-recovery-readiness-are-non-negotiable">Securing the supply chain: Why zero trust and recovery readiness are non-negotiable</a></li><li><a href="https://www.itpro.com/security/data-breaches/logistics-firm-supply-chain-breach-hits-valve-and-other-customers">Logistics firm supply chain breach hits Valve and other customers</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-cyber-attack-financial-impact-cyber-monitoring-centre">Former NCSC head says the Jaguar Land Rover attack was the 'single most financially damaging cyber event ever to hit the UK' as impact laid bare</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/the-litellm-supply-chain-attack-this-year-could-be-the-biggest-ever">The LiteLLM supply chain attack this year could be the biggest ever</a></li><li><a href="https://www.itpro.com/security/why-is-supply-chain-resilience-under-the-spotlight">Why supply chain resilience is under the spotlight</a></li><li><a href="https://www.itpro.com/security/cyber-attacks/jaguar-land-rover-did-the-right-thing-shutting-down-systems-to-thwart-cyber-attack">Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack</a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The LiteLLM supply chain attack this year could be the biggest ever ]]></title>
                                                                                                <dc:content><![CDATA[ <p>More than 2,500 organizations were exposed in the <a href="https://www.itpro.com/security/litellm-pypi-compromise-everything-we-know-so-far">LiteLLM supply chain attack</a> earlier this year, according to CloudSEK, making it the biggest-ever supply chain attack.</p><p>The company <a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines" target="_blank"><u>said</u></a> a host of major organisations, including Nvidia, Samsung, Cisco, ServiceNow, Zscaler, and more were exposed. The company stressed that this isn’t proof they were actually compromised, however. </p><p>Information exposed in the campaign included AWS, Google Cloud, and Microsoft Azure credentials, SSH keys, Kubernetes tokens, .env files and CI/CD secrets – including the values <a href="https://www.itpro.com/security/github-action-supply-chain-incident">GitHub Actions</a> tries to mask, scraped directly from /proc//mem. </p><p>Meanwhile, in the case of AI builds, LLM API keys and gateway configuration – the credentials to an organization's entire AI stack – were exposed.</p><p>This could have allowed attackers to access corporate cloud environments, break into internal servers and systems, steal proprietary source code, and access or manipulate <a href="https://www.itpro.com/software/development/software-developers-not-checking-ai-generated-code-verification-debt">software development</a> infrastructure.</p><p>"For businesses, these credentials can be extremely sensitive because they are often what employees, applications and automated systems use to prove their identity. If attackers successfully obtained them, they may not need to hack the company again. They could simply log in using legitimate credentials," CloudSEK said.</p><p>"That creates a particularly serious risk because malicious activity performed through valid credentials can be much harder for security teams to detect."</p><h2 id="what-happened-in-the-litellm-supply-chain-attack">What happened in the LiteLLM supply chain attack?</h2><p>The <a href="https://www.itpro.com/security/litellm-pypi-compromise-everything-we-know-so-far"><u>incident</u></a> took place in March, when the Team PCP cybercriminal group breached LiteLLM, an open source tool widely used by organizations to connect applications with AI models.</p><p>Malicious versions of LiteLLM were reportedly available through the Python software repository PyPI for just 40 minutes – but still saw the potential exposure of 434,000 CI/CD pipelines used to build, test and deploy software. </p><p>The breach appeared to be linked to the earlier compromise of Trivy, in which the abuse of a trusted vulnerability scanner in CI/CD pipelines enabled credential theft that was apparently used to poison LiteLLM’s PyPI release chain.</p><p>Because <a href="https://www.itpro.com/business/digital-transformation/cicd-comes-into-focus-as-enterprises-ramp-up-application-modernization-efforts">CI/CD pipelines</a> can automatically download software packages without a developer manually reviewing every component, a malicious package can potentially spread across large numbers of corporate systems very quickly.</p><p>Researchers noted that even when the original malicious package has been removed, the security risk may not have ended with it.</p><p>"If attackers copied credentials while the compromised package was active, removing LiteLLM does not automatically invalidate those credentials," the researchers said.</p><p>"A cloud key, API token or server credential could remain valid until the organization itself changes or revokes it. This means organizations potentially exposed during the March incident could continue to face risk weeks or months later."</p><p>CloudSEK has since released a free <a href="https://exposure.cloudsek.com/ai-supply-chain-incident"><u>exposure-checking tool</u></a> to help organizations find out whether credentials or infrastructure associated with them appear in its dataset. </p><p>If they do, it said, firms should check out the relevant systems, review access logs and immediately rotate or revoke potentially exposed credentials.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/the-litellm-supply-chain-attack-this-year-could-be-the-biggest-ever</link>
                                                                            <description>
                            <![CDATA[ CloudSEK has identified dozens of major global organizations whose data was exposed ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SP5EPpVEVGmXudoYhcwu7m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DD7oSG7mL3LVWBrNQQCQu7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 10:16:11 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DD7oSG7mL3LVWBrNQQCQu7-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Digital chain concept art]]></media:description>                                                            <media:text><![CDATA[Digital chain concept art]]></media:text>
                                <media:title type="plain"><![CDATA[Digital chain concept art]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DD7oSG7mL3LVWBrNQQCQu7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>More than 2,500 organizations were exposed in the <a href="https://www.itpro.com/security/litellm-pypi-compromise-everything-we-know-so-far">LiteLLM supply chain attack</a> earlier this year, according to CloudSEK, making it the biggest-ever supply chain attack.</p><p>The company <a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines" target="_blank"><u>said</u></a> a host of major organisations, including Nvidia, Samsung, Cisco, ServiceNow, Zscaler, and more were exposed. The company stressed that this isn’t proof they were actually compromised, however. </p><p>Information exposed in the campaign included AWS, Google Cloud, and Microsoft Azure credentials, SSH keys, Kubernetes tokens, .env files and CI/CD secrets – including the values <a href="https://www.itpro.com/security/github-action-supply-chain-incident">GitHub Actions</a> tries to mask, scraped directly from /proc//mem. </p><p>Meanwhile, in the case of AI builds, LLM API keys and gateway configuration – the credentials to an organization's entire AI stack – were exposed.</p><p>This could have allowed attackers to access corporate cloud environments, break into internal servers and systems, steal proprietary source code, and access or manipulate <a href="https://www.itpro.com/software/development/software-developers-not-checking-ai-generated-code-verification-debt">software development</a> infrastructure.</p><p>"For businesses, these credentials can be extremely sensitive because they are often what employees, applications and automated systems use to prove their identity. If attackers successfully obtained them, they may not need to hack the company again. They could simply log in using legitimate credentials," CloudSEK said.</p><p>"That creates a particularly serious risk because malicious activity performed through valid credentials can be much harder for security teams to detect."</p><h2 id="what-happened-in-the-litellm-supply-chain-attack">What happened in the LiteLLM supply chain attack?</h2><p>The <a href="https://www.itpro.com/security/litellm-pypi-compromise-everything-we-know-so-far"><u>incident</u></a> took place in March, when the Team PCP cybercriminal group breached LiteLLM, an open source tool widely used by organizations to connect applications with AI models.</p><p>Malicious versions of LiteLLM were reportedly available through the Python software repository PyPI for just 40 minutes – but still saw the potential exposure of 434,000 CI/CD pipelines used to build, test and deploy software. </p><p>The breach appeared to be linked to the earlier compromise of Trivy, in which the abuse of a trusted vulnerability scanner in CI/CD pipelines enabled credential theft that was apparently used to poison LiteLLM’s PyPI release chain.</p><p>Because <a href="https://www.itpro.com/business/digital-transformation/cicd-comes-into-focus-as-enterprises-ramp-up-application-modernization-efforts">CI/CD pipelines</a> can automatically download software packages without a developer manually reviewing every component, a malicious package can potentially spread across large numbers of corporate systems very quickly.</p><p>Researchers noted that even when the original malicious package has been removed, the security risk may not have ended with it.</p><p>"If attackers copied credentials while the compromised package was active, removing LiteLLM does not automatically invalidate those credentials," the researchers said.</p><p>"A cloud key, API token or server credential could remain valid until the organization itself changes or revokes it. This means organizations potentially exposed during the March incident could continue to face risk weeks or months later."</p><p>CloudSEK has since released a free <a href="https://exposure.cloudsek.com/ai-supply-chain-incident"><u>exposure-checking tool</u></a> to help organizations find out whether credentials or infrastructure associated with them appear in its dataset. </p><p>If they do, it said, firms should check out the relevant systems, review access logs and immediately rotate or revoke potentially exposed credentials.</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 24 hours to recover from a cyber attack ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The way an organization recovers from a cyber attack can be the difference between minimal disruption and going out of business. But while effective recovery can take time, business leaders are increasingly focusing on speed. </p><p>Recent data shows CEOs are placing huge demands on security professionals to be able to get back up and running quickly. Two-thirds of CEOs expect to be notified of a cyberattack within half an hour, according to <a href="https://www.itpro.com/security/with-jobs-on-the-line-ceos-now-demand-cyber-attack-recovery-in-hours-not-days-or-weeks"><u>research</u></a> from Cohesity. While 19% of business leaders think they should be alerted to a breach within five minutes.Around 38% of CEOs expect basic operations to be back up and running within a day, with 14% saying this should happen in just one hour. </p><p>The UK government’s recent <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"><u>Cyber Security Breaches Survey</u></a> shows most firms can recover within 24 hours. Is this really possible, and if so, how can firms <a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>harden defences</u></a> so they are able to get back up and running swiftly?</p><h2 id="attack-timelines">Attack timelines</h2><p>After a <a href="https://www.itpro.com/security/cyber-attacks/threat-actors-exploiting-quickly-what-business-leaders-should-do"><u>cyberattack</u></a> hits, some businesses will descend into chaos. “Systems are down, normal tooling doesn’t work – and you may even be isolated from the internet,” says Ade Clewlow MBE, associate director and senior advisor at NCC Group.</p><p>Yet amid this complex and high-stakes environment, experts say the first few hours after discovering an incident are critical. “How companies react to a breach in the first few hours matters,” says Dennis Martin, cyber and crisis resilience specialist at Axians UK.</p><p>He explains how during a live <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware attack</u></a>, for example, the call on whether to disconnect the network and shut down systems needs to be made quickly. “In practice, this means teams monitoring the network need clear pre-authorisation to shut it down if they suspect an attack. It also means there should be a plan on how to restore once the system has been taken down, for both false-positive cases and confirmed attacks.”</p><p>Among the steps required, victims need to rapidly establish what has happened, assess whether the threat actor is still active, and work out which systems are affected. They then need to identify the steps needed to minimize the attack’s impact. “Immediate priorities typically include containing the attack and engaging key stakeholders,” according to Adam Harrison, managing director in the cybersecurity practice at FTI Consulting. </p><p>Speed is important, but acting on incomplete or inaccurate information “can be just as damaging as acting too slowly”, Harrison warns. He says overreacting to a false positive, disconnecting systems in a manner that makes recovery more difficult, or causing unnecessary business disruption “can serve as a self-inflicted wound”.</p><h2 id="understanding-the-scope">Understanding the scope</h2><p>Some steps can be taken straight after an attack, such as the initial containment. While this can often begin within the first hours, understanding the full scope of an incident may “take days or even weeks”, says Harrison.</p><p>Dan Wood, CISO at Cyberfort concurs. He believes recovering quickly and recovering well are “two very different things”. </p><p>“Everybody pats you on the back for getting operations restored in 24 hours after a cyber breach, but if you haven't recovered well, recovering quickly is pointless,” he says.</p><p>Wood says he’s seen organizations seemingly back up and running within hours, but at a cost. “Then they suffer the same attack days later because compromised backups placed the vulnerability and the attacker's back door straight back into live operation.”</p><p>The goal should be to have core services running in a clean environment, and to be able to prove this, Martin advises. “Otherwise, systems may be quickly compromised again, and, if a clean environment can’t be proven, partners won’t allow reactivation of vital interfaces.”</p><p>Yet at the same time, a slow response can be damaging. The impact of this will depend on the phase of the attack, according to Harrison. In the early stages, any delay gives an attacker more opportunity to achieve their objectives, he says. “They may access more systems, steal additional data, deploy ransomware, or establish persistence that makes later eradication significantly harder.”</p><p>Sluggish responses also increase business disruption. “Systems that could have been isolated early may instead require complete rebuilding,” says Harrison. “Recovery costs can also escalate and regulatory obligations will become more complex if additional data is compromised.”</p><p>In the latter stages of an incident, or after the adversary has already performed their <a href="https://www.ncsc.gov.uk/sites/default/files/documents/common_cyber_attacks_ncsc.pdf"><u>‘actions on objective’</u></a>, the focus shifts from preventing compromise and limiting further damage to restoring operations safely and understanding the full extent of the impact, according to Harrison. “At that point, delays can prolong downtime and increase recovery costs.”</p><h2 id="recovery-timelines">Recovery timelines</h2><p>The pressure is on, and the initial response should be rapid. But CEOS must also be realistic about the possibility of recovering too quickly. </p><p>“The number of variables involved in an attack will always dictate the speed of recovery,” Clewlow says. “For example, the threat from AI is moving at pace, so a successful AI-enabled technical attack has the potential to be more damaging in a shorter time.”</p><p>However, an organization that experiences minor disruption, such as a website being defaced, can usually recover relatively quickly, says Clewlow. </p><p>“Although technically a cyber incident, this is at the less severe end of the sliding scale. The larger and more complex the network is, the more severe the incident is likely to be, and the longer it will take to return to business as usual.”</p><p>Meeting the 24-hour benchmark demands “genuine organizational rigour”, according to Tracey Hannan-Jones, consulting director in information security, UBDS Digital. </p><p>“This means documented and rehearsed response plans, clearly assigned roles, pre-approved communication templates, and recovery infrastructure that is tested regularly and never assumed to work.”</p><p>Some of the basics include foundational cyber hygiene and ensuring your network is adequately segmented, according to Clewlow.</p><p>It’s also key to know what the minimum viable operations are for the business and to understand the assets on the network, says Clewlow. He believes rehearsed response plans are a key factor. </p><p>“CISOs should work with colleagues to ensure business continuity plans are shared and verified against information security realities, and that priorities for restoring systems and services after an incident are clearly understood,” he said.</p><p>“Recovery from a cyberattack is a team effort, in which the CISO will play an integral role.” </p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/24-hours-to-recover-from-a-cyber-attack</link>
                                                                            <description>
                            <![CDATA[ Two-thirds of CEOs want to be notified of a cyber attack within half an hour, with most expecting basic operations to be back up and running within a day. How can firms speed up their recovery? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7duEk2zWApDg82TDioAbkS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 07:00:00 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Aug 2026 11:12:57 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kate O&#039;Flaherty ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/LUULv6n7VJ3BHPnaoLHHdg.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:description>                                                            <media:text><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized image showing a glowing red cyber attack warning on top of a reflective metal surface bearing the flag of Iran.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VHuoRHN7D2BMLU3pbN3Xv4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The way an organization recovers from a cyber attack can be the difference between minimal disruption and going out of business. But while effective recovery can take time, business leaders are increasingly focusing on speed. </p><p>Recent data shows CEOs are placing huge demands on security professionals to be able to get back up and running quickly. Two-thirds of CEOs expect to be notified of a cyberattack within half an hour, according to <a href="https://www.itpro.com/security/with-jobs-on-the-line-ceos-now-demand-cyber-attack-recovery-in-hours-not-days-or-weeks"><u>research</u></a> from Cohesity. While 19% of business leaders think they should be alerted to a breach within five minutes.Around 38% of CEOs expect basic operations to be back up and running within a day, with 14% saying this should happen in just one hour. </p><p>The UK government’s recent <a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-20252026/cyber-security-breaches-survey-20252026"><u>Cyber Security Breaches Survey</u></a> shows most firms can recover within 24 hours. Is this really possible, and if so, how can firms <a href="https://www.itpro.com/security/data-breaches/businesses-need-to-boost-cyber-resilience-heres-how"><u>harden defences</u></a> so they are able to get back up and running swiftly?</p><h2 id="attack-timelines">Attack timelines</h2><p>After a <a href="https://www.itpro.com/security/cyber-attacks/threat-actors-exploiting-quickly-what-business-leaders-should-do"><u>cyberattack</u></a> hits, some businesses will descend into chaos. “Systems are down, normal tooling doesn’t work – and you may even be isolated from the internet,” says Ade Clewlow MBE, associate director and senior advisor at NCC Group.</p><p>Yet amid this complex and high-stakes environment, experts say the first few hours after discovering an incident are critical. “How companies react to a breach in the first few hours matters,” says Dennis Martin, cyber and crisis resilience specialist at Axians UK.</p><p>He explains how during a live <a href="https://www.itpro.com/security/ransomware/new-ransomware-groups-worrying-security-researchers"><u>ransomware attack</u></a>, for example, the call on whether to disconnect the network and shut down systems needs to be made quickly. “In practice, this means teams monitoring the network need clear pre-authorisation to shut it down if they suspect an attack. It also means there should be a plan on how to restore once the system has been taken down, for both false-positive cases and confirmed attacks.”</p><p>Among the steps required, victims need to rapidly establish what has happened, assess whether the threat actor is still active, and work out which systems are affected. They then need to identify the steps needed to minimize the attack’s impact. “Immediate priorities typically include containing the attack and engaging key stakeholders,” according to Adam Harrison, managing director in the cybersecurity practice at FTI Consulting. </p><p>Speed is important, but acting on incomplete or inaccurate information “can be just as damaging as acting too slowly”, Harrison warns. He says overreacting to a false positive, disconnecting systems in a manner that makes recovery more difficult, or causing unnecessary business disruption “can serve as a self-inflicted wound”.</p><h2 id="understanding-the-scope">Understanding the scope</h2><p>Some steps can be taken straight after an attack, such as the initial containment. While this can often begin within the first hours, understanding the full scope of an incident may “take days or even weeks”, says Harrison.</p><p>Dan Wood, CISO at Cyberfort concurs. He believes recovering quickly and recovering well are “two very different things”. </p><p>“Everybody pats you on the back for getting operations restored in 24 hours after a cyber breach, but if you haven't recovered well, recovering quickly is pointless,” he says.</p><p>Wood says he’s seen organizations seemingly back up and running within hours, but at a cost. “Then they suffer the same attack days later because compromised backups placed the vulnerability and the attacker's back door straight back into live operation.”</p><p>The goal should be to have core services running in a clean environment, and to be able to prove this, Martin advises. “Otherwise, systems may be quickly compromised again, and, if a clean environment can’t be proven, partners won’t allow reactivation of vital interfaces.”</p><p>Yet at the same time, a slow response can be damaging. The impact of this will depend on the phase of the attack, according to Harrison. In the early stages, any delay gives an attacker more opportunity to achieve their objectives, he says. “They may access more systems, steal additional data, deploy ransomware, or establish persistence that makes later eradication significantly harder.”</p><p>Sluggish responses also increase business disruption. “Systems that could have been isolated early may instead require complete rebuilding,” says Harrison. “Recovery costs can also escalate and regulatory obligations will become more complex if additional data is compromised.”</p><p>In the latter stages of an incident, or after the adversary has already performed their <a href="https://www.ncsc.gov.uk/sites/default/files/documents/common_cyber_attacks_ncsc.pdf"><u>‘actions on objective’</u></a>, the focus shifts from preventing compromise and limiting further damage to restoring operations safely and understanding the full extent of the impact, according to Harrison. “At that point, delays can prolong downtime and increase recovery costs.”</p><h2 id="recovery-timelines">Recovery timelines</h2><p>The pressure is on, and the initial response should be rapid. But CEOS must also be realistic about the possibility of recovering too quickly. </p><p>“The number of variables involved in an attack will always dictate the speed of recovery,” Clewlow says. “For example, the threat from AI is moving at pace, so a successful AI-enabled technical attack has the potential to be more damaging in a shorter time.”</p><p>However, an organization that experiences minor disruption, such as a website being defaced, can usually recover relatively quickly, says Clewlow. </p><p>“Although technically a cyber incident, this is at the less severe end of the sliding scale. The larger and more complex the network is, the more severe the incident is likely to be, and the longer it will take to return to business as usual.”</p><p>Meeting the 24-hour benchmark demands “genuine organizational rigour”, according to Tracey Hannan-Jones, consulting director in information security, UBDS Digital. </p><p>“This means documented and rehearsed response plans, clearly assigned roles, pre-approved communication templates, and recovery infrastructure that is tested regularly and never assumed to work.”</p><p>Some of the basics include foundational cyber hygiene and ensuring your network is adequately segmented, according to Clewlow.</p><p>It’s also key to know what the minimum viable operations are for the business and to understand the assets on the network, says Clewlow. He believes rehearsed response plans are a key factor. </p><p>“CISOs should work with colleagues to ensure business continuity plans are shared and verified against information security realities, and that priorities for restoring systems and services after an incident are clearly understood,” he said.</p><p>“Recovery from a cyberattack is a team effort, in which the CISO will play an integral role.” </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Can AI fight AI? Where the security gap still exists in cybersecurity, and how MSPs can help. ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As the old saying goes, sometimes “you have to fight fire with fire”. That’s certainly true in 2026, with cyber threats increasingly coming from ever more sophisticated use of AI tools. </p><p>There’s a problem with that, though: most businesses are not yet fully set up to deal with AI-based attacks and don’t trust the tools to do the job. A <a href="https://www.proofpoint.com/uk/resources/threat-reports/ai-human-risk-landscape-report"><u>2026 Proofpoint AI and Human Risk Landscape Report</u></a> revealed that half of organizations using AI-based security controls still experienced suspicious or confirmed AI-related incidents. </p><p>There is a fundamental security gap in many organizations: AI adoption has outpaced the right security measures. In the report, nearly 9 in 10 (87%) organizations had moved AI assistants beyond the pilot stage, and 76% were actively piloting or rolling out autonomous agents. But that activity has outpaced security maturity: 63% had AI security controls in place, but 52% weren’t completely confident those controls would detect a compromised AI. </p><p>AI tools are embedded directly into communications to increase productivity and speed, but in the rush to be efficient and compete, AI permissions and access to sensitive data are being left unchecked. </p><p>These aren’t complex security engineering problems: they are organizational and process gaps that can be addressed without waiting for the tooling market to mature. Currently, only a few organizations have developed their incident response playbooks, logging coverage, or forensic tools needed to investigate a compromised AI agent. </p><p></p><p>For many businesses lacking the in-house skills needed to take on these items, which can be significant, contracting a trusted managed service provider (MSP) can help bridge the gap. Many MSPs have been assisting businesses with AI adoption for some time now, and many have the deep understanding and technical skills needed to help businesses of all sizes see tangible benefits to AI while keeping critical data safe.</p><h2 id="the-origins-of-ai-attacks">The origins of AI attacks </h2><p>Most attacks start with unrestrained access and end with autonomous systems exposing sensitive data from these environments. When threat actors target agentic systems that lack proper controls, they don’t need to trick employees to access internal intelligence; they only need to manipulate the AI. </p><p>Prompt injection attacks are a common way to do this. A bad actor might send a target user seemingly helpful AI instructions while posing as a trusted authority or co-worker. A well-intentioned employee may then ask an AI to answer what seems like a simple inquiry. </p><p>Depending on the attacker’s instructions, the AI agent may instead be tricked into reading manipulated webpages (i.e., white text on a white background) to unwittingly extract internal data and send it to the attacker’s server.</p><p>For prompt injection attacks, it’s important to limit AI agents’ access to only the tools and data they need to complete the designed task. This is a good solution to prevent AI from giving out more information than required. This can limit the scope of an external threat actor’s reach.</p><p>That said, the employee’s role isn’t lost in all AI-based attacks. An ongoing cybersecurity skills gap severely impacts defenses, and threat actors know this. </p><p>Over the last decade, multi-factor authentication (MFA) has been an important step toward stronger security authentication. But today, attackers can pair AI-generated phishing with ‘MFA bypass kits,’ such as open-source Evilginx (known as a penetration testing utility for these styles of attacks) and the W3LL panel (a private phishing kit) to deceive employees into handing over that ‘extra step’ of security. </p><p>Tools like Evilginx and the W3LL phishing kit are used to create realistic sign-in pages that mimic those of Google, Microsoft, and others. Without proper security training, employees may unwittingly be signing into these while attackers capture their session tokens – even those with MFA. </p><p>A good defense against MFA bypass kits is adopting phishing-resistant MFA technologies such as FIDO2 hardware keys, Windows Hello for Business, Certificate-based Authentication (CBA), and Passkeys. These methods are tied to legitimate sign-in pages and don’t work on fake pages. </p><p>However, stopping the threat from ever materializing starts with having proper cybersecurity awareness training. Nearly half of all organizations lack this training or simply adopt a checkbox approach, which is why implementing these programs is an important step to closing the gap. </p><p>These programs teach users to spot a myriad of cyber threats, including AI-based threats. Tools of this type are also a good example of using AI in defensive security, as some can leverage AI to customize the training an end user receives based on their performance in past training. </p><p>This is another area where MSPs are highly qualified to assist. MSPs typically run training programs across a vast number of users and industry types. They understand what training works and what doesn’t, and can help position the best security awareness training for a given organization.</p><h2 id="how-does-ai-enhance-threat-detection">How does AI enhance threat detection?</h2><p>To understand the power and importance of AI-powered cybersecurity, it helps to understand how it works. Once trained, a detection model becomes exceptionally good at spotting the characteristics of malicious activity. It can take into account thousands of different characteristics to spot anomalies, outliers, and similarities that humans are unable to correlate. </p><p>It’s important to have a reliable cybersecurity service provider with REAL AI skills, because machine learning systems aren’t perfect and (while rare) can produce false positives. A strong partner can minimize these false positives while offering real-time threat detection and analysis, as well as faster, well-informed response times. </p><p>A trusted MSP will have a wide range of capabilities and will have a deep understanding of the protection methods that work well within their target industries. By leveraging that deep knowledge from their partner MSPs, businesses will benefit from great protection, even with today’s AI-powered attacks.</p><h2 id="preparedness-in-2026-and-beyond">Preparedness in 2026 and beyond</h2><p>To operate in this new era, businesses must treat every AI agent as a high-risk workload identity. </p><p>In practice, this requires working with reputable MSPs to implement strict least-privilege access to avoid data leaks, constant monitoring to protect the integrity of the data, and comprehensive employee awareness training.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/technology/artificial-intelligence/can-ai-fight-ai-where-the-security-gap-still-exists-in-cybersecurity-and-how-msps-can-help</link>
                                                                            <description>
                            <![CDATA[ Why AI security is failing and how MSPs can close the gap ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">J7MpsYnhGWSkq4qUqQf66T</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/A2eUMwBBjVbDZpzbyz9BrQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 17:16:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Artificial Intelligence]]></category>
                                                    <category><![CDATA[Technology]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andy Syrewicze ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aGeMeVu7b6TCqvPzk8mRKJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/A2eUMwBBjVbDZpzbyz9BrQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI security concept image showing a digitized padlock symbol with &#039;AI&#039; symbol, connected to data points with multi-colored data flows emanating from each point.]]></media:description>                                                            <media:text><![CDATA[AI security concept image showing a digitized padlock symbol with &#039;AI&#039; symbol, connected to data points with multi-colored data flows emanating from each point.]]></media:text>
                                <media:title type="plain"><![CDATA[AI security concept image showing a digitized padlock symbol with &#039;AI&#039; symbol, connected to data points with multi-colored data flows emanating from each point.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/A2eUMwBBjVbDZpzbyz9BrQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As the old saying goes, sometimes “you have to fight fire with fire”. That’s certainly true in 2026, with cyber threats increasingly coming from ever more sophisticated use of AI tools. </p><p>There’s a problem with that, though: most businesses are not yet fully set up to deal with AI-based attacks and don’t trust the tools to do the job. A <a href="https://www.proofpoint.com/uk/resources/threat-reports/ai-human-risk-landscape-report"><u>2026 Proofpoint AI and Human Risk Landscape Report</u></a> revealed that half of organizations using AI-based security controls still experienced suspicious or confirmed AI-related incidents. </p><p>There is a fundamental security gap in many organizations: AI adoption has outpaced the right security measures. In the report, nearly 9 in 10 (87%) organizations had moved AI assistants beyond the pilot stage, and 76% were actively piloting or rolling out autonomous agents. But that activity has outpaced security maturity: 63% had AI security controls in place, but 52% weren’t completely confident those controls would detect a compromised AI. </p><p>AI tools are embedded directly into communications to increase productivity and speed, but in the rush to be efficient and compete, AI permissions and access to sensitive data are being left unchecked. </p><p>These aren’t complex security engineering problems: they are organizational and process gaps that can be addressed without waiting for the tooling market to mature. Currently, only a few organizations have developed their incident response playbooks, logging coverage, or forensic tools needed to investigate a compromised AI agent. </p><p></p><p>For many businesses lacking the in-house skills needed to take on these items, which can be significant, contracting a trusted managed service provider (MSP) can help bridge the gap. Many MSPs have been assisting businesses with AI adoption for some time now, and many have the deep understanding and technical skills needed to help businesses of all sizes see tangible benefits to AI while keeping critical data safe.</p><h2 id="the-origins-of-ai-attacks">The origins of AI attacks </h2><p>Most attacks start with unrestrained access and end with autonomous systems exposing sensitive data from these environments. When threat actors target agentic systems that lack proper controls, they don’t need to trick employees to access internal intelligence; they only need to manipulate the AI. </p><p>Prompt injection attacks are a common way to do this. A bad actor might send a target user seemingly helpful AI instructions while posing as a trusted authority or co-worker. A well-intentioned employee may then ask an AI to answer what seems like a simple inquiry. </p><p>Depending on the attacker’s instructions, the AI agent may instead be tricked into reading manipulated webpages (i.e., white text on a white background) to unwittingly extract internal data and send it to the attacker’s server.</p><p>For prompt injection attacks, it’s important to limit AI agents’ access to only the tools and data they need to complete the designed task. This is a good solution to prevent AI from giving out more information than required. This can limit the scope of an external threat actor’s reach.</p><p>That said, the employee’s role isn’t lost in all AI-based attacks. An ongoing cybersecurity skills gap severely impacts defenses, and threat actors know this. </p><p>Over the last decade, multi-factor authentication (MFA) has been an important step toward stronger security authentication. But today, attackers can pair AI-generated phishing with ‘MFA bypass kits,’ such as open-source Evilginx (known as a penetration testing utility for these styles of attacks) and the W3LL panel (a private phishing kit) to deceive employees into handing over that ‘extra step’ of security. </p><p>Tools like Evilginx and the W3LL phishing kit are used to create realistic sign-in pages that mimic those of Google, Microsoft, and others. Without proper security training, employees may unwittingly be signing into these while attackers capture their session tokens – even those with MFA. </p><p>A good defense against MFA bypass kits is adopting phishing-resistant MFA technologies such as FIDO2 hardware keys, Windows Hello for Business, Certificate-based Authentication (CBA), and Passkeys. These methods are tied to legitimate sign-in pages and don’t work on fake pages. </p><p>However, stopping the threat from ever materializing starts with having proper cybersecurity awareness training. Nearly half of all organizations lack this training or simply adopt a checkbox approach, which is why implementing these programs is an important step to closing the gap. </p><p>These programs teach users to spot a myriad of cyber threats, including AI-based threats. Tools of this type are also a good example of using AI in defensive security, as some can leverage AI to customize the training an end user receives based on their performance in past training. </p><p>This is another area where MSPs are highly qualified to assist. MSPs typically run training programs across a vast number of users and industry types. They understand what training works and what doesn’t, and can help position the best security awareness training for a given organization.</p><h2 id="how-does-ai-enhance-threat-detection">How does AI enhance threat detection?</h2><p>To understand the power and importance of AI-powered cybersecurity, it helps to understand how it works. Once trained, a detection model becomes exceptionally good at spotting the characteristics of malicious activity. It can take into account thousands of different characteristics to spot anomalies, outliers, and similarities that humans are unable to correlate. </p><p>It’s important to have a reliable cybersecurity service provider with REAL AI skills, because machine learning systems aren’t perfect and (while rare) can produce false positives. A strong partner can minimize these false positives while offering real-time threat detection and analysis, as well as faster, well-informed response times. </p><p>A trusted MSP will have a wide range of capabilities and will have a deep understanding of the protection methods that work well within their target industries. By leveraging that deep knowledge from their partner MSPs, businesses will benefit from great protection, even with today’s AI-powered attacks.</p><h2 id="preparedness-in-2026-and-beyond">Preparedness in 2026 and beyond</h2><p>To operate in this new era, businesses must treat every AI agent as a high-risk workload identity. </p><p>In practice, this requires working with reputable MSPs to implement strict least-privilege access to avoid data leaks, constant monitoring to protect the integrity of the data, and comprehensive employee awareness training.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Delta Airlines flight Wi-Fi tampered with after DEF CON conference ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The day after DEF CON 34 wound up in Las Vegas this week, a passenger on a Delta flight out of the city apparently jammed the in-flight Wi-Fi.</p><p>According to reports, on the on the Vegas-to-Atlanta flight on Monday, the scammer broadcast a rogue network named 'Delta WiFi Fast', designed to look like the airline’s service, in an apparent phishing attempt.</p><p>The incident was spotted by the crew, with one Instagram user <a href="https://www.instagram.com/reel/Db3gtVquS50/"><u>posting</u></a> Aircraft Communications Addressing and Reporting System (ACARS) messages from the plane's crew to ground staff. </p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX,” one message reads, with another highlighting the presence of “A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS”. </p><p>According to one person who <a href="https://x.com/vxunderground/status/2087203218862350580" target="_blank">claims to have been present</a> when the plane landed, the fake hotspot served up a phishing landing page designed to harvest passengers' personal credentials and Google login data.</p><p>"Upon docking at Gate A18, federal authorities and airport police immediately boarded the aircraft to hold the cabin, question the suspects, and seize the broadcasting hardware,” they said. </p><p>The attacker is believed to have used a portable wireless device that can broadcast fake networks and carry out deauthorization attacks – the Pineapple Wi-Fi module has been mentioned, but not confirmed. </p><p>This can be used to send fake management frames that tell devices to drop off a legitimate wireless network – making them then susceptible to joining the fake one.  </p><p>"That creates an opening for credential theft or phishing. None of that means the aircraft itself was in danger. The risk is much more personal and quieter. Travelers may expose passwords or sensitive account information without realizing anything is wrong," said Ross Filipek, CISO at Corsica Technologies.</p><p>"Incidents like this are a reminder that convenience can create trust very quickly. Public Wi-Fi depends on users recognizing the right network. Attackers can take advantage when that trust gets misplaced.”</p><p>While the true motive of the attacker remains unclear, Wi-Fi blocking can be a federal crime which carries a potential jail sentence.</p><p>A spokesperson for Delta Airlines told <em>ITPro </em>it is working closely with law enforcement to ensure the incident is "thoroughly investigated". </p><p>“Safety of flight was never in question and no aircraft operating systems were affected. We are fully investigating to gather a complete set of facts, which will take time," the spokesperson said. </p><p>"We thank our crew for their professionalism and our customers for their understanding.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3> ]]></dc:content>
                                                                                                                                            <link>https://www.itpro.com/security/cyber-attacks/delta-airlines-flight-wi-fi-tampered-with-after-def-con-conference</link>
                                                                            <description>
                            <![CDATA[ A rogue network named 'Delta WiFi Fast' was created in an apparent in-flight phishing attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LtB7yCM6PedX9MJDvTYkYZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QSGcR2b7rexszHpZpr9d9d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 11:49:52 +0000</pubDate>                                                                                                                                <updated>Wed, 12 Aug 2026 12:45:59 +0000</updated>
                                                                                                                                            <category><![CDATA[Cyber Attacks]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Emma Woollacott ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/aWfskavxoVSMDy6cDWtYmJ.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QSGcR2b7rexszHpZpr9d9d-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Delta Airlines plane during take off at Schiphol Amsterdam Airport on March 26, 2026 in Schiphol, Netherlands.]]></media:description>                                                            <media:text><![CDATA[Delta Airlines plane during take off at Schiphol Amsterdam Airport on March 26, 2026 in Schiphol, Netherlands.]]></media:text>
                                <media:title type="plain"><![CDATA[Delta Airlines plane during take off at Schiphol Amsterdam Airport on March 26, 2026 in Schiphol, Netherlands.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QSGcR2b7rexszHpZpr9d9d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The day after DEF CON 34 wound up in Las Vegas this week, a passenger on a Delta flight out of the city apparently jammed the in-flight Wi-Fi.</p><p>According to reports, on the on the Vegas-to-Atlanta flight on Monday, the scammer broadcast a rogue network named 'Delta WiFi Fast', designed to look like the airline’s service, in an apparent phishing attempt.</p><p>The incident was spotted by the crew, with one Instagram user <a href="https://www.instagram.com/reel/Db3gtVquS50/"><u>posting</u></a> Aircraft Communications Addressing and Reporting System (ACARS) messages from the plane's crew to ground staff. </p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX,” one message reads, with another highlighting the presence of “A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS”. </p><p>According to one person who <a href="https://x.com/vxunderground/status/2087203218862350580" target="_blank">claims to have been present</a> when the plane landed, the fake hotspot served up a phishing landing page designed to harvest passengers' personal credentials and Google login data.</p><p>"Upon docking at Gate A18, federal authorities and airport police immediately boarded the aircraft to hold the cabin, question the suspects, and seize the broadcasting hardware,” they said. </p><p>The attacker is believed to have used a portable wireless device that can broadcast fake networks and carry out deauthorization attacks – the Pineapple Wi-Fi module has been mentioned, but not confirmed. </p><p>This can be used to send fake management frames that tell devices to drop off a legitimate wireless network – making them then susceptible to joining the fake one.  </p><p>"That creates an opening for credential theft or phishing. None of that means the aircraft itself was in danger. The risk is much more personal and quieter. Travelers may expose passwords or sensitive account information without realizing anything is wrong," said Ross Filipek, CISO at Corsica Technologies.</p><p>"Incidents like this are a reminder that convenience can create trust very quickly. Public Wi-Fi depends on users recognizing the right network. Attackers can take advantage when that trust gets misplaced.”</p><p>While the true motive of the attacker remains unclear, Wi-Fi blocking can be a federal crime which carries a potential jail sentence.</p><p>A spokesperson for Delta Airlines told <em>ITPro </em>it is working closely with law enforcement to ensure the incident is "thoroughly investigated". </p><p>“Safety of flight was never in question and no aircraft operating systems were affected. We are fully investigating to gather a complete set of facts, which will take time," the spokesperson said. </p><p>"We thank our crew for their professionalism and our customers for their understanding.”</p><h3 class="article-body__section" id="section-follow-us-on-social-media"><span>FOLLOW US ON SOCIAL MEDIA</span></h3>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>